NIST 800-171 Update For 32 CFR Part 170

NIST 800-171 Update For 32 CFR Part 170

ComplianceForge Support ComplianceForge Support
1 minute read

Listen to article
Audio generated by DropInBlog's Blog Voice AI™ may have slight pronunciation nuances. Learn more

The 2024.3 version of the NIST 800-171 Compliance Program (NCP) addresses changes associated with 32 CFR Part 170 and updated CMMC 2.0 L2 scoping guidance

The biggest issue with 32 CFR Part 170 is the DoD cites NIST SP 800-171 R2 in this final rule, even though NIST SP 800-171 R3 was released earlier this year and per OMB NIST 800-171 R2 will be considered a deprecated standard in May 2025. The DoD’s reason for focusing on the old version of NIST SP 800-171 includes the time needed:

  • For industry preparation to implement; and
  • To prepare the CMMC ecosystem to perform assessments against the new version.

Given this DoD's focus on NIST SP 800-171 R2 for the immediate future, ComplianceForge reorganized the NCP into three different formats to meet client needs:

  • NCP R2 is tailored for organizations that want to focus entirely on only NIST SP 800-171 R2.
  • NCP R3 is tailored for organizations that want to focus entirely on only NIST SP 800-171 R3.
  • NCP Combined R2 & R3 is tailored for organizations that want to address both NIST SP 800-171 R2 & R3 simultaneously.

Learn more at: https://complianceforge.com/product/nist-800-171-compliance-program/ 

« Back to Blog

NIST SP 800‑53 R5 Control Families

This release includes a total of 1,189 controls, organized into 20 families:

  1. Access Control
  2. Awareness & Training
  3. Audit & Accountability
  4. Assessment, Authorization & Monitoring
  5. Configuration Management
  6. Contingency Planning
  7. Identification & Authentication
  8. Incident Response
  9. Maintenance
  10. Media Protection
  11. Physical & Environmental Protection
  12. Planning
  13. Program Management
  14. Personnel Security
  15. Personally Identifiable Information (PII) Processing & Transparency
  16. Risk Assessment
  17. System & Services Acquisition
  18. System & Communications Protection
  19. System & Information Integrity
  20. Supply Chain Risk Management

This count includes deprecated controls that have been removed or folded into others. Some controls are not categorized under baselines—low, moderate, high, or privacy—per NIST SP 800‑53B.

ComplianceForge provides full 1:1 mapping of all 20 families and their controls in its CDPP documentation.