File-sharing controls aligned with NIST 800-171 security practices.
NIST 800-171 compliant file sharing for controlled CUI workflows, with named access, permissions and detailed transfer records.
Keep access associated with named people and intended business relationships.
Protect sensitive data in transit and at rest without arbitrary file-size limits.
Keep a clearer history of the exchange after data leaves the sender.
Use file-exchange controls as part of the wider security control set.
Access control
Keep sensitive exchanges associated with named users and explicit permissions.
Protected handling
Use encrypted transfer and storage alongside the organization's broader security architecture.
Audit evidence
Retain activity records that can support monitoring, review and incident investigation.
Scope, control implementation, assessment, policies, configuration and overall compliance responsibility remain with the organization.
Trusted for sensitive, accountable file exchange.
★★★★★The platform feels precise, not overloaded, and that gave staff confidence right away. It’s rare to find something both highly secure and easy to live with day to day.
★★★★★It’s built for security first, which means our compliance team sleeps easier. We just send files now without worrying about what’s happening behind the scenes.
★★★★★MX protects, manages and transfers highly classified data of any type and size. I can share information with confidence that it cannot be misused.
★★★★★We wanted staff to stop improvising whenever controlled unclassified information exchanged with subcontractors appeared in their workload. Named access, expiration and activity records give us a more consistent way to support our handling requirements. Assessment preparation takes less manual reconstruction.
★★★★★The recurring headache for us was contract files shared with approved external teams, especially when someone needed proof of what happened later. The previous setup meant we sometimes used a broad collaboration folder for a task that only required a narrow transfer. The exchange can be limited to the participants involved in that specific task. The platform helps with one practical part of the control environment rather than claiming to solve the entire framework. Subcontractor exchanges are more consistent across programs.
★★★★★Our policy for engineering records that need a documented external transfer made sense on paper, but the day to day process was much less consistent. The audit history gives assessors and internal reviewers a clearer record of the operational steps. Staff have a clearer answer when they need to send sensitive contract material externally.
★★★★★The weak point in our process was sensitive project information moving between prime and subcontractor teams, especially once the file left our own systems. The messy part was that project teams had several approved tools and still were not always sure which one fit a sensitive handoff. A defined transfer route makes it easier for staff to follow the control without interpreting it differently on every project. Our security team likes that the evidence is created during the work instead of assembled later. We have fewer one off sharing methods to review after a project milestone.
★★★★★The file itself was rarely the issue with CUI exchanged with approved subcontractors; it was the loose access and follow-up around it. What looked convenient at the point of sending usually created more uncertainty for somebody else later. Named access, expiration and activity records give us a consistent way to support the handling rules around CUI. We did not need to change every surrounding system just to fix this one part of the workflow. Prime and subcontractor teams can use a narrow transfer instead of opening a broad collaboration area for a single task. We checked the process with a few users before making it the standard route. That has taken pressure off both operations and security. For me, the useful part is that CUI exchanged with approved subcontractors no longer depends on somebody remembering the unwritten rules.
★★★★★Our old setup could move the file, but contract and engineering files moving between prime and subcontractor teams still left too many questions afterward. Prime and subcontractor teams can use a narrow transfer instead of opening a broad collaboration area for a single task. Named access, expiration and activity records give us a consistent way to support the handling rules around CUI. Our reviewers ask fewer follow-up questions because the record is much easier to read. We now have fewer loose ends around contract and engineering files moving between prime and subcontractor teams, which is what I care about most.
Frequently asked questions
Clear answers about NIST 800-171 Compliance.
What is NIST SP 800-171-compliant file sharing?
NIST SP 800-171-compliant file sharing generally means a controlled approach to Controlled Unclassified Information exchanged in nonfederal environments that keeps recipient, access and activity controls around the exchange.
For nist 800-171 compliance, the practical focus is on Controlled Unclassified Information exchanged in nonfederal environments rather than treating every file as an open link or an unmanaged attachment. The practical test is whether the process gives the team enough control for the sensitivity of the file without creating workarounds that people are likely to bypass.
For more detail on the related MX workflow, see MX security and administration features. NIST SP 800-171 applies to the protection of CUI in covered nonfederal systems and organizations, so file transfer is only one part of the wider control environment.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. Where the workflow is business-critical, the organization should document who owns the process and who is responsible for reviewing exceptions or incomplete exchanges.
Does My MX Data by itself make an organization compliant with NIST SP 800-171?
No. Using My MX Data does not automatically make an organization compliant with NIST SP 800-171. The organization still needs to decide matters such as lawful use, data classification, retention, supplier due diligence, training and incident response where those duties apply.
Technology can support specific controls, but compliance also depends on the organization's policies, contracts, configuration, staff practices, risk decisions and wider governance. For higher-risk workflows, legal, compliance and security stakeholders should review the intended recipients, data type, access period and evidence requirements before rollout.
MX should be assessed as one part of that wider control environment rather than as a substitute for the organization's own compliance program. For more detail on the related MX workflow, see MX feature set.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. Controls also need to be configured appropriately; the presence of an encryption or audit feature does not prove that every exchange has been handled correctly.
How can access controls and multi-factor authentication help protect controlled unclassified information?
Protection in MX relies on several controls working together rather than a single security feature. The sender retains a clearer connection between the file, the intended recipient and the access window applied to that exchange.
AES-256 encryption forms part of the model alongside named-recipient access, permissions, multi-factor authentication, expiry controls and detailed activity records. For particularly sensitive information, MX can also use ASR (Anonymize, Shard and Restore) as an additional protection method that is distinct from conventional encryption.
For more detail on the related MX workflow, see file-exchange controls. Different transactions can carry different conditions, so routine material does not need to be handled exactly like highly sensitive information.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. Administrative oversight matters because access can change during a project as people join, leave or move between responsibilities.
How can audit records support accountability for CUI file exchanges?
MX records activity associated with file exchanges, giving relevant senders and administrators a clearer history after information has been shared. That history can help a team follow up on incomplete exchanges, investigate unexpected activity and prepare evidence for internal review.
Records may include uploads, access, downloads, comments, recipient activity, timestamps, transaction history and relevant user or IP details. NIST SP 800-171 applies to the protection of CUI in covered nonfederal systems and organizations, so file transfer is only one part of the wider control environment.
For more detail on the related MX workflow, see MX security and administration features. Notifications can also draw attention to pending downloads, new comments or expiring access without requiring somebody to check each exchange manually.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. A transaction record is most useful when it answers practical questions such as who accessed the file, when they did it and whether the current version was downloaded.
What role does encryption play when organizations exchange CUI with external parties?
Protection in MX relies on several controls working together rather than a single security feature. For particularly sensitive information, MX can also use ASR (Anonymize, Shard and Restore) as an additional protection method that is distinct from conventional encryption.
AES-256 encryption forms part of the model alongside named-recipient access, permissions, multi-factor authentication, expiry controls and detailed activity records. Layered controls are useful because identity, confidentiality and evidence solve different parts of the file-exchange problem.
For more detail on the related MX workflow, see encrypted file sharing. Administrative oversight matters because access can change during a project as people join, leave or move between responsibilities. NIST SP 800-171 applies to the protection of CUI in covered nonfederal systems and organizations, so file transfer is only one part of the wider control environment.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. Security still depends on the wider environment, including endpoint protection, account management, recipient behavior and the organization's own operating procedures.
Can recipient permissions, expiry settings and data-location requirements be configured for sensitive workflows?
Yes. MX supports expiry settings and configurable access conditions, helping teams avoid leaving sensitive files available indefinitely after the business purpose has passed. NIST SP 800-171 applies to the protection of CUI in covered nonfederal systems and organizations, so file transfer is only one part of the wider control environment.
Recipient permissions and download conditions can add further control where the relevant workflow supports them. The sender retains a clearer connection between the file, the intended recipient and the access window applied to that exchange.
For more detail on the related MX workflow, see file-exchange controls. Different transactions can carry different conditions, so routine material does not need to be handled exactly like highly sensitive information.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. Administrative oversight matters because access can change during a project as people join, leave or move between responsibilities.
Can contractors and suppliers exchange large technical files through MX without arbitrary file-size restrictions?
Yes. MX is designed to support very large files and complete datasets without arbitrary file-size restrictions. This is useful for engineering, media, software and project teams that need to move complete working packages without breaking the process apart.
That can include CUI, technical data and contract-related information, reducing the need to split an exchange across multiple uploads or move it to another tool simply because the file is large. Keeping the complete package in one controlled exchange can reduce workarounds such as compression, fragmented uploads or use of an unapproved temporary transfer tool.
For more detail on the related MX workflow, see controlled large-file exchange.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. NIST SP 800-171 applies to the protection of CUI in covered nonfederal systems and organizations, so file transfer is only one part of the wider control environment.
Which NIST SP 800-171 controls and organizational responsibilities sit outside the file-sharing platform itself?
MX can support Controlled Unclassified Information exchanged in nonfederal environments with controls designed around recipient identity, access conditions and a traceable exchange history. Different transactions can carry different conditions, so routine material does not need to be handled exactly like highly sensitive information.
That is useful where contractors, suppliers and approved project participants need to handle CUI, technical data and contract-related information without losing sight of who received the information and what happened next.
For more detail on the related MX workflow, see MX feature set. Notifications can also draw attention to pending downloads, new comments or expiring access without requiring somebody to check each exchange manually. The sender retains a clearer connection between the file, the intended recipient and the access window applied to that exchange.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. NIST SP 800-171 applies to the protection of CUI in covered nonfederal systems and organizations, so file transfer is only one part of the wider control environment.
Put NIST 800-171 Compliance into a controlled workflow your team can actually use.
Start with a seven-day trial for up to five users, or speak to the team about a larger deployment, SSO or governance requirements. No credit card is required for the trial.