Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Assessing Enhanced Security Requirements for Controlled Unclassified Information



Ronald S. Ross, Victoria Yan Pillitteri, Kelley L. Dempsey


The protection of Controlled Unclassified Information (CUI) in nonfederal systems and organizations is important to federal agencies and can directly impact the ability of the Federal Government to successfully carry out its assigned missions and business operations. This publication provides federal agencies and nonfederal organizations with assessment procedures that can be used to carry out assessments of the requirements in NIST Special Publication 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171. The assessment procedures are flexible and can be tailored to the needs of organizations and assessors. Assessments can be conducted as 1) self-assessments; 2) independent, third-party assessments; or 3) government-sponsored assessments. The assessments can be conducted with varying degrees of rigor based on customer-defined depth and coverage attributes. The findings and evidence produced during the assessments can be used to facilitate risk-based decisions by organizations related to the CUI enhanced security requirements.
Special Publication (NIST SP) - 800-172A
Report Number


assessment, assessment method, assessment object, assessment procedure, assurance, enhanced security requirement, Controlled Unclassified Information, coverage, CUI Registry, depth, Executive Order 13556, FISMA, NIST Special Publication 800-53, NIST Special Publication 800-53A, nonfederal organization, nonfederal system, security assessment, security control.


Ross, R. , Pillitteri, V. and Dempsey, K. (2022), Assessing Enhanced Security Requirements for Controlled Unclassified Information, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, [online],, (Accessed April 21, 2024)
Created March 15, 2022, Updated November 29, 2022