Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
CROSSWALK · IT / OTv1.0 · REVIEWED 2026-07-28

NIST SP 800-171 Rev. 3 Crosswalk

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

How each practice relates to NIST SP 800-171 Rev. 3 requirement identifiers. Rev. 3 renumbers and reorganizes Rev. 2 rather than replacing it wholesale — where a reviewed Rev. 3 mapping does not yet exist for a practice, the row is deliberately absent rather than guessed.

How to use it

Use the identifier column to find the requirement in its own source document, then read the caveat before drawing any conclusion. Where a row is marked Supporting or Contextual, the practice is one contribution among several — it is not the whole requirement.

How these mappings were made

Each mapping was read against the primary source text and then classified by relationship type and confidence. No automated mapping tool was used, and no row asserts equivalence.

Relationship type and confidence are editorial judgements, not authoritative equivalence. Read the caveat column before using any row in a compliance conversation.

TermMeaning
DirectThe practice addresses the substance of the requirement head-on.
SupportingThe practice materially helps satisfy the requirement but does not cover it alone.
EnablingThe practice is a prerequisite that makes the requirement achievable.
ContextualThe practice informs or constrains how the requirement is met.
High confidenceReviewed against the primary source text; the relationship is explicit.
Moderate confidenceReviewed against the primary source; the relationship is a reasoned interpretation.
Low confidenceDirectional only. Treat as a starting point for your own analysis.

IT Top 10

PracticeShort titleIdentifierRelationshipConfidenceCaveat
IT-01Phishing-resistant MFA03.05.03DirectHighRev 3 does not require phishing-resistant methods by name. Choosing them exceeds the stated requirement rather than being compelled by it.
IT-02Asset inventory03.04.01DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-05Logical segmentation03.13.01DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-06Risk-based vulnerability management03.11.02DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-09Backup and disaster recovery03.08.09DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-10Technical workforce readiness03.02.01 / 03.02.02DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.

NIST SP 800-171 Rev. 3 Crosswalk · version 1.0 · reviewed 2026-07-28 · file name batb-nist-800-171-rev3-crosswalk

Generated from Framework crosswalk at brilliantatthebasics.us. The live pages carry the current version of this guidance.

Independent educational material published by inDirectIT, Inc. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Cybersecurity practices must be tailored to each organization’s technical, operational, contractual, regulatory, and safety requirements.

All downloads

Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-nist-800-171-rev3-crosswalk to keep filenames consistent across your team.