An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
Welcome to Microsoft Q&A
Hello @Jay Deena I hope you are doing well.
The NIST 800-171 Customer Responsibility Matrix (CRM) referenced in Appendix J of the Azure – Commercial – System Security Plan (2025) is not always published directly in the Service Trust Portal. Some compliance artifacts are provided only upon request because they are considered controlled audit documentation.
Check the following:
- Verify that you are signed in to the Service Trust Portal with an account that has access to audit documentation.
- If the CRM is still not available, open a Service Trust Portal support request or contact Microsoft Support and reference:
- Azure – Commercial – System Security Plan (2025)
- Appendix J
- The specific document requested: Azure Commercial Cloud NIST SP 800-171 Customer Responsibility Matrix (CRM).
- Appendix J
- Azure – Commercial – System Security Plan (2025)
- If the document has been moved or is restricted, Microsoft can confirm its availability or provide the appropriate access path.
References
- Azure NIST SP 800-171 compliance offering: https://learn.microsoft.com/azure/compliance/offerings/offering-nist-800-171
- Microsoft Service Trust Portal: https://servicetrust.microsoft.com/
If my answer helped you resolve your issue, please consider marking it as the correct answer. This helps others in the community find solutions more easily.