Framework module · nist-800-171-rev3
NIST SP 800-171
The security requirements for Controlled Unclassified Information held on non-federal systems — the technical substance underneath CMMC Level 2.
Rev. 3 · NIST Computer Security Resource Center · published 2024-05-14
Standing today
Catalog only
01Standing
Catalog only
A directory entry — authority, version ledger, verification — not a workspace you can open.
NIST SP 800-171 is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.
Named and tracked only; requirements not ingested as a control catalog.
02Registry record
checked 2026-08-06
- Registry status
- Planned · namedWe name the regime and track its authority. Nothing is modelled yet.
- Control units
- 97Security requirements in SP 800-171 Rev. 3 across 17 families, as published by NIST.
- Control families
- AC · AT · AU · CM · IA · IR · MA · MP · PE · PL · PS · RA · CA · SA · SC · SI · SR
- Applies to
- defense industrial base · federal contractors · US
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
- Pending change
- Rev. 3 is the current NIST publication, but DoD contracts still enforce Rev. 2 through DFARS. Do not tell a defense contractor Rev. 3 is their contractual baseline without checking their clause.Expected: DFARS transition not yet dated
03Version ledger
2 editions
| Rev. 2 | Superseded | date not published |
| Rev. 3 | Current edition · supersedes Rev. 2 | 2024-05-14 |