Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

NIST SP 800-171 Rev 3 Compliance Resource Center

The current version of this standard is NIST SP 800-171 Rev 3, published by NIST on May 14, 2024, which supersedes Rev 2. Note: DoD contracts still reference NIST SP 800-171 Rev 2 (DFARS class deviation 2024-O0013 and the CMMC Level 2 rule), so many defense contractors need to support both revisions.

  • Publication Title: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
  • Published Date: May 14, 2024
NIST 800-171 Rev 3 documentation template
Key Takeaways - NIST SP 800-171 R3 Compliance
  • NIST SP 800-171 Rev 3 (May 14, 2024) is the current NIST version and supersedes Rev 2. Federal agencies are expected to adopt new NIST guidance within one year (OMB Circular A-130), but your contract clauses set the revision you must meet.
  • While CUI controls dropped from 110 to 97, discrete requirements increased 170% (from 110 to 297) and Assessment Objectives increased 59% (from 320 to 510).
  • All 61 NFO controls were absorbed into the CUI control set, increasing governance burden on contractors.
  • The heaviest lifts are NFO-to-CUI migration (more governance) and implementing an operational C-SCRM Plan with evidence.
  • DoD class deviation 2024-O0013 keeps DFARS 252.204-7012 on R2 until it is rescinded, and CMMC Level 2 is still based on R2. Plan for R3 now to avoid rebuilding your documentation twice.
  • ComplianceForge recommends the Secure Controls Framework (SCF) as the best framework for NIST SP 800-171 R3, since it maps to R3 at the Assessment Objective (AO) level and to 200+ other laws, regulations and frameworks.
Overview

What Is NIST SP 800-171 Rev 3?

NIST SP 800-171 Rev 3 is focused on the protection of Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations (e.g., defense contractors). NIST SP 800-171 provides US federal agencies (including the US Department of Defense (DoD)) with recommended security requirements to protect the confidentiality of CUI in nonfederal systems and organizations. NIST SP 800-171 was first published in 2015 and the current version (Rev 3) was published on May 14, 2024.

NIST SP 800-171 is designed to require contractors to adhere with reasonably-expected security requirements that have been in use by the US government for years. NIST 800-171 establishes a basic set of expectations and maps these requirements to NIST 800-53, which is the de facto standard for US government cybersecurity controls. NIST 800-171 creates a standardized and uniform set of requirements for all Controlled Unclassified Information (CUI) security needs. This is designed to address common deficiencies in managing and protecting unclassified information that is being stored, transmitted or processed by private businesses.  

Note

While NIST SP 800-171 Rev 3 is the current version of NIST SP 800-171, the DoD issued a class deviation (2024-O0013) in May 2024 that ties DFARS Clause 252.204-7012 to NIST SP 800-171 Rev 2 until the deviation is rescinded. DFARS Clause 252.204-7012 mandates defense contractors to:

  • Safeguard CUI;
  • Report cyber incidents; and
  • Comply with NIST SP 800-171.
NIST 800-171 R3 Compliance Resources

How Do You Comply With NIST 800-171 Rev 3?

This material provides a guide for each requirement in NIST 800-171 Rev 3. The purpose is to provide a comprehensive compliance resource for NIST 800-171 Rev 3 that points you in the right direction to become secure, compliant & resilient.  

  • 03.01.06
    -
    Least Privilege - Privileged Accounts
  • 03.01.07
    -
    Least Privilege - Privileged Functions
  • 03.01.18
    -
    Access Control for Mobile Devices
  • 03.02.01
    -
    Literacy Training and Awareness
  • 03.03.04
    -
    Response to Audit Logging Process Failures
  • 03.03.05
    -
    Audit Record Review, Analysis, and Reporting
  • 03.03.06
    -
    Audit Record Reduction and Report Generation
  • 03.03.08
    -
    Protection of Audit Information
  • 03.04.08
    -
    Authorized Software - Allow by Exception
  • 03.04.12
    -
    System and Component Configuration for High-Risk Areas
  • 03.05.01
    -
    User Identification, Authentication, and Re-Authentication
  • 03.05.02
    -
    Device Identification and Authentication
  • 03.05.04
    -
    Replay-Resistant Authentication
  • 03.06.02
    -
    Incident Monitoring, Reporting, and Response Assistance
  • 03.08.09
    -
    System Backup - Cryptographic Protection
  • 03.09.02
    -
    Personnel Termination and Transfer
  • 03.10.08
    -
    Access Control for Transmission
  • 03.11.02
    -
    Vulnerability Monitoring and Scanning
  • 03.13.04
    -
    Information in Shared System Resources
  • 03.13.06
    -
    Network Communications - Deny by Default - Allow by Exception
  • 03.13.08
    -
    Transmission and Storage Confidentiality
  • 03.13.10
    -
    Cryptographic Key Establishment and Management
  • 03.13.12
    -
    Collaborative Computing Devices and Applications
  • 03.14.03
    -
    Security Alerts, Advisories, and Directives
  • 03.14.08
    -
    Information Management and Retention
  • 03.16.01
    -
    Security Engineering Principles
  • 03.17.01
    -
    Supply Chain Risk Management Plan
  • 03.17.02
    -
    Acquisition Strategies, Tools, and Methods
  • 03.17.03
    -
    Supply Chain Requirements and Processes
Regulatory Mandate

Why Do You Need To Upgrade To NIST SP 800-171 Rev 3?

OMB Circular A-130 expects federal agencies to comply with new or updated NIST publications within one year of their publication dates, which pointed to May 2025 for NIST SP 800-171 Rev 3. In practice, the revision you must meet is set by the clauses in your contract. DoD has kept Rev 2 in place through class deviation 2024-O0013 and the CMMC program rule (32 CFR Part 170), so a DoD move to Rev 3 is expected to come through future rulemaking. Organizations that build their program around Rev 3 now, while still meeting Rev 2 where contracts require it, avoid a second documentation rebuild later.

Per OMB in CIRCULAR NO. A-130: "For legacy information systems, agencies are expected to meet the requirements of, and be in compliance with, NIST standards and guidelines within one year of their respective publication dates unless otherwise directed by OMB. The one-year compliance date for revisions to NIST publications applies only to new or updated material in the publications. For information systems under development or for legacy systems undergoing significant changes, agencies are expected to meet the requirements of, and be in compliance with, NIST standards and guidelines immediately upon deployment of the systems."

Who Needs To Comply?

Who Needs To Comply With NIST SP 800-171 Rev 3?

An organization that stores, processes and/or transmits CUI as part of a contract with the US government is required to comply with NIST SP 800-171. Examples of these organizations that may store, process and/or transmit CUI as part of a contract include, but are not limited to:

DoD Contractors
Federal Contractors
Technology Companies
MSPs / MSSPs
Systems Integrators
Manufacturers
Higher Education (e.g., colleges & universities)
Healthcare Providers
Research Institutions
Source Of Requirements

What Is The Source of NIST SP 800-171 Rev 3 Requirements?

The requirements in NIST SP 800-171 Rev 3 support the CUI program established by 32 CFR Part 2002 and are derived from:

  • Federal Information Processing Standards (FIPS) Publication 200 (FIPS 200); and
  • The moderate security control baseline in NIST SP 800-53 Rev 5.

NIST determined the requirements in NIST SP 800-171 Rev 3 provide the necessary protection for federal information and systems that are covered under the Federal Information Security Modernization Act (FISMA). NIST applied five (5) tailoring criteria (NCO, FED, ORC, NA and CUI) to the NIST SP 800-53 Rev 5 moderate baseline controls, as described in Appendix C of NIST SP 800-171 Rev 3. The four criteria that shape the requirements are:

Not Required

NCO Controls

What Are NCO Requirements? NCO controls are not directly related to protecting the confidentiality of CUI. NCO controls are not included as NIST SP 800-171 Rev 3 requirements.

Not Required

FED Controls

What Are FED Requirements? FED controls are “uniquely federal” and primarily the responsibility of the US federal government. FED controls are not included as NIST SP 800-171 Rev 3 requirements.

Not Required

ORC Controls

What Are ORC Requirements? ORC controls are NIST SP 800-53 Rev 5 controls whose outcome for protecting the confidentiality of CUI is adequately covered by other related controls. ORC controls are not listed as separate NIST SP 800-171 Rev 3 requirements, but their outcome is still expected through those related requirements.

Required

CUI Controls

What Are CUI Requirements? CUI controls are directly related to protecting the confidentiality of CUI. They became the security requirements that must be implemented to comply with NIST SP 800-171 Rev 3.

Note

Non-Federal Organization (NFO) requirements were removed from NIST SP 800-171 Rev 3

NIST SP 800-171 Rev 3 Requirements To Protect CUI

What Are The NIST SP 800-171 R3 Families?

While NIST SP 800-171 Rev 3 contains 97 core requirements, the total number of discrete requirements is 297. As for Assessment Objectives (AOs) in NIST SP 800-171A Rev 3, there are 510 AOs that must be used to evaluate the requirements from NIST SP 800-171 R3. The requirement to use NIST SP 800-171A AOs was first defined by NARA’s Information Security Oversight Office (ISOO) in 2020 with CUI Notice 2020-04.

NIST SP 800-171 Rev 3 organizes the requirements according to 17 families. The requirements in NIST SP 800-171 Rev 3 use a “03.XX.YY” numbering format (e.g., 03.01.01 Account Management) because the requirements are in Chapter 3 of NIST SP 800-171.

The NIST SP 800-171 Rev 3 families are:

3.1 Access Control

This family of NIST SP 800-171 Rev 3 requirements focuses on logical access control.

3.2 Awareness & Training

This family of NIST SP 800-171 Rev 3 requirements focuses on end user training, specifically for personnel who handle CUI or administer technologies that support and/or protect CUI.

3.3 Audit & Accountability

This family of NIST SP 800-171 Rev 3 requirements focuses on technology-related event logging to maintain situational awareness of the CUI environment.

3.4 Configuration Management

This family of NIST SP 800-171 Rev 3 requirements focuses on technology-related configuration management practices to secure the CUI environment.

3.5 Identification & Authentication

This family of NIST SP 800-171 Rev 3 requirements focuses on technology-related Identity and Access Management (IAM) practices to securely limit access to only those people and processes with a legitimate business need.

3.6 Incident Response

This family of NIST SP 800-171 Rev 3 requirements focuses on incident response practices associated with the CUI environment.

3.7 Maintenance

This family of NIST SP 800-171 Rev 3 requirements focuses on technology-related maintenance activities within CUI environment.

3.8 Media Protection

This family of NIST SP 800-171 Rev 3 requirements focuses on technology-related media protection and handling practices.

3.9 Personnel Security

This family of NIST SP 800-171 Rev 3 requirements focuses on personnel-related management practices to ensure only necessary individuals have access to the CUI environment.

3.10 Physical Protection

This family of NIST SP 800-171 Rev 3 requirements focuses on physical security-related practices to physically secure the CUI environment.

3.11 Risk Assessment

This family of NIST SP 800-171 Rev 3 requirements focuses on risk management practices associated with the CUI environment.

3.12 Security Assessment & Monitoring

This family of NIST SP 800-171 Rev 3 requirements focuses on security assessments, Plans of Action & Milestones (POA&M), continuous monitoring and information exchange agreements for the CUI environment.

3.13 System & Communications Protection

This family of NIST SP 800-171 Rev 3 requirements focuses on technology-related network security aspects of the CUI environment.

3.14 System & Information Integrity

This family of NIST SP 800-171 Rev 3 requirements focuses on flaw remediation, malicious code protection and system monitoring to maintain the integrity and situational awareness of the CUI environment.

3.15 Planning

This family of NIST SP 800-171 Rev 3 requirements focuses on the organization’s strategic plans to govern cybersecurity risks and threats to protect the CUI environment.

3.16 System and Services Acquisition

This family of NIST SP 800-171 Rev 3 requirements focuses on technology-related development and acquisition processes to maintain the confidentiality and integrity of the CUI environment.

3.17 Supply Chain Risk Management

This family of NIST SP 800-171 Rev 3 requirements focuses on Cybersecurity Supply Chain Risk Management (C-SCRM)-related practices to operationalize concepts from NIST SP 800-161 Rev 1 to protect the CUI environment.

Penalties For Non-Compliance

What Are The Penalties For Non-Compliance With NIST 800-171 Rev 3?

Non-compliance with NIST SP 800-171 (whichever revision your contract requires) could be a False Claims Act (FCA) violation and the US Department of Justice (DOJ) is taking FCA violations seriously. Additional penalties for non-compliance with NIST SP 800-171 include, but are not limited to:

Contract Termination

It is reasonably expected that the U.S. Government will terminate contracts with prime contractors over non-compliance with DFARS / NIST 800-171 requirements since it is a failure to uphold contract requirements. Subcontractor non-compliance will cause a prime contractor to be non-compliant, as a whole.

False Claims Act Liability

If a company states it is compliant when it knowingly is not compliant, that is a misrepresentation of material facts. Under the False Claims Act (31 U.S.C. §§ 3729-3733), a civil statute, knowingly false claims or statements made to obtain government payment can lead to treble damages plus civil penalties for each false claim. Whistleblowers can also file FCA lawsuits on the government's behalf.

Breach of Contract Lawsuits

Both prime contractors and subcontractors could be exposed legally. A tort is a civil breach committed against another in which the injured party can sue for damages. The likely scenario for a DFARS / NIST 800-171-related tort would be around negligence on behalf of the accused party by not maintaining a specific code of conduct (e.g., DFARS / NIST 800-171 cybersecurity controls).

As you can see from those examples, the cost of non-compliance is quite significant. As always, seek competent legal counsel for any pertinent questions on your specific compliance obligations.

Upgrade To NIST 800-171 Rev 3

How Do I Upgrade To NIST 800-171 R3?

Sooner, rather than later, the US Government's global supply chain will have to transition to NIST 800-171 R3. ComplianceForge provides a free resource for organizations migrating from NIST 800-171 R2 to R3. This guide provides an Assessment Objective (AO)-level analysis to address differences:

  • Over 1/3 are minimal effort (clear, direct mapping);
  • Approximately 1/5 are moderate effort (indirect mapping); and
  • Approximately 1/2 are significant effort (no clear mapping or new AOs).

This guide also addresses the logical dependencies that exist from "orphaned AOs" that are not in NIST 800-171A R3, but a requirement to demonstrate evidence of due diligence and due care still exists for specific functions (e.g., maintenance operations, roles & responsibilities, inventories, physical security, etc.).

NIST 800-171 R2 To R3 Upgrade
Best Framework For NIST 800-171 R3

What Is The Best Framework For NIST SP 800-171 Rev 3 Compliance?

ComplianceForge recommends the Secure Controls Framework (SCF) as the best framework for NIST SP 800-171 Rev 3. Most organizations that handle CUI have more than NIST SP 800-171 to comply with, such as CMMC, FAR 52.204-21, ISO 27001, SOC 2, state privacy laws and customer contract requirements. The SCF is a free metaframework with 1,500+ controls across 34 domains that are mapped to 200+ laws, regulations and frameworks, so one set of controls can demonstrate conformity with NIST SP 800-171 Rev 3 at the Assessment Objective (AO) level while also addressing your other obligations.

Assessment Objective (AO) Level Mapping
The SCF publishes Set Theory Relationship Mapping (STRM) for both NIST SP 800-171 R3 and NIST SP 800-171A R3. Each AO (e.g., A.03.01.01.a) is mapped to the SCF control that satisfies it, which is the level where assessors evaluate your evidence.
One Control Set, Many Obligations
The SCF maps its controls to 200+ laws, regulations and frameworks. Evidence you produce for a NIST SP 800-171 Rev 3 AO can also support CMMC, ISO 27001, SOC 2 and other requirements, instead of running parallel compliance programs.
Rev 2 Today, Rev 3 Tomorrow
The SCF maps to both NIST SP 800-171 Rev 2 and Rev 3. You can meet the Rev 2 requirements in current DoD contracts while building toward Rev 3 in the same control set, without rebuilding your documentation.
Scales As Your Scope Changes
When a new customer, contract or regulation adds requirements, you map it to the SCF controls you already operate. Your program grows with your business instead of starting over for each new framework.
Transparent, Defensible Mappings
STRM is the methodology described in NIST IR 8477. Each mapping states the relationship (equal, subset of, superset of, intersects with or no relationship) and its strength, so you can explain to an assessor why a control meets a requirement.
Free To Use
The SCF is free to use under a Creative Commons license, so there is no framework licensing cost to adopt it as your common control set.
How ComplianceForge Uses The SCF

ComplianceForge is an authorized SCF Licensed Content Provider (LCP). Our SCF-based policies and standards (SCRP), procedures (CSOP) and CMMC Bundle 4 (SCF) give you editable documentation that is already aligned to SCF controls, so your evidence traces back to NIST SP 800-171 Rev 3 AOs through the SCF mappings. You can review the AO-level mapping in the SCF's NIST SP 800-171A R3 STRM.

ComplianceForge's Solution

What Problem Does ComplianceForge's NIST SP 800-171 Rev 3 Documentation Solve?

We sell cybersecurity documentation - policies, standards, procedures and more! Our documentation is meant to help companies become audit-ready!

Lack of In House Security Experience
Writing security documentation is a skill that many good cybersecurity professionals simply are not proficient at and avoid the task at all cost. Tasking your security analysts and engineers to write comprehensive NIST 800-171 compliance documentation means you are actively taking them away from protecting and defending your network, which is not a wise use of their time. ComplianceForge offers NIST 800-171 documentation solutions that can save your organization significant time and money!
Compliance Requirements
The reality of non-compliance with NIST 800-171 requirements means lost business and potential fines. In addition to losing contracts, charges of fraud may be leveled on companies that claim to be compliant with NIST 800-171 but cannot provide evidence. Our documentation can help you become and stay compliant with NIST 800-171 where you have documented evidence to prove it!
Audit Failures
Security documentation does not age gracefully like a fine wine. Outdated documentation leads to gaps that expose organizations to audit failures and system compromises. Our documentation provides mapping to NIST 800-53 and other leading security frameworks to show you exactly what is required to both stay secure and compliant. Being editable documentation, you are able to easily maintain it as your needs or technologies change.  
How Does ComplianceForge Help?

How Does ComplianceForge Help Me Comply With NIST SP 800-171 Rev 3?

We take a holistic approach to creating comprehensive cybersecurity documentation that is both scalable and affordable. This is beyond just generic policies and allows you to build out an audit-ready cybersecurity program for your organization!

Clear Documentation
In an audit, clear and concise documentation is half the battle. ComplianceForge provides comprehensive documentation that can prove your NIST 800-171 compliant security program exists. This equates to a time saving of hundreds of hours and tens of thousands of dollars in staff and consultant expenses!
Time Savings
Time is money! Our cybersecurity documentation addresses DFARS and FAR requirements and this can provide your organization with a semi-customized solution that requires minimal resources to fine tune for your organization's specific needs.
Alignment With Leading Practices
We did the heavy lifting. Our documentation is mapped to the NIST 800-53, as well as other leading security frameworks!
Flower ComplianceForge Products
Editable NIST 800-171 Documentation Templates

Editable NIST 800-171 Policies, Standards, Procedures Templates

ComplianceForge’s NIST 800-171 / CMMC documentation has been used successfully by multiple companies during DIBCAC assessments to efficiently and effectively generate the necessary artifact documentation to demonstrate compliance with NIST SP 800-171 controls and NIST SP 800-171A control objectives. This battle tested documentation includes the necessary policies, standards, procedures, SSP, POA&M, Incident Response Plan (IRP) and other documentation that are expected to exist to successfully pass a third-party assessment, be it DIBCAC or a C3PAO.

The "NIST 800-171 in a nutshell" graphic show below helps depict NIST 800-171 R3 requirements from Peope, Process, Technology, Data and Facility (PPTDF) perspective. This can help better visualize what the various requirements are (e.g., administrative, technical solutions, configurations, etc.). You can download the PDF version here and you can read more about the concept of PPTDF here.

People
A "people" control is primarily applied to humans (e.g., employees, contractors, third-parties, etc.).
Process
A "process" control is primarily applied to a manual or automated process.
Technology
A "technology" control is primarily applied to a system, application and/or service.
Data
A "data" control is primarily applied to data (e.g., CUI, CHD, PII, etc.).
Facility
A "facility" control is primarily applied to a physical building (e.g., office, data center, warehouse, home office, etc.).
NIST 800-171 R3 In A Nutshell