Back to Frameworks

NIST SP 800-181

United States
vRevision 1 (November 2020), components v1.0.0 (March 2024)
7 domains
52 controls

Workforce Framework for Cybersecurity (NICE Framework). Defines the cybersecurity work of an organization as Work Roles built from Task, Knowledge and Skill statements. This node models the 52 Work Roles across 7 Work Role Categories published in NICE Framework Components v1.0.0, the enumerated list referenced by SP 800-181r1.

Verified

NIST SP 800-181 is a compliance framework from United States with 7 domains and 52 controls that map to 18 other frameworks. The largest domains are Oversight and Governance (OG) (16 controls), Design and Development (DD) (8 controls), Cyberspace Effects (CE) (7 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Cyberspace Effects (CE)

7 controls
Controls in the Cyberspace Effects (CE) domain of NIST SP 800-1817 controls
CodeTitle
NICE-CE-WRL-001Cyberspace Operations
NICE-CE-WRL-002Cyber Operations Planning
NICE-CE-WRL-003Exploitation Analysis
NICE-CE-WRL-004Mission Assessment
NICE-CE-WRL-005Partner Integration Planning
NICE-CE-WRL-006Target Analysis
NICE-CE-WRL-007Target Network Analysis

Cyberspace Intelligence (CI)

5 controls
Controls in the Cyberspace Intelligence (CI) domain of NIST SP 800-1815 controls
CodeTitle
NICE-CI-WRL-001All-Source Analysis
NICE-CI-WRL-002All-Source Collection Management
NICE-CI-WRL-003All-Source Collection Requirements Management
NICE-CI-WRL-004Cyber Intelligence Planning
NICE-CI-WRL-005Multi-Disciplined Language Analysis

Design and Development (DD)

8 controls
Controls in the Design and Development (DD) domain of NIST SP 800-1818 controls
CodeTitle
NICE-DD-WRL-001Cybersecurity Architecture
NICE-DD-WRL-002Enterprise Architecture
NICE-DD-WRL-003Secure Software Development
NICE-DD-WRL-004Secure Systems Development
NICE-DD-WRL-005Software Security Assessment
NICE-DD-WRL-006Systems Requirements Planning
NICE-DD-WRL-007Systems Testing and Evaluation
NICE-DD-WRL-008Technology Research and Development

Implementation and Operation (IO)

7 controls
Controls in the Implementation and Operation (IO) domain of NIST SP 800-1817 controls
CodeTitle
NICE-IO-WRL-001Data Analysis
NICE-IO-WRL-002Database Administration
NICE-IO-WRL-003Knowledge Management
NICE-IO-WRL-004Network Operations
NICE-IO-WRL-005Systems Administration
NICE-IO-WRL-006Systems Security Analysis
NICE-IO-WRL-007Technical Support

Investigation (IN)

2 controls
Controls in the Investigation (IN) domain of NIST SP 800-1812 controls
CodeTitle
NICE-IN-WRL-001Cybercrime Investigation
NICE-IN-WRL-002Digital Evidence Analysis

Oversight and Governance (OG)

16 controls
Controls in the Oversight and Governance (OG) domain of NIST SP 800-18116 controls
CodeTitle
NICE-OG-WRL-001Communications Security (COMSEC) Management
NICE-OG-WRL-002Cybersecurity Policy and Planning
NICE-OG-WRL-003Cybersecurity Workforce Management
NICE-OG-WRL-004Cybersecurity Curriculum Development
NICE-OG-WRL-005Cybersecurity Instruction
NICE-OG-WRL-006Cybersecurity Legal Advice
NICE-OG-WRL-007Executive Cybersecurity Leadership
NICE-OG-WRL-008Privacy Compliance
NICE-OG-WRL-009Product Support Management
NICE-OG-WRL-010Program Management
NICE-OG-WRL-011Secure Project Management
NICE-OG-WRL-012Security Control Assessment
NICE-OG-WRL-013Systems Authorization
NICE-OG-WRL-014Systems Security Management
NICE-OG-WRL-015Technology Portfolio Management
NICE-OG-WRL-016Technology Program Auditing

Protection and Defense (PD)

7 controls
Controls in the Protection and Defense (PD) domain of NIST SP 800-1817 controls
CodeTitle
NICE-PD-WRL-001Defensive Cybersecurity
NICE-PD-WRL-002Digital Forensics
NICE-PD-WRL-003Incident Response
NICE-PD-WRL-004Infrastructure Support
NICE-PD-WRL-005Insider Threat Analysis
NICE-PD-WRL-006Threat Analysis
NICE-PD-WRL-007Vulnerability Analysis

Your Compliance Coverage

If you comply with NIST SP 800-181, you already cover:

Maps to 18 other frameworks

52 total controls
NIST SP 800-53 Rev 5
9 source controls mapped|12 target controls covered
17%
PCI DSS 4.0
7 source controls mapped|6 target controls covered
13%
FedRAMP High
6 source controls mapped|4 target controls covered
12%
NIST SP 800-53 Revision 5.1 HIGH
6 source controls mapped|4 target controls covered
12%
FedRAMP Moderate
6 source controls mapped|4 target controls covered
12%
NIST SP 800-53 Rev 5 MODERATE
6 source controls mapped|4 target controls covered
12%
NIST SP 800-53 Rev 5 LOW
6 source controls mapped|4 target controls covered
12%
CIS Controls v8
6 source controls mapped|5 target controls covered
12%
ISO 27002:2022
6 source controls mapped|3 target controls covered
12%
ISO 27001:2022
6 source controls mapped|3 target controls covered
12%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
6 source controls mapped|4 target controls covered
12%
SOC 2
5 source controls mapped|2 target controls covered
10%
NIST Cybersecurity Framework 2.0
5 source controls mapped|6 target controls covered
10%
HIPAA Security Rule
5 source controls mapped|2 target controls covered
10%
NIST SP 800-66 Rev 2
5 source controls mapped|2 target controls covered
10%
CMMC 2.0
4 source controls mapped|3 target controls covered
8%
NIST SP 800-171 Rev 3
4 source controls mapped|3 target controls covered
8%
Azure Security Benchmark
3 source controls mapped|1 target controls covered
6%

What is NIST SP 800-181 and who does it apply to?

NIST SP 800-181 is a compliance framework from United States with 7 domains and 52 controls. Workforce Framework for Cybersecurity (NICE Framework). Defines the cybersecurity work of an organization as Work Roles built from Task, Knowledge and Skill statements. This node models the 52 Work Roles across 7 Work Role Categories published in NICE Framework Components v1.0.0, the enumerated list referenced by SP 800-181r1. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does NIST SP 800-181 actually require?

NIST SP 800-181 has 52 controls organised across 7 domains. The largest domains are Oversight and Governance (OG) (16 controls), Design and Development (DD) (8 controls), Cyberspace Effects (CE) (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of NIST SP 800-181 do I already cover?

NIST SP 800-181 maps to 18 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (17% coverage), PCI DSS 4.0 (13% coverage), FedRAMP High (12% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement NIST SP 800-181?

Start your NIST SP 800-181 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-181 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 52 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required