This section emphasizes confidentiality, integrity, and availability of CUI. The guidance outlines requirements for access control, system monitoring, incident response, and supply chain management, among others. It aims to provide a unified cybersecurity framework for organizations handling sensitive government data, ensuring compliance and strengthening overall security posture.

Official PDF (nvlpubs.nist.gov) NIST Special Publication 800 NIST SP 800-171r3: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

Many Control Families are ITAR related.

Example Section 3.0 Requirements - in this example, the physical controls have been identified. This should assist in isolating those that are are tied to net electronic storage of CUI. Family Controls for Physical Compliance Only

CMMC 2.0 Level 1

What is the Differences Between CMMC 2.0 Levels 1,2,3 (JCP and ITAR)