Trust & Compliance / NIST SP 800-171

NIST SP 800-171 compliance

Protect CUI wherever it goes.

NIST SP 800-171 sets the security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems. XQ supports its data-protection requirements by classifying CUI at ingestion, encrypting each object with customer-held keys, enforcing access policy every time it is opened, and logging every access attempt.

Built for Contractors handling CUI under DFARS 252.204-7012 · IT and security teams in the Defense Industrial Base

At a glance

StandardNIST SP 800-171 Rev. 2 — 110 requirements, 14 families

XQ coversAccess control, audit, authentication, media and communications protection for CUI

Works acrossEmail, cloud storage, chat, forms, apps

EvidenceEvery key request logged, including denials

Works with Gmail · Outlook · AWS S3 · Azure Blob · OneDrive · Google Drive · Splunk · QRadar

Find and label CUI automatically

AI classification tags CUI at ingestion and maps it to NIST SP 800-171 controls.

Protect it in every tool

Email, files, chat, forms and cloud storage — without changing how teams work.

Prove it to auditors

Signed, per-object access logs export straight to your SIEM.

What NIST SP 800-171 requires

Contractors that handle CUI under DFARS 252.204-7012 must implement NIST SP 800-171. Its 110 requirements in Revision 2 — the revision CMMC Level 2 assesses against — are grouped into 14 families, from access control and audit to media protection and system and communications protection.

Cloud workflows and distributed teams make that hard: CUI moves through email, shared drives and partner systems that your network controls never see. Protecting the data itself closes that gap.

How XQ maps to NIST SP 800-171 families

Requirement familyHow XQ helps
Access Control (3.1)Policy-based key distribution: only authenticated, authorized users and software can obtain the key for a given object, under RBAC, ABAC, IP allow-listing and geofencing rules.
Audit & Accountability (3.3)Every key request is logged — including failed ones — so nothing happens to protected data without an entry. Logs are indexed, signed and exportable to SIEMs such as Splunk and QRadar.
Identification & Authentication (3.5)Access to protected data requires the recipient to authenticate, including multi-factor authentication, before a key is released.
Media Protection (3.8)CUI stays encrypted wherever it is stored — AWS S3, Azure Blob, OneDrive, Google Drive or on-premises — and access can be revoked per object.
System & Communications Protection (3.13)Object-level AES-256 encryption protects CUI at rest and in transit, with keys separated from the data and held by you.

No single product satisfies all 110 requirements — many are organizational. XQ covers the requirements that depend on protecting and tracing the data itself, and produces the evidence to show it.

Want the requirement-by-requirement view for your environment?

Where XQ protects CUI

  • Email and attachments in Gmail and Microsoft Outlook, including on iOS and Android.
  • Files in cloud storage and sync services, without changing how teams work.
  • Chat, support conversations and secure web forms that collect CUI.
  • On-premises to hybrid-cloud transfer through the XQ Secure Gateway.
  • Your own applications, through REST APIs and free SDKs.

Data loss prevention rules detect CUI before it is sent and apply encryption and access controls automatically, so protection does not depend on every user remembering to click.

Related resources and articles

NIST SP 800-171, answered directly.

What is Controlled Unclassified Information (CUI)?

CUI is information the U.S. government creates or possesses that requires safeguarding under law, regulation or policy but is not classified — for example export-controlled technical data or sensitive contract information. Contractors that handle it must protect it to NIST SP 800-171.

How does NIST SP 800-171 relate to CMMC?

CMMC Level 2 assesses contractors against the 110 requirements of NIST SP 800-171 Revision 2. Contractors handling CUI already owe those requirements under DFARS 252.204-7012; CMMC verifies that they are in place.

Does XQ make an organization NIST SP 800-171 compliant on its own?

No single product does: many of the 110 requirements are policies and processes. XQ implements the data-centric requirements — access control, audit, identification and authentication for protected data, media and communications protection — and provides the audit evidence for them.

How does XQ find and label CUI?

AI classification tags CUI at ingestion and maps it to NIST SP 800-171 controls. Data loss prevention rules then detect CUI before it is sent and apply encryption and access controls automatically.

How does XQ help with audit and accountability?

XQ logs every key request for every protected object, including denied attempts, with who, when and where. The logs are signed, searchable and exportable to your SIEM.

Where are the encryption keys held?

Keys are always separated from the data. XQ supports SaaS, private-cloud and on-premises deployment of its key and policy service, so you can keep key custody entirely in your own environment.

Protect CUI without changing how you work.

See how XQ covers the data-protection requirements of NIST SP 800-171 in your current tools.