Back to Frameworks

NIST SP 800-171

United States
vRev 3
30 domains
88 controls

Protecting Controlled Unclassified Information in Nonfederal Systems

Verified

NIST SP 800-171 is a compliance framework from United States with 30 domains and 88 controls that map to 8 other frameworks. The largest domains are System and Communications Protection (7 controls), NIST SP 800-171: Access Control & Identity (6 controls), NIST SP 800-171: System & Communications Protection (6 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (30)

Access Control

3 controls
Controls in the Access Control domain of NIST SP 800-1713 controls
CodeTitle
171-AC-1Access Control Policy and Procedures
171-AC-2Least Privilege and Separation of Duties
171-AC-3Remote Access and Mobile Devices

Access Control Assessment

4 controls
Controls in the Access Control Assessment domain of NIST SP 800-1714 controls
CodeTitle
3.1.20External Connections Control
A.03.01.01Account Management Assessment
A.03.01.05Least Privilege Assessment
A.03.01.12Remote Access Assessment

Audit and Accountability

2 controls
Controls in the Audit and Accountability domain of NIST SP 800-1712 controls
CodeTitle
171-AU-1Audit Event Capture
171-AU-2Audit Review and Analysis

Audit and Accountability Assessment

2 controls
Controls in the Audit and Accountability Assessment domain of NIST SP 800-1712 controls
CodeTitle
A.03.03.01Event Logging Assessment
SP800-171-3.5.2Authenticate identities before access

Awareness and Training

1 controls
Controls in the Awareness and Training domain of NIST SP 800-1711 controls
CodeTitle
171-AT-1Security Awareness and Role-Based Training

Configuration Management

2 controls
Controls in the Configuration Management domain of NIST SP 800-1712 controls
CodeTitle
171-CM-1Baseline Configuration and Inventory
SP800-171-3.5.1Identify system users, processes, and devices

Configuration Management Assessment

3 controls
Controls in the Configuration Management Assessment domain of NIST SP 800-1713 controls
CodeTitle
3.4.6Least Functionality
A.03.04.01Baseline Configuration Assessment
A.03.04.02Configuration Settings Assessment

Identification and Authentication

2 controls
Controls in the Identification and Authentication domain of NIST SP 800-1712 controls
CodeTitle
171-IA-1Identification and Authentication
171-IA-2Multi-Factor Authentication

Identification and Authentication Assessment

2 controls
Controls in the Identification and Authentication Assessment domain of NIST SP 800-1712 controls
CodeTitle
3.5.3Multi Factor Authentication
A.03.05.03Multi Factor Authentication Assessment

Incident Response

2 controls
Controls in the Incident Response domain of NIST SP 800-1712 controls
CodeTitle
171-IR-1Incident Handling Capability
171-IR-2Incident Reporting

Incident Response Assessment

1 controls
Controls in the Incident Response Assessment domain of NIST SP 800-1711 controls
CodeTitle
A.03.06.01Incident Handling Assessment

Maintenance

1 controls
Controls in the Maintenance domain of NIST SP 800-1711 controls
CodeTitle
171-MA-1Maintenance Authorisation and Control

Maintenance Assessment

1 controls
Controls in the Maintenance Assessment domain of NIST SP 800-1711 controls
CodeTitle
A.03.07.04Maintenance Tools Assessment

Media Protection

1 controls
Controls in the Media Protection domain of NIST SP 800-1711 controls
CodeTitle
171-MP-1Media Protection

Media Protection Assessment

2 controls
Controls in the Media Protection Assessment domain of NIST SP 800-1712 controls
CodeTitle
3.8.3Media Sanitization
A.03.08.03Media Sanitization Assessment

NIST SP 800-171: Access Control & Identity

6 controls

Managing access to information systems (NIST SP 800-171)

Controls in the NIST SP 800-171: Access Control & Identity domain of NIST SP 800-1716 controls
CodeTitle
SP800-171-3.5.10Store and transmit only encrypted passwords
SP800-171-3.5.4Replay-resistant authentication
SP800-171-3.6.1Operational incident-handling capability
SP800-171-3.6.2Track, document, and report incidents
SP800-171-3.6.3Test incident response capability
SP800-171-3.7.1Perform system maintenance

NIST SP 800-171: Audit & Accountability

5 controls

Audit logging and accountability measures (NIST SP 800-171)

Controls in the NIST SP 800-171: Audit & Accountability domain of NIST SP 800-1715 controls
CodeTitle
SP800-171-3.13.16Protect confidentiality of CUI at rest
SP800-171-3.14.1Identify, report, and correct flaws
SP800-171-3.14.2Malicious code protection
SP800-171-3.14.3Monitor security alerts and advisories
SP800-171-3.14.6Monitor systems and traffic for attacks

NIST SP 800-171: Configuration Management

5 controls

Managing system configurations securely (NIST SP 800-171)

Controls in the NIST SP 800-171: Configuration Management domain of NIST SP 800-1715 controls
CodeTitle
SP800-171-3.12.3Continuously monitor controls
SP800-171-3.13.1Monitor and protect communications at boundaries
SP800-171-3.13.11Employ FIPS-validated cryptography
SP800-171-3.13.6Deny network traffic by default
SP800-171-3.13.8Encrypt CUI in transmission

NIST SP 800-171: Incident Response

5 controls

Detecting and responding to security incidents (NIST SP 800-171)

Controls in the NIST SP 800-171: Incident Response domain of NIST SP 800-1715 controls
CodeTitle
SP800-171-3.11.1Periodically assess risk
SP800-171-3.11.2Scan for vulnerabilities
SP800-171-3.11.3Remediate vulnerabilities
SP800-171-3.12.1Periodically assess security controls
SP800-171-3.12.2Plans of action for deficiencies

NIST SP 800-171: Risk Assessment & Management

5 controls

Identifying and managing cybersecurity risks (NIST SP 800-171)

Controls in the NIST SP 800-171: Risk Assessment & Management domain of NIST SP 800-1715 controls
CodeTitle
SP800-171-3.10.1Limit physical access
SP800-171-3.10.3Escort and monitor visitors
SP800-171-3.10.6Safeguard CUI at alternate work sites
SP800-171-3.9.1Screen individuals before CUI access
SP800-171-3.9.2Protect CUI during personnel actions

NIST SP 800-171: System & Communications Protection

6 controls

Protecting systems and communications (NIST SP 800-171)

Controls in the NIST SP 800-171: System & Communications Protection domain of NIST SP 800-1716 controls
CodeTitle
SP800-171-3.7.2Control maintenance tools and personnel
SP800-171-3.7.5MFA for nonlocal maintenance
SP800-171-3.8.1Protect system media containing CUI
SP800-171-3.8.3Sanitize or destroy media before disposal
SP800-171-3.8.6Encrypt CUI on digital media during transport
SP800-171-3.8.7Control removable media

Personnel Security Assessment

2 controls
Controls in the Personnel Security Assessment domain of NIST SP 800-1712 controls
CodeTitle
3.9.2Personnel Transfer and Termination
A.03.09.02Personnel Termination Assessment

Physical Protection

1 controls
Controls in the Physical Protection domain of NIST SP 800-1711 controls
CodeTitle
171-PE-1Physical Access Authorisations

Physical Protection Assessment

1 controls
Controls in the Physical Protection Assessment domain of NIST SP 800-1711 controls
CodeTitle
3.10.6Alternate Work Site Safeguards

Physical and Environmental Protection Assessment

1 controls
Controls in the Physical and Environmental Protection Assessment domain of NIST SP 800-1711 controls
CodeTitle
A.03.10.01Physical Access Authorization Assessment

Planning

1 controls
Controls in the Planning domain of NIST SP 800-1711 controls
CodeTitle
A.03.15.01System Security Plan Assessment

Risk Assessment

6 controls
Controls in the Risk Assessment domain of NIST SP 800-1716 controls
CodeTitle
171-RA-1Risk Assessment
171-RA-2Vulnerability Scanning and Remediation
3.11.1Risk Assessments
3.11.2Vulnerability Scanning
A.03.11.01Risk Assessment Process
A.03.11.02Vulnerability Monitoring Assessment

Security Assessment

2 controls
Controls in the Security Assessment domain of NIST SP 800-1712 controls
CodeTitle
3.12.1Security Control Assessment
A.03.12.01Security Control Assessments

System and Communications Protection

7 controls
Controls in the System and Communications Protection domain of NIST SP 800-1717 controls
CodeTitle
171-SC-1Boundary Protection
171-SC-2Encryption of Controlled Unclassified Information
3.13.11Cryptographic Protection
3.13.5Network Segmentation
3.13.8Transmission Confidentiality
A.03.13.11Cryptographic Protection of CUI at Rest
SP800-171-3.5.3Multifactor authentication for privileged/network access

System and Information Integrity

6 controls
Controls in the System and Information Integrity domain of NIST SP 800-1716 controls
CodeTitle
171-SI-1Flaw Remediation
171-SI-2Malicious Code Protection
3.14.1Flaw Remediation
3.14.6Monitoring for Attacks
A.03.14.01Flaw Remediation Assessment
A.03.14.06System Monitoring Assessment

Your Compliance Coverage

If you comply with NIST SP 800-171, you already cover:

Maps to 8 other frameworks

88 total controls
NIST SP 800-53 Rev 5
35 source controls mapped|35 target controls covered
40%
NIST SP 800-207
9 source controls mapped|28 target controls covered
10%
ACSC Essential Eight
4 source controls mapped|15 target controls covered
5%
ISO 22301:2019
2 source controls mapped|2 target controls covered
2%
ISO 31000:2018
2 source controls mapped|1 target controls covered
2%
ISO/IEC 23894:2023
2 source controls mapped|2 target controls covered
2%
ISO 27018:2019
1 source controls mapped|1 target controls covered
1%
ISO 13485:2016
1 source controls mapped|1 target controls covered
1%

What is NIST SP 800-171 and who does it apply to?

NIST SP 800-171 is a compliance framework from United States with 30 domains and 88 controls. Protecting Controlled Unclassified Information in Nonfederal Systems It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does NIST SP 800-171 actually require?

NIST SP 800-171 has 88 controls organised across 30 domains. The largest domains are System and Communications Protection (7 controls), NIST SP 800-171: Access Control & Identity (6 controls), NIST SP 800-171: System & Communications Protection (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of NIST SP 800-171 do I already cover?

NIST SP 800-171 maps to 8 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (40% coverage), NIST SP 800-207 (10% coverage), ACSC Essential Eight (5% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement NIST SP 800-171?

Start your NIST SP 800-171 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-171 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 88 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required