Quick answer
NIST 800-171 defines how controlled unclassified information (CUI) must be protected when it lives in nonfederal systems, meaning contractors, subcontractors, universities, and service providers working with the US government. Its 110 requirements across 14 families are contractually mandated through federal acquisition clauses, and for defense contractors they're the substance of CMMC Level 2. If federal information flows into your systems, this is the standard you're on the hook for.
What counts as CUI
CUI is information the government requires safeguarding for, but that isn't classified: technical drawings, contract deliverables, export-controlled data, certain personnel or financial records, and much more, usually marked or designated in your contract. The trap is sprawl: CUI arrives in an email, gets saved to a shared drive, quoted in a ticket, and suddenly your entire collaboration stack is in scope. Scoping (knowing exactly where CUI lives and constraining it) is the difference between a bounded compliance effort and an unbounded one.
The 14 families in brief
The requirements derive from the 800-53 Moderate baseline, trimmed for the contractor context: access control, awareness and training, audit and accountability, configuration management, identification and authentication (MFA features prominently), incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection (encryption of CUI at rest and in transit), and system and information integrity.
Two structural obligations matter as much as the technical ones: the System Security Plan describing how you meet each requirement, and POA&Ms (plans of action) for anything not yet implemented, both of which contracting officers and assessors ask for by name.
Enforcement is real now
Self-attested compliance is scored (the DoD methodology subtracts points per missing requirement) and posted to the government's supplier database, executives affirm it, and False Claims Act cases over false cybersecurity attestations have been brought and won. With CMMC assessments phasing into contracts, "we'll get to the SSP later" is a bid-losing posture; see how OptiTech makes 800-171 tractable.

Get a personalized walkthrough of automated compliance for your team. No commitment required.