NCP 2025.3.1
A substantial release that rebuilt the Supply Chain Risk Management component, added a TPRM template, and replaced DIBNet references with DC3 for incident reporting.
What changed in this release
- Corrected a hyperlink redirect issue.
- Updated the System Security Plan (SSP) template to address Assessment Objectives (AOs).
- Added a Third-Party Risk Management (TPRM) template.
- Based on DoD guidance, references to DIBNet were replaced with the Department of Defense Cyber Crime Center (DC3) for cyber incident reporting purposes.
- Affected control objectives, standards and procedures were updated based on changes to the Secure Controls Framework (SCF) 2025.2. Green highlights in the documents indicate changes.
- The entire Supply Chain Risk Management (SCRM) component was revised to include two versions of a Supply Chain Risk Management (SCRM) Plan (choose between NIST 800-161 R1 or DI-MGMT-82256A), as well as a Cybersecurity Supply Chain Risk Assessment (C-SCRA) template to perform supply chain specific risk assessments.
- Updated version of the NIST 800-171 R2 to R3 Transition Guide, to help organizations understand what is expected to transition from R2 to R3 in the most efficient manner possible.
Releases older than 2024 (2023 and beyond) are not covered by this errata archive and are significantly out of date. Existing customers are encouraged to repurchase the current version at 50% of the original product price.