Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
CROSSWALK · IT / OTv1.0 · REVIEWED 2026-07-28

NIST SP 800-171 Rev. 2 Crosswalk

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

How each practice relates to NIST SP 800-171 Rev. 2 requirement identifiers, with the relationship type, our confidence in the mapping, and what the row explicitly does not claim.

How to use it

Use the identifier column to find the requirement in its own source document, then read the caveat before drawing any conclusion. Where a row is marked Supporting or Contextual, the practice is one contribution among several — it is not the whole requirement.

How these mappings were made

Each mapping was read against the primary source text and then classified by relationship type and confidence. No automated mapping tool was used, and no row asserts equivalence.

Relationship type and confidence are editorial judgements, not authoritative equivalence. Read the caveat column before using any row in a compliance conversation.

TermMeaning
DirectThe practice addresses the substance of the requirement head-on.
SupportingThe practice materially helps satisfy the requirement but does not cover it alone.
EnablingThe practice is a prerequisite that makes the requirement achievable.
ContextualThe practice informs or constrains how the requirement is met.
High confidenceReviewed against the primary source text; the relationship is explicit.
Moderate confidenceReviewed against the primary source; the relationship is a reasoned interpretation.
Low confidenceDirectional only. Treat as a starting point for your own analysis.

IT Top 10

PracticeShort titleIdentifierRelationshipConfidenceCaveat
IT-01Phishing-resistant MFA3.5.3DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-02Asset inventory3.4.1DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-03Technical debt reduction3.4.1 / 3.14.1SupportingModerate800-171 does not contain a technical-debt requirement. This is a reasoned relationship, not a stated one.
IT-04Flexible technology stack3.4.2SupportingModerate800-171 requires configuration settings to be enforced. It says nothing about vendor flexibility or portability, which is the campaign's emphasis here.
IT-05Logical segmentation3.13.1 / 3.13.5DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-06Risk-based vulnerability management3.11.2 / 3.11.3DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-07Security in the development lifecycle3.4.3 / 3.14.1SupportingModerate800-171 does not contain secure-development requirements. This is a reasoned relationship, not a stated one.
IT-08Secure AI adoption3.1.3 / 3.1.20SupportingModerate800-171 has no AI-specific requirement. The relationship holds only where the AI service is an external system handling controlled information.
IT-09Backup and disaster recovery3.8.9DirectHighThe 800-171 requirement is specifically about protecting backup confidentiality. Availability and tested recovery are good practice and campaign intent, not that requirement's text.
IT-10Technical workforce readiness3.2.1 / 3.2.2DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.

OT Top 10

PracticeShort titleIdentifierRelationshipConfidenceCaveat
OT-01OT identity and access control3.1.1 / 3.1.5SupportingModerateMost OT is outside the CUI boundary. The mapping applies only where OT systems process, store, or transmit controlled information.
OT-03OT network segmentation3.13.1 / 3.13.5SupportingModerateMost OT is outside the CUI boundary. The mapping applies only where controlled information is present.
OT-04OT incident response and recovery3.6.1 / 3.6.3SupportingModerateMost OT is outside the CUI boundary. The mapping applies only where controlled information is present.
OT-05OT vulnerability management3.11.2 / 3.14.1SupportingModerateMost OT is outside the CUI boundary, and 800-171 does not contemplate the patch constraints of control systems.
OT-06OT remote access pathways3.1.12 / 3.1.14SupportingModerateMost OT is outside the CUI boundary. The mapping applies only where controlled information is present.
OT-07OT continuous monitoring3.14.6 / 3.14.7SupportingModerateMost OT is outside the CUI boundary. The mapping applies only where controlled information is present.
OT-08OT system resiliency3.8.9SupportingLowDirectional only. Most controller backups contain no controlled information, so this mapping rarely applies.
OT-10OT change review3.4.3 / 3.4.4SupportingModerateMost OT is outside the CUI boundary, and 800-171 does not contemplate safety impact analysis.

NIST SP 800-171 Rev. 2 Crosswalk · version 1.0 · reviewed 2026-07-28 · file name batb-nist-800-171-rev2-crosswalk

Generated from Framework crosswalk at brilliantatthebasics.us. The live pages carry the current version of this guidance.

Independent educational material published by inDirectIT, Inc. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Cybersecurity practices must be tailored to each organization’s technical, operational, contractual, regulatory, and safety requirements.

All downloads

Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-nist-800-171-rev2-crosswalk to keep filenames consistent across your team.