NIST SP 800-172
What is NIST SP 800-172?
Enhanced Security Requirements for Protecting CUI. It comprises 35 controls organised across 10 domains, published by NIST, and applies in the United States.
How NIST SP 800-172 maps to other frameworks
All 35 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 10 domains NIST SP 800-172 groups its controls into
Frameworks that share controls with NIST SP 800-172
Each of these has at least one control mapped to a control in NIST SP 800-172. The number is how many NIST SP 800-172 controls are shared, counted from the mapping graph.
Implementation guides for frameworks that overlap NIST SP 800-172
Training on frameworks that overlap NIST SP 800-172
There is no course on NIST SP 800-172 itself. These cover frameworks that share controls with it, so the material carries across even though the standard named is different.
Where NIST SP 800-172 overlaps with the standards you already hold
What NIST SP 800-172 means in your sector
What NIST SP 800-172 means for your job
Questions people ask about NIST SP 800-172
What is NIST SP 800-172?
How many controls does NIST SP 800-172 have?
Where does NIST SP 800-172 apply?
What frameworks does NIST SP 800-172 map to?
How do I get started with NIST SP 800-172 compliance?
Query NIST SP 800-172 programmatically
NIST SP 800-172, its 35 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
NIST SP 800-172 API reference and MCP config →What NIST SP 800-172 requires, control by control
Each page carries the requirement text for one NIST SP 800-172 control and what an assessor expects to see as evidence.
- 3-1-1E Dual Authorization for Sensitive System Operations
- 3-1-2E Restrict Access to Organization-Owned, Provisioned, or Issued Information Resources
- 3-1-3E Employ Secure Information Transfer Solutions
- 3-11-1E Threat-Aware Risk Assessment
- 3-11-2E Threat Hunting
- 3-11-3E Advanced Automation and Analytics Capabilities
- 3-11-4E Security Solution Rationale Document
- 3-11-5E Assess Effectiveness of Security Solutions
- 3-11-6E Supply Chain Risk Assessment, Response, and Monitoring
- 3-11-7E Supply Chain Risk Management Plan
How much of another standard NIST SP 800-172 already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- NIST SP 800-172 to Azure Security Benchmark crosswalk
- C5 (Germany) to NIST SP 800-172 crosswalk
- CIS Controls v8 to NIST SP 800-172 crosswalk
- Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 to NIST SP 800-172 crosswalk
- NIST SP 800-172 to CMMC 2.0 crosswalk
- FedRAMP Moderate to NIST SP 800-172 crosswalk
- NIST SP 800-172 to ISO 27001:2022 crosswalk
- NIST SP 800-172 to ISO 27002:2022 crosswalk
How ready are you for NIST SP 800-172?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.