IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
C31-R1 candidate · acceptance pending

NIST SP 800-171 Rev. 3

97 active Rev. 3 security requirements, 422 assessment determinations and 88 organization-defined parameter review items. Define applicable parameters and retain supporting evidence.

Assessment preparation in Professional and MSP

Create a scoped program, review requirement descriptions and evidence guidance, link evidence, record workpaper conclusions, assess readiness and export reports. Incident workflows use the selected framework. Free retains its existing ISO assessment limits.

What still requires review

Only explicitly mapped technical checks provide supporting observations. Missing data never means passed. Applicability, scope, parameters, governance evidence and final conclusions require human review. There is no automatic certification or authorization.

C12 is the owner-confirmed working baseline. C31-R1 installation acceptance and signing remain pending; other framework packs remain in development.