Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

How Do I Implement NIST 800-171 R3 03.01.22 Publicly Accessible Content?

NIST 800-171 R3 03.01.22 Publicly Accessible Content at a Glance

  • Family: 03.01 Access Control (AC)
  • Requirement ID: 03.01.22 Publicly Accessible Content
  • Assessment Objectives (AOs): Three (3) determination statements
  • Organization-Defined Parameters (ODPs): None (0). This requirement contains no organization-defined values
  • Source NIST 800-53 R5 Control: AC-22
  • NIST 800-171 R3 Kill Chain Phase: Phase 6c, Identify Compliance Stakeholders for parts a; Phase 8, Segmented Network Architecture for parts b

Publicly Accessible Content is the requirement that keeps Controlled Unclassified Information (CUI) off the systems anyone can reach, such as public websites. It is the last requirement in the Access Control family and one of the most straightforward, but it is also one of the easiest to leave unproven. Publicly Accessible Content (03.01.22) does two things: train the authorized individuals who post content so that publicly accessible information does not contain CUI, and review publicly accessible systems for CUI and remove it if any is found. Per the NIST discussion, the public is not authorized to have access to nonpublic information, including CUI, so this requirement is about preventing accidental disclosure through public-facing systems.

A common difficulty with this requirement is doing the review but never documenting the training, or doing neither on a recurring basis. The requirement has a people half and a systems half. Training the people who publish content is a distinct objective from reviewing the systems, and an assessor will look for both. A one-time cleanup of the public website does not demonstrate ongoing review, and an undocumented "everyone knows not to post CUI" does not demonstrate training.

Where things stand for companies facing the transition from NIST 800-171 R2 to R3:

  • The National Institute of Standards and Technology (NIST) withdrew R2 on May 14, 2024, the same day R3 was published. The withdrawal notice states that R2 "has been withdrawn (archived), and is provided solely for historical purposes," so it will never receive another correction or clarification from NIST.
  • R2 remains the contractual standard for the Department of Defense (DoD) and the Defense Industrial Base (DIB). Cybersecurity Maturity Model Certification (CMMC) assessments reference it directly: per Title 32 of the Code of Federal Regulations (CFR), section 170.14(c)(3), "the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2."
  • The rulemaking points the other direction. The proposed Controlled Unclassified Information (CUI) rule for the Federal Acquisition Regulation (FAR), published June 23, 2026 as part of the Revolutionary FAR Overhaul, would apply CUI safeguarding requirements government wide rather than only to DoD contracts, and it sets the baseline at R3. That rule is not final, and DoD has separately signaled an interim rule to move CMMC to R3.

What Does NIST 800-171 R3 03.01.22 Actually Require?

The following is reproduced verbatim from NIST 800-171 R3, requirement 03.01.22 Publicly Accessible Content. Only the formatting has been adjusted for readability. This requirement has two (2) lettered parts:

  • a. Train authorized individuals to ensure that publicly accessible information does not contain CUI.
  • b. Review the content on publicly accessible systems for CUI and remove such information, if discovered.

The source control is AC-22 from NIST 800-53. There are no Organization-Defined Parameters (ODPs). Per the NIST discussion, in accordance with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidelines, the public is not authorized to have access to nonpublic information, including CUI. You can read the requirement directly at NIST 800-171 R3, 03.01.22 (p. 18).

What Are the Organization-Defined Parameters (ODPs) Associated with NIST 800-171 R3 03.01.22?

None (0). Requirement 03.01.22 contains no bracketed assignment, so there is no organization-defined value to select and nothing for the DoD to specify. The requirement applies as written.

Your System Security Plan (SSP) narrative for 03.01.22 therefore records how the requirement is implemented rather than a parameter you chose.

What Are the Assessment Objectives (AOs) For NIST 800-171 R3 03.01.22?

NIST 800-171A R3 breaks 03.01.22 into three (3) determination statements, and it has no Organization-Defined Parameters (ODPs). These AOs are:

  • A.03.01.22.a: authorized individuals are trained to ensure that publicly accessible information does not contain CUI.
  • A.03.01.22.b[01]: the content on publicly accessible systems is reviewed for CUI.
  • A.03.01.22.b[02]: CUI is removed from publicly accessible systems, if discovered.

The three (3) objectives are the training (A.03.01.22.a), the review (A.03.01.22.b[01]), and the removal (A.03.01.22.b[02]). Each is separately assessed, so training without review, or review without a removal process, leaves an objective open. The full guidance on assessment methods and objects, is in NIST 800-171A R3, 03.01.22 (p. 21).

Assessment Methods and Objects for NIST 800-171 R3 03.01.22

Examine: access control policy and procedures; procedures for publicly accessible content; list of users authorized to post publicly accessible content on organizational systems; training materials or records; records of publicly accessible information reviews; records of response to CUI discovered on public websites; system audit logs; security awareness training records; system security plan.

Interview: personnel with responsibilities for managing publicly accessible information posted on organizational systems; personnel with information security responsibilities.

Test: mechanisms for implementing the management of publicly accessible content.

How Does NIST 800-171 R3 03.01.22 Map From NIST 800-171 R2?

03.01.22 maps from NIST 800-171 R2 requirement 3.1.22 (control CUI posted or processed on publicly accessible systems):

  • A.03.01.22.b[01] maps directly to R2 3.1.22[c] and 3.1.22[d] (the content is reviewed for CUI).
  • A.03.01.22.b[02] maps directly to R2 3.1.22[e] (CUI is removed if discovered).
  • A.03.01.22.a has no clear mapping to any R2 AO.

Mapped against the three (3) AOs, two (2) are direct (minimal effort) and one (1) has no clear mapping (significant effort), with none indirect and none net new. The review and removal carry forward cleanly. The training objective is the one to watch: even though R2 addressed publicly accessible content, the R3 training objective does not trace cleanly to a R2 objective, so treat it as work you need to document rather than assume.

How Does NIST 800-171 R3 03.01.22 Map to NIST 800-53 R5 and the SCF?

Source Control in NIST 800-53 R5:

  • AC-22

Secure Controls Framework (SCF) Crosswalk

Organizations running a single control set across multiple frameworks can satisfy 03.01.22 through the following SCF controls:

  • MON-19 Monitoring For Information Disclosure
  • DCH-08.2 Disclosure of Sensitive / Regulated Data
  • DCH-24 Publicly Accessible Content
  • HRS-04 Defined Roles & Responsibilities
  • HRS-04.1 Assigned Roles & Responsibilities Awareness
  • HRS-05.1 Roles With Special Protection Measures
  • HRS-06 Terms of Employment
  • HRS-06.1 Rules of Behavior
  • HRS-08.1 Formal Indoctrination
  • IRO-20 Sensitive / Regulated Data Spill Response
  • SAT-04 Security, Compliance & Resilience Awareness Training
  • SAT-05 Role-Based Security, Compliance & Resilience Training
  • SAT-05.1 Sensitive / Regulated Data Storage, Handling & Processing
  • WEB-02 Web Security
  • WEB-13 Publicly Accessible Content Reviews

The crosswalks from NIST 800-171 R3 and NIST 800-171A R3 to the SCF are available at no cost through the SCF Set Theory Relationship Mapping (STRM): https://securecontrolsframework.com/start-here/set-theory-relationship-mapping-strm. The STRM also carries the relationship type for each mapping (Equal, Subset Of, Intersects With), which tells you whether an SCF control fully satisfies the requirement or only part of it. Mapping above taken from SCF 2026.3.

Common Pitfalls with NIST 800-171 R3 03.01.22

The following are issues teams may encounter rather than certainties. They are about the training objective and recurring evidence, each of which needs documented evidence of due diligence and due care such as policies, standards, procedures, and configuration screenshots:

  • Training is its own objective. A.03.01.22.a requires that the authorized individuals who post content are trained so that publicly accessible information does not contain CUI. It has no clear R2 mapping, so plan to build and document it, not assume it.
  • Review has to be ongoing. A.03.01.22.b[01] is a review of publicly accessible systems for CUI. A single cleanup does not demonstrate a recurring review, so keep dated records.
  • Removal needs a process, not just an intent. A.03.01.22.b[02] requires that discovered CUI is removed. Evidence of a defined removal process, and of actual removals when found, is what an assessor looks for.
  • Know your publicly accessible systems. You cannot review what you have not inventoried. Identify every public-facing system in scope so the review and removal objectives actually cover them.

What Is Reasonable Evidence For NIST 800-171 R3 03.01.22?

Reasonable objective evidence for an assessment is often subjective. The following examples of evidence to address NIST 800-171 R3 03.01.22 are sourced from the SCF Evidence Request List (ERL), available at https://securecontrolsframework.com/free-content/scf-download. These ERL artifacts are mapped to NIST 800-171 R3 03.01.22 through SCF controls. They establish a starting point for discussions on what an organization needs to have for evidence of due diligence and due care to withstand external scrutiny by an assessor or regulator.

  • E-DCH-11 Authorized Users To Post Publicly Accessible Content. List of users authorized to post publicly accessible content on organizational systems.
  • E-DCH-12 Publicly Accessible Information Reviews. Reviews for publicly accessible sensitive / regulated data.
  • E-DCH-16 Data Loss Prevention (DLP) Configuration. Data loss prevention (dlp) and exfiltration prevention configurations.
  • E-HRS-02 Assigned Roles - Application Developers. List of employed or contract personnel assigned to application development roles.
  • E-HRS-03 Assigned Roles - Cybersecurity Staff. List of employed or contract personnel assigned to cybersecurity roles.
  • E-HRS-04 Assigned Roles - Data Privacy Staff. List of employed or contract personnel assigned to data privacy roles.
  • E-HRS-11 Role Assignment - Sensitive / Regulated Data. A formal role assignment to personnel who are cleared to handle sensitive/regulated data.
  • E-HRS-13 Defined Cybersecurity & Data Privacy Responsibilities. A role-based cybersecurity & data privacy responsibilities to ensure personnel are both educated on the role and are responsible for the associated control execution.
  • E-HRS-14 Responsibilities Review. A formal review process to ensure assigned responsibilities currently reflect business needs for the assigned role.
  • E-HRS-16 Access Agreements. Personnel management practices protecting sensitive/regulated data through formal access agreements.
  • E-HRS-17 Background Checks. Personnel screening practices, which centers around some form of formalized background check process.
  • E-HRS-18 Provisioning Checklist (Onboarding). Personnel management practices to formally onboard personnel into their assigned roles.
  • E-HRS-22 Rules of Behavior. Personnel management practices to define "acceptable use" or "rules of behavior" criteria that specify acceptable and unacceptable user behaviors.
  • E-IRO-12 Sensitive / Regulated Data Spills. Records of response to sensitive / regulated data spills.
  • E-SAT-02 Initial User Training. Initial user training for security, compliance and/or resilience topics.
  • E-SAT-04 Recurring User Training. Recurring (e.g., annual) user training for security, compliance and/or resilience topics.
  • E-SAT-05 Role-Based Training. Specialized user training for privileged users, executives, individuals who handle sensitive/regulated data, etc.
  • E-SAT-06 Training Materials. Security awareness training materials (e.g., curriculum, course work, presentations, etc.).
  • E-WEB-01 Web Security Standard & Application Framework. The organization's web security standard and approved web application framework(s).

Alongside these, keep the System Security Plan (SSP) narrative for 03.01.22.

Timeline Considerations for NIST 800-171 R3 03.01.22

With two (2) AOs mapping directly and one with no clear mapping, 03.01.22 is a light lift with one objective to build. A realistic sequence:

  1. Build and document training for authorized individuals who post content (A.03.01.22.a), the objective with no clear R2 predecessor.
  2. Inventory your publicly accessible systems so the review has defined scope.
  3. Establish a recurring review of publicly accessible systems for CUI (A.03.01.22.b[01]).
  4. Define and use a removal process when CUI is discovered (A.03.01.22.b[02]).
  5. Collect evidence for all three (3) AOs, including training records and dated review and removal records.

Frequently Asked Questions About NIST 800-171 R3 03.01.22

How many assessment objectives does NIST 800-171 R3 03.01.22 have? NIST 800-171A R3 breaks 03.01.22 into three (3) assessment objectives. An assessor works through each one separately, so each needs its own evidence.

Which NIST 800-53 R5 control does NIST 800-171 R3 03.01.22 come from? AC-22.

How many Organization-Defined Parameters (ODPs) does NIST 800-171 R3 03.01.22 have? None (0). The requirement contains no bracketed assignment, so there is no organization-defined value and nothing for the DoD to specify.

Where does NIST 800-171 R3 03.01.22 sit in the NIST 800-171 R3 Kill Chain? Phase 6c, Identify Compliance Stakeholders for parts a; Phase 8, Segmented Network Architecture for parts b. The Kill Chain is a phased model for sequencing R3 implementation, and it assigns this requirement to that phase.

Bottom Line on NIST 800-171 R3 03.01.22

03.01.22 Publicly Accessible Content trains the people who post content and reviews public-facing systems for CUI, removing any that is found. It maps from R2 3.1.22 with the review and removal transitioning directly, while the training objective has no clear R2 mapping and is effectively new. The recurring problem is doing the review but never documenting the training or the recurring cadence. Train your content authors, inventory your public systems, review them for CUI on a schedule, remove what you find, and keep the records.

Authoritative sources:

Authoritative sources:

This guide reproduces U.S. Government text from NIST 800-171 R3 and NIST 800-171A R3. It is educational, not legal or assessment advice. Last reviewed: 2026-09-22.