File-sharing controls aligned with NIST 800-171 security practices.
NIST 800-171 compliant file sharing for controlled CUI workflows, with named access, permissions and detailed transfer records.
Keep access associated with named people and intended business relationships.
Protect sensitive data in transit and at rest without arbitrary file-size limits.
Keep a clearer history of the exchange after data leaves the sender.
Use file-exchange controls as part of the wider security control set.
Access control
Keep sensitive exchanges associated with named users and explicit permissions.
Protected handling
Use encrypted transfer and storage alongside the organization's broader security architecture.
Audit evidence
Retain activity records that can support monitoring, review and incident investigation.
Scope, control implementation, assessment, policies, configuration and overall compliance responsibility remain with the organization.
Governance and assurance
Control you can evidence
Bring audit evidence, authorized-recipient access, retention, expiry and data-location choices together in one controlled exchange environment.
Trusted for sensitive, accountable file exchange.
Frequently asked questions
Clear answers about NIST 800-171 Compliance.
What is NIST SP 800-171-compliant file sharing?
NIST SP 800-171-compliant file sharing generally means a controlled approach to Controlled Unclassified Information exchanged in nonfederal environments that keeps recipient, access and activity controls around the exchange.
For nist 800-171 compliance, the practical focus is on Controlled Unclassified Information exchanged in nonfederal environments rather than treating every file as an open link or an unmanaged attachment. The practical test is whether the process gives the team enough control for the sensitivity of the file without creating workarounds that people are likely to bypass.
For more detail on the related MX workflow, see MX security and administration features. NIST SP 800-171 applies to the protection of CUI in covered nonfederal systems and organizations, so file transfer is only one part of the wider control environment.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. Where the workflow is business-critical, the organization should document who owns the process and who is responsible for reviewing exceptions or incomplete exchanges.
Does My MX Data by itself make an organization compliant with NIST SP 800-171?
No. Using My MX Data does not automatically make an organization compliant with NIST SP 800-171. The organization still needs to decide matters such as lawful use, data classification, retention, supplier due diligence, training and incident response where those duties apply.
Technology can support specific controls, but compliance also depends on the organization's policies, contracts, configuration, staff practices, risk decisions and wider governance. For higher-risk workflows, legal, compliance and security stakeholders should review the intended recipients, data type, access period and evidence requirements before rollout.
MX should be assessed as one part of that wider control environment rather than as a substitute for the organization's own compliance program. For more detail on the related MX workflow, see MX feature set.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. Controls also need to be configured appropriately; the presence of an encryption or audit feature does not prove that every exchange has been handled correctly.
How can access controls and multi-factor authentication help protect controlled unclassified information?
Protection in MX relies on several controls working together rather than a single security feature. The sender retains a clearer connection between the file, the intended recipient and the access window applied to that exchange.
AES-256 encryption forms part of the model alongside named-recipient access, permissions, multi-factor authentication, expiry controls and detailed activity records. For particularly sensitive information, MX can also use ASR (Anonymize, Shard and Restore) as an additional protection method that is distinct from conventional encryption.
For more detail on the related MX workflow, see file-exchange controls. Different transactions can carry different conditions, so routine material does not need to be handled exactly like highly sensitive information.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. Administrative oversight matters because access can change during a project as people join, leave or move between responsibilities.
How can audit records support accountability for CUI file exchanges?
MX records activity associated with file exchanges, giving relevant senders and administrators a clearer history after information has been shared. That history can help a team follow up on incomplete exchanges, investigate unexpected activity and prepare evidence for internal review.
Records may include uploads, access, downloads, comments, recipient activity, timestamps, transaction history and relevant user or IP details. NIST SP 800-171 applies to the protection of CUI in covered nonfederal systems and organizations, so file transfer is only one part of the wider control environment.
For more detail on the related MX workflow, see MX security and administration features. Notifications can also draw attention to pending downloads, new comments or expiring access without requiring somebody to check each exchange manually.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. A transaction record is most useful when it answers practical questions such as who accessed the file, when they did it and whether the current version was downloaded.
What role does encryption play when organizations exchange CUI with external parties?
Protection in MX relies on several controls working together rather than a single security feature. For particularly sensitive information, MX can also use ASR (Anonymize, Shard and Restore) as an additional protection method that is distinct from conventional encryption.
AES-256 encryption forms part of the model alongside named-recipient access, permissions, multi-factor authentication, expiry controls and detailed activity records. Layered controls are useful because identity, confidentiality and evidence solve different parts of the file-exchange problem.
For more detail on the related MX workflow, see encrypted file sharing. Administrative oversight matters because access can change during a project as people join, leave or move between responsibilities. NIST SP 800-171 applies to the protection of CUI in covered nonfederal systems and organizations, so file transfer is only one part of the wider control environment.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. Security still depends on the wider environment, including endpoint protection, account management, recipient behavior and the organization's own operating procedures.
Can recipient permissions, expiry settings and data-location requirements be configured for sensitive workflows?
Yes. MX supports expiry settings and configurable access conditions, helping teams avoid leaving sensitive files available indefinitely after the business purpose has passed. NIST SP 800-171 applies to the protection of CUI in covered nonfederal systems and organizations, so file transfer is only one part of the wider control environment.
Recipient permissions and download conditions can add further control where the relevant workflow supports them. The sender retains a clearer connection between the file, the intended recipient and the access window applied to that exchange.
For more detail on the related MX workflow, see file-exchange controls. Different transactions can carry different conditions, so routine material does not need to be handled exactly like highly sensitive information.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. Administrative oversight matters because access can change during a project as people join, leave or move between responsibilities.
Can contractors and suppliers exchange large technical files through MX without arbitrary file-size restrictions?
Yes. MX is designed to support very large files and complete datasets without arbitrary file-size restrictions. This is useful for engineering, media, software and project teams that need to move complete working packages without breaking the process apart.
That can include CUI, technical data and contract-related information, reducing the need to split an exchange across multiple uploads or move it to another tool simply because the file is large. Keeping the complete package in one controlled exchange can reduce workarounds such as compression, fragmented uploads or use of an unapproved temporary transfer tool.
For more detail on the related MX workflow, see controlled large-file exchange.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. NIST SP 800-171 applies to the protection of CUI in covered nonfederal systems and organizations, so file transfer is only one part of the wider control environment.
Which NIST SP 800-171 controls and organizational responsibilities sit outside the file-sharing platform itself?
MX can support Controlled Unclassified Information exchanged in nonfederal environments with controls designed around recipient identity, access conditions and a traceable exchange history. Different transactions can carry different conditions, so routine material does not need to be handled exactly like highly sensitive information.
That is useful where contractors, suppliers and approved project participants need to handle CUI, technical data and contract-related information without losing sight of who received the information and what happened next.
For more detail on the related MX workflow, see MX feature set. Notifications can also draw attention to pending downloads, new comments or expiring access without requiring somebody to check each exchange manually. The sender retains a clearer connection between the file, the intended recipient and the access window applied to that exchange.
The NIST SP 800-171 Rev. 3 is the primary reference for the security requirements used to protect CUI in covered nonfederal systems and organizations. NIST SP 800-171 applies to the protection of CUI in covered nonfederal systems and organizations, so file transfer is only one part of the wider control environment.
Put NIST 800-171 Compliance into a controlled workflow your team can actually use.
Start with a seven-day trial for up to five users, or speak to the team about a larger deployment, SSO or governance requirements. No credit card is required for the trial.