Back to Frameworks

NIST SP 800-172

United States
vFebruary 2021 edition
10 domains
35 controls

Enhanced Security Requirements for Protecting CUI

Verified

NIST SP 800-172 is a compliance framework from United States with 10 domains and 35 controls that map to 23 other frameworks. The largest domains are RA (7 controls), SI (7 controls), SC (5 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

AC

3 controls
Controls in the AC domain of NIST SP 800-1723 controls
CodeTitle
3.1.1eDual Authorization for Sensitive System Operations
3.1.2eRestrict Access to Organization-Owned, Provisioned, or Issued Information Resources
3.1.3eEmploy Secure Information Transfer Solutions

AT

2 controls
Controls in the AT domain of NIST SP 800-1722 controls
CodeTitle
3.2.1eProvide Awareness Training on Advanced Persistent Threat
3.2.2ePractical Exercises in Awareness Training

CA

1 controls
Controls in the CA domain of NIST SP 800-1721 controls
CodeTitle
3.12.1ePenetration Testing by Independent Agents

CM

3 controls
Controls in the CM domain of NIST SP 800-1723 controls
CodeTitle
3.4.1eAuthoritative Source for Software and Firmware
3.4.2eAutomated Detection and Remediation of Unauthorized Software
3.4.3eAutomated Inventory of System Components

IA

3 controls
Controls in the IA domain of NIST SP 800-1723 controls
CodeTitle
3.5.1eIdentification of Systems, Components, and Devices
3.5.2ePassword Manager Use
3.5.3eProhibit Connection of Unknown or Unverified System Components

IR

2 controls
Controls in the IR domain of NIST SP 800-1722 controls
CodeTitle
3.6.1eEstablish Security Operations Center (SOC)
3.6.2eEstablish and Maintain a Cyber Incident Response Team

PS

2 controls
Controls in the PS domain of NIST SP 800-1722 controls
CodeTitle
3.9.1eEnhanced Personnel Screening
3.9.2eInsider Threat Program

RA

7 controls
Controls in the RA domain of NIST SP 800-1727 controls
CodeTitle
3.11.1eThreat-Aware Risk Assessment
3.11.2eThreat Hunting
3.11.3eAdvanced Automation and Analytics Capabilities
3.11.4eSecurity Solution Rationale Document
3.11.5eAssess Effectiveness of Security Solutions
3.11.6eSupply Chain Risk Assessment, Response, and Monitoring
3.11.7eSupply Chain Risk Management Plan

SC

5 controls
Controls in the SC domain of NIST SP 800-1725 controls
CodeTitle
3.13.1eCreate Diversity in System Components to Limit Malicious Code Propagation
3.13.2eIntroduce Unpredictability into System Operations
3.13.3eConfuse and Mislead Adversaries
3.13.4ePhysical and Logical Isolation Techniques
3.13.5eDistribute and Relocate System Functions or Resources

SI

7 controls
Controls in the SI domain of NIST SP 800-1727 controls
CodeTitle
3.14.1eVerify Integrity of Security Critical Software and Firmware
3.14.2eMonitor Organizational Systems with Specialized Capabilities
3.14.3eInclude Systems in Scope of Enhanced Requirements or Segregate into Purpose-Specific Networks
3.14.4eRefresh Systems and Components from a Trusted Baseline
3.14.5eReview Persistent Storage and Remove CUI No Longer Needed
3.14.6eUse Threat Indicator Information for Detection
3.14.7eVerify Correctness of Security Functions

Your Compliance Coverage

If you comply with NIST SP 800-172, you already cover:

Maps to 23 other frameworks

35 total controls
NIST SP 800-161 Rev 1
35 source controls mapped|87 target controls covered
100%
NIST SP 800-53 Rev 5
35 source controls mapped|80 target controls covered
100%
C5 (Germany)
33 source controls mapped|46 target controls covered
94%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
33 source controls mapped|62 target controls covered
94%
PCI DSS 4.0
33 source controls mapped|79 target controls covered
94%
NIST Cybersecurity Framework 2.0
33 source controls mapped|63 target controls covered
94%
FedRAMP High
32 source controls mapped|91 target controls covered
91%
FedRAMP Moderate
32 source controls mapped|92 target controls covered
91%
NIST SP 800-171 Rev 3
32 source controls mapped|49 target controls covered
91%
NIST SP 800-53 Revision 5.1 HIGH
31 source controls mapped|63 target controls covered
89%
NIST SP 800-53 Rev 5 MODERATE
31 source controls mapped|60 target controls covered
89%
ISO 27002:2022
31 source controls mapped|48 target controls covered
89%
ISO 27001:2022
31 source controls mapped|48 target controls covered
89%
CMMC 2.0
30 source controls mapped|50 target controls covered
86%
CIS Controls v8
28 source controls mapped|74 target controls covered
80%
Azure Security Benchmark
27 source controls mapped|51 target controls covered
77%
SOC 2
27 source controls mapped|24 target controls covered
77%
HIPAA Security Rule
26 source controls mapped|27 target controls covered
74%
NIST SP 800-66 Rev 2
26 source controls mapped|27 target controls covered
74%
NIST SP 800-53 Rev 5 LOW
25 source controls mapped|33 target controls covered
71%
NIST SP 800-218
16 source controls mapped|20 target controls covered
46%
ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
15 source controls mapped|14 target controls covered
43%
ISO 22301:2019
6 source controls mapped|8 target controls covered
17%

What is NIST SP 800-172 and who does it apply to?

NIST SP 800-172 is a compliance framework from United States with 10 domains and 35 controls. Enhanced Security Requirements for Protecting CUI It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does NIST SP 800-172 actually require?

NIST SP 800-172 has 35 controls organised across 10 domains. The largest domains are RA (7 controls), SI (7 controls), SC (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of NIST SP 800-172 do I already cover?

NIST SP 800-172 maps to 23 other compliance frameworks. The top mapping partners are NIST SP 800-161 Rev 1 (100% coverage), NIST SP 800-53 Rev 5 (100% coverage), C5 (Germany) (94% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement NIST SP 800-172?

Start your NIST SP 800-172 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-172 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required