NIST SP 800-171 Rev 3: What Changed and What It Means for CMMC
NIST SP 800-171 Revision 3, published May 14, 2024, replaced Rev 2’s 110 security requirements with 97 across 17 families, added organization-defined parameters, and dropped the basic/derived split. As of August 2026, CMMC and DFARS 252.204-7012 still assess against Rev 2, but a June 2026 proposed FAR rule would require Rev 3 government-wide.
- Rev 3 has 97 security requirements in 17 families, versus 110 requirements in 14 families under Rev 2. Thirty-three Rev 2 requirement numbers are now marked Withdrawn.
- Rev 3 added three families — Planning, System and Services Acquisition, and Supply Chain Risk Management — and introduced organization-defined parameters (ODPs) in 50 of the 97 requirements.
- CMMC has not adopted Rev 3. 32 CFR 170.14 states Level 2 requirements are identical to NIST SP 800-171 R2, and DoD class deviation 2024-O0013 pins DFARS 252.204-7012 to Rev 2.
- On July 13, 2026 the Department of War suspended CMMC Phase 2 and launched a 60-day CMMC Reform Task Force review. Phase 1 self-assessments, SPRS scores, annual affirmations and DFARS 7012 all remain in force.
- The June 23, 2026 FAR CUI proposed rule would require Rev 3 across all federal agencies — meaning contractors may face Rev 3 from the FAR side before DoD moves CMMC off Rev 2.
What Changed in NIST SP 800-171 Revision 3?
NIST published SP 800-171 Revision 3 on May 14, 2024, alongside its assessment companion, SP 800-171A Revision 3. The headline is the count: Rev 3 specifies 97 security requirements, down from the 110 in Revision 2. Fewer requirements does not mean less work.
Those 97 requirements are spread across 17 families instead of Rev 2’s 14. Rev 3 adds Planning, System and Services Acquisition, and Supply Chain Risk Management, contributing nine new requirements including 03.15.02 (System Security Plan), 03.16.02 (Unsupported System Components), and 03.17.01 (Supply Chain Risk Management Plan). Two more are new elsewhere: 03.12.05 Information Exchange and 03.14.08 Information Management and Retention.
Rev 3 also retires a great deal. Thirty-three requirement numbers now appear in the publication marked simply “Withdrawn” — either removed as outdated and redundant, or absorbed into an adjacent requirement. Rev 2’s 3.12.4 System Security Plan, for example, did not disappear; it moved into the new Planning family as 03.15.02.
Basic and derived requirements are gone
Rev 2 split every family into “basic” requirements (from FIPS 200) and “derived” requirements (from SP 800-53). Rev 3 eliminates that distinction entirely and traces each requirement directly to the SP 800-53B moderate baseline, using SP 800-53 as the single authoritative source. NIST also stripped the word “periodically” throughout and added titles to every requirement to reduce ambiguity during assessments.
Organization-defined parameters are the biggest practical change
Rev 3 embeds assignment and selection operations inside requirement text — brackets that must be filled in with a specific value before the requirement is complete. Appendix D lists these organization-defined parameters (ODPs) in 50 of the 97 requirements: account lockout thresholds, inactivity time periods, log review frequencies, password length, vulnerability remediation windows.
NIST is explicit about who fills them in, stating that “NIST does not establish or assign values for ODPs” and that if a federal agency does not formally assign a value, “nonfederal organizations must assign those values to complete the requirements.” Once specified, the value becomes part of the requirement — and part of what an assessor tests.
DoD has already done this work. In an April 2025 memorandum, the DoD Chief Information Security Officer published DoD-specific ODP values, issued “in preparation to implement [SP 800-171 Rev 3] as the minimum requirement for contractors.” That memo is the clearest signal available that Rev 3 is a question of when, not whether — and that contractors will not get to pick their own thresholds.
Rev 2 vs Rev 3: Side-by-Side Comparison
The table below summarizes the differences that matter for planning. Anyone mapping across federal frameworks should also review how these requirements relate to the broader catalog in our comparison of NIST 800-53 and 800-171 mandates.
| Attribute | SP 800-171 Rev 2 (Feb 2020, updated Jan 2021) | SP 800-171 Rev 3 (May 14, 2024) |
|---|---|---|
| Security requirements | 110 | 97 (33 requirement numbers marked Withdrawn) |
| Requirement families | 14 | 17 (adds Planning, System and Services Acquisition, Supply Chain Risk Management) |
| Requirement structure | Basic and derived requirements | Single set; no basic/derived distinction |
| Source baseline | FIPS 200 plus SP 800-53 moderate baseline | SP 800-53B moderate baseline as single authoritative source |
| Organization-defined parameters | None | ODPs in 50 of 97 requirements (Appendix D) |
| Assessment companion | SP 800-171A (June 2018) | SP 800-171A Rev 3 (May 14, 2024) |
| DFARS 252.204-7012 status | Required (via class deviation 2024-O0013) | Not required by DoD |
| CMMC status (32 CFR 170.14) | Level 2 requirements are identical to Rev 2 | Not referenced |
| Proposed FAR CUI rule (June 23, 2026) | Superseded by Rev 3 in the proposal | Required |
The drift is not limited to 800-171. NIST released SP 800-172r3 and SP 800-172Ar3 on May 13, 2026, restructured to align with the Rev 3 families, while CMMC Level 3 still points at the February 2021 edition of SP 800-172.
Does CMMC Assess Against Rev 2 or Rev 3 in 2026?
Rev 2. Unambiguously, and by regulation. 32 CFR 170.14 states that “the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2,” and that Level 3 requirements are “selected from NIST SP 800-172 Feb2021.” Both versions are incorporated by reference into the CMMC Program rule, so changing them requires rulemaking, not a policy memo.
The DFARS side is held in place the same way. DFARS 252.204-7012 nominally points to whichever version of SP 800-171 is current at solicitation. To stop Rev 3 from taking effect automatically, DoD issued class deviation 2024-O0013 on May 2, 2024, hard-linking the clause to Rev 2 and giving industry time for “a more deliberate transition.” That deviation remains the operative instruction as of August 2026.
Practically, this means every SPRS score, every System Security Plan, and every C3PAO assessment scope in use today is a Rev 2 artifact scored out of 110 points. If you are building or refreshing that documentation, work from the CMMC Level 2 requirements and checklist rather than the Rev 3 catalog.
What Did the July 2026 CMMC Phase 2 Suspension Change?
On July 13, 2026, the Department of War (formerly the Department of Defense) issued two memoranda suspending CMMC Phase 2. DoW Chief Information Officer Kirsten Davies signed the first, titled “Removing Barriers to Defense Industrial Base Expansion”; the Under Secretary of War for Acquisition and Sustainment signed the implementation memo. Phase 2 would have required Level 2 third-party (C3PAO) certification as a condition of award beginning November 10, 2026. Davies wrote that the program “imposes significant and often prohibitive burdens on the Defense Industrial Base, particularly the small and non-traditional businesses.”
What did not change is the part that matters for 800-171. According to Holland & Knight’s July 2026 analysis, DFARS 252.204-7012, 72-hour cyber incident reporting, implementation of all 110 Rev 2 requirements, SPRS score postings, annual affirmations, and Phase 1 self-assessment obligations all remain in effect. Active solicitations carrying Level 2 or Level 3 assessment requirements will be amended, but no waivers are being granted during the review.
A CMMC Reform Task Force is running a 60-day top-to-bottom review. It issued a public request for information — “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base” — with responses due August 14, 2026. Notably, the RFI asks industry about cost drivers under “NIST SP 800-171 Rev 2” and which requirements create the highest overhead with the least measurable risk reduction. The direction of travel implied by those questions is fewer requirements, not the newer catalog.
Why the FAR CUI Rule Could Force Rev 3 Anyway
While DoD reconsiders CMMC, the FAR Council moved in the opposite direction. On June 23, 2026, it published a revised Controlled Unclassified Information proposed rule as part of the Revolutionary FAR Overhaul, with comments closing July 23, 2026. Per Wiley’s analysis of the proposal, it would require NIST SP 800-171 Revision 3 on contractor systems handling CUI, across all federal agencies — not just DoD.
The rule introduces provision FAR 52.240-6 and clause FAR 52.240-7 plus a new standard form for identifying CUI in contracts. It also softened several items from the January 2025 version: incident reporting moved from 8 hours to 72 hours, the definition of a CUI incident was narrowed to exclude “suspected” incidents, and the mandatory training mandate was dropped, according to Mayer Brown’s July 2026 summary.
That produces an awkward split. If the FAR rule is finalized as drafted while the class deviation stands, a company holding both DoD and civilian-agency CUI contracts could owe Rev 3 on one and Rev 2 on the other. It is a proposed rule, not final — but it is the strongest evidence yet that Rev 3 becomes a contractual obligation in this rulemaking cycle.
What Should Defense Contractors Do Now?
The suspension is not permission to stop. It removes a certification event, not a contract clause, and DOJ’s Civil Cyber-Fraud Initiative continues to treat inaccurate SPRS self-attestations as False Claims Act exposure.
- Keep your Rev 2 program current. All 110 requirements, a live System Security Plan, an accurate SPRS score, and annual affirmations are still contractual today. Use a complete CMMC compliance checklist to confirm nothing has quietly drifted.
- Run a Rev 3 delta, not a Rev 3 migration. Map your existing Rev 2 evidence to the 97 Rev 3 requirements and isolate the genuinely new work: the Planning, System and Services Acquisition, and Supply Chain Risk Management families, plus Information Exchange and Information Management and Retention.
- Adopt the DoD ODP values now where they are stricter. DoD has already published its values. Aligning to them costs little today and removes rework later.
- Do not disband the assessment prep. C3PAO capacity was the binding constraint before the pause. If Phase 2 restarts on a compressed schedule, organizations that stayed assessment-ready will move first. Our CMMC Phase 2 compliance guide covers the readiness sequence.
- Watch three triggers: the CMMC Reform Task Force recommendations, the final FAR CUI rule, and any rescission of class deviation 2024-O0013. Any one of them can change your baseline.
The strategic read is simple: Rev 3 is better-organized and already parameterized by DoD, but Rev 2 is what your contract says. Build a control environment that satisfies both, and the transition becomes a documentation exercise rather than a program restart.
Frequently asked questions
How many requirements are in NIST SP 800-171 Rev 3?
Does CMMC use NIST 800-171 Rev 2 or Rev 3?
What are organization-defined parameters in NIST 800-171 Rev 3?
Is CMMC canceled after the July 2026 suspension?
When will contractors have to comply with NIST 800-171 Rev 3?
What are the three new families in NIST 800-171 Rev 3?
- NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information (May 14, 2024)
- NIST SP 800-171A Rev. 3, Assessing Security Requirements for CUI
- NIST SP 800-171 Rev. 2 (PDF)
- 32 CFR 170.14 – CMMC Model (eCFR)
- 32 CFR 170.3 – Applicability and Phased Implementation (eCFR)
- DoD CIO Memorandum: Organization-Defined Parameters for NIST SP 800-171 Rev. 3 (April 2025)
- Crowell & Moring: DoD Class Deviation 2024-O0013 Linking DFARS 7012 to Rev. 2
- Federal News Network: Pentagon Suspends CMMC Phase Two Requirements (July 2026)
- Holland & Knight: DoW Suspends CMMC Phase II Requirements (July 2026)
- SBA Office of Advocacy: DoW Requests Information for CMMC Reform Task Force (July 20, 2026)
- Wiley: FAR Council Proposes Revised CUI Framework (June 2026)
- Mayer Brown: FAR Council Proposes Revised CUI Safeguarding Framework While DoW Pauses CMMC (July 2026)
- NIST: Releases of SP 800-172r3 and SP 800-172Ar3 (May 13, 2026)
- DoW CIO: CMMC Phase II Suspended to Boost DIB Innovation
Stay Ready for Rev 2 and Rev 3 With Compyl
Compyl maps your controls and evidence once, then keeps them aligned to NIST SP 800-171 Rev 2, Rev 3, and CMMC simultaneously, so a class deviation, a Task Force recommendation, or a final FAR CUI rule becomes a mapping update instead of a restart.
About this article. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.