Back to Frameworks

NIST SP 800-171 Rev 3

United States
34 domains
194 controls

NIST SP 800-171 Rev 3 (May 2024). Restructured requirements for CUI protection. Note CMMC 2.0 still references Rev 2.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (34)

03.01 AC (Access Control)

16 controls
Controls in the 03.01 AC (Access Control) domain of NIST SP 800-171 Rev 316 controls
CodeTitle
03.01.01Account Management
03.01.02Access Enforcement
03.01.03Information Flow Enforcement
03.01.04Separation of Duties
03.01.05Least Privilege
03.01.06Least Privilege - Privileged Accounts
03.01.07Least Privilege - Privileged Functions
03.01.08Unsuccessful Logon Attempts
03.01.09System Use Notification
03.01.10Device Lock
03.01.11Session Termination
03.01.12Remote Access
03.01.16Wireless Access
03.01.18Access Control for Mobile Devices
03.01.20Use of External Systems
03.01.22Publicly Accessible Content

03.02 AT (Awareness and Training)

2 controls
Controls in the 03.02 AT (Awareness and Training) domain of NIST SP 800-171 Rev 32 controls
CodeTitle
03.02.01Literacy Training and Awareness
03.02.02Role-Based Training

03.03 AU (Audit and Accountability)

8 controls
Controls in the 03.03 AU (Audit and Accountability) domain of NIST SP 800-171 Rev 38 controls
CodeTitle
03.03.01Event Logging
03.03.02Audit Record Content
03.03.03Audit Record Generation
03.03.04Response to Audit Logging Process Failures
03.03.05Audit Record Review, Analysis, and Reporting
03.03.06Audit Record Reduction and Report Generation
03.03.07Time Stamps
03.03.08Protection of Audit Information

03.04 CM (Configuration Management)

10 controls
Controls in the 03.04 CM (Configuration Management) domain of NIST SP 800-171 Rev 310 controls
CodeTitle
03.04.01Baseline Configuration
03.04.02Configuration Settings
03.04.03Configuration Change Control
03.04.04Impact Analyses
03.04.05Access Restrictions for Change
03.04.06Least Functionality
03.04.08Authorized Software - Allow by Exception
03.04.10System Component Inventory
03.04.11Information Location
03.04.12System and Component Configuration for High-Risk Areas

03.05 IA (Identification and Authentication)

8 controls
Controls in the 03.05 IA (Identification and Authentication) domain of NIST SP 800-171 Rev 38 controls
CodeTitle
03.05.01User Identification and Authentication
03.05.02Device Identification and Authentication
03.05.03Multi-Factor Authentication
03.05.04Replay-Resistant Authentication
03.05.05Identifier Management
03.05.07Password Management
03.05.11Authentication Feedback
03.05.12Authenticator Management

03.06 IR (Incident Response)

5 controls
Controls in the 03.06 IR (Incident Response) domain of NIST SP 800-171 Rev 35 controls
CodeTitle
03.06.01Incident Handling
03.06.02Incident Monitoring, Reporting, and Response Assistance
03.06.03Incident Response Testing
03.06.04Incident Response Training
03.06.05Incident Response Plan

03.07 MA (Maintenance)

3 controls
Controls in the 03.07 MA (Maintenance) domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.07.04Maintenance Tools
03.07.05Nonlocal Maintenance
03.07.06Maintenance Personnel

03.08 MP (Media Protection)

7 controls
Controls in the 03.08 MP (Media Protection) domain of NIST SP 800-171 Rev 37 controls
CodeTitle
03.08.01Media Storage
03.08.02Media Access
03.08.03Media Sanitization
03.08.04Media Marking
03.08.05Media Transport
03.08.07Media Use
03.08.09System Backup - Cryptographic Protection

03.09 PS (Personnel Security)

2 controls
Controls in the 03.09 PS (Personnel Security) domain of NIST SP 800-171 Rev 32 controls
CodeTitle
03.09.01Personnel Screening
03.09.02Personnel Termination and Transfer

03.10 PE (Physical Protection)

5 controls
Controls in the 03.10 PE (Physical Protection) domain of NIST SP 800-171 Rev 35 controls
CodeTitle
03.10.01Physical Access Authorizations
03.10.02Monitoring Physical Access
03.10.06Alternate Work Site
03.10.07Physical Access Control
03.10.08Access Control for Transmission

03.11 RA (Risk Assessment)

3 controls
Controls in the 03.11 RA (Risk Assessment) domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.11.01Risk Assessment
03.11.02Vulnerability Monitoring and Scanning
03.11.04Risk Response

03.12 CA (Security Assessment and Monitoring)

4 controls
Controls in the 03.12 CA (Security Assessment and Monitoring) domain of NIST SP 800-171 Rev 34 controls
CodeTitle
03.12.01Security Assessment
03.12.02Plan of Action and Milestones
03.12.03Continuous Monitoring
03.12.05Information Exchange

03.13 SC (System and Communications Protection)

10 controls
Controls in the 03.13 SC (System and Communications Protection) domain of NIST SP 800-171 Rev 310 controls
CodeTitle
03.13.01Boundary Protection
03.13.04Information in Shared System Resources
03.13.06Network Communications - Deny by Default - Allow by Exception
03.13.08Transmission Confidentiality and Integrity
03.13.09Network Disconnect
03.13.10Cryptographic Key Establishment and Management
03.13.11Cryptographic Protection
03.13.12Collaborative Computing Devices and Applications
03.13.13Mobile Code
03.13.15Session Authenticity

03.14 SI (System and Information Integrity)

5 controls
Controls in the 03.14 SI (System and Information Integrity) domain of NIST SP 800-171 Rev 35 controls
CodeTitle
03.14.01Flaw Remediation
03.14.02Malicious Code Protection
03.14.03Security Alerts, Advisories, and Directives
03.14.06System Monitoring
03.14.08Information Management and Retention

03.15 PL (Planning)

3 controls
Controls in the 03.15 PL (Planning) domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.15.01Policy and Procedures
03.15.02System Security Plan
03.15.03Rules of Behavior

03.16 SA (System and Services Acquisition)

3 controls
Controls in the 03.16 SA (System and Services Acquisition) domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.16.01Security Engineering Principles
03.16.02Unsupported System Components
03.16.03External System Services

03.17 SR (Supply Chain Risk Management)

3 controls
Controls in the 03.17 SR (Supply Chain Risk Management) domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.17.01Supply Chain Risk Management Plan
03.17.02Acquisition Strategies, Tools, and Methods
03.17.03Supply Chain Requirements and Processes

Access Control 03.01

16 controls
Controls in the Access Control 03.01 domain of NIST SP 800-171 Rev 316 controls
CodeTitle
03.01.01Account Management
03.01.02Access Enforcement
03.01.03Information Flow Enforcement
03.01.04Separation of Duties
03.01.05Least Privilege
03.01.06Least Privilege - Privileged Accounts
03.01.07Least Privilege - Privileged Functions
03.01.08Unsuccessful Logon Attempts
03.01.09System Use Notification
03.01.10Device Lock
03.01.11Session Termination
03.01.12Remote Access
03.01.16Wireless Access
03.01.18Access Control for Mobile Devices
03.01.20Use of External Systems
03.01.22Publicly Accessible Content

Audit Accountability 03.03

8 controls
Controls in the Audit Accountability 03.03 domain of NIST SP 800-171 Rev 38 controls
CodeTitle
03.03.01Event Logging
03.03.02Audit Record Content
03.03.03Audit Record Generation
03.03.04Response to Audit Logging Process Failures
03.03.05Audit Record Review, Analysis, and Reporting
03.03.06Audit Record Reduction and Report Generation
03.03.07Time Stamps
03.03.08Protection of Audit Information

Awareness Training 03.02

2 controls
Controls in the Awareness Training 03.02 domain of NIST SP 800-171 Rev 32 controls
CodeTitle
03.02.01Literacy Training and Awareness
03.02.02Role-Based Training

Configuration Mgmt 03.04

10 controls
Controls in the Configuration Mgmt 03.04 domain of NIST SP 800-171 Rev 310 controls
CodeTitle
03.04.01Baseline Configuration
03.04.02Configuration Settings
03.04.03Configuration Change Control
03.04.04Impact Analyses
03.04.05Access Restrictions for Change
03.04.06Least Functionality
03.04.08Authorized Software - Allow by Exception
03.04.10System Component Inventory
03.04.11Information Location
03.04.12System and Component Configuration for High-Risk Areas

Identification Authentication 03.05

8 controls
Controls in the Identification Authentication 03.05 domain of NIST SP 800-171 Rev 38 controls
CodeTitle
03.05.01User Identification and Authentication
03.05.02Device Identification and Authentication
03.05.03Multi-Factor Authentication
03.05.04Replay-Resistant Authentication
03.05.05Identifier Management
03.05.07Password Management
03.05.11Authentication Feedback
03.05.12Authenticator Management

Incident Response 03.06

5 controls
Controls in the Incident Response 03.06 domain of NIST SP 800-171 Rev 35 controls
CodeTitle
03.06.01Incident Handling
03.06.02Incident Monitoring, Reporting, and Response Assistance
03.06.03Incident Response Testing
03.06.04Incident Response Training
03.06.05Incident Response Plan

Maintenance 03.07

3 controls
Controls in the Maintenance 03.07 domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.07.04Maintenance Tools
03.07.05Nonlocal Maintenance
03.07.06Maintenance Personnel

Media Protection 03.08

7 controls
Controls in the Media Protection 03.08 domain of NIST SP 800-171 Rev 37 controls
CodeTitle
03.08.01Media Storage
03.08.02Media Access
03.08.03Media Sanitization
03.08.04Media Marking
03.08.05Media Transport
03.08.07Media Use
03.08.09System Backup - Cryptographic Protection

Personnel Security 03.09

2 controls
Controls in the Personnel Security 03.09 domain of NIST SP 800-171 Rev 32 controls
CodeTitle
03.09.01Personnel Screening
03.09.02Personnel Termination and Transfer

Physical Protection 03.10

5 controls
Controls in the Physical Protection 03.10 domain of NIST SP 800-171 Rev 35 controls
CodeTitle
03.10.01Physical Access Authorizations
03.10.02Monitoring Physical Access
03.10.06Alternate Work Site
03.10.07Physical Access Control
03.10.08Access Control for Transmission

Planning 03.15

3 controls
Controls in the Planning 03.15 domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.15.01Policy and Procedures
03.15.02System Security Plan
03.15.03Rules of Behavior

Risk Assessment 03.11

3 controls
Controls in the Risk Assessment 03.11 domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.11.01Risk Assessment
03.11.02Vulnerability Monitoring and Scanning
03.11.04Risk Response

Security Assessment 03.12

4 controls
Controls in the Security Assessment 03.12 domain of NIST SP 800-171 Rev 34 controls
CodeTitle
03.12.01Security Assessment
03.12.02Plan of Action and Milestones
03.12.03Continuous Monitoring
03.12.05Information Exchange

Supply Chain Risk Mgmt 03.17

3 controls
Controls in the Supply Chain Risk Mgmt 03.17 domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.17.01Supply Chain Risk Management Plan
03.17.02Acquisition Strategies, Tools, and Methods
03.17.03Supply Chain Requirements and Processes

System Communications Protection 03.13

10 controls
Controls in the System Communications Protection 03.13 domain of NIST SP 800-171 Rev 310 controls
CodeTitle
03.13.01Boundary Protection
03.13.04Information in Shared System Resources
03.13.06Network Communications - Deny by Default - Allow by Exception
03.13.08Transmission Confidentiality and Integrity
03.13.09Network Disconnect
03.13.10Cryptographic Key Establishment and Management
03.13.11Cryptographic Protection
03.13.12Collaborative Computing Devices and Applications
03.13.13Mobile Code
03.13.15Session Authenticity

System Information Integrity 03.14

5 controls
Controls in the System Information Integrity 03.14 domain of NIST SP 800-171 Rev 35 controls
CodeTitle
03.14.01Flaw Remediation
03.14.02Malicious Code Protection
03.14.03Security Alerts, Advisories, and Directives
03.14.06System Monitoring
03.14.08Information Management and Retention

System Services Acquisition 03.16

3 controls
Controls in the System Services Acquisition 03.16 domain of NIST SP 800-171 Rev 33 controls
CodeTitle
03.16.01Security Engineering Principles
03.16.02Unsupported System Components
03.16.03External System Services

Frequently Asked Questions

What is NIST SP 800-171 Rev 3?

NIST SP 800-171 Rev 3 is a compliance framework from United States with 34 domains and 194 controls. NIST SP 800-171 Rev 3 (May 2024). Restructured requirements for CUI protection. Note CMMC 2.0 still references Rev 2. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-171 Rev 3 have?

NIST SP 800-171 Rev 3 has 194 controls organised across 34 domains. The largest domains are 03.01 AC (Access Control) (16 controls), Access Control 03.01 (16 controls), 03.04 CM (Configuration Management) (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-171 Rev 3 map to?

NIST SP 800-171 Rev 3 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with NIST SP 800-171 Rev 3 compliance?

Start your NIST SP 800-171 Rev 3 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-171 Rev 3 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 194 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required