Skip to main content
Framework library
Framework module · nist-800-172-rev3

NIST SP 800-172

Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.

Rev. 3 · National Institute of Standards and Technology · published 2026-05-13

Standing today
Directory entry

00Answer

from the registry record
What is NIST SP 800-172?
Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.
Who does NIST SP 800-172 apply to?
NIST SP 800-172 applies to defense industrial base, federal contractors, critical programs, US, per National Institute of Standards and Technology.
What is the current version of NIST SP 800-172?
The current edition is Rev. 3, issued by National Institute of Standards and Technology and published 2026-05-13. Source: https://csrc.nist.gov/pubs/sp/800/172/r3/final.
What does an assessment under NIST SP 800-172 require?
No control catalog has been ingested for NIST SP 800-172 yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

NIST SP 800-172 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

NIST publishes the final requirements and assessment procedures in human-readable and OSCAL formats; pin the final Rev. 3 artifacts before ingestion.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Access control · Asset management · Network segmentation · Supply-chain risk management · Cyber resiliency
Applies to
defense industrial base · federal contractors · critical programs · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28

03Version ledger

2 editions
2021Superseded2021-02-02
Rev. 3Current edition · supersedes 20212026-05-13

05Change history

06Related frameworks

scored from registry facts
  1. NERC CIPCIP-002 through CIP-015 (per-standard versions)

    Commonly assessed together · The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number.

  2. Also applies to defense industrial base · NIST's current recommended security requirements for Controlled Unclassified Information in non-federal systems. Contractual applicability is agreement-specific; CMMC Phase I continues to use Rev. 2 rather than automatically inheriting Rev. 3.

  3. Commonly assessed together · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

  4. NIS2 DirectiveDirective (EU) 2022/2555

    Commonly assessed together · The EU directive establishing a cybersecurity baseline for essential and important entities across 18 critical sectors, with management accountability and incident reporting. Operational obligations depend on each Member State's transposing law.

NIST SP 800-172 | ControlFrame