- NIST SP 800-172 Rev 3 (May 2026) contains "enhanced security requirements" to protect Controlled Unclassified Information (CUI).
- Contains a total number of 115 security requirements.
- Requirements are derived from NIST SP 800-53 R5 but exceed what is found in the High Baseline from NIST SP 800-53B Rev 5.
- These requirements are designed to protect High Value Assets (HVAs) that are at risk from Advanced Persistent Threats (APTs).
What Is NIST SP 800-172 Rev 3?
NIST SP 800-172 is a supplement to NIST SP 800-171 that provides a set of enhanced security requirements for protecting Controlled Unclassified Information (CUI). Where NIST SP 800-171 establishes the baseline expectations for safeguarding CUI in nonfederal systems and organizations, NIST SP 800-172 adds a higher tier of protection for the most sensitive CUI, specifically CUI that is associated with a critical program or a High Value Asset (HVA). The Third Revision (Rev 3) was published by NIST in May 2026 and supersedes the original NIST SP 800-172 that was released in February 2021.
The enhanced security requirements are applied on top of a full NIST SP 800-171 implementation, not in place of it. They are derived from NIST SP 800-53 Rev 5 and are designed to counter the Advanced Persistent Threat (APT), meaning well-resourced and highly capable adversaries that target sensitive government information. Rather than a simple checklist, the requirements focus on outcomes such as penetration-resistant architecture, damage-limiting operations, and cyber resiliency and survivability. NIST SP 800-172 is not a standalone framework and it does not apply to all CUI. It applies only when a federal agency selects specific enhanced requirements and requires them through a contract or agreement.
Who Needs To Comply With NIST SP 800-172 Rev 3?
Compliance with NIST SP 800-172 is selective rather than universal. An organization is expected to meet these enhanced requirements only when it stores, processes, or transmits CUI that supports a critical program or High Value Asset (HVA), and a US Federal agency has explicitly required the enhanced protections through a contract or agreement. In practice this is a subset of the organizations that already fall under NIST SP 800-171, and it is closely tied to the highest assurance level of the Cybersecurity Maturity Model Certification (CMMC). Organizations that may be required to meet NIST SP 800-172 include, but are not limited to:
What Are The Penalties For Non-Compliance With NIST SP 800-172 Rev 3?
NIST SP 800-172 is imposed through federal contracts and agreements, so the consequences of non-compliance are significant. When an agency requires these enhanced protections and a contractor cannot meet them, or misrepresents its status, the exposure can be significant. Non-compliance can also be a False Claims Act (FCA) violation, and the US Department of Justice has pursued cybersecurity-related FCA cases against contractors. Potential consequences include, but are not limited to:
Contract Termination
When enhanced requirements are a condition of award, an organization that cannot demonstrate them may be found ineligible for the contract or have an existing contract terminated. Because these requirements flow down the supply chain, a subcontractor that falls short can make the prime contractor non-compliant as a whole.
False Claims Act Exposure
Stating that enhanced requirements are met when they are not is a misrepresentation of material fact. Under the False Claims Act, knowingly submitting or causing false claims that are tied to unmet security requirements can lead to civil liability and substantial financial damages.
Breach of Contract Lawsuits
Both prime contractors and subcontractors can be exposed to breach of contract claims and civil liability. A failure to maintain the agreed security posture, such as the enhanced controls required to counter Advanced Persistent Threats, can support claims of negligence and damages.
As these examples show, the cost of non-compliance can be substantial, both financially and to an organization's eligibility for sensitive work. As always, seek competent legal counsel for any questions about your specific compliance obligations.
How Does ComplianceForge Help Me Comply With NIST SP 800-172 Rev 3?
We take a holistic approach to creating comprehensive cybersecurity documentation that is both scalable and affordable. This goes beyond generic policies and lets you build an audit-ready cybersecurity program that can support the enhanced requirements in NIST SP 800-172.
Editable NIST 800-172 Policies, Standards, Procedures Templates
ComplianceForge's NIST 800-171 / CMMC documentation has been used successfully by multiple companies during DIBCAC and C3PAO assessments to efficiently generate the artifact documentation needed to demonstrate compliance. Because NIST SP 800-172 builds directly on NIST SP 800-171, that same documentation foundation gives you the policies, standards, procedures, SSP, POA&M, Incident Response Plan (IRP), and related artifacts you need before layering on the enhanced requirements for high-value CUI. The SCF-based Security, Compliance & Resilience Program (SCRP) has coverage for NIST 800-172 R3.
The People, Process, Technology, Data and Facility (PPTDF) model shown below helps visualize how requirements are applied, whether a given control is primarily administrative, technical, or physical in nature. You can read more about the concept of PPTDF here.

