Double Whammy: NIST Unveils Draft Enhanced Security Requirements and Revisions to NIST SP 800-171
Client Alert | 1 min read | 06.21.19
The National Institute of Standards and Technology (NIST) has released drafts of NIST SP 800-171 Revision 2 and a companion standard NIST SP 800-171B, designed to protect Controlled Unclassified Information (CUI) from advanced persistent threats (APTs). 800-171B details 33 “enhanced” controls, reflecting core principles of penetration resistance, damage-limiting operations, and resiliency. Specific controls include those related to segregation, hunt teams, AI-enabled tools, IoT security, and supply chain – some of which arguably do not have firm industry definitions.
Unlike the non-substantive updates to Revision 2, 800-171B will apply only to contractors handling CUI that the government determines is part of a “critical program” or is a “high value asset.” A cost estimate from the Department of Defense – expected to quickly implement 800-171B – anticipates that less than one percent of its contractors will be impacted but that (allowable) costs could exceed $1 million.
Comments for all three documents are due July 19, 2019.
Contacts

Partner, Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 3 min read | 01.20.26
DoW Joins SBA’s Fight Against Alleged Pass-Through Fraud in the 8(a) Program
On January 16, 2026, U.S. Secretary of War Pete Hegseth posted a video on social media outlining the U.S. Department of War’s (DoW) plan to combat fraud, waste, and abuse in the Small Business Administration’s (SBA) 8(a) Business Development Program.
Client Alert | 3 min read | 01.20.26
Federal Government Challenges Minnesota Law Requiring Affirmative Action in State Government
Client Alert | 1 min read | 01.20.26
Client Alert | 6 min read | 01.16.26
Trump Administration Rolls Out New DOJ Division for National Fraud Enforcement

