---
title: "NIST 800-171 & NIST 800-53 Compliance"
url: "https://www.lbmc.com/services/cybersecurity/nist-compliance/"
description: "With 20 years’ experience with NIST, we now offer 800-171 certification. NIST SP 800-171 compliance should be viewed as an opportunity."
site: "LBMC"
type: "Page"
published: "2025-11-14"
updated: "2026-09-21"
---

[Home](https://www.lbmc.com/) » [Services & Solutions](https://www.lbmc.com/services/) » [Cybersecurity](https://www.lbmc.com/services/cybersecurity/) » NIST 800-171 & NIST 800-53 Compliance

# NIST Compliance

LBMC Cybersecurity has been in the IT security and compliance business for over 20 years. During that time, we have amassed considerable experience with FISMA/NIST 800-53. Now we have extended that expertise to NIST 800-171 certification. All non-federal agencies that access Controlled Unclassified Information (CUI) and DoD Covered Defense Information require 800-171 certification.

### Questions About Cybersecurity Services?

If you’re evaluating risks, preparing for an assessment, or responding to new security requirements, our team can help you understand your options and determine next steps.

Request a Consultation

## Steps to Conduct a NIST Assessment

To ensure that our clients maintain a compliant state and strong control environment, LBMC performs our NIST assessments using the following steps:

- **Kickoff Call** – To discuss engagement logistics, verify controls to be tested, confirm onsite scheduling, review evidence request processes, and answer any pre-engagement questions
- **Documentation Review**
- **Interviews with individuals responsible** for the control implementations to gain an understanding of the current processing environment.
- **Conduct a performance review audit** of NIST specified controls and an onsite walk-around.
- **Debrief and issuance of the final audit report**

### Cybersecurity Insights — Delivered to Your Inbox

Stay informed on emerging threats, evolving compliance requirements, and practical strategies to strengthen your organization’s security posture.

What you’ll receive:

- Cybersecurity trends, threats, and risk insights
- Compliance updates across frameworks like [HITRUST](https://www.lbmc.com/services/cybersecurity/hitrust-assessment/), [CMMC](https://www.lbmc.com/services/cybersecurity/cmmc-assessment/), [SOC](https://www.lbmc.com/services/audit-assurance/soc-audit/), and NIST
- Practical guidance from LBMC cybersecurity advisors
- Invitations to webinars, events, and new resources

## Does my business need NIST compliance?

If you are like the thousands of other government contractors struggling to understand compliance and how many resources it will take to become compliant, know that you are not alone! Don’t worry, odds are you are already in compliance to a large degree.

Cybersecurity breaches are a common threat that seems almost normal in this day and age. However, our government, along with the security expertise of NIST, continue to seek more secure and efficient ways to safeguard our data. When determining the level of information security your organization should implement, the risks of your data being compromised should be the driving factor. Less-obvious, lower risk organizations are targets for the theft of confidential government information, and the federal government now is taking additional steps to safeguard their security.

A primary target for hackers are non-federal organizations that have access to federal data including citizen’s higher education, tax, and healthcare records. This type of information is of high value to malicious users looking to either directly exfiltrate this information or establish a foothold as a jumping off point to larger federal agency targets. Additional organizations of interest are higher learning institutions that leverage government data for research, development, and/or government grants. Although data in transit must be protected per federal encryption requirements, the larger question that comes to mind is – What controls should be in place to also protect the data once it reaches the intended recipient? That is where NIST 800-171 becomes relevant. This standard was implemented to help fill the gaps of protecting Controlled Unclassified Information (CUI) on non-federal information systems.

CUI is defined as “information that law, regulation, or government-wide policy requires safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended (Executive Order 13556)”. So what does this long and complex government definition really mean?

If you are a government support contractor, for example, that has access to federal information systems or government data that isn’t labeled as classified, or a university using Medicare data for statistical research, you may have access to CUI as part of your contract and therefore obligated to protect it. Any contractor that supports federal information systems and has access to CUI is potentially impacted by NIST SP 800-171, and CUI isn’t necessarily limited to raw data records. It also applies to data that is collected, stored, and documented in support of federal information system. This includes project management, technical writing, system development, and consulting.

## The Differences between NIST 800-171 and NIST 800-53

At a high level, the NIST SP 800-53 security standard is intended for internal use by the Federal Government and contains controls that often do not apply to a contractor’s internal information system. NIST SP 800-53 provides federal organizations with the top-level requirements and is more specific to providing security and privacy controls for federal information systems and organizations.

On the other hand, NIST SP 800-171 applies to internal contractor information systems and provides a standardized set of requirements for all CUI security needs to allow non-federal organizations to follow statutory and regulatory requirements by consistently implementing CUI safeguards. Additionally, many of the NIST SP 800-171 controls are about general best security practices for policy, process, and configuring IT securely, and this means in many regards, NIST SP 800-171 is viewed as less complicated and easier to understand than its NIST SP 800-53 counterpart.

NIST SP 800-171 is unique in that it is tailored to eliminate FIPS 200 and NIST SP 800-53 requirements that are:

1. specific to government-owned systems
2. not related to CUI, or
3. expected to be satisfied without specifications (i.e., policy and procedure controls).

NIST SP 800-171 includes just over a hundred controls broken across 14 control families and is more concise in nature, making it less complex to implement for non-federal organizations.

One of the unique characteristics of the NIST SP 800-171 is the flexibility non-federal organizations have in defining how requirements are implemented. The requirements do not mandate any particular technological solutions, and allow contractors, if they choose, to protect information using the systems they already have in place, rather than trying to use government-specific approaches. This is great news for organizations that already have existing mature systems and will likely mean that they will not have to “rip and replace” their existing security program.

Security requirements in NIST SP 800-171 are designed to protect CUI residing in contractor information systems while generally reducing the burden placed on contractors to maintain federal-centric processes and requirements. Compliance with NIST SP 800-171 should be viewed as an opportunity to be good stewards of government data as well as an opportunity for these organizations to compete for federal opportunities that others may not qualify for.

## All NIST Reports are not Created Equal

Our team members have extensive experience on your side of the desk in a variety of industries with security and compliance mandates. This client-side experience means that we understand how data moves between a user entity’s network and its service organizations. We help you achieve compliance while providing the insights your leaders and stakeholders need to make better business decisions.

Whether you are just getting started with NIST certification, or have been navigating regulations for years from another provider, LBMC Cybersecurity can help you maintain NIST compliance in a complex landscape

If you’re navigating complex security, compliance, or risk challenges, LBMC’s cybersecurity advisors can help you prioritize next steps with clarity. Start with a conversation focused on your goals, risks, and operational realities.

Talk to an Advisor

## Industries We Serve

Our cybersecurity advisory team works with organizations across industries to address security risks, compliance requirements, and operational challenges. We help clients strengthen controls, reduce exposure, and align security efforts with business priorities. Whether you’re responding to new regulations, supporting growth, or improving security maturity, our team provides clear guidance grounded in real-world experience.

#### All Industries We Support

- [Government](https://www.lbmc.com/industries/government/)
- [Healthcare](https://www.lbmc.com/industries/healthcare/)
- [Manufacturing and Distribution](https://www.lbmc.com/industries/manufacturing-distribution/)
- [Private Equity](https://www.lbmc.com/industries/private-equity/)
- [Real Estate and Construction](https://www.lbmc.com/industries/real-estate-construction/)
- [All Industries We Serve](https://www.lbmc.com/industries/)

### Local Expertise, Wherever You Are

With offices in [Chattanooga](https://www.lbmc.com/locations/chattanooga/), [Memphis](https://www.lbmc.com/locations/memphis/), [Louisville](https://www.lbmc.com/locations/louisville/), [Nashville](https://www.lbmc.com/locations/nashville/), [Knoxville](https://www.lbmc.com/locations/knoxville/), [Philadelphia](https://www.lbmc.com/locations/philadelphia/), and [Charlotte](https://www.lbmc.com/locations/charlotte/), plus remote offices, LBMC partners with businesses across the region and beyond.

[Find an office near you](https://www.lbmc.com/locations/)

## IT Security Compliance and Assurance Resources

[![CMMC Compliance Strategy: Start Smart, Avoid Costly Mistakes](https://www.lbmc.com/wp-content/uploads/2026/04/iStock-2117357383_security_compliance-300x200.jpg)](https://www.lbmc.com/blog/cmmc-compliance-strategy/)

### [Why CMMC Strategy Matters Before You Start](https://www.lbmc.com/blog/cmmc-compliance-strategy/)

April 6, 2026

[![Simplifying ISO Certification: A More Integrated Approach for Growing Organizations](https://www.lbmc.com/wp-content/uploads/2026/04/iStock-2214157303_ISO-9001_certification_accredited-e1775838743297-300x169.jpg)](https://www.lbmc.com/blog/integrated-iso-certification-services/)

### [Simplifying ISO Certification: A More Integrated Approach for Growing Organizations](https://www.lbmc.com/blog/integrated-iso-certification-services/)

April 3, 2026

[![How to Take Over a PCI Compliance Program ](https://www.lbmc.com/wp-content/uploads/2025/11/iStock-2174551157-e1763064300596-300x169.jpg)](https://www.lbmc.com/blog/how-to-take-over-a-pci-compliance-program/)

### [How to Take Over a PCI Compliance Program](https://www.lbmc.com/blog/how-to-take-over-a-pci-compliance-program/)

November 13, 2025

[See More Resources](https://www.lbmc.com/blog/tag/it-security-compliance-assurance/)

## NIST Compliance FAQs

**What is NIST compliance?**

NIST compliance generally refers to aligning an organization’s cybersecurity practices with standards, frameworks, and guidance developed by the National Institute of Standards and Technology (NIST). The specific requirements depend on the NIST publication that applies to your organization, the information you handle, and any contractual, regulatory, or customer obligations.

**What is FISMA?**

The Federal Information Security Modernization Act (FISMA) establishes requirements for protecting federal information systems and data. Federal agencies use NIST standards and guidance, including NIST SP 800-53, to support their FISMA cybersecurity and risk management programs. Organizations that support federal agencies may encounter FISMA-related security requirements through contracts, information systems, or data handling obligations.

**What is the difference between NIST SP 800-53 and NIST SP 800-171?**

NIST SP 800-53 provides a broad catalog of security and privacy controls used by federal agencies and organizations responsible for federal information systems. NIST SP 800-171 focuses on protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

While NIST SP 800-53 contains hundreds of controls and serves as the foundation for many federal cybersecurity programs, NIST SP 800-171 identifies requirements specifically designed to protect CUI in nonfederal environments. For contractors and other nonfederal organizations that handle CUI, NIST SP 800-171 may be particularly relevant.

**What is Controlled Unclassified Information (CUI)?**

Controlled Unclassified Information, or CUI, is information that requires safeguarding or dissemination controls under applicable laws, regulations, or government-wide policies but is not classified information. Organizations that receive, process, store, or transmit CUI may be subject to specific cybersecurity requirements.

**Does my organization need to comply with NIST SP 800-171?**

NIST SP 800-171 may apply if your organization stores, processes, or transmits CUI on behalf of the federal government. This can include government contractors, subcontractors, research institutions, universities, and other nonfederal organizations.

The requirements that apply to your organization depend on factors such as the information you handle and the terms of your contracts. Reviewing those requirements and understanding where CUI resides are important first steps.

**What is the NIST Cybersecurity Framework (CSF)?**

The NIST Cybersecurity Framework (CSF) is a risk-based framework that helps organizations manage and reduce cybersecurity risk. It is organized around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover.

The CSF can be used by organizations across industries and of different sizes and maturity levels. It provides a practical structure for assessing cybersecurity risk, strengthening security programs, and identifying priorities for improvement.

**How can I prepare for a NIST assessment?**

Preparation starts with understanding which NIST requirements apply to your organization and defining the systems, data, and processes within scope. From there, organizations can review existing policies and controls, identify supporting documentation, perform a gap assessment, prioritize remediation activities, and develop a plan to address deficiencies before the assessment.

LBMC works with organizations to evaluate their current environment, assess applicable NIST controls, identify gaps, and determine practical next steps based on their security and compliance requirements.

## Executive Team

[![Based in Knoxville, Bill Dean is a Shareholder and the East Tennessee Cybersecurity Market Lead for LBMC's Cybersecurity practice, where he spearheads penetration testing, application testing, purple team engagements, incident response, digital forensics, electronic discovery, and litigation support services.](https://www.lbmc.com/wp-content/uploads/2025/07/Bill-Dean-150x150.jpg)](https://www.lbmc.com/team/bill-dean/)

## [Bill Dean](https://www.lbmc.com/team/bill-dean/)

#### Shareholder, Cybersecurity

[bill.dean@lbmc.com](mailto:bill.dean@lbmc.com)

[![Brian Willis, CISSP, QSA, is a Cybersecurity Advisor in Nashville, guiding clients across industries on risk, compliance, and security.](https://www.lbmc.com/wp-content/uploads/2025/07/Brian-Willis-150x150.jpg)](https://www.lbmc.com/team/brian-willis/)

## [Brian Willis](https://www.lbmc.com/team/brian-willis/)

#### Shareholder, Cybersecurity

[brian.willis@LBMC.com](mailto:brian.willis@LBMC.com)

[![Drew Hendrickson, CPA, leads LBMC’s Cybersecurity & Compliance practice in Nashville, specializing in SOC, HITRUST, and privacy risk.](https://www.lbmc.com/wp-content/uploads/2025/07/Hendrickson_Drew_2025-150x150.jpg)](https://www.lbmc.com/team/drew-hendrickson/)

## [Drew Hendrickson](https://www.lbmc.com/team/drew-hendrickson/)

#### Shareholder - LBMC Cybersecurity Practice Leader

[drew.hendrickson@lbmc.com](mailto:drew.hendrickson@lbmc.com)

[![Robyn Barton](https://www.lbmc.com/wp-content/uploads/2025/07/Barton-Robyn-web-2022-150x150.jpg)](https://www.lbmc.com/team/robyn-barton/)

## [Robyn Barton](https://www.lbmc.com/team/robyn-barton/)

#### Shareholder, HITRUST and CMMC Practice Leader

[robyn.barton@lbmc.com](mailto:robyn.barton@lbmc.com)

[![Van Steel, CISA, CISSP, CCSFP, leads LBMC’s cybersecurity consulting service line, driving national cyber risk assessment leadership.](https://www.lbmc.com/wp-content/uploads/2025/07/Steel-Van-2023-web-150x150.jpg)](https://www.lbmc.com/team/van-steel/)

## [Van Steel](https://www.lbmc.com/team/van-steel/)

#### Shareholder, Cybersecurity

[van.steel@LBMC.com](mailto:van.steel@LBMC.com)

[![Stewart Fey](https://www.lbmc.com/wp-content/uploads/2026/08/stewart-fey-headshot-150x150.jpg)](https://www.lbmc.com/team/stewart-fey/)

## [Stewart Fey](https://www.lbmc.com/team/stewart-fey/)

#### Shareholder, Cybersecurity and PCI Compliance Practice Leader

[stewart.fey@lbmc.com](mailto:stewart.fey@lbmc.com)

## Let’s Talk About Your Cybersecurity Priorities

Whether you’re preparing for a compliance assessment, addressing security gaps, or strengthening your overall risk posture, LBMC’s cybersecurity advisors are ready to help. We’ll start with a conversation focused on your current environment, requirements, and the steps needed to move forward with confidence.
