Contractors Should Prepare as NIST Finalizes Enhanced Security Requirements for Protecting Controlled Unclassified Information On May 13, 2026, the National Institute of Standards and Technology (NIST) finalized a revision to Special Publication (SP) 800-172r3 (Revision 3), Enhanced Security Requirements for Protecting Controlled Unclassified Information (CUI), which provides a selection of recommended cybersecurity controls for protecting CUI resident on a nonfederal information system when associated with a “high value asset” or “critical program.” The revised publication highlights the importance of contractors being able to identify CUI and having plans to implement SP 800-172r3 controls even before the revisions are adopted into the Department of War (DOW) Cybersecurity Maturity Model Certification (CMMC) Program. The SP 800-172 controls are tailored to protect CUI and associated systems that may be the target of “Advanced Persistent Threats” (APTs), which are cybersecurity threat actors generally associated with nation-states such as China, Russia, Iran, or North Korea that NIST assesses have the “expertise and resources” to use cyber, physical and deception capabilities to achieve their objectives. SP 800-172 Revision 3 is intended to supplement controls featured in NIST’s SP 800-171 Revision 3 and SP 800-53: Security and Privacy Controls for Information Systems and Organizations. Alongside SP 800-172 Revision 3, NIST revised the companion assessment publication, SP 800-172Ar3: Assessing Enhanced Security Requirements for Controlled Unclassified Information, to reflect new controls added to SP 800-172r3. This publication provides assessment procedures for organizations to determine how effectively an organization is implementing the security controls outlined in SP 800-172r3. These publications do not immediately apply to contractors; however, agencies have required contractors to meet certain SP 800-172 requirements through terms of contracts, grants, or other agreements. For example, DOW selected certain controls from an earlier version (Revision 2) of SP 800-172 for its CMMC Level 3 requirement. The SP 800-172 Controls