NIST SP 800-172
Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.
Rev. 3 · National Institute of Standards and Technology · published 2026-05-13
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
NIST SP 800-172 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
NIST publishes the final requirements and assessment procedures in human-readable and OSCAL formats; pin the final Rev. 3 artifacts before ingestion.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Access control · Asset management · Network segmentation · Supply-chain risk management · Cyber resiliency
- Applies to
- defense industrial base · federal contractors · critical programs · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-28
03Version ledger
| 2021 | Superseded | 2021-02-02 |
| Rev. 3 | Current edition · supersedes 2021 | 2026-05-13 |
05Change history
06Related frameworks
- NERC CIPCIP-002 through CIP-015 (per-standard versions)
Commonly assessed together · The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number.
- NIST SP 800-171Rev. 3
Also applies to defense industrial base · NIST's current recommended security requirements for Controlled Unclassified Information in non-federal systems. Contractual applicability is agreement-specific; CMMC Phase I continues to use Rev. 2 rather than automatically inheriting Rev. 3.
- HITRUST CSFv11.8.0
Commonly assessed together · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
- NIS2 DirectiveDirective (EU) 2022/2555
Commonly assessed together · The EU directive establishing a cybersecurity baseline for essential and important entities across 18 critical sectors, with management accountability and incident reporting. Operational obligations depend on each Member State's transposing law.