Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Assessing Security Requirements for Controlled Unclassified Information



Ronald S. Ross, Victoria Yan Pillitteri


The protection of Controlled Unclassified Information (CUI) is of paramount importance to federal agencies and can directly impact the ability of the Federal Government to successfully conduct its essential missions and functions. This publication provides organizations with assessment procedures and a methodology that can be used to conduct assessments of the security requirements in NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. The assessment procedures are flexible and can be customized to the needs of organizations and assessors. Assessments can be conducted as independent, third-party assessments or as government-sponsored assessments. The assessments can be applied with various degrees of rigor based on customer-defined depth and coverage attributes.
Special Publication (NIST SP) - 800-171Ar3
Report Number


assessment, assessment method, assessment object, assessment procedure, assurance, Controlled Unclassified Information, coverage, FISMA, NIST Special Publication 800-171, NIST Special Publication 800-53A, nonfederal organization, nonfederal system, security assessment, security requirement.


Ross, R. and Pillitteri, V. (2024), Assessing Security Requirements for Controlled Unclassified Information, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, [online],, (Accessed May 26, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created May 14, 2024