NIST SP 800-171 Rev 3
NIST SP 800-171 Rev 3 (May 2024). Restructured requirements for CUI protection. Note CMMC 2.0 still references Rev 2.
NIST SP 800-171 Rev 3 is a compliance framework from United States with 17 domains and 97 controls that map to 41 other frameworks. The largest domains are 03.01 AC (Access Control) (16 controls), 03.04 CM (Configuration Management) (10 controls), 03.13 SC (System and Communications Protection) (10 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (17)
03.01 AC (Access Control)
| Code | Title |
|---|---|
| 03.01.01 | Account Management |
| 03.01.02 | Access Enforcement |
| 03.01.03 | Information Flow Enforcement |
| 03.01.04 | Separation of Duties |
| 03.01.05 | Least Privilege |
| 03.01.06 | Least Privilege - Privileged Accounts |
| 03.01.07 | Least Privilege - Privileged Functions |
| 03.01.08 | Unsuccessful Logon Attempts |
| 03.01.09 | System Use Notification |
| 03.01.10 | Device Lock |
| 03.01.11 | Session Termination |
| 03.01.12 | Remote Access |
| 03.01.16 | Wireless Access |
| 03.01.18 | Access Control for Mobile Devices |
| 03.01.20 | Use of External Systems |
| 03.01.22 | Publicly Accessible Content |
03.02 AT (Awareness and Training)
03.03 AU (Audit and Accountability)
| Code | Title |
|---|---|
| 03.03.01 | Event Logging |
| 03.03.02 | Audit Record Content |
| 03.03.03 | Audit Record Generation |
| 03.03.04 | Response to Audit Logging Process Failures |
| 03.03.05 | Audit Record Review, Analysis, and Reporting |
| 03.03.06 | Audit Record Reduction and Report Generation |
| 03.03.07 | Time Stamps |
| 03.03.08 | Protection of Audit Information |
03.04 CM (Configuration Management)
| Code | Title |
|---|---|
| 03.04.01 | Baseline Configuration |
| 03.04.02 | Configuration Settings |
| 03.04.03 | Configuration Change Control |
| 03.04.04 | Impact Analyses |
| 03.04.05 | Access Restrictions for Change |
| 03.04.06 | Least Functionality |
| 03.04.08 | Authorized Software - Allow by Exception |
| 03.04.10 | System Component Inventory |
| 03.04.11 | Information Location |
| 03.04.12 | System and Component Configuration for High-Risk Areas |
03.05 IA (Identification and Authentication)
| Code | Title |
|---|---|
| 03.05.01 | User Identification and Authentication |
| 03.05.02 | Device Identification and Authentication |
| 03.05.03 | Multi-Factor Authentication |
| 03.05.04 | Replay-Resistant Authentication |
| 03.05.05 | Identifier Management |
| 03.05.07 | Password Management |
| 03.05.11 | Authentication Feedback |
| 03.05.12 | Authenticator Management |
03.06 IR (Incident Response)
03.07 MA (Maintenance)
03.08 MP (Media Protection)
03.09 PS (Personnel Security)
03.10 PE (Physical Protection)
03.11 RA (Risk Assessment)
03.12 CA (Security Assessment and Monitoring)
03.13 SC (System and Communications Protection)
| Code | Title |
|---|---|
| 03.13.01 | Boundary Protection |
| 03.13.04 | Information in Shared System Resources |
| 03.13.06 | Network Communications - Deny by Default - Allow by Exception |
| 03.13.08 | Transmission Confidentiality and Integrity |
| 03.13.09 | Network Disconnect |
| 03.13.10 | Cryptographic Key Establishment and Management |
| 03.13.11 | Cryptographic Protection |
| 03.13.12 | Collaborative Computing Devices and Applications |
| 03.13.13 | Mobile Code |
| 03.13.15 | Session Authenticity |
03.14 SI (System and Information Integrity)
03.15 PL (Planning)
03.16 SA (System and Services Acquisition)
Your Compliance Coverage
If you comply with NIST SP 800-171 Rev 3, you already cover:
FedRAMP Moderate
100%
97 controls mapped
Compare →Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
99%
96 controls mapped
Compare →FedRAMP High
99%
96 controls mapped
Compare →+ 38 more: ISO 27001:2022 (99%), NIST SP 800-53 Rev 5 (98%)
See all 41 mapped frameworks ↓Maps to 41 other frameworks
What is NIST SP 800-171 Rev 3 and who does it apply to?
NIST SP 800-171 Rev 3 is a compliance framework from United States with 17 domains and 97 controls. NIST SP 800-171 Rev 3 (May 2024). Restructured requirements for CUI protection. Note CMMC 2.0 still references Rev 2. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does NIST SP 800-171 Rev 3 actually require?
NIST SP 800-171 Rev 3 has 97 controls organised across 17 domains. The largest domains are 03.01 AC (Access Control) (16 controls), 03.04 CM (Configuration Management) (10 controls), 03.13 SC (System and Communications Protection) (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of NIST SP 800-171 Rev 3 do I already cover?
NIST SP 800-171 Rev 3 maps to 41 other compliance frameworks. The top mapping partners are FedRAMP Moderate (100% coverage), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (99% coverage), FedRAMP High (99% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement NIST SP 800-171 Rev 3?
Start your NIST SP 800-171 Rev 3 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-171 Rev 3 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 97 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required