If you sell to civilian agencies and you handle Controlled Unclassified Information, you do not have a governmentwide NIST 800-171 mandate today. You very likely do have agency specific clauses, basic safeguarding obligations, and a proposed FAR rule that has been redrafted and reopened for comment, which is a reasonable signal about where this is heading.
That gap between "not required yet" and "clearly coming" is the hardest place to make budget decisions. This post is about what you can do now that holds its value regardless of how the final rule lands.
What Actually Applies to Civilian Contractors Right Now?
Three things, and it is worth separating them cleanly.
First, FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, and the fifteen basic safeguarding requirements already in your contracts, is final and already in most contracts that involve federal contract information. They are a subset of NIST 800-171, not a substitute for it, and they are enforceable today.
Second, individual civilian agencies have their own supplements. DHS has HSAR clauses covering the safeguarding of CUI. NASA has its own information technology security clause in the NASA FAR Supplement. Other agencies impose 800-171 by reference in statements of work, security addenda, or task order level language. There is no single list, which is exactly why this catches contractors by surprise. The obligation is in your contract file, not in a headline.
Third, the FAR CUI rule remains proposed. It was published for public comment and, based on recent practitioner reporting, the draft language has been revisited with a further opportunity to comment. Nothing in it is in force. Read the coverage as a preview, not as a compliance deadline.
Does the Recent FAR CUI News Change What I Owe Today?
No. It changes what you should plan for.
The commentary circulating this week focuses on draft clause language, how CUI would be identified in a contract, and how obligations would flow down to subcontractors. Two points from that reporting are worth holding onto, because they are structural rather than cosmetic.
One, the draft approach ties your safeguarding duty to CUI being actually identified in the contract, typically through a standard form or notice attached to the award. That is meaningful. It shifts part of the burden to the agency to tell you what you are receiving, and it gives you something concrete to point at when scoping.
Two, flow down to subcontractors is a central feature. If you use teaming partners, resellers, or subs who touch the same data, the obligation does not stop at your perimeter. Contractors who wait until the rule is final to map their supply chain will be doing that work under time pressure.
Also note that clause numbering has been in motion as the broader FAR overhaul reorganizes cybersecurity provisions. Do not rely on a clause number you remember from a webinar. Check the numbers in your actual awards.
Is There a Civilian Equivalent of CMMC?
There is not, and this is the single most common misunderstanding we see.
CMMC is a Department of War program, and here is how CMMC differs from civilian agency requirements: it applies through DFARS clauses to defense contracts, it involves third party assessment organizations, and it produces a certification status that gates award eligibility. None of that machinery exists on the civilian side.
The proposed FAR CUI rule, as drafted, does not create a civilian certification body, does not require a third party audit, and does not issue a certificate. If a vendor tells you they will get you "certified" for civilian CUI work, they are selling you something that does not exist. What civilian agencies have leaned on instead is self attestation, contract clauses, and the enforcement backstop of the False Claims Act, which the Department of Justice has used in cybersecurity misrepresentation cases. That backstop is real, and it is a good reason to make sure anything you assert in writing is accurate.
Which Revision of 800-171 Should I Build To?
This is genuinely unsettled, and you should treat anyone who tells you otherwise with suspicion.
NIST published Revision 3 of SP 800-171, which restructured the control families, folded in some previously non federal organization content, and introduced organization defined parameters. Revision 2 remains the version referenced in a great deal of existing contract language, including on the defense side. Federal acquisition rules generally point to a specific revision, and the transition from one revision to another in contract clauses does not happen automatically or instantly.
The practical answer for most civilian contractors: build to the controls that are stable across both revisions. Access control, identification and authentication, media protection, incident response, configuration management, and audit logging do not disappear between versions. Roughly speaking, the bones are the same. Where Rev 3 differs is in specificity and parameterization, not in the fundamental idea that you must know where CUI lives and control who reaches it. Do the durable work first. Chase revision specific deltas after the rule is final and names a version.
Where Do I Actually Start?
Start with scope, not with tools. This order matters, because buying a platform before you know your boundary is how firms spend money on the wrong thing.
- 1
Find out whether you have CUI at all.
Read your active contracts and task orders. Look for CUI markings on deliverables and government furnished information. Look for security clauses in the contract, in incorporated attachments, and in the statement of work. Many contractors discover they hold federal contract information but not CUI, which changes the analysis substantially.
- 2
Draw the boundary.
Identify every system, service, laptop, mailbox, file share, and cloud tenant where that information actually sits. Include the places it leaks into, which in practice is email, shared drives, and personal devices. A smaller, deliberately drawn boundary is cheaper and easier to defend than an enterprise wide one.
- 3
Do a real gap assessment against 800-171.
Not a vendor questionnaire. Go control by control, document what you do today, and be honest about what you do not do. The output is not a score. The output is a list.
- 4
Write the System Security Plan and the Plan of Action and Milestones.
These two documents are the artifacts that make everything else credible. Without them, you have opinions. With them, you have a record, and a record is what holds up when a contracting officer, an auditor, or a prime asks.
- 5
Close gaps in order of data exposure, not in order of ease.
Multifactor authentication, access control, and encryption on the systems holding the data come before the polish.
Everything in that sequence is useful under FAR 52.204-21 today, useful under any agency supplement you already carry, and directly reusable if and when the FAR CUI rule is finalized. None of it is wasted. If you want a structured way to work through it, reviewing your Schedule contract for security clauses with the free GSA Ready Now readiness assessment is a reasonable place to begin.
What Should I Not Do Yet?
Do not buy a certification. Do not restructure your entire enterprise around a rule text that is still subject to change. Do not sign a contract clause you have not read because a prime told you it was routine.
And do not assume your cloud provider handles this. Shared responsibility models are real, and the provider's compliance posture is not the same as yours. Their infrastructure being suitable for CUI does not mean your configuration of it is. That distinction has caught more contractors than any missing control.
Frequently Asked Questions
Is NIST 800-171 currently required for civilian agency contracts?
Not as a governmentwide requirement. The FAR CUI rule that would standardize this across federal contracts is proposed and has not been finalized. However, many individual civilian agencies already impose 800-171 or similar safeguarding obligations through their own FAR supplements and contract clauses, so the answer for your specific contract depends on what is written in your contract.
Do civilian contractors need CMMC certification?
No. CMMC is a Department of War program applied through DFARS clauses to defense contracts. There is no equivalent certification program on the civilian side, and the proposed FAR CUI rule as drafted does not create one. Civilian obligations rest on contract clauses and self attestation rather than third party certification.
What is the difference between FAR 52.204-21 and NIST 800-171?
FAR 52.204-21 is a final, in force clause containing fifteen basic safeguarding requirements that apply to federal contract information. NIST 800-171 is a much broader control set covering CUI, with over a hundred requirements across multiple families. The fifteen basic requirements are effectively a subset, so work done for 52.204-21 counts toward 800-171, but it is nowhere near sufficient on its own.
Should I implement Revision 2 or Revision 3 of NIST 800-171?
It is not settled which revision a final FAR CUI rule would reference, and existing contract clauses across government still point to different versions. The practical approach is to implement the controls that are common to both revisions first, since the core disciplines do not change between them, and to document your System Security Plan in a way that can be remapped when a version is named.
What is the first document I should produce?
A scoping memo that identifies whether you hold CUI, and if so, exactly which systems it touches. Everything else, including your System Security Plan, depends on that boundary being drawn accurately. Firms that skip this step routinely assess the wrong systems and pay for controls they did not need.
Does the proposed rule affect my subcontractors?
The draft language addresses flow down to subcontractors, meaning obligations would not stop at the prime. Even before any rule is final, it is worth mapping which partners, resellers, and subcontractors handle the same information, because that mapping takes longer than most contractors expect and is not something you can compress after an award.
If you are not sure whether your current civilian contracts already carry CUI safeguarding clauses, a contract review is the cheapest hour you will spend this quarter.
Run the Gap Assessment