Which information is CUI?
Use contract markings, agency guidance and the CUI Registry context to identify the information that requires controlled handling.
Quantum secure · GDPR & ISO 27001 focused
My MX Data provides a controlled exchange route for sensitive federal information shared with employees, subcontractors and program partners. Named-recipient access, MFA, configurable permissions, protected delivery and detailed activity records can support selected operational safeguards within a NIST SP 800-171 program.
My MX Data is not a certification service and does not independently establish NIST SP 800-171, DFARS or CMMC compliance. Your organization remains responsible for identifying CUI, defining the system boundary, implementing every applicable requirement and maintaining assessment evidence.
No credit card required. Up to 5 users.
BOUNDARY CONFIRMEDPackage linked to the approved CUI environment and system security plan.
IDENTITY VERIFIEDNamed user matched to the approved organization, role and business need.
ACTIVITY RECORDEDVerification and file events added to the assessment evidence history.
NIST SP 800-171 protects the confidentiality of Controlled Unclassified Information in nonfederal systems. The requirements apply to components that process, store or transmit CUI, as well as components that protect them.
The current publication is NIST SP 800-171 Revision 3, published in May 2024. Contracting agencies and agreements determine how the requirements apply to a particular organization.
A file-sharing platform can support part of the control environment. It cannot identify all CUI, draw the complete boundary, write the SSP or satisfy requirements that extend across people, facilities, devices, networks and suppliers.
Use contract markings, agency guidance and the CUI Registry context to identify the information that requires controlled handling.
Map the systems, users, devices, services and protection components that process, store, transmit or safeguard CUI.
Confirm identity, organization, role and business need before granting access to a CUI package or exchange space.
Use the applicable contract or agreement, the selected revision and assigned organization-defined parameters to complete the requirement set.
Scoping is not limited to the folder where a file is stored. The boundary should reflect each component that handles CUI or provides security protection for those components.
Applications, workstations and user actions that create, view, change, analyze or otherwise use CUI belong in the scoping discussion.
Primary storage, temporary locations, archives, backups, exports and recovery copies should be mapped to accountable owners and safeguards.
Email, portals, APIs, file exchange, remote access and supplier handoffs can all move CUI beyond its original system context.
Identity services, logging, security tools, network controls and administrative components may be in scope because they protect CUI components.
NIST states that Revision 3 requirements apply to nonfederal system components that process, store or transmit CUI or provide protection for those components. Review the official scope and applicability and document the actual architecture.
The workflow should connect the approved CUI boundary, the named user and the retained evidence used to demonstrate how the exchange operated.
Confirm the CUI package, owner, markings and handling context before creating the exchange.
Place the exchange inside the approved system boundary and documented architecture.
Confirm the named user, organization, role and continuing need before access.
Apply authentication, permissions and the approved transmission safeguards.
Retain user, permission and file events with the wider assessment documentation.
Revision 3 is the current NIST publication, yet an organization should confirm which revision, agency instructions and organization-defined parameters govern its actual obligation. For DoD work, review the contract language and the current DFARS 252.204-7012 clause.
A user should not gain access merely because a link exists or the person belongs to a familiar company. Provisioning should reflect the approved role, file scope and business purpose.
Use named accounts and a defined identity lifecycle rather than shared credentials or open links.
Match access to the user’s approved employer, project function and contractual relationship.
Provide only the files and actions required for the task, then review or remove access promptly.
Grant role-based access after identity, training, need and device requirements are confirmed.
Match the named user, company, CUI scope, contract flow-down and exchange purpose.
Define time-limited permissions, supervision, logging and removal conditions before access.
Hold the exchange until identity, authorization, accountability and technical conditions are resolved.
This matrix is an operational illustration. Organizations should apply their own policies, contract terms, risk decisions and the relevant NIST SP 800-171 requirements to the actual environment.
Revision 3 contains 17 requirement families. The groups below show where a controlled exchange can intersect with the wider program, without suggesting that one tool satisfies an entire family.
Limit information-system access, enforce approved privileges and manage remote or external access routes.
Uniquely identify users, authenticate identities and apply stronger verification where required.
Generate, protect, review and retain records that help reconstruct relevant system and user activity.
Protect CUI at external boundaries and during transmission using approved architectural safeguards.
Prepare for detection, analysis, containment, recovery, reporting and evidence preservation.
Establish approved configurations, control changes and restrict unnecessary functions or services.
Assess controls, monitor the environment and track corrective action through accountable plans.
Address supplier services, external dependencies and the risks introduced across the CUI lifecycle.
Use the complete NIST SP 800-171 Revision 3 publication rather than treating these representative groups as a substitute for the full requirement set.
NIST SP 800-171A provides assessment procedures for the requirements. Evidence should show how the safeguard is designed, implemented and operating across the actual CUI environment.
File events can support examination and testing, but assessors may also need policies, SSP content, configurations, interviews, tickets, account records, screenshots and technical outputs.
My MX Data can help operationalize approved exchanges through identity, access, file protection and activity controls.
Use accountable user accounts rather than broad links or shared credentials for sensitive exchanges.
Explore platform featuresMove approved CUI packages through an encrypted route with additional recipient verification.
See encrypted file sharingUse My MX Data’s patented anonymize, shard and restore methodology within the protected exchange.
Understand the protection modelRetain a clearer account of sender, recipient and file events for oversight and investigation.
Review audit featuresGive designated administrators a clearer way to manage users, exchanges and operational policy.
View the product walkthroughSet the exchange route around the intended recipient and the approved interaction with each file.
Review permission featuresUse a structured business-to-business exchange for primes, subcontractors and program partners.
Explore secure file exchangeDiscuss how the exchange could sit inside your defined CUI architecture and operating procedures.
Talk to the teamThe common need is a defined boundary, an approved recipient, protected delivery and evidence that can be connected to the organization’s wider control environment.
Deliver approved drawings, specifications and contract data to the named supplier team responsible for a defined task.
CUI scope • verified recipient • activity historyExchange versioned engineering files, test results and comments among approved program participants.
least privilege • protected route • review evidenceProvide approved policies, logs, screenshots and supporting files to a named assessor through a restricted exchange.
named reviewer • file integrity • traceabilityShare approved logs, forensic outputs and response evidence with designated internal or external specialists.
need to know • time control • accountable accessMy MX Data can support controlled file handoffs and the activity evidence around them. Compliance depends on how the organization scopes, configures, documents and operates the service within the complete CUI environment.
No single file-sharing platform creates compliance. NIST SP 800-171 requirements span governance, people, facilities, devices, networks, services, suppliers, incident response and ongoing assessment.
Named accounts, MFA, permissions, protected exchange and activity records can reduce uncertainty around delivery.
Contract owners, security teams and information owners determine what is in scope and where it moves.
The platform does not write policy, secure every endpoint, manage facilities or replace the wider technical architecture.
Activity history should be retained with policies, SSP content, configurations, interviews and other assessment objects.
DFARS, agency instructions, reporting duties, subcontractor flow-downs and corrective actions must be addressed separately.
These answers provide practical context. Always apply the exact contract, agreement, agency instructions and current authoritative publications to the organization’s facts.
NIST SP 800-171 provides federal agencies with recommended security requirements for protecting the confidentiality of Controlled Unclassified Information when CUI resides in nonfederal systems and organizations.
The requirements are intended for use through contracts, agreements and other relationships between federal agencies and nonfederal organizations. They are not a general label applied automatically to every private system.
Revision 3 was published in May 2024 and superseded Revision 2 as the current NIST publication. The actual contractual obligation still depends on the language governing the organization’s work.
No universal answer applies to every agreement. NIST publishes the current recommended requirements, while the federal agency, contract or other agreement determines which version and instructions govern a particular relationship.
For example, DFARS 252.204-7012 refers to the NIST SP 800-171 version in effect when the solicitation is issued or another version authorized by the Contracting Officer.
Organizations should record the governing source, revision, agency direction and any assigned organization-defined parameters instead of assuming that publication of a new revision silently changes every contract.
NIST describes the scope as components of nonfederal systems that process, store or transmit CUI, together with components that provide security protection for those components.
The organization therefore needs a defensible boundary. That boundary may be narrower than the whole enterprise, but it is rarely limited to one folder because identity, logging, endpoints, networking, backups and administration may support the CUI environment.
Document data flows, users, devices, services, integrations, security dependencies and external providers. A clear boundary makes implementation and assessment far more manageable.
CUI is information that requires safeguarding or dissemination controls under applicable law, regulation or government-wide policy, but is not classified national security information.
The organization should not decide that ordinary sensitive business information is CUI merely because it feels important. Identification should be grounded in the contract, agency markings, program context and the federal CUI framework.
Practical handling also requires attention to markings, approved users, system boundaries, supplier flow-downs and the rules governing reproduction, transmission and disposal.
No. A controlled exchange can support selected safeguards such as unique user access, stronger authentication, permission management, protected transmission and useful activity records.
Compliance still depends on the organization’s full implementation across all applicable requirements. This includes policies, training, devices, configuration, incident response, physical safeguards, supplier risk, assessment and corrective action.
The service should be mapped to precise requirements and assessment objectives, configured inside the approved boundary and supported by evidence showing how it is actually operated.
NIST SP 800-171 states the security requirements. NIST SP 800-171A provides the assessment procedures and methodology used to evaluate those requirements.
The procedures use assessment methods such as examine, interview and test. Evidence may therefore include policies, plans, configurations, records, screenshots, technical outputs and discussions with responsible personnel.
Revision 3 of 800-171A was published alongside 800-171 Revision 3 in May 2024. The organization should align implementation evidence to the relevant assessment objectives rather than collecting logs without a clear purpose.
NIST SP 800-171 is a security-requirements publication. DFARS clauses can make those requirements contractual for covered DoD work and add obligations concerning areas such as cyber incident reporting, media preservation and subcontractor flow-downs.
CMMC is a Department of Defense program that uses NIST SP 800-171 requirements within a broader assessment and certification structure for applicable defense contracts.
Do not treat the three terms as interchangeable. Review the specific solicitation and contract clauses, current DoD guidance and any assessment obligations that apply to the organization.
Start with the defined boundary and the organization’s actual use case. Identify who will administer the service, where CUI and backups reside, how identities are managed and how the exchange connects to the rest of the environment.
Evaluate at least:
Then map the service to the SSP, policies, requirement implementation and assessment evidence. A platform claim is not a substitute for that tailored review.
Bring security, contract owners, administrators and approved external partners into a more accountable exchange, with clearer recipient controls and a more useful activity history.
No credit card required. Up to 5 users.
Free for 7 days · up to 5 users
Trusted for 150K+ exchanges weekly
No credit card required. Set up in minutes.
Check your inbox, your MX trial details are on their way. Welcome to properly secure file sharing.