NIST 800-171 lays out the specific security controls a company has to have in place to protect Controlled Unclassified Information on its own, non-government systems. It is the rulebook CMMC compliance is actually measured against, so if a contract requires you to safeguard CUI, this standard applies whether or not a formal CMMC certification is also required. Working through it is a real project, covering access control, incident response, and system monitoring among other areas, so treat it as infrastructure to build before you need it, not paperwork to produce after a solicitation asks for it.
In a sentence
"The contractor shall implement the security requirements specified in NIST SP 800-171 to protect covered defense information." That single sentence can mean months of security work behind the scenes, so read it as an early flag to assess your systems, not a box you check at proposal time.