NIST SP 800-171 Rev. 2 Crosswalk
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
How each practice relates to NIST SP 800-171 Rev. 2 requirement identifiers, with the relationship type, our confidence in the mapping, and what the row explicitly does not claim.
How to use it
Use the identifier column to find the requirement in its own source document, then read the caveat before drawing any conclusion. Where a row is marked Supporting or Contextual, the practice is one contribution among several — it is not the whole requirement.
How these mappings were made
Each mapping was read against the primary source text and then classified by relationship type and confidence. No automated mapping tool was used, and no row asserts equivalence.
Relationship type and confidence are editorial judgements, not authoritative equivalence. Read the caveat column before using any row in a compliance conversation.
| Term | Meaning |
|---|---|
| Direct | The practice addresses the substance of the requirement head-on. |
| Supporting | The practice materially helps satisfy the requirement but does not cover it alone. |
| Enabling | The practice is a prerequisite that makes the requirement achievable. |
| Contextual | The practice informs or constrains how the requirement is met. |
| High confidence | Reviewed against the primary source text; the relationship is explicit. |
| Moderate confidence | Reviewed against the primary source; the relationship is a reasoned interpretation. |
| Low confidence | Directional only. Treat as a starting point for your own analysis. |
This is independent educational material. It supports planning and evidence collection; it does not establish compliance with NIST SP 800-171, DFARS 252.204-7012, CMMC, export-control obligations, or any contract requirement, and it is not an assessment. Tailor every item to your own technical, operational, contractual, regulatory, and safety requirements.
IT Top 10
| Practice | Short title | Identifier | Relationship | Confidence | Caveat |
|---|---|---|---|---|---|
| IT-01 | Phishing-resistant MFA | 3.5.3 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-02 | Asset inventory | 3.4.1 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-03 | Technical debt reduction | 3.4.1 / 3.14.1 | Supporting | Moderate | 800-171 does not contain a technical-debt requirement. This is a reasoned relationship, not a stated one. |
| IT-04 | Flexible technology stack | 3.4.2 | Supporting | Moderate | 800-171 requires configuration settings to be enforced. It says nothing about vendor flexibility or portability, which is the campaign's emphasis here. |
| IT-05 | Logical segmentation | 3.13.1 / 3.13.5 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-06 | Risk-based vulnerability management | 3.11.2 / 3.11.3 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-07 | Security in the development lifecycle | 3.4.3 / 3.14.1 | Supporting | Moderate | 800-171 does not contain secure-development requirements. This is a reasoned relationship, not a stated one. |
| IT-08 | Secure AI adoption | 3.1.3 / 3.1.20 | Supporting | Moderate | 800-171 has no AI-specific requirement. The relationship holds only where the AI service is an external system handling controlled information. |
| IT-09 | Backup and disaster recovery | 3.8.9 | Direct | High | The 800-171 requirement is specifically about protecting backup confidentiality. Availability and tested recovery are good practice and campaign intent, not that requirement's text. |
| IT-10 | Technical workforce readiness | 3.2.1 / 3.2.2 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
OT Top 10
| Practice | Short title | Identifier | Relationship | Confidence | Caveat |
|---|---|---|---|---|---|
| OT-01 | OT identity and access control | 3.1.1 / 3.1.5 | Supporting | Moderate | Most OT is outside the CUI boundary. The mapping applies only where OT systems process, store, or transmit controlled information. |
| OT-03 | OT network segmentation | 3.13.1 / 3.13.5 | Supporting | Moderate | Most OT is outside the CUI boundary. The mapping applies only where controlled information is present. |
| OT-04 | OT incident response and recovery | 3.6.1 / 3.6.3 | Supporting | Moderate | Most OT is outside the CUI boundary. The mapping applies only where controlled information is present. |
| OT-05 | OT vulnerability management | 3.11.2 / 3.14.1 | Supporting | Moderate | Most OT is outside the CUI boundary, and 800-171 does not contemplate the patch constraints of control systems. |
| OT-06 | OT remote access pathways | 3.1.12 / 3.1.14 | Supporting | Moderate | Most OT is outside the CUI boundary. The mapping applies only where controlled information is present. |
| OT-07 | OT continuous monitoring | 3.14.6 / 3.14.7 | Supporting | Moderate | Most OT is outside the CUI boundary. The mapping applies only where controlled information is present. |
| OT-08 | OT system resiliency | 3.8.9 | Supporting | Low | Directional only. Most controller backups contain no controlled information, so this mapping rarely applies. |
| OT-10 | OT change review | 3.4.3 / 3.4.4 | Supporting | Moderate | Most OT is outside the CUI boundary, and 800-171 does not contemplate safety impact analysis. |
Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-nist-800-171-rev2-crosswalk to keep filenames consistent across your team.