Framework overlap

Does NIST SP 800-171 cover ISO 15189:2022?

You hold NIST SP 800-171 and have been told to do ISO 15189:2022. Here is how much overlaps, control by control.

26% of ISO 15189:2022 you already have

NIST SP 800-171 already covers about 26% of ISO 15189:2022, leaving 55 of 74 controls as genuinely new work.

Already covered 0 Likely covered 19 New work 55

No control in NIST SP 800-171 maps directly to one in ISO 15189:2022. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in NIST SP 800-171 reaches these. This is the list to scope.

27006-6.1
Competence of personnel
27006-6.2
Personnel Records
5.4
Establishing Audit Programme
6.8
Externally Provided Products and Services
7.5
Threat assessment
7.7
Likelihood estimation
7.8
Consequence estimation
8.9
Management Reviews
ISO-15189-4.1
Impartiality
ISO-15189-4.2
Confidentiality
ISO-15189-4.3
Requirements regarding patients
ISO-15189-5.2
Laboratory director
ISO-15189-5.3
Laboratory activities
ISO-15189-5.5
Objectives and policies
ISO-15189-6.4
Equipment
ISO-15189-6.6
Reagents and consumables
ISO-15189-7.2
Pre-examination processes
ISO-15189-7.3
Examination processes
ISO-15189-7.5
Nonconforming work
ISO-15189-7.6
Data and information management
ISO-15189-7.7
Complaints
ISO-15189-8.1
General requirements
ISO-15189-8.2
Management system documentation
ISO-15189-8.3
Control of documents
ISO-15189-8.5
Actions addressing risks and opportunities
ISO-15189-8.6
Improvement
ISO-15189-8.7
Nonconformities and corrective actions
ISO-15189-8.8
Evaluations
ISO-15189-8.9
Management reviews
ISO-17025-4.1
Impartiality
ISO-17025-4.2
Confidentiality
ISO-17025-6.2
Personnel
ISO-17025-6.3
Facilities and environmental conditions
ISO-17025-6.4
Equipment
ISO-17025-6.6
Externally provided products and services
ISO-17025-7.1
Review of requests, tenders and contracts
ISO-17025-7.10
Nonconforming work
ISO-17025-7.11
Control of data and information management
ISO-17025-7.2
Selection, verification and validation of methods
ISO-17025-7.3
Sampling
ISO-17025-7.4
Handling of test or calibration items
ISO-17025-7.5
Technical records
ISO-17025-7.6
Evaluation of measurement uncertainty
ISO-17025-7.7
Ensuring the validity of results
ISO-17025-7.8
Reporting of results
ISO-17025-7.9
Complaints
ISO-17025-8.1
Options
ISO-17025-8.2
Management system documentation
ISO-17025-8.3
Control of management system documents
ISO-17025-8.4
Control of records
ISO-17025-8.5
Actions to address risks and opportunities
ISO-17025-8.6
Improvement
ISO-17025-8.7
Corrective actions
ISO-17025-8.8
Internal audits
ISO-17025-8.9
Management reviews
Show the 19 you already have
6.4
Logging and Monitoring
6.5
Preparing and Distributing Audit Report
6.6
Confidentiality or non-disclosure agreements
6.7
Conducting Audit Follow-up
8.5
Control effectiveness review
8.8
Management of technical vulnerabilities
A.1
Point-of-Care Testing Additional Requirements
ISO-15189-5.1
Legal entity
ISO-15189-5.4
Structure and authority
ISO-15189-5.6
Risk management
ISO-15189-6.2
Personnel
ISO-15189-6.3
Facilities and environmental conditions
ISO-15189-6.5
Equipment calibration and metrological traceability
ISO-15189-6.7
Service agreements
ISO-15189-6.8
Externally provided products and services
ISO-15189-7.4
Post-examination processes
ISO-15189-7.8
Continuity and emergency preparedness
ISO-15189-8.4
Control of records
ISO-17025-6.5
Metrological traceability

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-171 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition