How do I get the Azure Commercial Cloud NIST 800-171 CRM?

Jay Deena 0 Reputation points
2026-07-13T20:00:09.7266667+00:00

Hello,

I am looking to get the Azure Commercial Cloud NIST 800-171 CRM. It is referenced in the Azure – Commercial – System Security Plan (2025) in Appendix J. But the workbook is not available on the Service Trust Portal.

Thanks,

Jay

Azure Policy
Azure Policy

An Azure service that is used to implement corporate governance and standards at scale for Azure resources.


3 answers

Sort by: Most helpful
  1. Christos Panagiotidis 3,546 Reputation points
    2026-07-14T07:23:46.7+00:00

    Hi, the document you are looking for is normally provided through the Service Trust Portal rather than the public Azure documentation set. Sign in to the Service Trust Portal with the organizational account tied to your agreement, search the compliance documents for Azure and NIST SP 800-171, and check the restricted documents/download area. Access can vary by tenant and agreement, so if the CRM referenced by your SSP is not visible, use the portal's support/contact option and provide the exact document title and Appendix J reference. I would not substitute a FedRAMP CRM or an older downloaded copy without confirming the service/cloud scope and revision date with your compliance owner.

    Was this answer helpful?

    0 comments No comments

  2. Bharath Y P 10,450 Reputation points Microsoft External Staff Moderator
    2026-07-13T21:31:15.0166667+00:00

    Hello Jay Deena,

    Thank you for reaching out, You're looking for the Azure Commercial Cloud NIST SP 800-171 Customer Responsibility Matrix (CRM). It is referenced in the Azure – Commercial – System Security Plan (2025) under Appendix J, but you're unable to locate the workbook on the Service Trust Portal (STP).

    There are actually two distinct CRM artifacts, which is the source of the confusion:

    Appendix J – CIS / Customer Responsibilities Matrix (referenced in the SSP)[NIST 800-53 (FedRAMP High baseline)]: Delivered inside the Azure Commercial FedRAMP authorization package > STP Audit Reports > FedRAMP Reports (access-controlled)

    Standalone NIST SP 800-171 CRM[NIST 800-171]: STP > Azure Security and Compliance Blueprint section (last updated 23 Oct 2025)

    Direct link to the standalone 800-171 CRM: https://servicetrust.microsoft.com/DocumentPage/278a71c1-0438-4330-abb3-ad475f982f1e

    To access the document:

    1. Sign in to the Service Trust Portal (https://servicetrust.microsoft.com) using your organization's Azure AD (Entra ID) account — sign-in is required to download.
    2. Use the direct link above, or search for "NIST SP 800-171 Customer Responsibility Matrix."
    3. Alternatively, browse to the Azure Security and Compliance Blueprint grouping (not the FedRAMP SSP package).
    4. If you specifically need the Appendix J CIS/CRM (800-53), go to Audit Reports → FedRAMP Reports — note this requires the appropriate STP entitlement/NDA access.
    5. If the file still doesn't appear after sign-in, this is typically an STP access/entitlement issue rather than a missing document.

    Reference:

    Hope this helps, If you have any question, please do let us know, Thank you

    Was this answer helpful?

    0 comments No comments

  3. Jose Benjamin Solis Nolasco 10,891 Reputation points Volunteer Moderator
    2026-07-13T20:25:56.05+00:00

    Welcome to Microsoft Q&A

    Hello @Jay Deena I hope you are doing well.

    The NIST 800-171 Customer Responsibility Matrix (CRM) referenced in Appendix J of the Azure – Commercial – System Security Plan (2025) is not always published directly in the Service Trust Portal. Some compliance artifacts are provided only upon request because they are considered controlled audit documentation.

    Check the following:

    • Verify that you are signed in to the Service Trust Portal with an account that has access to audit documentation.
    • If the CRM is still not available, open a Service Trust Portal support request or contact Microsoft Support and reference:
      • Azure – Commercial – System Security Plan (2025)
        • Appendix J
          • The specific document requested: Azure Commercial Cloud NIST SP 800-171 Customer Responsibility Matrix (CRM).
    • If the document has been moved or is restricted, Microsoft can confirm its availability or provide the appropriate access path.

    References

    If my answer helped you resolve your issue, please consider marking it as the correct answer. This helps others in the community find solutions more easily.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.