Back to Frameworks

NIST SP 800-171 Rev 3

United States
vRev 3 (May 2024)
17 domains
97 controls

NIST SP 800-171 Rev 3 (May 2024). Restructured requirements for CUI protection. Note CMMC 2.0 still references Rev 2.

Verified

NIST SP 800-171 Rev 3 is a compliance framework from United States with 17 domains and 97 controls that map to 41 other frameworks. The largest domains are 03.01 AC (Access Control) (16 controls), 03.04 CM (Configuration Management) (10 controls), 03.13 SC (System and Communications Protection) (10 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (17)

03.01 AC (Access Control)

16 controls
Controls in the 03.01 AC (Access Control) domain of NIST SP 800-171 Rev 316 controls
CodeTitle
03.01.01Account Management
03.01.02Access Enforcement
03.01.03Information Flow Enforcement
03.01.04Separation of Duties
03.01.05Least Privilege
03.01.06Least Privilege - Privileged Accounts
03.01.07Least Privilege - Privileged Functions
03.01.08Unsuccessful Logon Attempts
03.01.09System Use Notification
03.01.10Device Lock
03.01.11Session Termination
03.01.12Remote Access
03.01.16Wireless Access
03.01.18Access Control for Mobile Devices
03.01.20Use of External Systems
03.01.22Publicly Accessible Content

03.02 AT (Awareness and Training)

2 controls
Controls in the 03.02 AT (Awareness and Training) domain of NIST SP 800-171 Rev 32 controls
CodeTitle
03.02.01Literacy Training and Awareness
03.02.02Role-Based Training

03.03 AU (Audit and Accountability)

8 controls
Controls in the 03.03 AU (Audit and Accountability) domain of NIST SP 800-171 Rev 38 controls
CodeTitle
03.03.01Event Logging
03.03.02Audit Record Content
03.03.03Audit Record Generation
03.03.04Response to Audit Logging Process Failures
03.03.05Audit Record Review, Analysis, and Reporting
03.03.06Audit Record Reduction and Report Generation
03.03.07Time Stamps
03.03.08Protection of Audit Information

03.04 CM (Configuration Management)

10 controls
Controls in the 03.04 CM (Configuration Management) domain of NIST SP 800-171 Rev 310 controls
CodeTitle
03.04.01Baseline Configuration
03.04.02Configuration Settings
03.04.03Configuration Change Control
03.04.04Impact Analyses
03.04.05Access Restrictions for Change
03.04.06Least Functionality
03.04.08Authorized Software - Allow by Exception
03.04.10System Component Inventory
03.04.11Information Location
03.04.12System and Component Configuration for High-Risk Areas

03.05 IA (Identification and Authentication)

8 controls
Controls in the 03.05 IA (Identification and Authentication) domain of NIST SP 800-171 Rev 38 controls
CodeTitle
03.05.01User Identification and Authentication
03.05.02Device Identification and Authentication
03.05.03Multi-Factor Authentication
03.05.04Replay-Resistant Authentication
03.05.05Identifier Management
03.05.07Password Management
03.05.11Authentication Feedback
03.05.12Authenticator Management

03.06 IR (Incident Response)

5 controls
Controls in the 03.06 IR (Incident Response) domain of NIST SP 800-171 Rev 35 controls
CodeTitle
03.06.01Incident Handling
03.06.02Incident Monitoring, Reporting, and Response Assistance
03.06.03Incident Response Testing
03.06.04Incident Response Training
03.06.05Incident Response Plan

03.07 MA (Maintenance)

3 controls
Controls in the 03.07 MA (Maintenance) domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.07.04Maintenance Tools
03.07.05Nonlocal Maintenance
03.07.06Maintenance Personnel

03.08 MP (Media Protection)

7 controls
Controls in the 03.08 MP (Media Protection) domain of NIST SP 800-171 Rev 37 controls
CodeTitle
03.08.01Media Storage
03.08.02Media Access
03.08.03Media Sanitization
03.08.04Media Marking
03.08.05Media Transport
03.08.07Media Use
03.08.09System Backup - Cryptographic Protection

03.09 PS (Personnel Security)

2 controls
Controls in the 03.09 PS (Personnel Security) domain of NIST SP 800-171 Rev 32 controls
CodeTitle
03.09.01Personnel Screening
03.09.02Personnel Termination and Transfer

03.10 PE (Physical Protection)

5 controls
Controls in the 03.10 PE (Physical Protection) domain of NIST SP 800-171 Rev 35 controls
CodeTitle
03.10.01Physical Access Authorizations
03.10.02Monitoring Physical Access
03.10.06Alternate Work Site
03.10.07Physical Access Control
03.10.08Access Control for Transmission

03.11 RA (Risk Assessment)

3 controls
Controls in the 03.11 RA (Risk Assessment) domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.11.01Risk Assessment
03.11.02Vulnerability Monitoring and Scanning
03.11.04Risk Response

03.12 CA (Security Assessment and Monitoring)

4 controls
Controls in the 03.12 CA (Security Assessment and Monitoring) domain of NIST SP 800-171 Rev 34 controls
CodeTitle
03.12.01Security Assessment
03.12.02Plan of Action and Milestones
03.12.03Continuous Monitoring
03.12.05Information Exchange

03.13 SC (System and Communications Protection)

10 controls
Controls in the 03.13 SC (System and Communications Protection) domain of NIST SP 800-171 Rev 310 controls
CodeTitle
03.13.01Boundary Protection
03.13.04Information in Shared System Resources
03.13.06Network Communications - Deny by Default - Allow by Exception
03.13.08Transmission Confidentiality and Integrity
03.13.09Network Disconnect
03.13.10Cryptographic Key Establishment and Management
03.13.11Cryptographic Protection
03.13.12Collaborative Computing Devices and Applications
03.13.13Mobile Code
03.13.15Session Authenticity

03.14 SI (System and Information Integrity)

5 controls
Controls in the 03.14 SI (System and Information Integrity) domain of NIST SP 800-171 Rev 35 controls
CodeTitle
03.14.01Flaw Remediation
03.14.02Malicious Code Protection
03.14.03Security Alerts, Advisories, and Directives
03.14.06System Monitoring
03.14.08Information Management and Retention

03.15 PL (Planning)

3 controls
Controls in the 03.15 PL (Planning) domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.15.01Policy and Procedures
03.15.02System Security Plan
03.15.03Rules of Behavior

03.16 SA (System and Services Acquisition)

3 controls
Controls in the 03.16 SA (System and Services Acquisition) domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.16.01Security Engineering Principles
03.16.02Unsupported System Components
03.16.03External System Services

03.17 SR (Supply Chain Risk Management)

3 controls
Controls in the 03.17 SR (Supply Chain Risk Management) domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.17.01Supply Chain Risk Management Plan
03.17.02Acquisition Strategies, Tools, and Methods
03.17.03Supply Chain Requirements and Processes

Maps to 41 other frameworks

97 total controls
FedRAMP Moderate
97 source controls mapped|216 target controls covered
100%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
96 source controls mapped|132 target controls covered
99%
FedRAMP High
96 source controls mapped|215 target controls covered
99%
ISO 27001:2022
96 source controls mapped|74 target controls covered
99%
NIST SP 800-53 Rev 5
95 source controls mapped|133 target controls covered
98%
NIST SP 800-53 Rev 5 MODERATE
92 source controls mapped|168 target controls covered
95%
NIST SP 800-53 Revision 5.1 HIGH
92 source controls mapped|170 target controls covered
95%
NIST Cybersecurity Framework 2.0
88 source controls mapped|77 target controls covered
91%
CMMC 2.0
88 source controls mapped|107 target controls covered
91%
PCI DSS 4.0
87 source controls mapped|211 target controls covered
90%
C5 (Germany)
87 source controls mapped|101 target controls covered
90%
NIST SP 800-161 Rev 1
82 source controls mapped|105 target controls covered
85%
ISO 27002:2022
79 source controls mapped|72 target controls covered
81%
CIS Controls v8
74 source controls mapped|115 target controls covered
76%
SOC 2
72 source controls mapped|39 target controls covered
74%
HIPAA Security Rule
71 source controls mapped|50 target controls covered
73%
NIST SP 800-53 Rev 5 LOW
70 source controls mapped|102 target controls covered
72%
AWS Well-Architected Security Pillar
70 source controls mapped|62 target controls covered
72%
Azure Security Benchmark
68 source controls mapped|74 target controls covered
70%
NIST SP 800-66 Rev 2
68 source controls mapped|44 target controls covered
70%
ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
67 source controls mapped|42 target controls covered
69%
NIST SP 800-172
49 source controls mapped|32 target controls covered
51%
CFTC System Safeguards (17 CFR 37, 38, 39, 49)
48 source controls mapped|22 target controls covered
49%
ISO 27701:2019
44 source controls mapped|45 target controls covered
45%
Australia Consumer Data Right - Banking (CDR)
42 source controls mapped|13 target controls covered
43%
NIS2 Directive
37 source controls mapped|18 target controls covered
38%
UK Cyber Essentials
36 source controls mapped|36 target controls covered
37%
ACSC Essential Eight
32 source controls mapped|20 target controls covered
33%
ASD Strategies to Mitigate Cyber Security Incidents
32 source controls mapped|36 target controls covered
33%
APRA CPS 234
23 source controls mapped|21 target controls covered
24%
APRA CPS 230 Operational Risk Management
20 source controls mapped|17 target controls covered
21%
NIST SP 800-218
17 source controls mapped|20 target controls covered
18%
Authorised Economic Operator (AEO) Programmes - Global Standards
8 source controls mapped|6 target controls covered
8%
ISO/IEC 42001:2023
3 source controls mapped|3 target controls covered
3%
NIST SP 800-53A Rev. 5
3 source controls mapped|5 target controls covered
3%
NIST SP 800-181
3 source controls mapped|4 target controls covered
3%
ISO 27018:2019
2 source controls mapped|2 target controls covered
2%
ISO/IEC 23894:2023
1 source controls mapped|2 target controls covered
1%
ISO 22301:2019
1 source controls mapped|2 target controls covered
1%
ISO 31000:2018
1 source controls mapped|1 target controls covered
1%

What is NIST SP 800-171 Rev 3 and who does it apply to?

NIST SP 800-171 Rev 3 is a compliance framework from United States with 17 domains and 97 controls. NIST SP 800-171 Rev 3 (May 2024). Restructured requirements for CUI protection. Note CMMC 2.0 still references Rev 2. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does NIST SP 800-171 Rev 3 actually require?

NIST SP 800-171 Rev 3 has 97 controls organised across 17 domains. The largest domains are 03.01 AC (Access Control) (16 controls), 03.04 CM (Configuration Management) (10 controls), 03.13 SC (System and Communications Protection) (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of NIST SP 800-171 Rev 3 do I already cover?

NIST SP 800-171 Rev 3 maps to 41 other compliance frameworks. The top mapping partners are FedRAMP Moderate (100% coverage), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (99% coverage), FedRAMP High (99% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement NIST SP 800-171 Rev 3?

Start your NIST SP 800-171 Rev 3 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-171 Rev 3 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 97 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required