Back to Frameworks

NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)

United States
vRevision 3 (May 2024)
17 domains
97 controls

NIST SP 800-171A Revision 3 provides the assessment procedures for the 97 active security requirements of NIST SP 800-171 Rev 3. Each procedure sets out the assessment objective and the examine, interview and test methods used to determine whether a requirement is implemented and operating. Used by CMMC assessors, DoD contractors and federal agencies.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (17)

171A 03.01 Access Control

16 controls
Controls in the 171A 03.01 Access Control domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)16 controls
CodeTitle
171A-03.01.01Account Management
171A-03.01.02Access Enforcement
171A-03.01.03Information Flow Enforcement
171A-03.01.04Separation of Duties
171A-03.01.05Least Privilege
171A-03.01.06Least Privilege - Privileged Accounts
171A-03.01.07Least Privilege - Privileged Functions
171A-03.01.08Unsuccessful Logon Attempts
171A-03.01.09System Use Notification
171A-03.01.10Device Lock
171A-03.01.11Session Termination
171A-03.01.12Remote Access
171A-03.01.16Wireless Access
171A-03.01.18Access Control for Mobile Devices
171A-03.01.20Use of External Systems
171A-03.01.22Publicly Accessible Content

171A 03.02 Awareness and Training

2 controls
Controls in the 171A 03.02 Awareness and Training domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)2 controls
CodeTitle
171A-03.02.01Literacy Training and Awareness
171A-03.02.02Role-Based Training

171A 03.03 Audit and Accountability

8 controls
Controls in the 171A 03.03 Audit and Accountability domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)8 controls
CodeTitle
171A-03.03.01Event Logging
171A-03.03.02Audit Record Content
171A-03.03.03Audit Record Generation
171A-03.03.04Response to Audit Logging Process Failures
171A-03.03.05Audit Record Review, Analysis, and Reporting
171A-03.03.06Audit Record Reduction and Report Generation
171A-03.03.07Time Stamps
171A-03.03.08Protection of Audit Information

171A 03.04 Configuration Management

10 controls
Controls in the 171A 03.04 Configuration Management domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)10 controls
CodeTitle
171A-03.04.01Baseline Configuration
171A-03.04.02Configuration Settings
171A-03.04.03Configuration Change Control
171A-03.04.04Impact Analyses
171A-03.04.05Access Restrictions for Change
171A-03.04.06Least Functionality
171A-03.04.08Authorized Software - Allow by Exception
171A-03.04.10System Component Inventory
171A-03.04.11Information Location
171A-03.04.12System and Component Configuration for High-Risk Areas

171A 03.05 Identification and Authentication

8 controls
Controls in the 171A 03.05 Identification and Authentication domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)8 controls
CodeTitle
171A-03.05.01User Identification, Authentication, and Re-Authentication
171A-03.05.02Device Identification and Authentication
171A-03.05.03Multi-Factor Authentication
171A-03.05.04Replay-Resistant Authentication
171A-03.05.05Identifier Management
171A-03.05.07Password Management
171A-03.05.11Authentication Feedback
171A-03.05.12Authenticator Management

171A 03.06 Incident Response

5 controls
Controls in the 171A 03.06 Incident Response domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)5 controls
CodeTitle
171A-03.06.01Incident Handling
171A-03.06.02Incident Monitoring, Reporting, and Response Assistance
171A-03.06.03Incident Response Testing
171A-03.06.04Incident Response Training
171A-03.06.05Incident Response Plan

171A 03.07 Maintenance

3 controls
Controls in the 171A 03.07 Maintenance domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)3 controls
CodeTitle
171A-03.07.04Maintenance Tools
171A-03.07.05Nonlocal Maintenance
171A-03.07.06Maintenance Personnel

171A 03.08 Media Protection

7 controls
Controls in the 171A 03.08 Media Protection domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)7 controls
CodeTitle
171A-03.08.01Media Storage
171A-03.08.02Media Access
171A-03.08.03Media Sanitization
171A-03.08.04Media Marking
171A-03.08.05Media Transport
171A-03.08.07Media Use
171A-03.08.09System Backup - Cryptographic Protection

171A 03.09 Personnel Security

2 controls
Controls in the 171A 03.09 Personnel Security domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)2 controls
CodeTitle
171A-03.09.01Personnel Screening
171A-03.09.02Personnel Termination and Transfer

171A 03.10 Physical Protection

5 controls
Controls in the 171A 03.10 Physical Protection domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)5 controls
CodeTitle
171A-03.10.01Physical Access Authorizations
171A-03.10.02Monitoring Physical Access
171A-03.10.06Alternate Work Site
171A-03.10.07Physical Access Control
171A-03.10.08Access Control for Transmission

171A 03.11 Risk Assessment

3 controls
Controls in the 171A 03.11 Risk Assessment domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)3 controls
CodeTitle
171A-03.11.01Risk Assessment
171A-03.11.02Vulnerability Monitoring and Scanning
171A-03.11.04Risk Response

171A 03.12 Security Assessment and Monitoring

4 controls
Controls in the 171A 03.12 Security Assessment and Monitoring domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)4 controls
CodeTitle
171A-03.12.01Security Assessment
171A-03.12.02Plan of Action and Milestones
171A-03.12.03Continuous Monitoring
171A-03.12.05Information Exchange

171A 03.13 System and Communications Protection

10 controls
Controls in the 171A 03.13 System and Communications Protection domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)10 controls
CodeTitle
171A-03.13.01Boundary Protection
171A-03.13.04Information in Shared System Resources
171A-03.13.06Network Communications - Deny by Default - Allow by Exception
171A-03.13.08Transmission and Storage Confidentiality
171A-03.13.09Network Disconnect
171A-03.13.10Cryptographic Key Establishment and Management
171A-03.13.11Cryptographic Protection
171A-03.13.12Collaborative Computing Devices and Applications
171A-03.13.13Mobile Code
171A-03.13.15Session Authenticity

171A 03.14 System and Information Integrity

5 controls
Controls in the 171A 03.14 System and Information Integrity domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)5 controls
CodeTitle
171A-03.14.01Flaw Remediation
171A-03.14.02Malicious Code Protection
171A-03.14.03Security Alerts, Advisories, and Directives
171A-03.14.06System Monitoring
171A-03.14.08Information Management and Retention

171A 03.15 Planning

3 controls
Controls in the 171A 03.15 Planning domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)3 controls
CodeTitle
171A-03.15.01Policy and Procedures
171A-03.15.02System Security Plan
171A-03.15.03Rules of Behavior

171A 03.16 System and Services Acquisition

3 controls
Controls in the 171A 03.16 System and Services Acquisition domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)3 controls
CodeTitle
171A-03.16.01Systems Security Engineering Principles
171A-03.16.02Unsupported System Components
171A-03.16.03External System Services

171A 03.17 Supply Chain Risk Management

3 controls
Controls in the 171A 03.17 Supply Chain Risk Management domain of NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)3 controls
CodeTitle
171A-03.17.01Supply Chain Risk Management Plan
171A-03.17.02Acquisition Strategies, Tools, and Methods
171A-03.17.03Supply Chain Requirements and Processes

Your Compliance Coverage

If you comply with NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI), you already cover:

Maps to 19 other frameworks

97 total controls
NIST SP 800-53 Rev 5
4 source controls mapped|9 target controls covered
4%
NIST SP 800-171 Rev 3
4 source controls mapped|4 target controls covered
4%
ISO 22301:2019
4 source controls mapped|4 target controls covered
4%
FedRAMP High
4 source controls mapped|9 target controls covered
4%
FedRAMP Moderate
4 source controls mapped|9 target controls covered
4%
NIST SP 800-53 Revision 5.1 HIGH
4 source controls mapped|8 target controls covered
4%
NIST SP 800-53 Rev 5 MODERATE
4 source controls mapped|8 target controls covered
4%
CMMC 2.0
4 source controls mapped|4 target controls covered
4%
SOC 2
3 source controls mapped|2 target controls covered
3%
NIST Cybersecurity Framework 2.0
3 source controls mapped|5 target controls covered
3%
HIPAA Security Rule
3 source controls mapped|2 target controls covered
3%
NIST SP 800-66 Rev 2
3 source controls mapped|2 target controls covered
3%
NIST SP 800-53 Rev 5 LOW
3 source controls mapped|5 target controls covered
3%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
3 source controls mapped|7 target controls covered
3%
ISO 27002:2022
2 source controls mapped|3 target controls covered
2%
ISO 27001:2022
2 source controls mapped|3 target controls covered
2%
Azure Security Benchmark
2 source controls mapped|2 target controls covered
2%
CIS Controls v8
2 source controls mapped|2 target controls covered
2%
PCI DSS 4.0
2 source controls mapped|5 target controls covered
2%

Frequently Asked Questions

What is NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)?

NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) is a compliance framework from United States with 17 domains and 97 controls. NIST SP 800-171A Revision 3 provides the assessment procedures for the 97 active security requirements of NIST SP 800-171 Rev 3. Each procedure sets out the assessment objective and the examine, interview and test methods used to determine whether a requirement is implemented and operating. Used by CMMC assessors, DoD contractors and federal agencies. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) have?

NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) has 97 controls organised across 17 domains. The largest domains are 171A 03.01 Access Control (16 controls), 171A 03.04 Configuration Management (10 controls), 171A 03.13 System and Communications Protection (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) map to?

NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) maps to 19 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (4% coverage), NIST SP 800-171 Rev 3 (4% coverage), ISO 22301:2019 (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) compliance?

Start your NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 97 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required