NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)
NIST SP 800-171A Revision 3 provides the assessment procedures for the 97 active security requirements of NIST SP 800-171 Rev 3. Each procedure sets out the assessment objective and the examine, interview and test methods used to determine whether a requirement is implemented and operating. Used by CMMC assessors, DoD contractors and federal agencies.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (17)
171A 03.01 Access Control
| Code | Title |
|---|---|
| 171A-03.01.01 | Account Management |
| 171A-03.01.02 | Access Enforcement |
| 171A-03.01.03 | Information Flow Enforcement |
| 171A-03.01.04 | Separation of Duties |
| 171A-03.01.05 | Least Privilege |
| 171A-03.01.06 | Least Privilege - Privileged Accounts |
| 171A-03.01.07 | Least Privilege - Privileged Functions |
| 171A-03.01.08 | Unsuccessful Logon Attempts |
| 171A-03.01.09 | System Use Notification |
| 171A-03.01.10 | Device Lock |
| 171A-03.01.11 | Session Termination |
| 171A-03.01.12 | Remote Access |
| 171A-03.01.16 | Wireless Access |
| 171A-03.01.18 | Access Control for Mobile Devices |
| 171A-03.01.20 | Use of External Systems |
| 171A-03.01.22 | Publicly Accessible Content |
171A 03.02 Awareness and Training
| Code | Title |
|---|---|
| 171A-03.02.01 | Literacy Training and Awareness |
| 171A-03.02.02 | Role-Based Training |
171A 03.03 Audit and Accountability
| Code | Title |
|---|---|
| 171A-03.03.01 | Event Logging |
| 171A-03.03.02 | Audit Record Content |
| 171A-03.03.03 | Audit Record Generation |
| 171A-03.03.04 | Response to Audit Logging Process Failures |
| 171A-03.03.05 | Audit Record Review, Analysis, and Reporting |
| 171A-03.03.06 | Audit Record Reduction and Report Generation |
| 171A-03.03.07 | Time Stamps |
| 171A-03.03.08 | Protection of Audit Information |
171A 03.04 Configuration Management
| Code | Title |
|---|---|
| 171A-03.04.01 | Baseline Configuration |
| 171A-03.04.02 | Configuration Settings |
| 171A-03.04.03 | Configuration Change Control |
| 171A-03.04.04 | Impact Analyses |
| 171A-03.04.05 | Access Restrictions for Change |
| 171A-03.04.06 | Least Functionality |
| 171A-03.04.08 | Authorized Software - Allow by Exception |
| 171A-03.04.10 | System Component Inventory |
| 171A-03.04.11 | Information Location |
| 171A-03.04.12 | System and Component Configuration for High-Risk Areas |
171A 03.05 Identification and Authentication
| Code | Title |
|---|---|
| 171A-03.05.01 | User Identification, Authentication, and Re-Authentication |
| 171A-03.05.02 | Device Identification and Authentication |
| 171A-03.05.03 | Multi-Factor Authentication |
| 171A-03.05.04 | Replay-Resistant Authentication |
| 171A-03.05.05 | Identifier Management |
| 171A-03.05.07 | Password Management |
| 171A-03.05.11 | Authentication Feedback |
| 171A-03.05.12 | Authenticator Management |
171A 03.06 Incident Response
| Code | Title |
|---|---|
| 171A-03.06.01 | Incident Handling |
| 171A-03.06.02 | Incident Monitoring, Reporting, and Response Assistance |
| 171A-03.06.03 | Incident Response Testing |
| 171A-03.06.04 | Incident Response Training |
| 171A-03.06.05 | Incident Response Plan |
171A 03.07 Maintenance
| Code | Title |
|---|---|
| 171A-03.07.04 | Maintenance Tools |
| 171A-03.07.05 | Nonlocal Maintenance |
| 171A-03.07.06 | Maintenance Personnel |
171A 03.08 Media Protection
| Code | Title |
|---|---|
| 171A-03.08.01 | Media Storage |
| 171A-03.08.02 | Media Access |
| 171A-03.08.03 | Media Sanitization |
| 171A-03.08.04 | Media Marking |
| 171A-03.08.05 | Media Transport |
| 171A-03.08.07 | Media Use |
| 171A-03.08.09 | System Backup - Cryptographic Protection |
171A 03.09 Personnel Security
| Code | Title |
|---|---|
| 171A-03.09.01 | Personnel Screening |
| 171A-03.09.02 | Personnel Termination and Transfer |
171A 03.10 Physical Protection
| Code | Title |
|---|---|
| 171A-03.10.01 | Physical Access Authorizations |
| 171A-03.10.02 | Monitoring Physical Access |
| 171A-03.10.06 | Alternate Work Site |
| 171A-03.10.07 | Physical Access Control |
| 171A-03.10.08 | Access Control for Transmission |
171A 03.11 Risk Assessment
| Code | Title |
|---|---|
| 171A-03.11.01 | Risk Assessment |
| 171A-03.11.02 | Vulnerability Monitoring and Scanning |
| 171A-03.11.04 | Risk Response |
171A 03.12 Security Assessment and Monitoring
| Code | Title |
|---|---|
| 171A-03.12.01 | Security Assessment |
| 171A-03.12.02 | Plan of Action and Milestones |
| 171A-03.12.03 | Continuous Monitoring |
| 171A-03.12.05 | Information Exchange |
171A 03.13 System and Communications Protection
| Code | Title |
|---|---|
| 171A-03.13.01 | Boundary Protection |
| 171A-03.13.04 | Information in Shared System Resources |
| 171A-03.13.06 | Network Communications - Deny by Default - Allow by Exception |
| 171A-03.13.08 | Transmission and Storage Confidentiality |
| 171A-03.13.09 | Network Disconnect |
| 171A-03.13.10 | Cryptographic Key Establishment and Management |
| 171A-03.13.11 | Cryptographic Protection |
| 171A-03.13.12 | Collaborative Computing Devices and Applications |
| 171A-03.13.13 | Mobile Code |
| 171A-03.13.15 | Session Authenticity |
171A 03.14 System and Information Integrity
| Code | Title |
|---|---|
| 171A-03.14.01 | Flaw Remediation |
| 171A-03.14.02 | Malicious Code Protection |
| 171A-03.14.03 | Security Alerts, Advisories, and Directives |
| 171A-03.14.06 | System Monitoring |
| 171A-03.14.08 | Information Management and Retention |
171A 03.15 Planning
| Code | Title |
|---|---|
| 171A-03.15.01 | Policy and Procedures |
| 171A-03.15.02 | System Security Plan |
| 171A-03.15.03 | Rules of Behavior |
171A 03.16 System and Services Acquisition
| Code | Title |
|---|---|
| 171A-03.16.01 | Systems Security Engineering Principles |
| 171A-03.16.02 | Unsupported System Components |
| 171A-03.16.03 | External System Services |
171A 03.17 Supply Chain Risk Management
| Code | Title |
|---|---|
| 171A-03.17.01 | Supply Chain Risk Management Plan |
| 171A-03.17.02 | Acquisition Strategies, Tools, and Methods |
| 171A-03.17.03 | Supply Chain Requirements and Processes |
Your Compliance Coverage
If you comply with NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI), you already cover:
NIST SP 800-53 Rev 5
4%
4 controls mapped
Compare →NIST SP 800-171 Rev 3
4%
4 controls mapped
Compare →ISO 22301:2019
4%
4 controls mapped
Compare →+ 16 more: FedRAMP High (4%), FedRAMP Moderate (4%)
See all 19 mapped frameworks ↓Maps to 19 other frameworks
Frequently Asked Questions
What is NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)?
NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) is a compliance framework from United States with 17 domains and 97 controls. NIST SP 800-171A Revision 3 provides the assessment procedures for the 97 active security requirements of NIST SP 800-171 Rev 3. Each procedure sets out the assessment objective and the examine, interview and test methods used to determine whether a requirement is implemented and operating. Used by CMMC assessors, DoD contractors and federal agencies. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) have?
NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) has 97 controls organised across 17 domains. The largest domains are 171A 03.01 Access Control (16 controls), 171A 03.04 Configuration Management (10 controls), 171A 03.13 System and Communications Protection (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) map to?
NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) maps to 19 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (4% coverage), NIST SP 800-171 Rev 3 (4% coverage), ISO 22301:2019 (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) compliance?
Start your NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 97 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required