NIST SP 800-171 SBOM Requirements: Protecting CUI in Software Supply Chains

How NIST SP 800-171 Rev 3 supply chain and component inventory controls relate to SBOM requirements for organizations handling Controlled Unclassified Information. Includes the CMMC phased rollout timeline through 2028.

TL;DR

NIST SP 800-171 protects Controlled Unclassified Information (CUI) in nonfederal systems and is required for DoD contractors via CMMC. Its supply chain risk management requirements align with SBOM practices for documenting and verifying software components.

← Back to Compliance Overview

Who it affects: Nonfederal organizations (primarily Department of Defense contractors) that process, store, or transmit Controlled Unclassified Information (CUI). Also relevant to organizations pursuing Cybersecurity Maturity Model Certification (CMMC) Level 2 or higher.

Need help with compliance? We can help you navigate your SBOM compliance journey.

Get in Touch

Overview

NIST Special Publication 800-171 Revision 3 (“Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations”), published in May 2024, defines the security requirements that nonfederal organizations must implement to protect Controlled Unclassified Information (CUI). CUI is information that the government creates or possesses that requires safeguarding, such as technical data, export-controlled information, and law enforcement sensitive data.

NIST SP 800-171 is most commonly encountered through Department of Defense (DoD) contracts. The DFARS clause 252.204-7012 requires DoD contractors to implement NIST 800-171, and the Cybersecurity Maturity Model Certification (CMMC) program uses 800-171 as the basis for its Level 2 assessment.

Which revision applies? Rev 3 is NIST’s current publication, but DoD contracts do not yet require it. Class Deviation 2024-O0013 pins DFARS 252.204-7012 compliance to Rev 2, and CMMC assessments under 32 CFR Part 170 are conducted against Rev 2’s 110 requirements. The deviation remains in effect until rescinded, and moving CMMC to Rev 3 requires formal rulemaking. Contractors should comply with Rev 2 today while tracking Rev 3, since its supply chain controls signal where DoD requirements are heading.

While NIST 800-171 does not explicitly use the term “SBOM,” Revision 3 introduced three new control families – including Supply Chain Risk Management – that create strong requirements for the kind of software component transparency that SBOMs provide.

Relationship to NIST SP 800-53

NIST SP 800-171 Rev 3 derives its controls from NIST SP 800-53 Rev 5, making 800-53 the “single authoritative source” for the underlying security requirements. Specifically, 800-171 Rev 3 controls are drawn from the 800-53 moderate control baseline defined in NIST SP 800-53B, tailored for nonfederal environments.

StandardScopeAudienceControls
NIST SP 800-53 Rev 5Full security control catalog for federal systemsFederal agencies1,000+ controls across 20 families
NIST SP 800-171 Rev 3Protecting CUI in nonfederal systemsDoD contractors, nonfederal organizations97 requirements across 17 families
NIST SP 800-172Enhanced requirements for high-value CUICMMC Level 3 organizations35 enhanced requirements

Understanding this hierarchy matters because some 800-53 controls highly relevant to SBOMs (such as SR-4, Provenance) are not directly included in 800-171 but may be required through DoD supplemental guidance or CMMC Level 3 assessments.

Note: NIST published SP 800-172 Rev 3 in May 2026, together with the SP 800-172A Rev 3 assessment procedures. CMMC Level 3 remains anchored to the requirements DoD selected from the 2021 version of 800-172 until the program adopts the revision through rulemaking.

Key Control Families Relevant to SBOMs

NIST 800-171 Rev 3 organizes its 97 requirements into 17 control families. Revision 3 added three new families that are particularly relevant to software supply chain security.

03.17 – Supply Chain Risk Management (New in Rev 3)

This family was added in Rev 3 to address the growing threat to software supply chains. It maps to the SR family in NIST SP 800-53.

03.17.01 – Supply Chain Risk Management Plan (maps to 800-53 SR-2)

Requires organizations to develop, review, and update a plan for managing supply chain risks across the system development life cycle, from acquisition through disposal. SBOMs are a practical implementation tool for the component visibility this plan requires.

03.17.02 – Acquisition Strategies, Tools, and Methods (maps to 800-53 SR-5)

Requires organizations to develop acquisition strategies that identify and mitigate supply chain risks. For software acquisitions, this increasingly means requiring SBOM delivery from vendors.

03.17.03 – Supply Chain Requirements and Processes (maps to 800-53 SR-3)

Requires establishing processes for identifying and addressing weaknesses in supply chain elements. The NIST discussion for this control explicitly mentions maintaining provenance – knowing where each component came from and ensuring it has not been tampered with. SBOMs provide exactly this component-level provenance documentation.

03.04 – Configuration Management

03.04.10 – System Component Inventory (maps to 800-53 CM-8, CM-8(1))

Requires maintaining an up-to-date inventory of system components and updating it as part of installations, removals, and system updates. NIST specifies that the inventory should include system names, software version numbers, software owners, and software license information. At the application level, this is precisely what an SBOM documents.

03.04.08 – Authorized Software – Allow by Exception

Requires identifying all software programs authorized to execute on the system and implementing a deny-all, allow-by-exception policy. Maintaining an SBOM makes it possible to verify that deployed software components match authorized inventories.

03.16 – System and Services Acquisition (New in Rev 3)

03.16.02 – Unsupported System Components

Requires replacing system components when the developer, vendor, or manufacturer no longer provides support. SBOMs with lifecycle data (such as CLE – Common Lifecycle Enumeration) make it possible to automatically detect end-of-life and end-of-support components.

03.16.03 – External System Services

Requires that providers of external system services comply with the organization’s security requirements. For software services, this can include requiring SBOMs as part of the vendor assessment process.

03.14 – System and Information Integrity

03.14.01 – Flaw Remediation

Requires identifying, reporting, and correcting system flaws, with security-relevant updates applied within defined timeframes. SBOMs enable this by providing the component inventory needed to match against vulnerability databases like the NVD and the CISA KEV catalog.

03.14.03 – Security Alerts, Advisories, and Directives

Requires receiving security alerts and advisories from external organizations on an ongoing basis. SBOMs make it possible to automatically correlate new advisories with your deployed components, rather than relying on manual cross-referencing.

CMMC and NIST 800-171

The Cybersecurity Maturity Model Certification (CMMC) is the DoD’s program for verifying that contractors have implemented the security requirements in NIST 800-171. CMMC 2.0 defines three levels:

  • Level 1 – 15 basic safeguarding requirements (self-assessment)
  • Level 2 – Full NIST SP 800-171 implementation (third-party assessment by a C3PAO)
  • Level 3 – NIST SP 800-171 plus selected 800-172 enhanced requirements (government-led assessment)

CMMC Level 2 assessments are currently conducted against the 110 requirements of NIST 800-171 Rev 2, using the assessment objectives in NIST SP 800-171A. The 97 requirements and 422 determination statements of Rev 3 will only apply to CMMC once DoD transitions the program to Rev 3 through formal rulemaking. The DoD CIO publishes Organization-Defined Parameters (ODPs) that specify values for customizable fields in the 800-171 Rev 3 controls ahead of that transition.

Organizations preparing for CMMC should treat SBOM generation and management as supporting evidence for multiple controls, particularly 03.17.01 (Supply Chain Risk Management Plan), 03.04.10 (System Component Inventory), and 03.14.01 (Flaw Remediation).

CMMC Rollout Timeline

CMMC requirements are being phased into DoD contracts under 32 CFR 170.3 and the DFARS acquisition final rule (effective 10 November 2025, adding contract clause 252.204-7021 and solicitation provision 252.204-7025):

PhaseStart DateWhat Applies
Phase 110 November 2025CMMC clauses appear in solicitations; Level 1 and Level 2 self-assessments required, at DoD’s discretion
Phase 210 November 2026CMMC Level 2 third-party (C3PAO) certification requirements begin appearing in applicable solicitations
Phase 310 November 2027Level 2 certification requirements broaden; Level 3 (government-led DIBCAC) assessments introduced
Phase 410 November 2028Full implementation: all applicable DoD contracts involving FCI or CUI include the required CMMC level as a condition of award

The practical takeaway: contractors handling CUI who will need a Level 2 certification should be assessment-ready before Phase 2 begins in November 2026. Evidence for the supply chain and component inventory controls, including SBOMs for the software you build and buy, takes time to put in place.

Key Changes from Rev 2 to Rev 3

ChangeDetails
Control countReduced from 110 to 97 requirements (but maps to 156 underlying 800-53 controls)
3 new familiesPlanning (03.15), System and Services Acquisition (03.16), Supply Chain Risk Management (03.17)
33 controls withdrawnVarious consolidations and removals
ODPs introduced88 Organization-Defined Parameters across 49 requirements, replacing vague terms like “periodically”
Assessment scope422 determination statements (32% more than Rev 2)
800-53 alignmentFull alignment with 800-53 Rev 5; “basic/derived” distinction eliminated

The addition of the Supply Chain Risk Management family (03.17) is the most significant change for SBOM relevance. Rev 2 had no dedicated supply chain controls.

Practical Implications

For DoD Contractors

If you handle CUI as a DoD contractor:

  1. Implement a supply chain risk management plan (03.17.01) that includes SBOM generation and monitoring for your software products
  2. Maintain a software component inventory (03.04.10) using SBOMs as the authoritative source for application-level components
  3. Automate flaw remediation (03.14.01) by matching SBOM data against vulnerability databases and the CISA KEV catalog
  4. Require SBOMs from your subcontractors as part of your acquisition strategy (03.17.02), ensuring supply chain transparency flows down

For Software Vendors to DoD Contractors

If you sell software to organizations that handle CUI:

  1. Be prepared to provide SBOMs in a standard format (CycloneDX or SPDX)
  2. Maintain vulnerability disclosure and response processes
  3. Provide component lifecycle information (end-of-support dates)

sbomify helps organizations meet these requirements by automating SBOM generation, enrichment, and vulnerability monitoring, with built-in distribution capabilities for sharing SBOMs with prime contractors and assessors. See our SBOM generation guides for language-specific instructions.

Official Sources


Frequently Asked Questions

What is NIST 800-171?

NIST Special Publication 800-171 is a set of security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. Currently in Revision 3 (published May 2024), it contains 97 requirements across 17 control families. It is most commonly required through DoD contracts and the CMMC certification program.

Does NIST 800-171 require SBOMs?

NIST 800-171 Rev 3 does not explicitly use the term “SBOM.” However, several controls create requirements that SBOMs directly support: 03.04.10 requires a system component inventory including software names, versions, and license information; 03.17.03 requires maintaining provenance in supply chain processes; and 03.14.01 requires timely flaw remediation, which depends on knowing what software components are deployed. SBOMs are the practical tool for satisfying these requirements.

What is the difference between NIST 800-171 and NIST 800-53?

NIST SP 800-53 is the comprehensive security control catalog for federal information systems, containing over 1,000 controls across 20 families. NIST SP 800-171 is a derived subset of 97 requirements tailored for protecting CUI in nonfederal systems. 800-171 Rev 3 controls map directly to 800-53 Rev 5 controls from the moderate baseline.

What is CMMC and how does it relate to NIST 800-171?

CMMC (Cybersecurity Maturity Model Certification) is the DoD’s program for verifying that contractors have implemented NIST 800-171 requirements. CMMC Level 2 assessments are currently conducted against the 110 requirements of NIST 800-171 Revision 2, because a DoD class deviation keeps DFARS 252.204-7012 pinned to Rev 2 until the CMMC program transitions to Rev 3 through rulemaking. Organizations seeking DoD contracts that involve CUI must achieve CMMC Level 2 through a third-party assessment.

When do I need CMMC certification?

CMMC requirements are being phased into DoD contracts under 32 CFR 170.3. Phase 1 began on November 10, 2025, when the DFARS acquisition rule took effect and self-assessment requirements started appearing in solicitations. Phase 2 begins on November 10, 2026, when CMMC Level 2 third-party (C3PAO) certification requirements start appearing in applicable solicitations. Full implementation across all applicable DoD contracts arrives with Phase 4 on November 10, 2028.

What changed in NIST 800-171 Rev 3?

The most significant changes include the addition of three new control families (Planning, System and Services Acquisition, and Supply Chain Risk Management), full alignment with NIST SP 800-53 Rev 5, the introduction of 88 Organization-Defined Parameters across 49 requirements, and an increase to 422 assessment determination statements. The new Supply Chain Risk Management family (03.17) is the most relevant addition for SBOM requirements.


Disclaimer: This page represents our interpretation of the referenced frameworks and standards. While we strive for accuracy, we may have made errors or omissions. This content is provided for informational purposes only and does not constitute legal advice. For compliance decisions, consult the official source documents and seek qualified legal counsel.

← Back to Compliance Overview