Date Published: May 2026
Supersedes:
SP 800-172 (02/02/2021)
Planning Note (05/13/2026):
The enhanced security requirements in SP 800-172r3 are available in multiple data formats. The PDF of SP 800-172r3 is the authoritative source of the enhanced security requirements. If there are any discrepancies noted in the content between the CPRT dataset, OSCAL dataset, and the SP 800-172r3 PDF, please contact [email protected] and refer to the PDF as the normative source.
None selected
Publication:
https://doi.org/10.6028/NIST.SP.800-172r3
Download URL
Supplemental Material:
Enhanced Security Requirements Overlay
SP 800-172 to SP 800-172r3 Change Analysis
172r3 dataset on CPRT
172r3 dataset in OSCAL
Publication Parts:
SP 800-172A Rev. 3
Related NIST Publications:
Document History:
11/13/24: SP 800-172 Rev. 3 (Draft)
09/29/25: SP 800-172 Rev. 3 (Draft)
05/13/26: SP 800-172 Rev. 3 (Final)
advanced persistent threats, continuous monitoring, planning, risk assessment
Laws and RegulationsFederal Information Security Modernization Act, OMB Circular A-130