---
title: Safeguarding Controlled Unclassified Information – Procedures to Consider and Your Chance to Comment
description: Let Your Voice Be Heard - Comment on the NIST Draft Procedures
image: https://info.redstonegci.com/hubfs/images/Blog_Images_with_title/RGCI%20-%20Safeguarding%20Controlled%20Unclassified%20Information%20-%20Procedures%20to%20Consider.png
---

[ PAY INVOICE](https://redstonegci.com/invoice-payment/) [Call Us Today 256-704-9800](tel:2567049800) [info@redstonegci.com](Mailto:info@redstonegci.com)

<http://www.facebook.com/redstonegci> <http://www.twitter.com/RedstoneGCI> <http://www.linkedin.com/company/redstone-government-consulting-inc-> <https://www.youtube.com/channel/UCQv3eAwiPTTQAnoy7hnUwgg>

[![Redstone_Logo](https://info.redstonegci.com/hubfs/redstone%20logo%20version%201%20-%20rgb-1.png)](https://www.redstonegci.com/)

# Safeguarding Controlled Unclassified Information – Procedures to Consider and Your Chance to Comment

[Posted by Lynne Nalley, CPA on Tue, May 18, 2021 @ 09:05 AM](https://info.redstonegci.com/blog/author/lynne-nalley)

- [Tweet](https://twitter.com/share)

![RGCI - Safeguarding Controlled Unclassified Information - Procedures to Consider](https://info.redstonegci.com/hs-fs/hubfs/images/Blog_Images_with_title/RGCI%20-%20Safeguarding%20Controlled%20Unclassified%20Information%20-%20Procedures%20to%20Consider.png?width=1000&name=RGCI%20-%20Safeguarding%20Controlled%20Unclassified%20Information%20-%20Procedures%20to%20Consider.png)

## What is CUI, CDI and CTI?

CUI is Controlled Unclassified Information and encompasses all Covered Defense Information (CDI) and Controlled Technical Information (CTI). CUI requires the safeguarding or dissemination of controls pursuant to applicable laws, regulations, and government-wide policies.

- Covered Defense Information (CDI) is unclassified controlled technical information or other information described in the Controlled Unclassified Information (CUI) Registry found [here.](http://www.archives.gov/cui/registry/category-list.html)
- Controlled Technical Information (CTI) is technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. It does not include information that is lawfully publicly available without restrictions.

## Why Should a Contractor be Concerned with CUI?

Contracting Officers are required to include the DFARS clauses 252.204-7008 and 252.204-7012, in all solicitations and contracts starting in GFY 2025, including those using FAR part 12 procedures for the acquisition of commercial items. The only exception is solicitations and contracts for the sole acquisition of Commercially Available Off the Shelf (COTS) Items. Even though the requirement is not likely to hit most contractors until 2025, efforts have to be undertaken now to be prepared.

## What is the DFARS Clause?

DFARS 252.204-7008, Compliance with Safeguarding Covered Defense Information Controls, and DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, require contractors to implement the security requirements in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Rev1, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations, to safeguard DoD’s covered defense information that is processed, stored, or transmitted on the contractor's internal unclassified information system(s) or network(s).

## Level of Compliance Requirement in Contracts

This is an evolving area and DoD is slowly rolling out the Cybersecurity Maturity Model Certification (CMMC). The plan is for DoD to begin specifying a level of CMMC compliance requirements in some new contracts beginning in 2021 with full implementation expected by September 30, 2025. There are five levels of CMMC certification, and the certification is valid for 3 years. The CMMC has different levels of cyber security maturity that can be required of a government contractor. Each level requires more controls than the previous one. One is the lowest and five is the highest. The contracting officer is required to identify the information the contractor will have to control and the CMMC compliance level required.

## Difference Between NIST and CMMC

DFARS 252.204-7012 requires contractors with DoD contracts to comply with NIST SP 800-171 through a self-assessment process. CMMC is the process being used to certify the maturity level of a contractor’s compliance with cyber security requirements. CMMC will require third party verification and audit who can take advantage of NIST initiatives that the contractor has in process.

## What are the Contractor’s Responsibilities?

Contractors must implement the security requirements addressed in the NIST Special Publication (SP) 800-171 when the clause is included in the solicitation/contract. If the contractor will vary from the security requirements in NIST SP 800-171 that are in effect at the time a solicitation is issued the contractor must submit a written explanation to the Contracting Officer as to why a particular security requirement is not applicable or whether there is an equally effective security measure to achieve equivalent protection.

Additionally, if a cyber incident is discovered, the contractor must conduct a timely review for evidence of compromise of covered defense information and report the cyber incident to the DoD. The contractor is also required to flow the clauses to subcontracts (excluding subcontracts for COTS). The contractor should require subcontractors to notify them when submitting a request to vary from the NIST SP 800-171 security requirement to the contracting officer or if the subcontractor reported an incident to the DoD. The subcontract incident report number (assigned by DOD) should be provided to the higher-tier contractors as soon as possible. The contractor must also determine if information it will provide to the subcontractor is controlled unclassified information and requires protection.

## NIST SP 800-171 vs. SP 800-172A

NIST SP 800-172A Assessing Enhanced Security Requirements for Controlled Unclassified Information (CUI) is being put in place to provide an assessment process for determining contractor compliance with SP 800-171.

## Draft Publication Available for Comment

NIST has published a draft Special Publication proposed Rules [SP 800-172A Assessing Enhanced Security Requirements for Controlled Unclassified Information (CUI) dated April 27, 2021.](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-172A-draft.pdf)

The publication includes assessment procedures that may be used in following the requirements in NIST SP 800-172. The assessment procedures can be tailored to the contractor’s needs whether they are conducted as self-assessment, independent third-party assessment or government sponsored assessment. Each security requirement includes an objective, and then provides procedures to facilitate understanding the requirement and obtaining evidence through examination, interviewing and testing. The contractor can determine if a security requirement has been satisfied by applying the procedures. There is no expectation that all the assessment procedures are required, however, it is a starting point for developing security assessment plans and risk-based decisions to determine compliance with the CUI enhanced security requirements.

NIST is providing procedures to use on a voluntary basis, and they are not intended to contradict mandatory standards and guidelines under statutory authority. We highly recommend contractors consider having the representative that handles CUI information review the draft assessment and procedures and provide comments/recommendations to NIST to enhance the process. Although there is a short time period to provide comments, the assessment/procedures are still available for contractors to apply as they see fit, to ensure they meet the security requirements.

## Comments Requested

Now is your chance to provide comments to improve the process – comments are due by June 11, 2021. NIST is seeking feedback on the assessment procedures from public and private sectors by June 11, 2021. You can access the draft publication and provide comments [here.](https://csrc.nist.gov/publications/detail/sp/800-172a/draft#:~:text=Draft%20NIST%20SP%20800%2D172A,in%20NIST%20SP%20800%2D172)

Redstone GCI can assist in the evaluation and determination of the various cybersecurity clauses and requirements that are applicable in the evolving government contracting lifecycle. Additionally, we are available to assist contractor’s in assessing their current policies and practices to ensure they meet the DFAR cyber security requirements.  [Redstone GCI](https://www.redstonegci.com/contact/) works with contractors throughout the [U.S.](https://www.redstonegci.com/u-s-business-consulting/) and [internationally](https://www.redstonegci.com/international-business-consulting/) with understanding the Government’s expectations in applying FAR requirements. 

 

[![Contact Us for a Consultation](https://no-cache.hubspot.com/cta/default/203971/interactive-173774226074.png) ](https://info.redstonegci.com/hs/cta/wi/redirect?encryptedPayload=AVxigLLTWZSRmmNmliCYpijXEpafQAjtTLOmuLBBx13YLAwjeVQV4NcR%2BUxT%2B%2Bblqbtb1c2gdHDIYBIZOBTQ1jYdV5yfXCEoVTL6MSsedUpulrDEybF1kthiue9G%2FgZch98WnVqveOYL6c9Gri4bcdjA%2F20IUrAAfY%2FsCZ6nMoCL%2FS15BEz0&webInteractiveContentId=173774226074&portalId=203971)

### Written by [Lynne Nalley, CPA](https://info.redstonegci.com/blog/author/lynne-nalley)

![Lynne Nalley, CPA](https://info.redstonegci.com/hubfs/images/Staff_/Lynne-Nalley.png) Lynne is a Director with Redstone Government Consulting, Inc. providing government contract consulting services to our clients primarily related to Commercial Item Determinations and support, Cost Accounting Standards, DFARS Business System Audits, Proposals, and Incurred Cost. Prior to joining Redstone Government Consulting, Lynne served in several capacities with DCAA and DCMA for over 35 years. Professional Experience Lynne began her career working with DCAA in the Honeywell Resident Office, Clearwater, FL in 1984. Lynne’s experience included various positions which involved conducting or reviewing forward proposals or rate audits, financial capability audits, progress payments, accounting and estimating systems, cost accounting standards, claims and disclosure statement reviews. She is an expert in FAR, DFARS, CAS and testified as an expert witness. Lynne assisted in drafting the commercial item guidance for DCAA Headquarters. Lynne was assigned as a Regional Technical Specialist where she provided guidance to 20 field offices on highly complex or technical issues relative to forward pricing, financial capability or progress payment issues. As an Assistant for Quality, she was involved in reviewing and ensuring audit reports were in compliance with policy and GAGAS as well as made NASBA certified presentations to the staff including but not limited to billing reviews, CAS, unallowable cost and progress payments. To enhance her experience in government contracting, Lynne accepted a position with DCMA in 2015 as part of the newly organized DCMA Cadre of Experts in the Commercial Item Group. This included performing reviews of prime contractor’s assertions and/or commercial item determinations as well as performing price analyses. Lynne was a project lead and later became a lead analyst where she engaged with the buying commands on requests and reviewed price analysis reviews performed by a team of 5 analysts. She also assisted the DCMA CPSR team relative to commercial items and co-instructed the Commercial Item Training presented to DCMA. Education Lynne earned a Bachelor of Science Degree in Accounting from the University of Central Florida. Certifications State of Florida Certified Public Accountant State of Alabama Certified Public Accountant Defense Acquisition Workforce Improvement Act (DAWIA) Level III- Auditing DAWIA Level III – Contracting

## About Redstone GCI

Redstone GCI is a consulting firm focused on fulfilling the needs of government contractors in all areas of compliance. With a singular mission to help contractors through the multiple layers of “red tape,” we allow contractors to focus on what they do best – support their mission with the U.S. Government. We are home to a group of consultants made up of GovCon industry professionals, CPAs, attorneys, and retired government audit and acquisition professionals.

Our focus and knowledge of audit and compliance functions administered by DCAA and DCMA will always be at the heart of what we do. However, for the past decade, we’ve strategically grown to support other areas of the government contractor back-office with that same level of focus and expertise. We’ve added expertise in contracts management, subcontract administration, proposal pricing, various software systems, HR and employment law, property administration, manufacturing, data analytics/reporting, Grant specialists, M&A, and many other areas. When we see a trend in the needs of contractors, we act to ensure we can provide the best expertise in the market to fulfill those needs.

One thing our clients can be certain of is that with the Redstone GCI Team in your corner, there is no problem too big and no issue too technical for our team to tackle.

 Topics: [Accounting System Compliance](https://info.redstonegci.com/blog/topic/accounting-system-compliance), [Cybersecurity](https://info.redstonegci.com/blog/topic/cybersecurity)

### Search Posts

This is a search field with an auto-suggest feature attached.

- There are no suggestions because the search field is empty.

### Subscribe via E-mail

### Latest Posts

### Posts by category

- [Accounting System Compliance (282)](https://info.redstonegci.com/blog/topic/accounting-system-compliance)
- [Commercial Determination (34)](https://info.redstonegci.com/blog/topic/commercial-determination)
- [Contractor Purchasing System Review (CPSR) (85)](https://info.redstonegci.com/blog/topic/contractor-purchasing-system-review-cpsr)
- [Contracts & Subcontracts Administration (300)](https://info.redstonegci.com/blog/topic/contracts-subcontracts-administration)
- [Cost Accounting Standards (CAS) (60)](https://info.redstonegci.com/blog/topic/cost-accounting-standards-cas)
- [COVID-19 (23)](https://info.redstonegci.com/blog/topic/covid-19)
- [Customer Success Story (2)](https://info.redstonegci.com/blog/topic/customer-success-story)
- [Cybersecurity (28)](https://info.redstonegci.com/blog/topic/cybersecurity)
- [DCAA Audit Support (249)](https://info.redstonegci.com/blog/topic/dcaa-audit-support)
- [Defense Procurement & Acquisition Policy (DPAP) (7)](https://info.redstonegci.com/blog/topic/defense-procurement-acquisition-policy-dpap)
- [Deltek Costpoint (54)](https://info.redstonegci.com/blog/topic/deltek-costpoint)
- [DFARS Business Systems (179)](https://info.redstonegci.com/blog/topic/dfars-business-systems)
- [DOD IG (10)](https://info.redstonegci.com/blog/topic/dod-ig)
- [Employee & Contractor Compensation (22)](https://info.redstonegci.com/blog/topic/employee-contractor-compensation)
- [Employers & Unions (8)](https://info.redstonegci.com/blog/topic/employers-unions)
- [Estimating System Compliance (18)](https://info.redstonegci.com/blog/topic/estimating-system-compliance)
- [Export & Import (19)](https://info.redstonegci.com/blog/topic/export-import)
- [Federal Acquisition Regulation (FAR) (187)](https://info.redstonegci.com/blog/topic/federal-acquisition-regulation-far)
- [Federal Construction Contracting (4)](https://info.redstonegci.com/blog/topic/federal-construction-contracting)
- [Government Compliance Training (59)](https://info.redstonegci.com/blog/topic/government-compliance-training)
- [Government Property Management (18)](https://info.redstonegci.com/blog/topic/government-property-management)
- [Government Regulations (265)](https://info.redstonegci.com/blog/topic/government-regulations)
- [Government Shutdown (9)](https://info.redstonegci.com/blog/topic/government-shutdown)
- [Grants & Cooperative Agreements (2 CFR 200) (32)](https://info.redstonegci.com/blog/topic/grants-cooperative-agreements-2-cfr-200)
- [Human Resources (118)](https://info.redstonegci.com/blog/topic/human-resources)
- [Incurred Cost Proposal Submission (ICP/ICE) (83)](https://info.redstonegci.com/blog/topic/incurred-cost-proposal-submission-icp-ice)
- [Litigation Consulting Support (17)](https://info.redstonegci.com/blog/topic/litigation-consulting-support)
- [Manufacturing Operations Consulting (26)](https://info.redstonegci.com/blog/topic/manufacturing-operations-consulting)
- [Material Management & Accounting System (MMAS) (23)](https://info.redstonegci.com/blog/topic/material-management-accounting-system-mmas)
- [Non-US Government Contractor (3)](https://info.redstonegci.com/blog/topic/non-us-government-contractor)
- [Office of Federal Contract Compliance Programs (31)](https://info.redstonegci.com/blog/topic/office-of-federal-contract-compliance-programs)
- [Organizational Change Management Consulting (17)](https://info.redstonegci.com/blog/topic/organizational-change-management-consulting)
- [Paycheck Protection Program (PPP) Loans (8)](https://info.redstonegci.com/blog/topic/paycheck-protection-program-ppp-loans)
- [Program Management & Project Cost Control (2)](https://info.redstonegci.com/blog/topic/program-management-project-cost-control)
- [Proposal Cost Volume Development & Pricing (79)](https://info.redstonegci.com/blog/topic/proposal-cost-volume-development-pricing)
- [Quickbooks (21)](https://info.redstonegci.com/blog/topic/quickbooks)
- [REAs, Claims & Terminations (10)](https://info.redstonegci.com/blog/topic/reas-claims-terminations)
- [Redstone GCI (50)](https://info.redstonegci.com/blog/topic/redstone-gci)
- [Sequestration (4)](https://info.redstonegci.com/blog/topic/sequestration)
- [Service Contract Act (14)](https://info.redstonegci.com/blog/topic/service-contract-act)
- [Small Business Compliance (121)](https://info.redstonegci.com/blog/topic/small-business-compliance)
- [System Award Management (SAM) (9)](https://info.redstonegci.com/blog/topic/system-award-management-sam)
- [UKG Ready HR Software Consulting (7)](https://info.redstonegci.com/blog/topic/ukg-ready-hr-software-consulting)
- [Unanet (35)](https://info.redstonegci.com/blog/topic/unanet)
- [Vlog (41)](https://info.redstonegci.com/blog/topic/vlog)

### Disclaimer

```
Data published on our website, such as our white papers, blogs and other government contracting commentary reflect our interpretations and opinions of current events and regulations, at the time such data is published, and the perspectives/opinions of other professionals in our industry may vary from our own.  Further, our commentary and perspectives do not reflect legal analyses, since we are not attorneys, but rather government contracts and accounting advisors.  We therefore make no representation that the use of our published information will insulate a company from government challenges, nor otherwise ensure a successful defense on any government procurement adverse action.  Readers agree that articles or blog commentary presented within our website shall not be replicated or re-published without requesting before publication in another medium, and our expressed written consent to do so.
```

**Redstone Government Consulting**  
501 Madison Street SE, Suite 100  
Huntsville, AL 35801

**Phone: ** [256.704.9800](tel:2567049800)  
**Email Us**[ info@redstonegci.com](mailto:info@redstonegci.com)

**[PAY INVOICE](https://redstonegci.com/invoice-payment/)**  
[PCI DSS compliance documentation](https://redstonegci.com/wp-content/uploads/2016/10/pci_dss_self_assessment_certificate.pdf)

<http://www.facebook.com/redstonegci> <http://www.twitter.com/RedstoneGCI> <http://www.linkedin.com/company/redstone-government-consulting-inc-> <https://www.youtube.com/channel/UCQv3eAwiPTTQAnoy7hnUwgg>

© 2026 Redstone Government Consulting | All Rights Reserved | [Privacy Policy](https://redstonegci.com/privacy-policy/) | [Event Refund / Cancellation Policy](https://redstonegci.com/event-refund-cancellation-policy/)