r/NISTControls Feb 24 '19

800-171 Megathread Series Hub

37 Upvotes

r/NISTControls Jan 12 '23

r/NISTControls Official Discord Group

26 Upvotes

We recently had a jump in new members on the sub and the Mod team wanted to formally welcome and thank everyone for joining our community and chatting about all things NIST Controls related.

For all those who aren't aware, the communities of r/GovIT, r/NISTControlsand, and r/CMMC actually have a designated Discord group. We've found that Discord offers an amazing forum to discuss some of the intricacies and rabbit holes many of often us find ourselves in, and we welcome anyone who cares to contribute and hang out with us.

Designated channels for everything from NIST 800-171, GCC-High and Training and Education. It's definitely an amazing place to ask questions and discuss all things r/NISTControls.

Thank you again and Happy New Year,

The Mod Team


r/NISTControls 8d ago

800-171 C3PAO goes away, but NIST 800-171 requirements still apply… for now anyway.

31 Upvotes

From the various press releases, it looks to me that (at least until the 60day review period is up) that 800-171 requirements are still in place. But the Phase 2 (Nov 10th deadline) for C3PAO goes away.

\- Press release calls out “It is critical to note that this action does not eliminate the requirement for companies to protect federal data. All defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012”

\- “[the number of available assessors is not large enough to conduct all the evaluations needed in time for the upcoming November deadline.](https://www.war.gov/News/News-Stories/Article/Article/4542849/war-department-changes-cybersecurity-maturity-model-certification-requirements/)”

\- L2 C3PAO deadline & listing have been removed from the [Overview of Assessments](https://dodcio.defense.gov/CMMC/About/)

I am getting employees stoked that all the controls will be pulled, but I don’t see that as the outcome here.
We still need data security, this just gives some breathing room while standards are re-evaluated.


r/NISTControls 7d ago

What would MA-4 and MA-4(3) implementation look like for an organisation?

2 Upvotes

Typically, the end-to-end process from ticketing of the maintenance request


r/NISTControls 12d ago

Implementing EFS/FIPS on a windows network

5 Upvotes

Hello,

About a year ago, an MSP setup a file server for ITAR/CUI file sharing. Despite the requirements shared with the MSP, they did not implement any type of encryption for data in transit or at rest. Additionally, they set this server up as a single drive. So, the shared data is on the bootable partition. This is a virtual server that is hosted on VMware and according to the Broadcom KB, BitLocker is not supported for boot drives in a VMWare environment. From my understanding, this means we can't enable BitLocker for the C: drive of this virtual server.

Ownership does not want to redo this server since the data stored on it is constantly in use. I was wondering if the following might satisfy 800-171R2 requirements:

- Enable EFS on the data folder that holds CUI/ITAR info.

- Enable mandatory FIPS on the server for network communication between the server and workstations.

Admittedly, I haven't implemented encryption for network traffic before, so this may not work the way I think it does. I'm in the process of learning more but figured I'd potentially save myself time and ask if it was feasible.


r/NISTControls 13d ago

800-171 NIST SP 800-171 Rev 3 is coming to CMMC

30 Upvotes

Thanks to Eric Crucius' diligence, he spotted, like always, the Department of War (DoW) announced a revision to 32 CFR Part 170 for the migration to NIST SP 800-171 Rev 3.

Here are the key Links:

Here is the abstract from the rule:

This amendment defines a deadline and period for transition from the requirement to comply with NIST SP 800-171 Revision 2, to a requirement to comply with NIST SP 800-171 Revision 3. Significant changes between these two documents include added specificity in the security requirements and introduction of organization-defined parameters (ODP) in select security requirements. In addition to revising the NIST documents that are incorporated by reference in 32 CFR part 170, this amendment adds administrative edits and clarifying content in multiple areas as necessary to effect the transition.

Here is the Summary of Need:

With this amendment, DoD amends the Cybersecurity Maturity Model Certification (CMMC) Program to define a period for transition from the requirement to comply with NIST SP 800-171 Revision 2, to a requirement to comply with NIST SP 800-171 Revision 3.  As described by NIST, the significant changes between these two documents include added specificity in the security requirements and introduction of organization-defined parameters (ODPs) in select security requirements. In addition to revising documents incorporated by reference in this rule, this amendment adds administrative edits and clarifying content in multiple areas. 

And the laughable part, DoW thinks 20% less companies will be impacted by 32 CFR Part 170:

In addition to the change from NIST SP 800-171 revision 2 to revision 3, which impacted CMMC Level 2 and LEvel 3 assessment objectives, this rule amendment is based on a more current estimate of the size of the Defense Industrial Base. Overall, we estimate approximately 20% fewer total companies will be impacted by 32 CFR Part 170.


r/NISTControls 15d ago

Deemed export risk when non-US-person employees use AI tools that process ITAR data — how are small suppliers handling this?

5 Upvotes

Trying to get specific here because I haven't found a post that addresses this exact scenario. (Transparency: I'm Jordan, an engineer researching compliance tooling for small defense suppliers — not selling anything in this thread.)

Take a common setup at the shops I'm researching: a small defense subcontractor (sub-50 people), the prime flows ITAR-controlled drawings down, and one or more employees are not US Persons. Under ITAR, releasing controlled technical data to a foreign person — even inside the US — is a deemed export requiring authorization.

Here's the gap I keep running into: most guidance stops at GCC High / AWS GovCloud for data storage. But what about the AI layer? If a non-US-Person employee uses a tool like Copilot or even ChatGPT on a system that could surface or process that drawing — does the model processing count as "access" or "release"? 22 CFR 120.50(a)(2) defines export to include "releasing or otherwise transferring technical data to a foreign person in the United States (a deemed export)." That reads like it could reach the AI inference layer, but I haven't seen a clear BIS/DDTC statement on it.

Two specific questions:

  1. Has anyone gotten a commodity jurisdiction opinion or DDTC guidance that touches AI tools specifically?
  2. For small shops without a full-time ISSO — what's the practical control you've implemented to address this (beyond "don't use those tools")?

r/NISTControls 17d ago

The Feb 2026 FAR overhaul renumbered the CMMC clauses — here's the quick map

14 Upvotes

Ran into this doing paperwork for a re-compete and it tripped me up, so posting in case it saves someone else the confusion. As of Feb 1, 2026 (the "Revolutionary FAR Overhaul," implemented via Class Deviation 2026-O0025, which stood up a new DFARS Part 240 and moved the FCI clause into a new FAR Part 40), several of the clause numbers we're all used to changed:

  • DFARS 252.204-7019 — deleted.
  • DFARS 252.204-7020 — renumbered to 252.240-7997, and rewritten. The new text only defines Medium and High assessments (both government-performed, per NIST SP 800-171A). The old "Basic" self-assessment definition is gone from the clause itself.
  • FAR 52.204-21 (the Level 1 / FCI "basic safeguarding" clause) — renumbered to 52.240-93.
  • DFARS 252.204-7012 — unchanged.
  • DFARS 252.204-7021 (the CMMC requirement clause) — unchanged.

The part that actually bit me: both the old and new numbers are "live" right now. Solicitations issued on/after Feb 1, 2026 use the new numbers (252.240-7997, 52.240-93); existing/older contracts still cite the legacy numbers (252.204-7020, 52.204-21). So it's not a clean find-and-replace in your own docs — you match the number to the contract's vintage.

What did not change, and this is the important part: your actual obligations. If you handle CUI and a solicitation calls for CMMC Level 2 (Self), you still self-assess against the same 110 controls, post to SPRS, and affirm — that all lives under 252.204-7021, which kept its number. And SPRS/CMMC scoring is still on NIST SP 800-171 Rev 2, not Rev 3.

TL;DR: the FAR overhaul was basically a filing-cabinet reorg for the cyber clauses. The numbers moved; the work didn't.

If I've got any of this wrong I'd genuinely like the correction — primary source is the DoD Class Deviation 2026-O0025 memo under the DFARS RFO Part 240 materials.


r/NISTControls Jun 18 '26

Using AI to write SSP implementation statements?

7 Upvotes

Curious if anyone here is using AI to update/write their SSP implementation statements?

If so, what is your preferred AI?

I've been trying out ChatGPT for this and so far have gotten pretty decent results.


r/NISTControls Jun 17 '26

GCC High and Commercial Cross-Tenant Access Issue

8 Upvotes

I'll preface this by saying I'm in no way an expert and barely know what I'm talking about but I need some help.

I am the product owner of a financial software at my company. We have users all over the country, mostly from other commercial environments. We have one subsidiary that is in a GCC High environment and they've had ongoing issues accessing the application due to this mismatch. We had originally added all of their users to our commercial tenant as guests and they were able to access the application fine at first. It suddenly broke one day, so I started researching. I found that I could set them up within the application to where they could authenticate on their own GCC High tenant by adding a new IdP and having them route to that when authenticating. That seemed to resolve the issue for the most part. Users could access the browser version but not the desktop client version of the software. We held troubleshooting for weeks. On so many occasions, someone would suggest that the new IdP I added was the problem. I argued it wasn't but have been continuously overruled. But every single time I turned it off, can you guess what happened? They couldn't access the browser or the desktop version any longer.

This past weekend, the subsidiary in question did an infrastructure change where they virtualized several old servers onto a brand new machine. Suddenly, all their accesses were working again. Problem solved, right? Today, the IT guy at the location and my VP of finance each suggested this IdP was still some sort of problem. So I turned it off. Again. And can you guess what happened? Again? That's right.

At this point I have no idea why they keep wanting to blame this thing but I also don't really know enough to defend it. Doesn't it make more sense to have the GCC High entity authenticate on their own tenant, rather than guest into a commercial tenant and authenticate there? How can I get through to these people??


r/NISTControls Jun 15 '26

Looking for a CMMC Compliance Tracking and Readiness Tool

Thumbnail
2 Upvotes

r/NISTControls Jun 13 '26

How are you proving what your AI agents actually did, when an assessor asks?

13 Upvotes

I'm researching how security teams are handling AI agents that take actions on a user's behalf.

A few things I keep wondering about and would love to hear how you handle:

  • How do you scope and grant an agent's access? Least-privilege for a non-human, task-scoped actor seems like it doesn't map cleanly.
  • After the fact, can you actually prove what an agent did if an assessor or your ISSM asks?
  • What do you do when doing it the "right" way reduces other's productivity?

r/NISTControls Jun 05 '26

Compliance-as-Code framework

20 Upvotes

I have an open-source compliance tool that helps developers throughout the software development lifecycle. It was recently classified as a Popular Project by Socket.dev.

Its a Compliance-as-Code framework that automatically enforces GDPR, OWASP, NIST, and CIS engineering standards in any software project — regardless of programming language.

Would it be okay if I shared it here?

Repo in here : https://github.com/greenarmor/gesf

Docs: https://greenarmor.github.io/gesf/getting-started/installation/

To anyone want to contribute on the code development you can fork and submit a PR to origin repo: https://github.com/greenarmor/gesf

Thank you to all who dm for link of this project!


r/NISTControls Jun 03 '26

How are people handling "new" deployments during the FIPS 140-2 → 140-3 gap (cert sunset, successor not yet validated)?

Thumbnail
7 Upvotes

r/NISTControls Jun 02 '26

Responsible AI Model Evaluations: 9 weeks of LLM red-team data, mapped directly to NIST AI RMF

Post image
7 Upvotes

We evaluated frontier LLMs (Claude, GPT, Gemini) for responsible AI safety and robustness, and mapped results to the NIST AI Risk Management Framework.

9 weeks of LLM red-team data (26,500 evaluations), mapped directly to NIST AI RMF 1.0. Here's what we found:

GOVERN - Election interference bypassed guardrails at 5.66% avg Attack Success Rate (ASR) across all 7 models, all 9 weeks. No provider improved meaningfully.

MAP - Chemical, Biological, Radiological, and Nuclear (CBRN): 35.41% avg Attack Success Rate. Cybersecurity threats: 21.99%. Malware generation: 12.26%. These are not model-specific failures. They are held across Anthropic, OpenAI, and Google every single week.

MEASURE - Four metrics tracked: Attack Success Rate, False Refusal Rate, Multi-turn Drift, and Provenance. The one most orgs overlook: Gemini 2.5 Pro and GPT-4o Mini are blocking 1 in 6–7 legitimate user requests. Over-refusal isn't just a UX problem - users finding workarounds is a threat surface.

As you are the experts, I am curious to know your feedback on the evaluations.

Here are the evaluation details:
Dashboard (with 9-week trends and insights): https://sushegaad.github.io/Responsible-AI-Model-Evaluations/ 

Github repository (with evaluation code, RedBench dataset + evaluation data): https://github.com/Sushegaad/Responsible-AI-Model-Evaluations

Research: https://github.com/Sushegaad/Responsible-AI-Model-Evaluations/blob/main/research-paper.pdf 


r/NISTControls May 21 '26

What Questions Do You Ask During SSP Control Interviews?

Thumbnail
5 Upvotes

r/NISTControls May 19 '26

Validating a NIST implementation problem: translating engineering procedures into policy

Thumbnail
6 Upvotes

r/NISTControls May 19 '26

CMMC Level 2: Is the WatchGuard Compliance Package worth it if we use PreVeil + M365 Business Premium?

Thumbnail
1 Upvotes

r/NISTControls May 16 '26

Identrust ECA and Yubikey

2 Upvotes

Anyone else use Yubikeys with the yubikey driver and have trouble with ECA?

My experience - yubikey minidriver does not work with HIDActiveClient. I need the minidriver since I have over 2 PIV certs loaded in it.

So I uninstall the active client, and yubikey works - but now I can’t use my ECA!


r/NISTControls May 05 '26

Open STIGs and eMASS help

14 Upvotes

I recently took over the ISSO position for my company as they needed someone last minute. For my first STIG check, I had an overwhelming number of open findings. Looking at eMASS, the previous ISSO did not annotate the reasons why there would be open findings on the STIG checklists or why certain STIGs are not applicable.

I am trying to understand why our infrastructure's configs are missing so many commands. My question is, if this was you, how would you go about this without getting overwhelmed? And at what point would I add these checklists to eMASS?

UPDATE: I have been reading all your posts. Thank you so much for taking the time to respond.

I am the only one in my team. I use Evaluate-Stig and have used SCAP. The results are from Evaluate-Stig. So far, I am checking one 'Open' or 'Not Reviewed' at a time. Since I am working on Cisco devices, most of my open findings relate to ACL's not implemented in our configs. I am not strong in ACL's to determine whether they are needed or not.


r/NISTControls May 05 '26

Is NIST actually usable in cloud, or are we all just faking it for audits?

20 Upvotes

I’ve been digging into NIST and trying to map it to real AWS/Azure/GCP environments, and honestly, the gap between “framework” and reality is bigger than I expected.

What I keep running into:

  • controls look clear (AC-2, CM-6, AU-6), but mapping them to actual cloud resources and owners is messy
  • evidence is the real problem (proving something works over time vs screenshots)
  • asset scope is never clean, especially multi-account/multi-cloud
  • identity sprawl makes access control hard to reason about
  • findings exist, but ownership + remediation tracking is weak
  • everything becomes a last-minute scramble before audits

Curious from people who’ve actually gone through audits.


r/NISTControls May 02 '26

Need Advice on Starting a CMMC Consultancy Business!!

Thumbnail
0 Upvotes

r/NISTControls Apr 26 '26

EMASS & JCAM/CSAM

11 Upvotes

Feels like most fed shops are still stuck in JCAM/CSAM (civilian) or EMASS (defense and maybe a requirement?)with basically zero automation or anything resembling AI. Are folks actually moving off that stack at all? Or is it still just the system of record no matter what?

I’ve heard some teams kicking the tires on stuff like Archer, Xacta, RegScale, etc., but not sure how real that is vs just pilots and slideware.

Anyone actually using one of these in a meaningful way?


r/NISTControls Apr 24 '26

Thoughts on the USB solution

Thumbnail
1 Upvotes

r/NISTControls Apr 18 '26

STIG Workbench — VSCode extension for .cklb files (looking for feedback)

13 Upvotes

So i had to create an ASD Stig for a codebase to submit for one of our contracts, I'm on a MAC. That should signal my frustration. I'm in VScode all day and i know it's available on NIPR AVD's, so i created a STIG workbench in VScode

What it does:

  1. **Open and edit .cklb files inline** — click the file, it opens like any other doc, status changes save back to the JSON

  2. **Filter/search/sort 300 rules instantly** — find your open CAT Is in two seconds

  3. **Multi-checklist dashboard** — aggregate view across every .cklb in your workspace

  4. **Diff checklists** — side-by-side comparison showing what changed between assessments

  5. **Upgrade wizard** — when DISA renumbers Vuln IDs in a quarterly release, matches by rule_version and carries findings forward

  6. **SCAP XCCDF import** — load OpenSCAP or SCC scan results

  7. **InSpec / MITRE SAF HDF import** — apply InSpec results directly, no Heimdall detour

  8. **NIST 800-53 crosswalk** — see which 800-53 controls your STIG actually satisfies via CCI mapping

  9. **CORA-aligned compliance scoring** — weighted CAT I/II/III, open CAT I forces at least High risk

  10. **Exports** — CKL, CSV, POA&M, evidence package

https://marketplace.visualstudio.com/items?itemName=rykelley.stig-workbench

It's on the Marketplace as "STIG Workbench."

But honestly — posting here because I want feedback from people who actually do this work. What's the single worst part of your current workflow? What would make the biggest difference? If you've used MITRE SAF, does the HDF importer actually match how you'd want it to behave? Do you even use VScode?

Roast freely. I'd rather hear "this is missing X" than nothing.