The Incident Response family (3.6) in NIST SP 800-171 is short — three requirements — but it separates paper programs from real ones. An assessor can tell within minutes whether your incident response exists only as a document or as something your team can actually do.
What 3.6 requires
- 3.6.1 — establish an operational incident-handling capability: preparation, detection, analysis, containment, recovery, and user response.
- 3.6.2 — track, document, and report incidents to the appropriate officials, internal and external.
- 3.6.3 — test your incident response capability. This is the one teams skip.
The 72-hour clock
For contractors under DFARS 252.204-7012, a cyber incident affecting covered information must be reported to DoD within 72 hours. That is not a lot of time to discover you do not know who declares an incident, how to preserve evidence, or where the reporting portal is. The clock starts whether or not you are ready for it.
Test it before it is real
Requirement 3.6.3 exists because plans that are never rehearsed fail under pressure. A tabletop exercise — walking a realistic scenario through your plan with the actual people who would respond — surfaces the gaps cheaply: unclear roles, missing contact info, an escalation path that dead-ends. Run one at least annually, and after any major change.
What good looks like
A mature capability has named roles, a tested playbook, evidence-preservation steps, the 72-hour reporting path mapped, and a record of exercises. That record is also your evidence at assessment time — proof the capability is real, not aspirational.
We help teams build incident response that holds up under both an attack and an assessment. See how we operationalize the 800-171 controls.