NIST PF PR.MA-P - Maintenance
Perform and log maintenance with approved, controlled tools; approve and log remote maintenance while preventing unauthorized access.
Where this comes from
Provision: PR.MA-P - Maintenance
Instrument: NIST Privacy Framework Version 1.0
Citation: NIST Privacy Framework Version 1.0 (16 January 2020), Core, PR.MA-P1 and PR.MA-P2
Text version: NIST Privacy Framework 1.0 Core, 16 January 2020 (not PF 1.1)
Checked against the source: 6 September 2026
Who it applies to
It applies when all of these are true:
- NIST PF 1.0 Target Profile adopted: YES
- PR.MA-P: Which outcomes are selected in this project's Target Profile? is PR.MA-P1 or PR.MA-P2
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Maintenance and repairs are performed in a timely manner with approved, controlled tools and are logged
- Remote maintenance is explicitly approved, logged, and performed so as to prevent unauthorized access
- Maintenance access is revoked promptly after the work is completed
- Maintenance records are retained for audit
- System handles null/empty input gracefully (no 500 errors)
Questions people ask
- Does NIST PF PR.MA-P - Maintenance apply to my service?
- It applies when NIST PF 1.0 Target Profile adopted: YES; PR.MA-P: Which outcomes are selected in this project's Target Profile? is PR.MA-P1 or PR.MA-P2.
- From when does this apply?
- NIST PF PR.MA-P - Maintenance applies from 16 January 2020. Its current status is: in force.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.