Back to Frameworks

NIST SP 800-171

United States
vRev 3
30 domains
93 controls

Protecting Controlled Unclassified Information in Nonfederal Systems

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (30)

Access Control

3 controls
Controls in the Access Control domain of NIST SP 800-1713 controls
CodeTitle
171-AC-1Access Control Policy and Procedures
171-AC-2Least Privilege and Separation of Duties
171-AC-3Remote Access and Mobile Devices

Access Control Assessment

6 controls
Controls in the Access Control Assessment domain of NIST SP 800-1716 controls
CodeTitle
3.1.1Authorized Access Control
3.1.2Transaction and Function Control
3.1.20External Connections Control
A.03.01.01Account Management Assessment
A.03.01.05Least Privilege Assessment
A.03.01.12Remote Access Assessment

Audit and Accountability

2 controls
Controls in the Audit and Accountability domain of NIST SP 800-1712 controls
CodeTitle
171-AU-1Audit Event Capture
171-AU-2Audit Review and Analysis

Audit and Accountability Assessment

3 controls
Controls in the Audit and Accountability Assessment domain of NIST SP 800-1713 controls
CodeTitle
3.3.1Audit Record Creation
A.03.03.01Event Logging Assessment
SP800-171-3.5.2Authenticate identities before access

Awareness and Training

1 controls
Controls in the Awareness and Training domain of NIST SP 800-1711 controls
CodeTitle
171-AT-1Security Awareness and Role-Based Training

Configuration Management

2 controls
Controls in the Configuration Management domain of NIST SP 800-1712 controls
CodeTitle
171-CM-1Baseline Configuration and Inventory
SP800-171-3.5.1Identify system users, processes, and devices

Configuration Management Assessment

4 controls
Controls in the Configuration Management Assessment domain of NIST SP 800-1714 controls
CodeTitle
3.4.1Baseline Configuration Maintenance
3.4.6Least Functionality
A.03.04.01Baseline Configuration Assessment
A.03.04.02Configuration Settings Assessment

Identification and Authentication

2 controls
Controls in the Identification and Authentication domain of NIST SP 800-1712 controls
CodeTitle
171-IA-1Identification and Authentication
171-IA-2Multi-Factor Authentication

Identification and Authentication Assessment

2 controls
Controls in the Identification and Authentication Assessment domain of NIST SP 800-1712 controls
CodeTitle
3.5.3Multi Factor Authentication
A.03.05.03Multi Factor Authentication Assessment

Incident Response

2 controls
Controls in the Incident Response domain of NIST SP 800-1712 controls
CodeTitle
171-IR-1Incident Handling Capability
171-IR-2Incident Reporting

Incident Response Assessment

2 controls
Controls in the Incident Response Assessment domain of NIST SP 800-1712 controls
CodeTitle
3.6.1Incident Response Capability
A.03.06.01Incident Handling Assessment

Maintenance

1 controls
Controls in the Maintenance domain of NIST SP 800-1711 controls
CodeTitle
171-MA-1Maintenance Authorisation and Control

Maintenance Assessment

1 controls
Controls in the Maintenance Assessment domain of NIST SP 800-1711 controls
CodeTitle
A.03.07.04Maintenance Tools Assessment

Media Protection

1 controls
Controls in the Media Protection domain of NIST SP 800-1711 controls
CodeTitle
171-MP-1Media Protection

Media Protection Assessment

2 controls
Controls in the Media Protection Assessment domain of NIST SP 800-1712 controls
CodeTitle
3.8.3Media Sanitization
A.03.08.03Media Sanitization Assessment

NIST SP 800-171: Access Control & Identity

6 controls

Managing access to information systems (NIST SP 800-171)

Controls in the NIST SP 800-171: Access Control & Identity domain of NIST SP 800-1716 controls
CodeTitle
SP800-171-3.5.10Store and transmit only encrypted passwords
SP800-171-3.5.4Replay-resistant authentication
SP800-171-3.6.1Operational incident-handling capability
SP800-171-3.6.2Track, document, and report incidents
SP800-171-3.6.3Test incident response capability
SP800-171-3.7.1Perform system maintenance

NIST SP 800-171: Audit & Accountability

5 controls

Audit logging and accountability measures (NIST SP 800-171)

Controls in the NIST SP 800-171: Audit & Accountability domain of NIST SP 800-1715 controls
CodeTitle
SP800-171-3.13.16Protect confidentiality of CUI at rest
SP800-171-3.14.1Identify, report, and correct flaws
SP800-171-3.14.2Malicious code protection
SP800-171-3.14.3Monitor security alerts and advisories
SP800-171-3.14.6Monitor systems and traffic for attacks

NIST SP 800-171: Configuration Management

5 controls

Managing system configurations securely (NIST SP 800-171)

Controls in the NIST SP 800-171: Configuration Management domain of NIST SP 800-1715 controls
CodeTitle
SP800-171-3.12.3Continuously monitor controls
SP800-171-3.13.1Monitor and protect communications at boundaries
SP800-171-3.13.11Employ FIPS-validated cryptography
SP800-171-3.13.6Deny network traffic by default
SP800-171-3.13.8Encrypt CUI in transmission

NIST SP 800-171: Incident Response

5 controls

Detecting and responding to security incidents (NIST SP 800-171)

Controls in the NIST SP 800-171: Incident Response domain of NIST SP 800-1715 controls
CodeTitle
SP800-171-3.11.1Periodically assess risk
SP800-171-3.11.2Scan for vulnerabilities
SP800-171-3.11.3Remediate vulnerabilities
SP800-171-3.12.1Periodically assess security controls
SP800-171-3.12.2Plans of action for deficiencies

NIST SP 800-171: Risk Assessment & Management

5 controls

Identifying and managing cybersecurity risks (NIST SP 800-171)

Controls in the NIST SP 800-171: Risk Assessment & Management domain of NIST SP 800-1715 controls
CodeTitle
SP800-171-3.10.1Limit physical access
SP800-171-3.10.3Escort and monitor visitors
SP800-171-3.10.6Safeguard CUI at alternate work sites
SP800-171-3.9.1Screen individuals before CUI access
SP800-171-3.9.2Protect CUI during personnel actions

NIST SP 800-171: System & Communications Protection

6 controls

Protecting systems and communications (NIST SP 800-171)

Controls in the NIST SP 800-171: System & Communications Protection domain of NIST SP 800-1716 controls
CodeTitle
SP800-171-3.7.2Control maintenance tools and personnel
SP800-171-3.7.5MFA for nonlocal maintenance
SP800-171-3.8.1Protect system media containing CUI
SP800-171-3.8.3Sanitize or destroy media before disposal
SP800-171-3.8.6Encrypt CUI on digital media during transport
SP800-171-3.8.7Control removable media

Personnel Security Assessment

2 controls
Controls in the Personnel Security Assessment domain of NIST SP 800-1712 controls
CodeTitle
3.9.2Personnel Transfer and Termination
A.03.09.02Personnel Termination Assessment

Physical Protection

1 controls
Controls in the Physical Protection domain of NIST SP 800-1711 controls
CodeTitle
171-PE-1Physical Access Authorisations

Physical Protection Assessment

1 controls
Controls in the Physical Protection Assessment domain of NIST SP 800-1711 controls
CodeTitle
3.10.6Alternate Work Site Safeguards

Physical and Environmental Protection Assessment

1 controls
Controls in the Physical and Environmental Protection Assessment domain of NIST SP 800-1711 controls
CodeTitle
A.03.10.01Physical Access Authorization Assessment

Planning

1 controls
Controls in the Planning domain of NIST SP 800-1711 controls
CodeTitle
A.03.15.01System Security Plan Assessment

Risk Assessment

6 controls
Controls in the Risk Assessment domain of NIST SP 800-1716 controls
CodeTitle
171-RA-1Risk Assessment
171-RA-2Vulnerability Scanning and Remediation
3.11.1Risk Assessments
3.11.2Vulnerability Scanning
A.03.11.01Risk Assessment Process
A.03.11.02Vulnerability Monitoring Assessment

Security Assessment

2 controls
Controls in the Security Assessment domain of NIST SP 800-1712 controls
CodeTitle
3.12.1Security Control Assessment
A.03.12.01Security Control Assessments

System and Communications Protection

7 controls
Controls in the System and Communications Protection domain of NIST SP 800-1717 controls
CodeTitle
171-SC-1Boundary Protection
171-SC-2Encryption of Controlled Unclassified Information
3.13.11Cryptographic Protection
3.13.5Network Segmentation
3.13.8Transmission Confidentiality
A.03.13.11Cryptographic Protection of CUI at Rest
SP800-171-3.5.3Multifactor authentication for privileged/network access

System and Information Integrity

6 controls
Controls in the System and Information Integrity domain of NIST SP 800-1716 controls
CodeTitle
171-SI-1Flaw Remediation
171-SI-2Malicious Code Protection
3.14.1Flaw Remediation
3.14.6Monitoring for Attacks
A.03.14.01Flaw Remediation Assessment
A.03.14.06System Monitoring Assessment

Your Compliance Coverage

If you comply with NIST SP 800-171, you already cover:

Maps to 221 other frameworks

93 total controls
NIST SP 800-53 Rev 5
37 source controls mapped|40 target controls covered
40%
NIST SP 800-207
9 source controls mapped|28 target controls covered
10%
ACSC Essential Eight
4 source controls mapped|15 target controls covered
4%
2%
NIST SP 800-146
2 source controls mapped|1 target controls covered
2%
NIST SP 800-145
2 source controls mapped|1 target controls covered
2%
NIST SP 800-144
2 source controls mapped|1 target controls covered
2%
MTCS (Singapore)
2 source controls mapped|2 target controls covered
2%
ISMAP (Japan)
2 source controls mapped|1 target controls covered
2%
HITECH Act
2 source controls mapped|2 target controls covered
2%
Ghana Cybersecurity Act
2 source controls mapped|3 target controls covered
2%
FTC GLBA Safeguards Rule (16 CFR Part 314)
2 source controls mapped|2 target controls covered
2%
FISMA
2 source controls mapped|2 target controls covered
2%
FedRAMP Rev 5
2 source controls mapped|3 target controls covered
2%
Saudi NCA ECC
2 source controls mapped|6 target controls covered
2%
BSI IT-Grundschutz
2 source controls mapped|6 target controls covered
2%
TISAX - Trusted Information Security Assessment Exchange
2 source controls mapped|4 target controls covered
2%
AWS Well-Architected Security Pillar
2 source controls mapped|2 target controls covered
2%
Telecommunications Sector Security Reforms (TSSR)
2 source controls mapped|2 target controls covered
2%
Protective Security Policy Framework (PSPF) Release 2024
2 source controls mapped|2 target controls covered
2%
FFIEC Cybersecurity Assessment Tool (CAT)
2 source controls mapped|2 target controls covered
2%
Spain ENS
2 source controls mapped|6 target controls covered
2%
ISO 27001:2022
2 source controls mapped|4 target controls covered
2%
ISO 27018
2 source controls mapped|2 target controls covered
2%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
2 source controls mapped|3 target controls covered
2%
OWASP DevSecOps Maturity Model (DSOMM)
2 source controls mapped|2 target controls covered
2%
ISO 27017
2 source controls mapped|2 target controls covered
2%
US Executive Order 14028 - Improving the Nation's Cybersecurity
2 source controls mapped|2 target controls covered
2%
TEFCA - Trusted Exchange Framework and Common Agreement
2 source controls mapped|2 target controls covered
2%
Belgium CyberFundamentals
2 source controls mapped|6 target controls covered
2%
Annex 11 to EU GMP - Computerised Systems
2 source controls mapped|2 target controls covered
2%
OWASP Top 10:2025
2 source controls mapped|1 target controls covered
2%
South Korea ISMS-P
2 source controls mapped|2 target controls covered
2%
UK Gambling Commission - Cyber Resilience Requirements
2 source controls mapped|2 target controls covered
2%
Azure Security Benchmark
2 source controls mapped|2 target controls covered
2%
NIST SP 800-190
2 source controls mapped|2 target controls covered
2%
TSA Pipeline Cybersecurity Directives
2 source controls mapped|2 target controls covered
2%
ISO/IEC 27010:2015
1 source controls mapped|1 target controls covered
1%
Oman National Cybersecurity Framework
1 source controls mapped|1 target controls covered
1%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
1 source controls mapped|1 target controls covered
1%
NIST SP 800-122
1 source controls mapped|1 target controls covered
1%
NIS2 Directive Implementing Acts
1 source controls mapped|1 target controls covered
1%
NIS2 Directive
1 source controls mapped|2 target controls covered
1%
Nigeria Open Banking Regulatory Framework (CBN, 2023)
1 source controls mapped|1 target controls covered
1%
Nigeria Data Protection Regulation (NDPR)
1 source controls mapped|1 target controls covered
1%
Nigeria Data Protection Act 2023 (NDPA)
1 source controls mapped|4 target controls covered
1%
Nebraska Data Privacy Act
1 source controls mapped|4 target controls covered
1%
New Jersey Data Privacy Act
1 source controls mapped|2 target controls covered
1%
New Hampshire Data Privacy Act
1 source controls mapped|1 target controls covered
1%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|1 target controls covered
1%
NERC CIP
1 source controls mapped|1 target controls covered
1%
Montana Consumer Data Privacy Act
1 source controls mapped|1 target controls covered
1%
Monetary Authority of Singapore Technology Risk Management Guidelines
1 source controls mapped|1 target controls covered
1%
Minnesota Consumer Data Privacy Act
1 source controls mapped|1 target controls covered
1%
Mexico LFPDPPP
1 source controls mapped|1 target controls covered
1%
Mauritius DPA
1 source controls mapped|1 target controls covered
1%
Maryland Online Data Privacy Act of 2024
1 source controls mapped|2 target controls covered
1%
Malaysia PDPA 2010
1 source controls mapped|2 target controls covered
1%
Liechtenstein DPA
1 source controls mapped|1 target controls covered
1%
LGPD
1 source controls mapped|1 target controls covered
1%
Ley Orgánica de Protección de Datos Personales (LOPDP)
1 source controls mapped|1 target controls covered
1%
Law No. 172-13 on the Protection of Personal Data
1 source controls mapped|1 target controls covered
1%
Laos Law on Prevention and Combating Cybercrime (2015)
1 source controls mapped|1 target controls covered
1%
South Korea PIPA
1 source controls mapped|2 target controls covered
1%
Kentucky Consumer Data Protection Act
1 source controls mapped|2 target controls covered
1%
Japan FSA Cybersecurity Guidelines for Financial Institutions
1 source controls mapped|1 target controls covered
1%
Jamaica Data Protection Act 2020
1 source controls mapped|2 target controls covered
1%
Iowa Consumer Data Protection Act
1 source controls mapped|2 target controls covered
1%
Indonesia PDP Law
1 source controls mapped|2 target controls covered
1%
Indiana Consumer Data Protection Act
1 source controls mapped|1 target controls covered
1%
India DPDP Act
1 source controls mapped|1 target controls covered
1%
India CERT-In Cyber Security Directions 2022
1 source controls mapped|1 target controls covered
1%
IEEE 1686
1 source controls mapped|1 target controls covered
1%
1%
HKMA SPM
1 source controls mapped|1 target controls covered
1%
HKMA Cyber Resilience Assessment Framework (C-RAF)
1 source controls mapped|1 target controls covered
1%
GLBA
1 source controls mapped|2 target controls covered
1%
FIRST CSIRT Services Framework and Standards
1 source controls mapped|1 target controls covered
1%
Family Educational Rights and Privacy Act (FERPA)
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27400:2022
1 source controls mapped|1 target controls covered
1%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
1 source controls mapped|1 target controls covered
1%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|2 target controls covered
1%
NIST Cybersecurity Framework 2.0
1 source controls mapped|3 target controls covered
1%
ISO 27019
1 source controls mapped|3 target controls covered
1%
PDPA Singapore
1 source controls mapped|2 target controls covered
1%
PCI PIN Security
1 source controls mapped|3 target controls covered
1%
SOC for Cybersecurity - Cybersecurity Risk Management Examination
1 source controls mapped|1 target controls covered
1%
Bahrain PDPL
1 source controls mapped|2 target controls covered
1%
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data
1 source controls mapped|1 target controls covered
1%
Serbia Law on Personal Data Protection (2018)
1 source controls mapped|1 target controls covered
1%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|2 target controls covered
1%
APRA CPS 234
1 source controls mapped|3 target controls covered
1%
Philippines DPA
1 source controls mapped|2 target controls covered
1%
Philippines Data Privacy Act (RA 10173)
1 source controls mapped|3 target controls covered
1%
ISO 22320:2018
1 source controls mapped|3 target controls covered
1%
Turkey KVKK
1 source controls mapped|2 target controls covered
1%
Turkey Personal Data Protection Law (KVKK - Law No. 6698)
1 source controls mapped|2 target controls covered
1%
Singapore Payment Services Act (PSA) - Digital Payment Token Regulation
1 source controls mapped|2 target controls covered
1%
Taiwan PDPA
1 source controls mapped|2 target controls covered
1%
Open Banking Security
1 source controls mapped|3 target controls covered
1%
Uruguay DPL
1 source controls mapped|2 target controls covered
1%
Switzerland FADP
1 source controls mapped|2 target controls covered
1%
API 1164
1 source controls mapped|3 target controls covered
1%
IEC 62443
1 source controls mapped|3 target controls covered
1%
PDPA Thailand
1 source controls mapped|2 target controls covered
1%
PCI SSF
1 source controls mapped|3 target controls covered
1%
Qatar DPL
1 source controls mapped|2 target controls covered
1%
Voluntary Principles on Security and Human Rights (VPs)
1 source controls mapped|1 target controls covered
1%
Saudi Arabia PDPL
1 source controls mapped|2 target controls covered
1%
Barbados Data Protection Act 2019
1 source controls mapped|1 target controls covered
1%
Zambia Data Protection Act (2021)
1 source controls mapped|1 target controls covered
1%
OSFI B-13
1 source controls mapped|3 target controls covered
1%
ISO 20000-1
1 source controls mapped|1 target controls covered
1%
Peru DPL
1 source controls mapped|2 target controls covered
1%
SWIFT CSP
1 source controls mapped|3 target controls covered
1%
NIST SP 1800-32
1 source controls mapped|3 target controls covered
1%
Privacy Act 2020
1 source controls mapped|2 target controls covered
1%
Tennessee IPA
1 source controls mapped|2 target controls covered
1%
POPIA
1 source controls mapped|2 target controls covered
1%
SANS Incident Handler's Handbook and PICERL Methodology
1 source controls mapped|3 target controls covered
1%
PCI P2PE
1 source controls mapped|3 target controls covered
1%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|1 target controls covered
1%
UK Data Protection Act 2018
1 source controls mapped|2 target controls covered
1%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|2 target controls covered
1%
Security of Critical Infrastructure Act 2018 (SOCI)
1 source controls mapped|3 target controls covered
1%
US NRC 10 CFR 73.54 - Cyber Security for Nuclear Power Plants
1 source controls mapped|1 target controls covered
1%
UK Open Banking Standard
1 source controls mapped|1 target controls covered
1%
Pakistan Personal Data Protection Bill 2023
1 source controls mapped|1 target controls covered
1%
FFIEC IT Examination Handbook
1 source controls mapped|3 target controls covered
1%
EASA Part-IS - Information Security in Aviation
1 source controls mapped|3 target controls covered
1%
Oregon Consumer Privacy Act
1 source controls mapped|2 target controls covered
1%
RFC 2350 - Expectations for Computer Security Incident Response (BCP 21)
1 source controls mapped|3 target controls covered
1%
ISO 28001:2007 Supply Chain Security Management
1 source controls mapped|1 target controls covered
1%
Rwanda DPL
1 source controls mapped|2 target controls covered
1%
UK Telecommunications (Security) Act 2021
1 source controls mapped|2 target controls covered
1%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
1 source controls mapped|2 target controls covered
1%
South Korea Cloud Security Assurance Program (CSAP)
1 source controls mapped|2 target controls covered
1%
ISO/IEC 30111:2019
1 source controls mapped|2 target controls covered
1%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
1%
TSA Pipeline Security
1 source controls mapped|3 target controls covered
1%
AICPA Privacy Management Framework (PMF)
1 source controls mapped|1 target controls covered
1%
SSAE 18 - Attestation Standards (SOC Reporting)
1 source controls mapped|2 target controls covered
1%
Singapore Cybersecurity Act 2018
1 source controls mapped|1 target controls covered
1%
SWIFT CSCF
1 source controls mapped|3 target controls covered
1%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
1 source controls mapped|1 target controls covered
1%
Canada ITSG-33 - IT Security Risk Management
1 source controls mapped|1 target controls covered
1%
NFPA 1600 - Standard on Continuity, Emergency, and Crisis Management
1 source controls mapped|1 target controls covered
1%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
1%
Privacy Act 1988 (Australia)
1 source controls mapped|2 target controls covered
1%
Vietnam PDPD
1 source controls mapped|2 target controls covered
1%
APPI
1 source controls mapped|2 target controls covered
1%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
1 source controls mapped|1 target controls covered
1%
Tanzania Personal Data Protection Act (Draft)
1 source controls mapped|1 target controls covered
1%
Trinidad and Tobago Data Protection Act 2011
1 source controls mapped|1 target controls covered
1%
Utah Consumer Privacy Act
1 source controls mapped|2 target controls covered
1%
APRA CPS 230 Operational Risk Management
1 source controls mapped|1 target controls covered
1%
PSD2 SCA
1 source controls mapped|3 target controls covered
1%
SOC 2
1 source controls mapped|2 target controls covered
1%
Papua New Guinea National Cybersecurity Policy & Cybercrime Act (2016)
1 source controls mapped|1 target controls covered
1%
RBI Cybersecurity Framework for Banks
1 source controls mapped|1 target controls covered
1%
1%
Virginia CDPA
1 source controls mapped|2 target controls covered
1%
Zimbabwe Data Protection Act (2021)
1 source controls mapped|1 target controls covered
1%
NIST AI Risk Management Framework (AI RMF 1.0)
1 source controls mapped|2 target controls covered
1%
Sri Lanka Personal Data Protection Act (No. 9 of 2022)
1 source controls mapped|1 target controls covered
1%
Personal Data Act (personopplysningsloven)
1 source controls mapped|2 target controls covered
1%
Regulation (EU) 2019/1239 on the Maritime Single Window (MSW)
1 source controls mapped|1 target controls covered
1%
ITIL 4
1 source controls mapped|1 target controls covered
1%
Texas Data Privacy Act
1 source controls mapped|2 target controls covered
1%
UK GDPR (UK General Data Protection Regulation)
1 source controls mapped|1 target controls covered
1%
O-RAN WG11 Security Specification
1 source controls mapped|1 target controls covered
1%
NIST SP 800-92
1 source controls mapped|1 target controls covered
1%
NIST SP 800-88
1 source controls mapped|1 target controls covered
1%
NIST SP 800-66
1 source controls mapped|1 target controls covered
1%
NIST SP 800-63-4
1 source controls mapped|1 target controls covered
1%
NIST SP 800-61
1 source controls mapped|1 target controls covered
1%
NIST SP 800-137
1 source controls mapped|1 target controls covered
1%
NIST SP 800-123
1 source controls mapped|1 target controls covered
1%
NIST Privacy Framework
1 source controls mapped|1 target controls covered
1%
NAIC Insurance Data Security Model Law (MDL-668)
1 source controls mapped|1 target controls covered
1%
MITRE D3FEND
1 source controls mapped|1 target controls covered
1%
MITRE ATT&CK
1 source controls mapped|1 target controls covered
1%
MDS2 (Medical Device)
1 source controls mapped|1 target controls covered
1%
MARS-E
1 source controls mapped|2 target controls covered
1%
ICH E6(R3) - Good Clinical Practice
1 source controls mapped|1 target controls covered
1%
HL7 FHIR Security Framework
1 source controls mapped|2 target controls covered
1%
GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
1 source controls mapped|1 target controls covered
1%
GHG Protocol
1 source controls mapped|1 target controls covered
1%
FDA 21 CFR Part 11
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27011:2024
1 source controls mapped|1 target controls covered
1%
Canada Artificial Intelligence and Data Act (AIDA)
1 source controls mapped|1 target controls covered
1%
SLSA
1 source controls mapped|1 target controls covered
1%
ISO 27799
1 source controls mapped|1 target controls covered
1%
UNECE WP.29 R155
1 source controls mapped|1 target controls covered
1%
ISO 27043
1 source controls mapped|1 target controls covered
1%
SSDF (NIST)
1 source controls mapped|1 target controls covered
1%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|1 target controls covered
1%
ISO 13485
1 source controls mapped|1 target controls covered
1%
SIG (Shared Assessments)
1 source controls mapped|1 target controls covered
1%
Sigstore - Software Artifact Signing and Verification
1 source controls mapped|1 target controls covered
1%
PTES
1 source controls mapped|1 target controls covered
1%
ISO/SAE 21434
1 source controls mapped|1 target controls covered
1%
UK PSTI Act
1 source controls mapped|1 target controls covered
1%
OWASP MASVS
1 source controls mapped|1 target controls covered
1%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
1 source controls mapped|1 target controls covered
1%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
1 source controls mapped|1 target controls covered
1%
Secure by Design: A Guide for Manufacturers (CISA)
1 source controls mapped|1 target controls covered
1%
OWASP ASVS
1 source controls mapped|1 target controls covered
1%
UNECE WP.29 R156
1 source controls mapped|1 target controls covered
1%
ISO/IEC 25012:2008 - Data Quality Model
1 source controls mapped|1 target controls covered
1%
OWASP SAMM
1 source controls mapped|1 target controls covered
1%
OpenSSF Scorecard
1 source controls mapped|1 target controls covered
1%

Frequently Asked Questions

What is NIST SP 800-171?

NIST SP 800-171 is a compliance framework from United States with 30 domains and 93 controls. Protecting Controlled Unclassified Information in Nonfederal Systems It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-171 have?

NIST SP 800-171 has 93 controls organised across 30 domains. The largest domains are System and Communications Protection (7 controls), Access Control Assessment (6 controls), NIST SP 800-171: Access Control & Identity (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-171 map to?

NIST SP 800-171 maps to 221 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (40% coverage), NIST SP 800-207 (10% coverage), ACSC Essential Eight (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NIST SP 800-171 compliance?

Start your NIST SP 800-171 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-171 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 93 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required