NIST 800-171 · System and Communications Protection

Requirement 3.13.11

SPRS weight
SPRS weight: 5
POA&M eligibility
POA&M-eligible
Assessment objectives
1 assessment objective

Official requirement text

Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.13.11FIPS-validated cryptography is employed to protect the confidentiality of CUI.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.