Edge Register
Standards ยท SP 800-171

NIST SP 800-171 Rev 3

Rendered when the buyer ticks "NIST SP 800-171 Rev 3 (sites handling CUI)". The register cites 7 of its 97 clauses, behind 4 findings: regulated data at a site with nobody there, remote access to plant, home and field devices with encryption not stated, hardware questions unanswered, and on the duty rows of every site it reaches.

Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim. Source framework: NIST SP 800-171 Rev 3. What it attaches to a site: the SP 800-171 regime page.

Clauses cited

7 of 97
SP 800-171 03.01.12 Remote Access

Establish usage restrictions, configuration requirements, and authorize remote access; route remote access via managed access control points; permit only approved remote execution of privileged commands.

Evidence an auditor accepts: VPN configuration; ZTNA policy; remote access authorization records
Common gap: split tunneling enabled
Source framework: NIST SP 800-171 Rev 3
SP 800-171 03.01.18 Access Control for Mobile Devices

Establish configuration requirements, connection requirements, and implementation guidance for mobile devices; encrypt CUI on mobile devices.

Evidence an auditor accepts: MDM/UEM configuration; device encryption attestations; mobile device inventory
Common gap: BYOD without containers
Source framework: NIST SP 800-171 Rev 3
SP 800-171 03.08.03 Media Sanitization

Sanitize or destroy system media containing CUI before disposal, release, or reuse; verify sanitization actions.

Evidence an auditor accepts: certificates of destruction; sanitization log per NIST SP 800-88; verification reports
Common gap: drives donated without wipe
Source framework: NIST SP 800-171 Rev 3
SP 800-171 03.08.05 Media Transport

Protect and control system media during transport outside controlled areas; maintain accountability; document activities associated with transport.

Evidence an auditor accepts: chain of custody forms; courier service contracts; encryption attestations for transit
Common gap: unencrypted laptops in transit
Source framework: NIST SP 800-171 Rev 3
SP 800-171 03.10.02 Monitoring Physical Access

Monitor physical access to the facility where the system resides; review logs of physical access; coordinate review with incident response.

Evidence an auditor accepts: CCTV retention policy; badge reader logs; physical security incident reports
Common gap: CCTV not retained 90 days
Source framework: NIST SP 800-171 Rev 3
SP 800-171 03.10.06 Alternate Work Site

Determine and document alternate work sites allowed; employ controls at alternate work sites; assess feasibility of controls.

Evidence an auditor accepts: telework policy; home office security checklist; VPN required attestation
Common gap: no home office security baseline
Source framework: NIST SP 800-171 Rev 3
SP 800-171 03.10.07 Physical Access Control

Enforce physical access authorizations at entry/exit points; maintain visitor logs; control access to keys, combinations, and other physical access devices.

Evidence an auditor accepts: visitor logs; key/combination inventory; entry/exit access reports
Common gap: unsigned visitor logs
Source framework: NIST SP 800-171 Rev 3

See which clauses your list engages

Paste the list and every site names the clauses behind it, filtered to the regimes that apply to you. Eight sites free, no account.

Build my edge register