NIST SP 800-171 Rev 3: What Changed and What It Means for CMMC
A practical breakdown of NIST SP 800-171 Revision 3: the new control families, reorganized requirements, and what DIB contractors should do now while CMMC still references Rev 2.
Table of Contents(14 sections)
Updated August 28, 2026: The August 14 Unified Agenda identifies RIN 0790-AM01 as a planned amendment to define a transition from NIST SP 800-171 Revision 2 to Revision 3. Revision 2 remains the current CMMC baseline. The agenda is not an effective rule, and no standalone transition rule or legally effective transition deadline has been published.
NIST SP 800-171 Rev 3 Is Published: Should You Panic?
No. But you should pay attention.
NIST published SP 800-171 Revision 3 in May 2024 as the current revision of the NIST publication. Rev. 3 substantially reorganizes the requirements and adds families, but CMMC Level 2 continues to use Rev. 2 unless DoD changes the program baseline.
However, CMMC Level 2 still references Rev 2 as of August 28, 2026. DoD has not updated CMMC to require Rev 3. DoD also suspended the transition to Phase 2 and future implementation milestones on July 13, 2026, so the former November 2026 rollout date is not a current deadline.
Organizations can track Rev. 3 without claiming a CMMC transition date. Here's what changed and how to prepare.
What Changed in Rev 3
Reorganized Requirements
Rev 2 had 110 controls across 14 families. Rev 3 consolidates and reorganizes these into 97 requirements across 17 families. While some controls were split into more granular requirements and new requirements were added, the overall structure was streamlined. It's a reduction in requirement count, not an expansion.
Three New Control Families
Rev 3 adds three families that didn't exist in Rev 2:
-
Planning (PL): Requires documented security plans describing system boundaries, operational environments, and control implementations. If you're building an SSP for CMMC today, you're already doing most of this.
-
System and Services Acquisition (SA): Addresses secure system acquisition, developer security testing requirements, and supply chain security safeguards at the acquisition level. Organizations procuring systems with CUI implications will need formal acquisition security requirements.
-
Supply Chain Risk Management (SR): Adds requirements for managing supply-chain risks across acquisition, suppliers, system components, and services.
Greater Use of Organization-Defined Parameters
Rev. 3 introduces organization-defined parameters in a number of requirements. Organizations should identify and document those values based on risk, applicable law, regulation, policy, and contractual direction rather than importing a universal value from this article.
Relationship to SP 800-53 Rev. 5
NIST derived the Rev. 3 requirements from the SP 800-53 Rev. 5 moderate baseline and provides mapping resources. The publications are not interchangeable, so organizations should use NIST's official analysis of changes and mappings.
The Transition Timeline
Here's what we know about the DOD's path from Rev 2 to Rev 3:
| Date | Event |
|---|---|
| May 2024 | NIST publishes SP 800-171 Rev 3 (final) |
| December 2024 | CMMC 32 CFR Final Rule takes effect; references Rev 2 |
| November 10, 2025 | Phase 1 begins with Level 1 and Level 2 self-assessment requirements in applicable solicitations and contracts |
| July 13, 2026 | DoD suspends the transition to Phase 2 and future implementation milestones |
| August 14, 2026 | The Unified Agenda identifies planned Revision 2-to-Revision 3 rulemaking under RIN 0790-AM01 |
| Future | Replacement rollout dates have not been announced |
| Future rulemaking | No standalone transition rule or legally effective transition deadline has been published |
The key takeaway: Revision 2 remains the current CMMC baseline. Continue using it for current CMMC Level 2 work unless DoD formally changes the baseline. Track Rev 3, but do not assume a transition date from planning documents.
What Should You Do Now?
1. Assess Against the Current Rev 2 Baseline
Review the CMMC requirement in each applicable solicitation, contract, and modification. Current Level 2 assessments use Rev 2's 110 security requirements. Although the regulatory framework provides for Self and C3PAO assessment types, current DoD suspension direction permits only Level 2 Self designations.
2. Understand the Gap
Do not assume that Rev. 2 implementation establishes Rev. 3 conformity. Use NIST's official analysis of changes to assess the organization-specific gap, including:
- Supply chain risk management
- Formal security planning documentation
- System and services acquisition security
- Added, withdrawn, consolidated, and reorganized requirements identified in NIST's official analysis of changes
3. Start Building Supply Chain Practices
The Supply Chain Risk Management (SR) family is the biggest new area and the hardest to implement quickly. Start by:
- Inventorying your critical ICT/OT suppliers
- Documenting your acquisition and procurement processes
- Establishing supplier assessment criteria
4. Document Your Cloud Architecture
If you use cloud services for CUI processing, document:
- Which cloud services handle CUI
- FedRAMP authorization status of each provider
- Shared responsibility matrix for each service
- Data flow diagrams showing CUI boundaries
5. Follow the DOD Rulemaking
Monitor official DoD rulemaking and guidance. The August 14, 2026 Unified Agenda identifies RIN 0790-AM01 as a planned amendment to define a Revision 2-to-Revision 3 transition. The official RIN detail lists it at Final Rule Stage, but this is planning evidence only. The agenda is not an effective rule. 32 CFR Part 170 still incorporates Revision 2, and no standalone transition rule or legally effective transition deadline has been published.
How CMMC Command Is Preparing
We're tracking the Rev 3 transition closely. Our roadmap includes:
- Rev 3 mapping support: using NIST's official mappings to help compare current Rev 2 implementation with Rev 3 requirements
- Gap identification: highlighting the net-new Rev 3 requirements you'll need to address
- Updated scoring support: if DOD adopts Rev 3 for CMMC and publishes a corresponding methodology, we'll evaluate the official model
- Transition planning tools: helping you prioritize the new requirements by effort and impact
Rev 2 implementation may provide useful evidence and technical foundations, but it does not establish Rev 3 conformity. NIST added, withdrew, consolidated, and reorganized requirements, so use the official mappings and an organization-specific gap analysis rather than assuming a straightforward transition.
Start your free CMMC assessment. Use the current Rev 2 baseline and monitor official DoD rulemaking for any future Rev 3 transition.
Related Resources
Organize your CMMC preparation
Review all 110 requirements and see an estimated SPRS score based on the statuses you enter. Completion time varies. Free, no credit card.