Skip to main content
Compliance

NIST SP 800-171 Rev 3: What Changed and What It Means for CMMC

A practical breakdown of NIST SP 800-171 Revision 3: the new control families, reorganized requirements, and what DIB contractors should do now while CMMC still references Rev 2.

CMMC Command Team
Compliance Engineering
Mar 12, 20268 min read
Table of Contents(14 sections)

Updated August 28, 2026: The August 14 Unified Agenda identifies RIN 0790-AM01 as a planned amendment to define a transition from NIST SP 800-171 Revision 2 to Revision 3. Revision 2 remains the current CMMC baseline. The agenda is not an effective rule, and no standalone transition rule or legally effective transition deadline has been published.

NIST SP 800-171 Rev 3 Is Published: Should You Panic?

No. But you should pay attention.

NIST published SP 800-171 Revision 3 in May 2024 as the current revision of the NIST publication. Rev. 3 substantially reorganizes the requirements and adds families, but CMMC Level 2 continues to use Rev. 2 unless DoD changes the program baseline.

However, CMMC Level 2 still references Rev 2 as of August 28, 2026. DoD has not updated CMMC to require Rev 3. DoD also suspended the transition to Phase 2 and future implementation milestones on July 13, 2026, so the former November 2026 rollout date is not a current deadline.

Organizations can track Rev. 3 without claiming a CMMC transition date. Here's what changed and how to prepare.

What Changed in Rev 3

Reorganized Requirements

Rev 2 had 110 controls across 14 families. Rev 3 consolidates and reorganizes these into 97 requirements across 17 families. While some controls were split into more granular requirements and new requirements were added, the overall structure was streamlined. It's a reduction in requirement count, not an expansion.

Three New Control Families

Rev 3 adds three families that didn't exist in Rev 2:

  • Planning (PL): Requires documented security plans describing system boundaries, operational environments, and control implementations. If you're building an SSP for CMMC today, you're already doing most of this.

  • System and Services Acquisition (SA): Addresses secure system acquisition, developer security testing requirements, and supply chain security safeguards at the acquisition level. Organizations procuring systems with CUI implications will need formal acquisition security requirements.

  • Supply Chain Risk Management (SR): Adds requirements for managing supply-chain risks across acquisition, suppliers, system components, and services.

Greater Use of Organization-Defined Parameters

Rev. 3 introduces organization-defined parameters in a number of requirements. Organizations should identify and document those values based on risk, applicable law, regulation, policy, and contractual direction rather than importing a universal value from this article.

Relationship to SP 800-53 Rev. 5

NIST derived the Rev. 3 requirements from the SP 800-53 Rev. 5 moderate baseline and provides mapping resources. The publications are not interchangeable, so organizations should use NIST's official analysis of changes and mappings.

The Transition Timeline

Here's what we know about the DOD's path from Rev 2 to Rev 3:

DateEvent
May 2024NIST publishes SP 800-171 Rev 3 (final)
December 2024CMMC 32 CFR Final Rule takes effect; references Rev 2
November 10, 2025Phase 1 begins with Level 1 and Level 2 self-assessment requirements in applicable solicitations and contracts
July 13, 2026DoD suspends the transition to Phase 2 and future implementation milestones
August 14, 2026The Unified Agenda identifies planned Revision 2-to-Revision 3 rulemaking under RIN 0790-AM01
FutureReplacement rollout dates have not been announced
Future rulemakingNo standalone transition rule or legally effective transition deadline has been published

The key takeaway: Revision 2 remains the current CMMC baseline. Continue using it for current CMMC Level 2 work unless DoD formally changes the baseline. Track Rev 3, but do not assume a transition date from planning documents.

What Should You Do Now?

1. Assess Against the Current Rev 2 Baseline

Review the CMMC requirement in each applicable solicitation, contract, and modification. Current Level 2 assessments use Rev 2's 110 security requirements. Although the regulatory framework provides for Self and C3PAO assessment types, current DoD suspension direction permits only Level 2 Self designations.

2. Understand the Gap

Do not assume that Rev. 2 implementation establishes Rev. 3 conformity. Use NIST's official analysis of changes to assess the organization-specific gap, including:

  • Supply chain risk management
  • Formal security planning documentation
  • System and services acquisition security
  • Added, withdrawn, consolidated, and reorganized requirements identified in NIST's official analysis of changes

3. Start Building Supply Chain Practices

The Supply Chain Risk Management (SR) family is the biggest new area and the hardest to implement quickly. Start by:

  • Inventorying your critical ICT/OT suppliers
  • Documenting your acquisition and procurement processes
  • Establishing supplier assessment criteria

4. Document Your Cloud Architecture

If you use cloud services for CUI processing, document:

  • Which cloud services handle CUI
  • FedRAMP authorization status of each provider
  • Shared responsibility matrix for each service
  • Data flow diagrams showing CUI boundaries

5. Follow the DOD Rulemaking

Monitor official DoD rulemaking and guidance. The August 14, 2026 Unified Agenda identifies RIN 0790-AM01 as a planned amendment to define a Revision 2-to-Revision 3 transition. The official RIN detail lists it at Final Rule Stage, but this is planning evidence only. The agenda is not an effective rule. 32 CFR Part 170 still incorporates Revision 2, and no standalone transition rule or legally effective transition deadline has been published.

How CMMC Command Is Preparing

We're tracking the Rev 3 transition closely. Our roadmap includes:

  • Rev 3 mapping support: using NIST's official mappings to help compare current Rev 2 implementation with Rev 3 requirements
  • Gap identification: highlighting the net-new Rev 3 requirements you'll need to address
  • Updated scoring support: if DOD adopts Rev 3 for CMMC and publishes a corresponding methodology, we'll evaluate the official model
  • Transition planning tools: helping you prioritize the new requirements by effort and impact

Rev 2 implementation may provide useful evidence and technical foundations, but it does not establish Rev 3 conformity. NIST added, withdrew, consolidated, and reorganized requirements, so use the official mappings and an organization-specific gap analysis rather than assuming a straightforward transition.

Start your free CMMC assessment. Use the current Rev 2 baseline and monitor official DoD rulemaking for any future Rev 3 transition.

NIST 800-171Rev 3CMMC Level 2ComplianceZero Trust

Organize your CMMC preparation

Review all 110 requirements and see an estimated SPRS score based on the statuses you enter. Completion time varies. Free, no credit card.