Updated requirements for Controlled Unclassified Information (CUI)

On May 14th, 2024, the National Institute of Standards and Technology (NIST) released an updated version of NIST Special Publication (SP) 800-171, Revision 3. This publication addresses safeguarding Controlled Unclassified Information (CUI) within nonfederal systems and organizations. The revision introduces several significant changes. For example, the revision consolidates certain security requirements resulting in an overall lower number of security requirements – but in effect actually creates more security requirements than in Revision 2. Second, it adds organization-defined parameters (OPDs) which allow for tailoring and flexibility of controls. But, in an effort to make things simpler, NIST added in a lot of ambiguity with these OPDs. Thankfully, NIST also released NIST SP 800-171a, Rev. 3, Assessing Security Requirements for Controlled Unclassified Information, which will help contractors assess their security posture for CUI. It is highly recommended to review the new requirements of NIST SP 800-171, Rev. 3, while also consulting the 800-171a.

Contractors seeking more information about these changes can refer to the frequently asked questions (FAQ) section and the Change Analysis available on the NIST website.

It’s worth noting that if a contract includes DFARS Clause 252.204-7012—and every contract that involves the DoD and CUI should—contractors are required to adhere to NIST SP 800-171. According to this clause, compliance is expected with the version of NIST SP 800-171 that was in effect at the time of solicitation issuance. This could mean that new contracts are required to follow Revision 3. But, in anticipation of Revision 3, the DoD issued a class deviation—that is a change to the language in the DFARS. This deviation specifies that contractors should continue to comply with the previous version, NIST SP 800-171 Revision 2, until further notice. Further details are available in the associated Press Release.

Consequently, contractors are not immediately required to adopt the changes outlined in Revision 3. However, it’s important to recognize that Revision 3 will eventually become the standard. Therefore, contractors are advised to utilize this transition period to prepare for the eventual implementation of Revision 3. Please contact Jason Moy if you have questions or need legal assistance with these matters.

Related Resources

Published on:

Josh Schnell elected to the Board of Governors of the U.S. Court of Federal Claims Bar Association

Partner Josh Schnell was recently elected to the Board of Governors of the U.S. Court of Federal Claims (COFC) Bar Association. Since its founding in 1987, the COFC Bar Association has supported the Court and promoted justice in disputes between the United States government and its citizens.
Published on:

AP – “Some Native Americans draw shocked response over contract to design immigration detention centers”

Josh Schnell was interviewed by the Associated Press regarding allegations of waste, fraud, and abuse in 8(a) set-aside contracts. In the article, which focuses on Department of Homeland Security sole-source 8(a) contracts, Josh stressed the importance of competition and transparency in federal contracting. Click the link to read the article in Politico. 
Published on:

Client Advisory: Legal Considerations for Africa’s Next Era of Growth

Seizing opportunities across the African continent and in other international contexts, particularly low- and middle-income countries (LMICs), can feel daunting. This client advisory outlines key legal considerations for structuring cross-border agreements, selecting appropriate entity types, engaging jurisdiction-specific counsel, and building compliance frameworks that support effective, scalable multi-country operations.