NIST 800-171 Compliance Program (NCP) Erratas
The NCP erratas apply to the NIST 800-171 Compliance Program (NCP) and provide a summary of what has changed between each version.
Aligns the NCP with Q2 wording changes from the SCF, rebrands the CDPP as the Security, Compliance & Resilience Program (SCRP), and restructures the CSOP around a RASCI model.
Primarily a terminology update, shifting the focus from compliance alone to being secure, compliant and resilient in line with NIST and industry practice.
A corrective release that updated CMMC Level 1 control numbering.
Updates control objectives and standards to match SCF 2025.4 and refreshes the Third-Party Risk Management templates.
A substantial release that rebuilt the Supply Chain Risk Management component, added a TPRM template, and replaced DIBNet references with DC3 for incident reporting.
A maintenance release covering SCF formatting changes, an updated Cybersecurity Risk Assessment template, and clarification of IAC-05.
Focused on addressing NIST 800-171 R3 and NIST 800-171A R3 requirements, with updated CSOP roles and three NIST-to-SCF crosswalks.
Expanded NCP scoping beyond NIST 800-171 R2 and CMMC 2.0 to cover DFARS, FAR and ITAR requirements, and added an Evidence Request List, risk catalog and threat catalog.
SCRP Erratas
As a note, the Digital Security Program (DSP) was rebranded to the Security, Compliance & Resilience Program (SCRP) at the beginning of 2026, which is why there is an updated naming convention. The SCRP erratas apply to the Security, Compliance & Resilience Program (SCRP), its corresponsing Cybersecurity Standardized Operating Procedures (CSOP) document, and bundle. Each of these provide a summary of what has changed between each version.
A moderate update that adds a new Quantum Security (QTS) domain to address post-quantum cryptography risk, refreshes policies against updated SCF domain principles, and strengthens DFARS-related standards.
A moderate update that standardizes terminology on "security, compliance and resilience", refreshes maturity model criteria, and expands the set of authoritative sources.
A minor update based on new and changed SCF controls, with Assessment Objectives enhanced to show People, Process, Technology, Data or Facility applicability.
A major update driven by new and changed SCF controls, with the majority of new controls focused on the governance of Artificial Intelligence and several new control sets added.
A major update based on new and changed SCF controls, with the majority of new controls focused on the governance of Artificial Intelligence.
A corrective release that restored a missing column in the crosswalk mapping spreadsheet.
A minor update based on new and changed controls in the Secure Controls Framework (SCF).
A minor update based on new and changed controls, including an SCF formatting change from bullet listings to numbered listings.
A minor update that added possible solutions and considerations content scaled to organization size, along with new risks and threats.
A moderate update that introduced PPTDF control tagging and added the MSP/MSSP Secure Practices Baseline as the SCF-M sub-control set.
A minor update with new controls, marking the point where the SCF began using Set Theory Relationship Mapping per NIST IR 8477.