NIST SP 800-171 Rev 3
What is NIST SP 800-171 Rev 3?
NIST SP 800-171 Rev 3 (May 2024). Restructured requirements for CUI protection. It comprises 97 controls organised across 17 domains, published by NIST, and applies in the United States.
How NIST SP 800-171 Rev 3 maps to other frameworks
All 97 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 17 domains NIST SP 800-171 Rev 3 groups its controls into
Frameworks that share controls with NIST SP 800-171 Rev 3
Each of these has at least one control mapped to a control in NIST SP 800-171 Rev 3. The number is how many NIST SP 800-171 Rev 3 controls are shared, counted from the mapping graph.
Implementation guides for frameworks that overlap NIST SP 800-171 Rev 3
Where NIST SP 800-171 Rev 3 overlaps with the standards you already hold
Where to get trained on NIST SP 800-171 Rev 3
3 courses in the catalogue cover NIST SP 800-171 Rev 3 directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What NIST SP 800-171 Rev 3 means in your sector
What NIST SP 800-171 Rev 3 means for your job
Questions people ask about NIST SP 800-171 Rev 3
What is NIST SP 800-171 Rev 3?
How many controls does NIST SP 800-171 Rev 3 have?
Where does NIST SP 800-171 Rev 3 apply?
What frameworks does NIST SP 800-171 Rev 3 map to?
How do I get started with NIST SP 800-171 Rev 3 compliance?
Query NIST SP 800-171 Rev 3 programmatically
NIST SP 800-171 Rev 3, its 97 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
NIST SP 800-171 Rev 3 API reference and MCP config →What NIST SP 800-171 Rev 3 requires, control by control
Each page carries the requirement text for one NIST SP 800-171 Rev 3 control and what an assessor expects to see as evidence.
- 03-01-01 Account Management
- 03-01-02 Access Enforcement
- 03-01-03 Information Flow Enforcement
- 03-01-04 Separation of Duties
- 03-01-05 Least Privilege
- 03-01-06 Least Privilege - Privileged Accounts
- 03-01-07 Least Privilege - Privileged Functions
- 03-01-08 Unsuccessful Logon Attempts
- 03-01-09 System Use Notification
- 03-01-10 Device Lock
How much of another standard NIST SP 800-171 Rev 3 already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- ACSC Essential Eight to NIST SP 800-171 Rev 3 crosswalk
- ANSSI Guide d'hygiene informatique (42 mesures, v2.0) to NIST SP 800-171 Rev 3 crosswalk
- APRA CPS 230 Operational Risk Management to NIST SP 800-171 Rev 3 crosswalk
- APRA CPS 234 to NIST SP 800-171 Rev 3 crosswalk
- ASD Strategies to Mitigate Cyber Security Incidents to NIST SP 800-171 Rev 3 crosswalk
- Australia Consumer Data Right - Banking (CDR) to NIST SP 800-171 Rev 3 crosswalk
- AWS Well-Architected Security Pillar to NIST SP 800-171 Rev 3 crosswalk
- Azure Security Benchmark to NIST SP 800-171 Rev 3 crosswalk
How ready are you for NIST SP 800-171 Rev 3?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.