NIST SP 800-171 Rev. 3 Crosswalk
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
How each practice relates to NIST SP 800-171 Rev. 3 requirement identifiers. Rev. 3 renumbers and reorganizes Rev. 2 rather than replacing it wholesale — where a reviewed Rev. 3 mapping does not yet exist for a practice, the row is deliberately absent rather than guessed.
How to use it
Use the identifier column to find the requirement in its own source document, then read the caveat before drawing any conclusion. Where a row is marked Supporting or Contextual, the practice is one contribution among several — it is not the whole requirement.
How these mappings were made
Each mapping was read against the primary source text and then classified by relationship type and confidence. No automated mapping tool was used, and no row asserts equivalence.
Relationship type and confidence are editorial judgements, not authoritative equivalence. Read the caveat column before using any row in a compliance conversation.
| Term | Meaning |
|---|---|
| Direct | The practice addresses the substance of the requirement head-on. |
| Supporting | The practice materially helps satisfy the requirement but does not cover it alone. |
| Enabling | The practice is a prerequisite that makes the requirement achievable. |
| Contextual | The practice informs or constrains how the requirement is met. |
| High confidence | Reviewed against the primary source text; the relationship is explicit. |
| Moderate confidence | Reviewed against the primary source; the relationship is a reasoned interpretation. |
| Low confidence | Directional only. Treat as a starting point for your own analysis. |
This is independent educational material. It supports planning and evidence collection; it does not establish compliance with NIST SP 800-171, DFARS 252.204-7012, CMMC, export-control obligations, or any contract requirement, and it is not an assessment. Tailor every item to your own technical, operational, contractual, regulatory, and safety requirements.
IT Top 10
| Practice | Short title | Identifier | Relationship | Confidence | Caveat |
|---|---|---|---|---|---|
| IT-01 | Phishing-resistant MFA | 03.05.03 | Direct | High | Rev 3 does not require phishing-resistant methods by name. Choosing them exceeds the stated requirement rather than being compelled by it. |
| IT-02 | Asset inventory | 03.04.01 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-05 | Logical segmentation | 03.13.01 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-06 | Risk-based vulnerability management | 03.11.02 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-09 | Backup and disaster recovery | 03.08.09 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-10 | Technical workforce readiness | 03.02.01 / 03.02.02 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-nist-800-171-rev3-crosswalk to keep filenames consistent across your team.