Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

How Do I Implement NIST 800-171 R3 03.01.20 Use of External Systems?

NIST 800-171 R3 03.01.20 Use of External Systems at a Glance

  • Family: 03.01 Access Control (AC)
  • Requirement ID: 03.01.20 Use of External Systems
  • Assessment Objectives (AOs): Six (6) total, including the one (1) Organization-Defined Parameters (ODPs) below and five (5) determination statements
  • Organization-Defined Parameters (ODPs): One (1), specified by the Department of Defense (DoD) for the Defense Industrial Base (DIB). One (1) of these is defined as guidance rather than a fixed value
  • Source NIST 800-53 R5 Controls: AC-20, AC-20(01), AC-20(02)
  • NIST 800-171 R3 Kill Chain Phase: Phase 16, IT Asset Management (ITAM)

Use of External Systems governs how authorized individuals may use systems that your organization does not own or control to reach your system or to handle Controlled Unclassified Information (CUI). External systems include personally owned devices, privately owned devices in public facilities, systems owned by nonfederal organizations, and systems managed by contractors. Use of External Systems (03.01.20) prohibits their use unless specifically authorized, requires you to establish the security requirements they must meet, permits their use only after verification and agreements are in place, and restricts organization-controlled portable storage devices on them. It is closely related to External System Services (03.16.03), which covers the services those external systems provide.

A common difficulty with this requirement is treating it as a simple "no personal devices" policy. R3 is more structured than that. It expects a defined set of security requirements for external systems, verification against your system security plan before use, retained connection or processing agreements, and a specific restriction on portable storage devices. The single Organization-Defined Parameter (ODP) here is the set of security requirements external systems must satisfy, and the Department of Defense (DoD) has published guidance on what that parameter should address.

Where things stand for companies facing the transition from NIST 800-171 R2 to R3:

  • The National Institute of Standards and Technology (NIST) withdrew R2 on May 14, 2024, the same day R3 was published. The withdrawal notice states that R2 "has been withdrawn (archived), and is provided solely for historical purposes," so it will never receive another correction or clarification from NIST.
  • R2 remains the contractual standard for the Department of Defense (DoD) and the Defense Industrial Base (DIB). Cybersecurity Maturity Model Certification (CMMC) assessments reference it directly: per Title 32 of the Code of Federal Regulations (CFR), section 170.14(c)(3), "the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2."
  • The rulemaking points the other direction. The proposed Controlled Unclassified Information (CUI) rule for the Federal Acquisition Regulation (FAR), published June 23, 2026 as part of the Revolutionary FAR Overhaul, would apply CUI safeguarding requirements government wide rather than only to DoD contracts, and it sets the baseline at R3. That rule is not final, and DoD has separately signaled an interim rule to move CMMC to R3.

What Does NIST 800-171 R3 03.01.20 Actually Require?

The following is reproduced verbatim from NIST 800-171 R3, requirement 03.01.20 Use of External Systems. Only the formatting has been adjusted for readability. This requirement has four (4) lettered parts, and part c has two sub-parts:

  • a. Prohibit the use of external systems unless the systems are specifically authorized.
  • b. Establish the following security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: [Assignment: organization-defined security requirements].
  • c. Permit authorized individuals to use external systems to access the organizational system or to process, store, or transmit CUI only after:
    1. Verifying that the security requirements on the external systems as specified in the organization's system security plans have been satisfied and
    2. Retaining approved system connection or processing agreements with the organizational entities hosting the external systems.
  • d. Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems.

The source controls are AC-20, AC-20(01), and AC-20(02) from NIST 800-53. The bracketed assignment in part b is the Organization-Defined Parameter (ODP): the security requirements external systems must satisfy. Per the NIST discussion, organizations may prohibit any type of external system or specific types, and terms and conditions are consistent with the trust relationships established with the entities that own, operate, or maintain those systems. You can read the requirement directly at NIST 800-171 R3, 03.01.20 (p. 17).

What Are the Organization-Defined Parameters (ODPs) Associated with NIST 800-171 R3 03.01.20?

One (1) value sits inside this requirement. Depending on your contract, your organization may be permitted to define it. Organizations in the DIB subject to CMMC are not, because the DoD has defined it as policy.

The value below comes from Attachment A of the DoD Chief Information Officer (CIO) memorandum dated 10 April 2025 (signed David W. McKeown). The memo identifies each parameter by requirement sub-part, while NIST 800-171A R3 identifies the same parameter by ODP number. Both identifiers appear below so you can match your System Security Plan (SSP) language to either document.

  • ODP[01] (DoD memo identifier 03.01.20.b). security requirements to be satisfied on external systems prior to allowing the use of or access to those systems by authorized individuals are defined. DoD Position: Guidance rather than a fixed value; see the memo text below.

The guidance for 03.01.20.b, quoted from the memo:

Organizations establish specific terms and conditions for the use of external systems in accordance with organizational security policies and procedures. At a minimum, terms and conditions address the specific types of applications that can be accessed on organizational systems from external systems and the highest security category of information that can be processed, stored, or transmitted on external systems. If the terms and conditions with the owners of the external systems cannot be established, organizations may impose restrictions on organizational personnel using those external systems. If applicable, use NIST SP 800-47 as a guide for establishing information exchanges between organizations.

Where the memo gives guidance rather than a fixed value, the guidance tells you how to approach the decision and the decision itself remains yours to make and document. The memorandum does this in four (4) instances across the whole publication.

The memo states that its values "will be updated as necessary," so confirm against the current version before writing them into policy.

What Are the Assessment Objectives (AOs) For NIST 800-171 R3 03.01.20?

NIST 800-171A R3 breaks 03.01.20 into six (6) assessment objectives: one (1) Organization-Defined Parameter (ODP) and five (5) determination statements. These AOs are:

  • A.03.01.20.ODP[01]: security requirements to be satisfied on external systems prior to allowing the use of or access to those systems by authorized individuals are defined.
  • A.03.01.20.a: the use of external systems is prohibited unless the systems are specifically authorized.
  • A.03.01.20.b: the following security requirements to be satisfied on external systems prior to allowing the use of or access to those systems by authorized individuals are established: <A.03.01.20.ODP[01]: security requirements>.
  • A.03.01.20.c.01: authorized individuals are permitted to use external systems to access the organizational system or to process, store, or transmit CUI only after verifying that the security requirements on the external systems as specified in the organization's system security plans have been satisfied.
  • A.03.01.20.c.02: authorized individuals are permitted to use external systems to access the organizational system or to process, store, or transmit CUI only after retaining approved system connection or processing agreements with the organizational entity hosting the external systems.
  • A.03.01.20.d: the use of organization-controlled portable storage devices by authorized individuals on external systems is restricted.

The ODP defines the security requirements external systems must satisfy. If you are a DoD contractor, treat it as guided rather than open. Per ComplianceForge's NIST 800-171 R3 Transition Guide, the DoD guidance for this parameter is that, at a minimum, the terms and conditions address the specific types of applications that can be accessed on organizational systems from external systems and the highest security category of information that can be processed, stored, or transmitted on external systems, and that if terms and conditions cannot be established with the external system owners, the organization may impose restrictions on personnel using those systems. The full guidance on assessment methods and objects, is in NIST 800-171A R3, 03.01.20 (p. 20).

Assessment Methods and Objects for NIST 800-171 R3 03.01.20

Examine: access control policy and procedures; procedures for the use of external systems; terms and conditions for the use of external systems; external systems security requirements; list of types of applications accessible from external systems; system configuration settings; system security plan.

Interview: personnel with responsibilities for defining terms, conditions, and security requirements for the use of external systems; personnel with information security responsibilities; system administrators.

Test: mechanisms for implementing or enforcing terms, conditions, and security requirements for the use of external systems.

How Does NIST 800-171 R3 03.01.20 Map From NIST 800-171 R2?

03.01.20 maps from NIST 800-171 R2 requirement 3.1.20 (verify and control or limit connections to and use of external systems), and it absorbs R2 requirement 3.1.21 (limit use of portable storage devices on external systems):

  • A.03.01.20.ODP[01], A.03.01.20.a, A.03.01.20.b, A.03.01.20.c.01, A.03.01.20.c.02, and A.03.01.20.d all map indirectly to elements of R2 3.1.20 and 3.1.21.

Mapped against the six (6) AOs, all six (6) are indirect (moderate effort), with no net-new AOs and none with no mapping. On the surface that means no brand-new objectives, but the indirect mapping is doing real work here. R3 pulled the external systems requirement and the portable storage requirement together and restructured them around a defined set of security requirements, verification against the system security plan, and retained agreements. You should re-analyze rather than assume your R2 external systems evidence transfers as-is.

How Does NIST 800-171 R3 03.01.20 Map to NIST 800-53 R5 and the SCF?

Source Controls in NIST 800-53 R5:

  • AC-20
  • AC-20(01)
  • AC-20(02)

Secure Controls Framework (SCF) Crosswalk

Organizations running a single control set across multiple frameworks can satisfy 03.01.20 through the following SCF controls:

  • DCH-07 Sensitive / Regulated Data Protection
  • DCH-08.1 Sensitive / Regulated Data Sharing Decisions
  • DCH-09 Sensitive / Regulated Data Access Mapping
  • DCH-20 Portable Storage Devices
  • DCH-22 Use of External Technology Assets, Applications and/or Services (TAAS)
  • DCH-22.1 Limits of Authorized Use To Process, Store and/or Transmit Data
  • DCH-22.2 Protecting Sensitive / Regulated Data on External Technology Assets, Applications and/or Services (TAAS)
  • DCH-22.3 Non-Organizationally Owned Technology Assets, Applications and/or Services (TAAS)
  • DCH-25 Ad-Hoc Transfers
  • DCH-26 Transfer Authorizations
  • DCH-27 Media & Data Retention
  • MDM-02 Centralized Management Of Mobile Devices
  • MDM-07 Organization-Owned Mobile Devices
  • NET-05 Interconnection Security Agreements (ISAs)
  • TPM-02 Third-Party Management
  • TPM-14 Third-Party Contract Requirements
  • TPM-22 First-Party Declaration (1PD)
  • TPM-23 Third-Party Attestation (3PA)

The crosswalks from NIST 800-171 R3 and NIST 800-171A R3 to the SCF are available at no cost through the SCF Set Theory Relationship Mapping (STRM): https://securecontrolsframework.com/start-here/set-theory-relationship-mapping-strm. The STRM also carries the relationship type for each mapping (Equal, Subset Of, Intersects With), which tells you whether an SCF control fully satisfies the requirement or only part of it. Mapping above taken from SCF 2026.3.

Common Pitfalls with NIST 800-171 R3 03.01.20

The following are issues teams may encounter rather than certainties. They are about structure and evidence, each of which needs documented evidence of due diligence and due care such as policies, standards, procedures, and configuration screenshots:

  • Define the security requirements parameter. A.03.01.20.b depends on ODP[01]. If you never defined the security requirements external systems must satisfy, there is nothing to verify against, and the DoD guidance sets the minimum topics to cover.
  • Verification and agreements are separate objectives. A.03.01.20.c.01 (verify against the system security plan) and c.02 (retain approved connection or processing agreements) are assessed independently. Verifying without retaining the agreements, or the reverse, leaves a gap.
  • Portable storage on external systems is called out. A.03.01.20.d restricts organization-controlled portable storage devices on external systems. This is the absorbed R2 3.1.21 obligation and is easy to overlook once it is folded into a larger requirement.
  • Coordinate with 03.16.03. Per the NIST discussion, this requirement is related to External System Services (03.16.03). Keep the use-of-external-systems evidence and the external-services evidence aligned.

What Is Reasonable Evidence For NIST 800-171 R3 03.01.20?

Reasonable objective evidence for an assessment is often subjective. The following examples of evidence to address NIST 800-171 R3 03.01.20 are sourced from the SCF Evidence Request List (ERL), available at https://securecontrolsframework.com/free-content/scf-download. These ERL artifacts are mapped to NIST 800-171 R3 03.01.20 through SCF controls. They establish a starting point for discussions on what an organization needs to have for evidence of due diligence and due care to withstand external scrutiny by an assessor or regulator.

  • E-AST-11 Data Retention Program. A formal data retention program that governs the retention and destruction of data types.
  • E-AST-18 Secure Baseline Configurations - Mobile Devices. Secure baseline configurations for all deployed types of mobile devices.
  • E-DCH-02 Data Handling Practices. An organization-specific data handling practices (e.g., guidance specific the data classification scheme).
  • E-DCH-18 Removable Media Controls. Removable media and portable storage device restrictions and use authorizations.
  • E-DCH-19 Sensitive / Regulated Data Transfer Authorizations. Authorizations and records for ad-hoc and external transfers of sensitive / regulated data.
  • E-MDM-01 Mobile Device Management (MDM) Configuration. Mobile device management (mdm) configuration, including centralized management, access restrictions for unauthorized devices, device / container encryption, separate profiles and geofencing.
  • E-MDM-02 Mobile Device Ownership & Enrollment Inventory. Enrolled mobile devices by ownership model (organization-owned, personally-owned / byod, third-party devices).
  • E-NET-06 Authorized Network Connections. Third-party technology assets, applications and/or services (taas) authorized to connect to organizational taas, including remote access authorizations.
  • E-RSK-02 Supply Chain Risk Management (SCRM) Plan. A supply chain risk management (scrm) plan. this is program-level documentation in the form of a playbook, concept of operations or a similar format provides guidance on organizational practices that support existing policies and standards.
  • E-TPM-01 Third-Party Contracts. Third-party contractual obligations for cybersecurity & data privacy protections.
  • E-TPM-03 Third-Party Service Reviews. A formal, annual stakeholder review of third-party services for each external service provider (esp).
  • E-TPM-06 Third-Party Terms & Conditions. Terms and conditions for external systems.
  • E-TPM-07 System Connection or Processing Agreements. System connection or processing agreements.

Alongside these, keep the System Security Plan (SSP) narrative for 03.01.20 recording the ODP values you adopted.

Timeline Considerations for NIST 800-171 R3 03.01.20

With all six (6) AOs mapping indirectly, 03.01.20 is a moderate lift, but the restructuring means real re-analysis. A realistic sequence:

  1. Define the security requirements external systems must satisfy (A.03.01.20.ODP[01]), using the DoD guidance for the minimum topics if you are a DoD contractor.
  2. Establish the prohibition on unauthorized external systems (A.03.01.20.a) and document the specific authorizations.
  3. Establish the security requirements in policy (A.03.01.20.b) and capture them in the system security plan so they can be verified.
  4. Put the verification step and the retained connection or processing agreements in place (A.03.01.20.c.01 and c.02).
  5. Restrict organization-controlled portable storage devices on external systems (A.03.01.20.d).
  6. Collect evidence for all six (6) AOs, keeping the defined requirements, authorizations, verifications, agreements, and portable storage restriction distinct.

Frequently Asked Questions About NIST 800-171 R3 03.01.20

What value does the DoD require for the organization-defined parameter in NIST 800-171 R3 03.01.20? R3 leaves the value to the organization. For the DIB, the DoD set it in the 10 April 2025 memorandum under ODP identifier 03.01.20.b: guidance rather than a fixed value. Organizations establish specific terms and conditions for the use of external systems in accordance with organizational security policies and procedures. At a minimum, terms and conditions address the specific types of applications that can be accessed on organizational systems from external systems and the highest security category of information that can be processed, stored, or transmitted on external systems. If the terms and conditions with the owners of the external systems cannot be established, organizations may impose restrictions on organizational personnel using those external systems. If applicable, use NIST SP 800-47 as a guide for establishing information exchanges between organizations.

How many assessment objectives does NIST 800-171 R3 03.01.20 have? NIST 800-171A R3 breaks 03.01.20 into six (6) assessment objectives: one (1) Organization-Defined Parameters (ODPs) and five (5) determination statements. An assessor works through each one separately, so each needs its own evidence.

Which NIST 800-53 R5 controls does NIST 800-171 R3 03.01.20 come from? AC-20, AC-20(01), AC-20(02).

Where does NIST 800-171 R3 03.01.20 sit in the NIST 800-171 R3 Kill Chain? Phase 16, IT Asset Management (ITAM). The Kill Chain is a phased model for sequencing R3 implementation, and it assigns this requirement to that phase.

Bottom Line on NIST 800-171 R3 03.01.20

03.01.20 Use of External Systems prohibits unauthorized external systems, defines the security requirements they must meet, permits their use only after verification and retained agreements, and restricts organization-controlled portable storage on them. It maps from R2 3.1.20 and absorbs 3.1.21, with all six (6) assessment objectives transitioning indirectly, so there is no net-new objective but real restructuring. Define the security-requirements parameter (guided by DoD for DoD work), authorize specific external systems, verify against your system security plan, retain the agreements, and restrict portable storage.

Authoritative sources:

Authoritative sources:

This guide reproduces U.S. Government text from NIST 800-171 R3 and NIST 800-171A R3 and references the DoD ODP memorandum of 10 April 2025. It is educational, not legal or assessment advice. Last reviewed: 2026-09-22.