NIST has published SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, alongside the companion assessment guide SP 800-171A Rev. 3.
Key changes
- Requirements are realigned with the SP 800-53 Rev. 5 moderate baseline.
- New requirement families, including supply chain risk management, planning and system and services acquisition.
- Organisation-defined parameters give more flexibility in how requirements are met.
- Some requirements are consolidated or withdrawn.
For UK and European suppliers in US defence and government supply chains, Revision 3 is the direction of travel. A well-run ISO/IEC 27001 ISMS remains a strong foundation.
Source: NIST SP 800-171 Rev. 3 (NIST CSRC)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.