An enhanced set of cybersecurity requirements published by the National Institute of Standards and Technology (NIST) to provide additional protection against Advanced Persistent Threats (APTs). Officially titled “Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST SP 800-171,” this framework builds on the 110 controls in NIST SP 800-171 by introducing advanced practices such as penetration-resistant architectures, more rigorous monitoring, and layered defensive strategies.

NIST SP 800-172 is intended for organizations that work with the highest-risk data in the Defense Industrial Base (DIB). While not every contractor is required to implement these controls, they are especially relevant for companies seeking to achieve CMMC Level 3 (Expert), where protection from sophisticated nation-state-level cyber threats is expected.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.