Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.11.01OFFICIAL TITLEPENDING NIST SME REVIEW

03.11.01Risk Assessment

03.11 Risk Assessment · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires assessing the risk — including supply chain risk — to organizational operations, assets, and individuals that results from operating the system and from processing, storing, or transmitting CUI, and updating those risk assessments at an organization-defined frequency.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

The risk assessment is where 'we should do something about security' becomes 'these are the threats that matter to our contracts, our production line, and our people — in this order.' Done honestly, it is the prioritization every other requirement's effort traces back to; done for the shelf, it is the first artifact an assessor notices has gone stale.

Across revisions

Carried forward from Rev. 2's 3.11.1 with two visible changes: supply chain risk is named in the requirement, and the update cadence becomes an organization-defined parameter rather than an unquantified 'periodically'.

Mapped practices

Brilliant at the Basics practices that support this requirement

Contextual relationshipModerate confidence

Why: Current, risk-ranked vulnerability data is one of the strongest inputs a periodic risk assessment can draw on — it grounds the exposure picture in what is actually reachable and exploitable in the environment rather than in generic threat lists.

What this does not claim: Feeding a risk assessment is not performing one. The requirement covers risk to operations, assets, and individuals — supply chain risk included — at a scope no scanner output reaches, and it needs a documented assessment updated on the defined frequency, which the practice neither produces nor schedules.

Practice-side activities
  • Provide ranked vulnerability and exposure summaries as an input to the organizational risk assessment
Evidence this produces
  • Risk assessment sections citing current vulnerability data as an input

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Scope the assessment around CUI: where it lives, how it moves, which systems and suppliers touch it — not a generic threat catalog copied from a template.
  • Cover supply chain risk explicitly — Rev. 3 names it — including the services and components the system depends on, not just your own perimeter.
  • Set and record the update frequency, and tie off-cycle updates to real triggers: a new contract, a new system, an incident, changed threat intelligence.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • A dated risk assessment identifying threats, exposures, likelihood, and impact for the systems handling CUI
  • The defined update frequency and records of updates on that cadence or on triggering events
  • Traceability from the top risks to decisions actually made about them

Suggested owners, derived from the mapped practices and artifacts: IT leader / MSP · IT leader or compliance lead. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated