Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

How Do I Implement NIST 800-171 R3 03.01.16 Wireless Access?

NIST 800-171 R3 03.01.16 Wireless Access at a Glance

  • Family: 03.01 Access Control (AC)
  • Requirement ID: 03.01.16 Wireless Access
  • Assessment Objectives (AOs): Eight (8) determination statements
  • Organization-Defined Parameters (ODPs): None (0). This requirement contains no organization-defined values
  • Source NIST 800-53 R5 Controls: AC-18, AC-18(01), AC-18(03)
  • NIST 800-171 R3 Kill Chain Phase: Phase 17, Layered Network Defenses

Wireless Access governs how wireless connections into your system are restricted, authorized, and protected. It parallels Remote Access (03.01.12) in structure but targets wireless technologies specifically. Wireless Access (03.01.16) does four things: establish usage, configuration, and connection requirements for each type of wireless access, authorize each type before connections are established, disable wireless capabilities that are not intended for use before a device is issued and deployed, and protect wireless access with authentication and encryption. Per the NIST discussion, wireless networking capabilities are a significant potential vulnerability, and strong authentication of users and devices, strong encryption, and disabling unneeded wireless capabilities reduce that exposure, with special attention to small form factor devices like smart phones, tablets, and smart watches.

A common difficulty with this requirement is assuming their R2 wireless work carries straight over. R3 combined the R2 "authorize wireless access" requirement with the separate "protect wireless with authentication and encryption" requirement, then added new objectives around configuration requirements, connection requirements, and disabling unused wireless capabilities before deployment. Several of those objectives are net new, so this is more than a renumbering.

Where things stand for companies facing the transition from NIST 800-171 R2 to R3:

  • The National Institute of Standards and Technology (NIST) withdrew R2 on May 14, 2024, the same day R3 was published. The withdrawal notice states that R2 "has been withdrawn (archived), and is provided solely for historical purposes," so it will never receive another correction or clarification from NIST.
  • R2 remains the contractual standard for the Department of Defense (DoD) and the Defense Industrial Base (DIB). Cybersecurity Maturity Model Certification (CMMC) assessments reference it directly: per Title 32 of the Code of Federal Regulations (CFR), section 170.14(c)(3), "the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2."
  • The rulemaking points the other direction. The proposed Controlled Unclassified Information (CUI) rule for the Federal Acquisition Regulation (FAR), published June 23, 2026 as part of the Revolutionary FAR Overhaul, would apply CUI safeguarding requirements government wide rather than only to DoD contracts, and it sets the baseline at R3. That rule is not final, and DoD has separately signaled an interim rule to move CMMC to R3.

What Does NIST 800-171 R3 03.01.16 Actually Require?

The following is reproduced verbatim from NIST 800-171 R3, requirement 03.01.16 Wireless Access. Only the formatting has been adjusted for readability. This requirement has four (4) lettered parts:

  • a. Establish usage restrictions, configuration requirements, and connection requirements for each type of wireless access to the system.
  • b. Authorize each type of wireless access to the system prior to establishing such connections.
  • c. Disable, when not intended for use, wireless networking capabilities prior to issuance and deployment.
  • d. Protect wireless access to the system using authentication and encryption.

The source controls are AC-18, AC-18(01), and AC-18(03) from NIST 800-53. There are no Organization-Defined Parameters (ODPs). Per the NIST discussion, establishing usage restrictions and configuration and connection requirements provides the criteria that support access authorization decisions, and wireless networks should use authentication protocols that provide credential protection and mutual authentication. You can read the requirement directly at NIST 800-171 R3, 03.01.16 (p. 15).

What Are the Organization-Defined Parameters (ODPs) Associated with NIST 800-171 R3 03.01.16?

None (0). Requirement 03.01.16 contains no bracketed assignment, so there is no organization-defined value to select and nothing for the DoD to specify. The requirement applies as written.

Your System Security Plan (SSP) narrative for 03.01.16 therefore records how the requirement is implemented rather than a parameter you chose.

What Are the Assessment Objectives (AOs) For NIST 800-171 R3 03.01.16?

NIST 800-171A R3 breaks 03.01.16 into eight (8) determination statements, and it has no Organization-Defined Parameters (ODPs). These AOs are:

  • A.03.01.16.a[01]: each type of wireless access to the system is defined.
  • A.03.01.16.a[02]: usage restrictions are established for each type of wireless access to the system.
  • A.03.01.16.a[03]: configuration requirements are established for each type of wireless access to the system.
  • A.03.01.16.a[04]: connection requirements are established for each type of wireless access to the system.
  • A.03.01.16.b: each type of wireless access to the system is authorized prior to establishing such connections.
  • A.03.01.16.c: wireless networking capabilities not intended for use are disabled prior to issuance and deployment.
  • A.03.01.16.d[01]: wireless access to the system is protected using authentication.
  • A.03.01.16.d[02]: wireless access to the system is protected using encryption.

The eight (8) objectives split part a into four (define the types, then usage, configuration, and connection requirements) and split part d into authentication and encryption as separate facts. An assessor checks each one, so protecting wireless with encryption but not authentication, or the reverse, leaves a gap. The full guidance on assessment methods and objects, is in NIST 800-171A R3, 03.01.16 (p. 18).

Assessment Methods and Objects for NIST 800-171 R3 03.01.16

Examine: access control policy and procedures; procedures for wireless system access; wireless system access configuration and connection requirements; configuration management plan; system configuration settings; wireless access authorizations; system audit records; system design documentation; system security plan.

Interview: personnel with responsibilities for managing wireless access connections; personnel with information security responsibilities; system developers; system administrators.

Test: wireless access management capability for the system; mechanisms for implementing wireless access protections to the system; mechanisms for managing the disabling of wireless networking capabilities.

How Does NIST 800-171 R3 03.01.16 Map From NIST 800-171 R2?

03.01.16 maps from NIST 800-171 R2 requirement 3.1.16 (authorize wireless access prior to allowing such connections), and it absorbs R2 requirement 3.1.17 (protect wireless access using authentication and encryption):

  • A.03.01.16.b maps directly to R2 3.1.16[b] (wireless access is authorized prior to connection).
  • A.03.01.16.d[01] and A.03.01.16.d[02] map directly to R2 3.1.17[b] and 3.1.17[a] (protection using authentication and encryption).
  • A.03.01.16.a[01] maps indirectly to elements of R2 3.1.16[a].
  • A.03.01.16.a[03], A.03.01.16.a[04], and A.03.01.16.c are net new for R3.
  • A.03.01.16.a[02] has no clear mapping to any R2 AO.

Mapped against the eight (8) AOs, three (3) are direct (minimal effort), one (1) is indirect (moderate effort), three (3) are net new, and one (1) has no clear mapping, with the last two (2) categories both counting as significant effort. The authorization and protection halves carry forward, but the configuration requirements, connection requirements, and the disable-before-deployment objective are new, so four of eight (8) objectives are significant effort.

How Does NIST 800-171 R3 03.01.16 Map to NIST 800-53 R5 and the SCF?

Source Controls in NIST 800-53 R5:

  • AC-18
  • AC-18(01)
  • AC-18(03)

Secure Controls Framework (SCF) Crosswalk

Organizations running a single control set across multiple frameworks can satisfy 03.01.16 through the following SCF controls:

  • CHG-04.2 Role-Based Permissions To Implement Changes
  • CFG-04 Secure Baseline Configurations
  • CFG-04.8 Wireless Access Authentication & Encryption
  • CFG-04.18 Disable Wireless Networking
  • IAC-03 Authenticate, Authorize and Audit (AAA)
  • IAO-09 Applied Security, Compliance and Resilience Controls Documentation
  • NET-02 Network Security Controls (NSC)
  • NET-22 Guest Networks
  • NET-24 Wireless Networking
  • NET-24.1 Wireless Networking Authentication & Encryption
  • SEA-04 Alignment With Enterprise Architecture
  • SEA-05 Secure Engineering Principles

The crosswalks from NIST 800-171 R3 and NIST 800-171A R3 to the SCF are available at no cost through the SCF Set Theory Relationship Mapping (STRM): https://securecontrolsframework.com/start-here/set-theory-relationship-mapping-strm. The STRM also carries the relationship type for each mapping (Equal, Subset Of, Intersects With), which tells you whether an SCF control fully satisfies the requirement or only part of it. Mapping above taken from SCF 2026.3.

Common Pitfalls with NIST 800-171 R3 03.01.16

The following are issues teams may encounter rather than certainties. They are about the new objectives and the split protections, each of which needs documented evidence of due diligence and due care such as policies, standards, procedures, and configuration screenshots:

  • Disable unused wireless before deployment. A.03.01.16.c is net new and easy to miss. It requires disabling wireless networking capabilities that are not intended for use before a device is issued, not after it is already in the field.
  • Authentication and encryption are separate objectives. A.03.01.16.d[01] and A.03.01.16.d[02] are assessed independently. Both must protect wireless access.
  • Configuration and connection requirements are new. A.03.01.16.a[03] and a[04] are net new, and usage restrictions (a[02]) have no clear R2 predecessor. Expect to build these per wireless access type.
  • Watch small form factor devices. Per the NIST discussion, give special attention to smart phones, tablets, and smart watches, which may have wireless capabilities embedded in system components.

What Is Reasonable Evidence For NIST 800-171 R3 03.01.16?

Reasonable objective evidence for an assessment is often subjective. The following examples of evidence to address NIST 800-171 R3 03.01.16 are sourced from the SCF Evidence Request List (ERL), available at https://securecontrolsframework.com/free-content/scf-download. These ERL artifacts are mapped to NIST 800-171 R3 03.01.16 through SCF controls. They establish a starting point for discussions on what an organization needs to have for evidence of due diligence and due care to withstand external scrutiny by an assessor or regulator.

  • E-AST-12 Secure Baseline Configurations Reviews. A review process to ensure secure baseline configurations (sbc) are current and applicable (e.g., system configuration settings and associated documentation).
  • E-AST-13 Secure Baseline Configurations - Cloud-Based Services. Secure baseline configurations for all deployed types of cloud-based services or applications.
  • E-AST-14 Secure Baseline Configurations - Databases. Secure baseline configurations for all deployed types of databases.
  • E-AST-15 Secure Baseline Configurations - Embedded Technologies. Secure baseline configurations for all deployed types of embedded technologies.
  • E-AST-16 Secure Baseline Configurations - Major Applications. Secure baseline configurations for all deployed types of major applications.
  • E-AST-17 Secure Baseline Configurations - Minor Applications. Secure baseline configurations for all deployed types of minor applications.
  • E-AST-18 Secure Baseline Configurations - Mobile Devices. Secure baseline configurations for all deployed types of mobile devices.
  • E-AST-19 Secure Baseline Configurations - Network Devices. Secure baseline configurations for all deployed types of network devices.
  • E-AST-20 Secure Baseline Configurations - Server Class Systems. Secure baseline configurations for all deployed types of server-class operating systems.
  • E-AST-21 Secure Baseline Configurations - Workstation Class Systems. Secure baseline configurations for all deployed types of workstation-class operating systems.
  • E-IAC-02 Defined Roles & Authorizations (RBAC). Defined access control-specific roles (e.g., role based access control (rbac)) that affect both logical and physical access authorizations.
  • E-IAC-06 Authenticate, Authorize and Audit (AAA) Solution. An authenticate, authorize and audit (aaa) solution (on-premises and hosted by external service providers (esp)).
  • E-NET-04 Network Security Controls (NSC). The organization's network security controls (e.g., boundary protections, content filtering, wireless infrastructure, etc.).
  • E-NET-14 Wireless Networking Configuration. Wireless networking configuration, including authentication and encryption, wireless boundaries and guest network isolation.
  • E-SEA-02 Security Architecture. Security architecture-related documentation.
  • E-TDA-02 Secure Engineering & Data Privacy (SEDP). A secure engineering & data privacy (sedp) program. this is program-level documentation in the form of a runbook, playbook or a similar format provides guidance on organizational practices that support existing policies and standards.
  • E-TDA-08 Secure Engineering Principles (SEP). Defined secure engineering principles used to ensure sensitivity, integrity, availability & safety (cias) concerns are properly addressed in the design and implementation of technology assets, applications and/or services (taas).
  • E-TDA-09 Security Architecture View. Documented evidence that identifies security-relevant system elements and their interfaces: • define security context, domains, boundaries, and external interfaces of the system; • align the architecture with (a) the system security objectives and requirements, (b) security design characteristics; and • establish traceability of architecture elements to user and system security requirements.
  • E-TDA-14 System Security Plan (SSP). At least one (1) system security plan (ssp) that covers the sensitive/regulated data environment. there may be multiple ssps, based on applicable contracts.
  • E-TDA-18 System Security Plan (SSP) Reviews. Reviews and/or updates to system security plan (ssp) documentation.

Alongside these, keep the System Security Plan (SSP) narrative for 03.01.16.

Timeline Considerations for NIST 800-171 R3 03.01.16

With four (4) of the eight (8) AOs at significant effort (three net new and one with no clear mapping), 03.01.16 is a meaningful lift. A realistic sequence:

  1. Define the types of wireless access to the system (A.03.01.16.a[01]).
  2. Establish usage, configuration, and connection requirements for each type (A.03.01.16.a[02] through a[04]), building the new configuration and connection requirements.
  3. Authorize each type of wireless access before connections are established (A.03.01.16.b).
  4. Disable wireless capabilities not intended for use before issuance and deployment (A.03.01.16.c), the net-new pre-deployment objective.
  5. Protect wireless access with both authentication and encryption (A.03.01.16.d[01] and d[02]).
  6. Collect evidence for all eight (8) AOs, keeping the per-type requirements, authorizations, disablement, and protections distinct.

Frequently Asked Questions About NIST 800-171 R3 03.01.16

How many assessment objectives does NIST 800-171 R3 03.01.16 have? NIST 800-171A R3 breaks 03.01.16 into eight (8) assessment objectives. An assessor works through each one separately, so each needs its own evidence.

Which NIST 800-53 R5 controls does NIST 800-171 R3 03.01.16 come from? AC-18, AC-18(01), AC-18(03).

How many Organization-Defined Parameters (ODPs) does NIST 800-171 R3 03.01.16 have? None (0). The requirement contains no bracketed assignment, so there is no organization-defined value and nothing for the DoD to specify.

Where does NIST 800-171 R3 03.01.16 sit in the NIST 800-171 R3 Kill Chain? Phase 17, Layered Network Defenses. The Kill Chain is a phased model for sequencing R3 implementation, and it assigns this requirement to that phase.

Bottom Line on NIST 800-171 R3 03.01.16

03.01.16 Wireless Access sets usage, configuration, and connection requirements for wireless access, authorizes each type before connection, disables unused wireless before deployment, and protects wireless with authentication and encryption. It maps from R2 3.1.16 and absorbs 3.1.17, but four of its eight (8) assessment objectives are significant effort because they are net new or lack a clear R2 mapping. The recurring problem is assuming R2 wireless work is enough. Define your wireless access types, build the configuration and connection requirements, authorize each type, disable unused wireless before deployment, and protect access with both authentication and encryption.

Authoritative sources:

Authoritative sources:

This guide reproduces U.S. Government text from NIST 800-171 R3 and NIST 800-171A R3. It is educational, not legal or assessment advice. Last reviewed: 2026-09-22.