Date Published: May 10, 2023
Comments Due: July 14, 2023 (public comment period is CLOSED)
Email Questions to:
800-171comments@list.nist.gov
This update to NIST SP 800-171 represents over one year of data collection, technical analyses, customer interaction, redesign, and development of the security requirements and supporting information for the protection of Controlled Unclassified Information (CUI). Many trade-offs have been made to ensure that the technical and non-technical requirements have been stated clearly and concisely while also recognizing the specific needs of both federal and nonfederal organizations.
Significant changes NIST SP 800-171, Revision 3 include:
Additional files include an FAQ, a detailed analysis of the changes between Revision 2 and Revision 3, and a prototype CUI Overlay.
The public comment period is open now through July 14, 2023. We strongly encourage you to use this comment template if possible, and submit it to 800-171comments@list.nist.gov.
Reviewers are encouraged to comment on all or parts of draft NIST SP 800-171, Revision 3. NIST is specifically interested in comments, feedback, and recommendations for the following topics:
Comments received in response to this request will be posted on the Protecting CUI project site after the due date. Submitters’ names and affiliations (when provided) will be included, while contact information will be removed.
Please direct questions and comments to 800-171comments@list.nist.gov.
NOTE: A call for patent claims is included on page ii of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy – Inclusion of Patents in ITL Publications.
Access Control; Awareness and Training; Audit and Accountability; Configuration Management; Identification and Authentication; Maintenance; Media Protection; Physical and Environmental Protection; Personnel Security; System and Communications Protection; System and Information Integrity
Publication:
https://doi.org/10.6028/NIST.SP.800-171r3.ipd
Download URL
Supplemental Material:
Comment template (xlsx)
FAQ (pdf)
Change analysis (Rev. 2 to Rev. 3 ipd) (xlsx)
Prototype CUI Overlay (xlsx)
Protecting CUI project
NIST news article
Document History:
07/19/22: SP 800-171 Rev. 3 (Draft)
05/10/23: SP 800-171 Rev. 3 (Draft)
11/09/23: SP 800-171 Rev. 3 (Draft)
05/14/24: SP 800-171 Rev. 3 (Final)
audit & accountability, awareness training & education, maintenance, security controls, threats
Laws and RegulationsFederal Acquisition Regulation, Federal Information Security Modernization Act