Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient - No AI Slop!
ComplianceForge

ComplianceForge Erratas

Every documented change to the NIST 800-171 Compliance Program (NCP) and Security, Compliance & Resilience Program (SCRP) subscription documentation, release by release. Use this to check what changed between the version you own and the current release.

NIST 800-171 Compliance Program (NCP) Erratas

The NCP erratas apply to the NIST 800-171 Compliance Program (NCP) and provide a summary of what has changed between each version.
NCP 2026.4
Aligns the NCP with Q2 wording changes from the SCF, rebrands the CDPP as the Security, Compliance & Resilience Program (SCRP), and restructures the CSOP around a RASCI model.
NCP 2026.2
Primarily a terminology update, shifting the focus from compliance alone to being secure, compliant and resilient in line with NIST and industry practice.
NCP 2025.4.1
A corrective release that updated CMMC Level 1 control numbering.
NCP 2025.4
Updates control objectives and standards to match SCF 2025.4 and refreshes the Third-Party Risk Management templates.
NCP 2025.3.1
A substantial release that rebuilt the Supply Chain Risk Management component, added a TPRM template, and replaced DIBNet references with DC3 for incident reporting.
NCP 2025.1
A maintenance release covering SCF formatting changes, an updated Cybersecurity Risk Assessment template, and clarification of IAC-05.
NCP 2024.2
Focused on addressing NIST 800-171 R3 and NIST 800-171A R3 requirements, with updated CSOP roles and three NIST-to-SCF crosswalks.
NCP 2024.1
Expanded NCP scoping beyond NIST 800-171 R2 and CMMC 2.0 to cover DFARS, FAR and ITAR requirements, and added an Evidence Request List, risk catalog and threat catalog.

SCRP Erratas

As a note, the Digital Security Program (DSP) was rebranded to the Security, Compliance & Resilience Program (SCRP) at the beginning of 2026, which is why there is an updated naming convention. The SCRP erratas apply to the Security, Compliance & Resilience Program (SCRP), its corresponsing Cybersecurity Standardized Operating Procedures (CSOP) document, and bundle. Each of these provide a summary of what has changed between each version.
SCRP 2026.2
A moderate update that adds a new Quantum Security (QTS) domain to address post-quantum cryptography risk, refreshes policies against updated SCF domain principles, and strengthens DFARS-related standards.
SCRP 2026.1
A moderate update that standardizes terminology on "security, compliance and resilience", refreshes maturity model criteria, and expands the set of authoritative sources.
DSP 2025.4
A minor update based on new and changed SCF controls, with Assessment Objectives enhanced to show People, Process, Technology, Data or Facility applicability.
DSP 2025.3
A major update driven by new and changed SCF controls, with the majority of new controls focused on the governance of Artificial Intelligence and several new control sets added.
DSP 2025.2
A major update based on new and changed SCF controls, with the majority of new controls focused on the governance of Artificial Intelligence.
DSP 2025.1.1
A corrective release that restored a missing column in the crosswalk mapping spreadsheet.
DSP 2025.1
A minor update based on new and changed controls in the Secure Controls Framework (SCF).
DSP 2024.4
A minor update based on new and changed controls, including an SCF formatting change from bullet listings to numbered listings.
DSP 2024.3
A minor update that added possible solutions and considerations content scaled to organization size, along with new risks and threats.
DSP 2024.2
A moderate update that introduced PPTDF control tagging and added the MSP/MSSP Secure Practices Baseline as the SCF-M sub-control set.
DSP 2024.1
A minor update with new controls, marking the point where the SCF began using Set Theory Relationship Mapping per NIST IR 8477.