Double Whammy: NIST Unveils Draft Enhanced Security Requirements and Revisions to NIST SP 800-171
Client Alert | 1 min read | 06.21.19
The National Institute of Standards and Technology (NIST) has released drafts of NIST SP 800-171 Revision 2 and a companion standard NIST SP 800-171B, designed to protect Controlled Unclassified Information (CUI) from advanced persistent threats (APTs). 800-171B details 33 “enhanced” controls, reflecting core principles of penetration resistance, damage-limiting operations, and resiliency. Specific controls include those related to segregation, hunt teams, AI-enabled tools, IoT security, and supply chain – some of which arguably do not have firm industry definitions.
Unlike the non-substantive updates to Revision 2, 800-171B will apply only to contractors handling CUI that the government determines is part of a “critical program” or is a “high value asset.” A cost estimate from the Department of Defense – expected to quickly implement 800-171B – anticipates that less than one percent of its contractors will be impacted but that (allowable) costs could exceed $1 million.
Comments for all three documents are due July 19, 2019.
Insights
Client Alert | 8 min read | 09.09.25
On September 5, 2025, the Federal Trade Commission (“FTC”) withdrew its appeals of decisions issued by Texas and Florida federal district courts, which enjoined the FTC from enforcing a nationwide rule banning almost all noncompete employment agreements. Companies, however, should not read this decision to mean that their noncompete agreements will no longer be subjected to antitrust scrutiny by federal enforcers. In a statement joined by Commissioner Melissa Holyoak, Chairman Andrew Ferguson stressed that the FTC “will continue to enforce the antitrust laws aggressively against noncompete agreements” and warned that “firms in industries plagued by thickets of noncompete agreements will receive [in the coming days] warning letters from me, urging them to consider abandoning those agreements as the Commission prepares investigations and enforcement actions.”
Client Alert | 12 min read | 09.09.25
Client Alert | 7 min read | 09.08.25
California’s Climate Disclosure Laws Continue to Roll Forward
Client Alert | 3 min read | 09.08.25
RADV Audits: Implications and Recommendations for Medicare Advantage Organizations