NIST 800-171 Rev 3 Has Not Gone Anywhere. Here's What Actually Changes.
NIST SP 800-171 Revision 2 is still the enforced standard during the CMMC pause, but the DoD has already told everyone Revision 3 is next. Here's what's different and why it matters.
Risk Level
Read Time
If you have Controlled Unclassified Information (CUI) in your environment, you're probably familiar with NIST SP 800-171, the baseline security requirements you're contractually obligated to implement under DFARS 252.204-7012. Revision 2 is still the version that governs your CMMC assessment today. But Revision 3 has existed since May 2024, and the DoW has said, more than once, they intend to transition to it. It's worth understanding what's actually different before that happens.
You may remember in another ACT post that the DoW suspended CMMC Phase II while a task force spends 60 days reviewing the whole program. That review doesn't touch on Revision 3 directly, but it's a reminder that the CMMC rulebook is not static. Revision 2 is the baseline today. Revision 3 is expected to be assessed against, eventually.
“Ok, so what's the difference between Rev 2 and Rev 3?”
The overall structure of Revision 3 aligns much more closely with NIST 800-53, the same control framework that underpins FedRAMP and FISMA. That means most requirements now come with multiple lettered parts and specific parameters your organization has to fill in and document, rather than one broad statement of intent.
Take least privilege as an example. In Revision 2, the entire requirement was one sentence: employ the principle of least privilege, including for specific security functions and privileged accounts. In Revision 3, that same requirement (now numbered 03.01.05) is broken into four parts. You still have to limit access to what's necessary for the job. But you now also have to name the specific security functions and security-relevant information you're authorizing access to, and define how often you'll review those privileges.
Additionally, Revision 2 organizes 110 security controls into 14 families. Each one splits into a “basic” requirement (the high-level obligation) and one or more “derived” requirements underneath it (the specifics). Revision 3 drops that split entirely and reorganizes everything into 97 controls across 17 families. The three new families NIST added that didn't exist before are:
Planning (PL) pulls together requirements that used to be scattered elsewhere, like maintaining a system security plan and giving system users documented rules of behavior they have to acknowledge before they get access to CUI.
System and Services Acquisition (SA) covers things like replacing system components once a vendor stops supporting them and applying security engineering principles when you build or modify a system. It also means holding external service providers (think cloud vendors) to the same security requirements you'd hold yourself to.
Supply Chain Risk Management (SR) requires an actual documented plan for managing risk in how you research, design, manufacture, acquire, and dispose of system components. It also covers acquisition practices like tamper-evident packaging and buying from trusted, vetted suppliers.
“97 is fewer than 110, so this is less work, right?”
A smaller number of requirements doesn't mean a smaller amount of work. The companion assessment guide for Revision 3, NIST SP 800-171Ar3, expanded the number of assessment objectives from 320 under Revision 2 to 422 under Revision 3, a 32% increase. Additionally, Revision 3 introduces organization-defined parameters (ODPs). In April 2025, the DoW issued a memo that sets official values for the ODPs in Revision 3. Account privilege reviews, for example, would have a defined frequency: at least every 12 months. While most ODPs are defined by DoW, some are not, and this will require additional effort from defense contractors.
“So should I stop building to Rev 2 and jump straight to Rev 3?”
No. DFARS 252.204-7012 and the current CMMC requirements still point to Revision 2 today, and the DoW's own class deviation keeps it that way until a rule says otherwise. Building your system security plan entirely to Revision 3 right now would leave you “Unmet” on the requirements you are assessed against.
“If Rev 2 is still being enforced, why should I prepare for Rev 3?”
The class deviation keeping Revision 2 alive can end at any time. No matter what the CMMC assessment process looks like at the end of the 60-day pause, once the new FAR rule finalizes, Revision 3 becomes the standard for every federal agency, not just the DoW.
Additionally, remapping your SSP takes real time, and you don't want to do it twice. New family structure, new numbering, new ODPs to document. That's weeks of work for most organizations and doing it now, on your own schedule, beats doing it later under a contract deadline.
You don't have to map the two revisions yourself to find your gaps. As a C3PAO, we run mock assessments against both today's Revision 2 requirements and the Revision 3 baseline you'll need next, and because we're not the ones certifying you, we can tell you exactly what to fix either way.
Ready to see where you actually stand?
Follow us - stay ahead.