Learn CMMC The Rev 3 Walkthrough

NIST 800-171 Rev 2 vs Rev 3: What Actually Changes (and Why You're Still on Rev 2)

Rev 3 cuts 800-171 from 110 requirements to 97, adds three families, and replaces vague wording with fill-in values. Here's the map — and why your contract still says Rev 2.

Key takeaways

  • You are assessed against Revision 2 today. A class deviation dated May 2, 2024 kept DFARS 252.204-7012 pointed at Revision 2, and that deviation is still standing.
  • Revision 3 has 97 requirements in 17 families, numbered 03.05.03 instead of 3.5.3, with fill-in values DoD has already published.
  • By NIST's own change analysis, 18 Rev 2 requirements carried over essentially unchanged, 14 changed in minor ways, 46 changed significantly, 32 were withdrawn and 19 are new.
  • The work that holds up under both revisions is worth doing now. The work that only makes sense under Rev 3 is not.

Start with the part that matters to your contract: you are assessed against Revision 2 today. NIST published Revision 3 on May 14, 2024. DoD got there first: a class deviation dated May 2, 2024 kept DFARS 252.204-7012 pointed at Revision 2, and that deviation is still standing. The rule meant to move the Department to Rev 3 — an interim final rule tracked as RIN 0790-AM01, targeted for July 2026 — has not been published. And with CMMC Phase 2 suspended since July 13 while a reform task force finishes its review, nothing about that is changing this month.

So why spend the next sixteen weeks on Rev 3?

Because the transition is coming, the overlap with Rev 2 is large, and the work that holds up under both revisions is worth doing now. The work that only makes sense under Rev 3 is not. This series is about telling those two apart, one family at a time.

This first post is the map.

The numbers

Revision 2Revision 3
Security requirements11097
Requirement families1417
Numbering3.5.303.05.03
Fill-in values (ODPs)noneyes — and DoD has published its values
Basic vs. derived requirementsyesdistinction removed

Fewer requirements does not mean less work. NIST's own change analysis sorts the 110 Rev 2 requirements like this (every one is browsable, word for word, on the CMMC Navigator's revision pages):

  • 18 carried over essentially unchanged
  • 14 changed in minor ways
  • 46 changed significantly
  • 32 were withdrawn — most folded into another requirement, not dropped
  • 19 requirements in Rev 3 are new

Other published tallies differ by one or two depending on how a merge is counted; NIST's is the one to use. The shape is what matters: about 60 of the 78 surviving requirements now read differently than the text your SSP was written against.

Five changes that account for most of the work

1. Organization-defined parameters

Rev 2 said things like "limit unsuccessful logon attempts" and left the number to you. Rev 3 writes the blank into the requirement — "[Assignment: organization-defined number]" — and lets the governing agency fill it in. DoD already has: an April 2025 memo sets a value for nearly every ODP in Rev 3, as policy, in preparation for making Rev 3 the contractor requirement. This is the most practical change in the whole revision, and it's next week's post.

2. Renumbering

3.5.3 becomes 03.05.03. Trivial to read. Tedious everywhere a control number is stored: POA&M entries, evidence folders, policy cross-references, ticket templates, the spreadsheet your MSP sends every quarter.

3. Withdrawals are mostly consolidations

When Rev 3 withdraws a requirement it keeps the number and tells you where the content went. Rev 2's four remote-access requirements, for example, collapse into one (03.01.12), with the encryption piece moving to the communications-protection family. Very little protection actually disappeared — it moved. If you only read "32 withdrawn" and conclude you have less to do, the next assessment will correct you.

4. Three new families

Planning (03.15), System and Services Acquisition (03.16), and Supply Chain Risk Management (03.17), three requirements each. Some of this was already expected of you under Rev 2 without being numbered: the system security plan itself moves from 3.12.4 into Planning as 03.15.02. Other parts — a supply chain risk management plan, handling of unsupported system components — are new obligations for most small contractors.

5. The language now matches SP 800-53

Rev 3 was rebuilt from the SP 800-53 Rev 5 moderate baseline, keeping the controls that bear on protecting CUI and dropping the ones that are the government's job. NIST also eliminated the old "NFO" category — the controls Rev 2 assumed you were doing anyway and didn't list. Some of those are now explicit requirements. That's where "policy and procedures" as a numbered requirement comes from.

What to do with this now

Worth doing today — it holds under either revision:

  • Pull DoD's ODP values and compare them to what you enforce. Where your setting is stricter or equal, you're done. Where it isn't, you have a cheap, early fix.
  • Organize evidence by what it proves ("MFA enrollment," "log retention"), not by control number. Renumbering then costs you a lookup table, not a re-filing project.
  • Ask whether your tools can carry both numbering schemes. Anything that hard-codes 3.x.x identifiers is rework waiting to happen.
  • Keep implementing Rev 2 properly. Real implementation transfers. Paper compliance doesn't transfer to anything.

Premature — don't:

  • Re-baseline your SSP to Rev 3 structure. Your SSP describes the requirements you're assessed against.
  • Score yourself against Rev 3 or post anything but a Rev 2 score to SPRS.
  • Drop a Rev 2 practice because Rev 3 withdrew it. Until the rule changes, the Rev 2 assessment objectives still apply.

What's coming in this series

One post every Tuesday. The next four:

  • Sep 22 — ODPs: the blanks DoD already filled in
  • Sep 29 — Passwords and MFA: what Identification & Authentication looks like in Rev 3
  • Oct 6 — Access Control: 22 requirements become 16
  • Oct 13 — The three new families

Every post links each requirement it discusses to its side-by-side Rev 2/Rev 3 comparison on the CMMC Navigator, our free, unofficial reference for all 110 requirements.

If the task force report, a new deviation, or the transitional rule lands mid-series, that week's post becomes the breakdown and the series slides a week.

Get each part by email

One short email every Wednesday: the week's change, the one thing to check, and a link. Subscribe

An unofficial reading aid. It doesn't create or waive obligations; where this post and your contract disagree, your contract is right.

Sources

  1. NIST SP 800-171 Rev. 3, final (May 14, 2024)
  2. NIST FAQ on SP 800-171 Rev. 3 and SP 800-171A Rev. 3
  3. Crowell & Moring: DoD class deviation linking DFARS 252.204-7012 to NIST SP 800-171 Rev. 2 (May 2024)
  4. DoD CIO memo: organization-defined parameters for NIST SP 800-171 Rev. 3 (April 10, 2025)
  5. Unified Agenda entry for RIN 0790-AM01, the DFARS rule moving to Rev. 3
  6. DefenseScoop: DoD halts CMMC Phase 2 requirements (July 13, 2026)
  7. Washington Technology: CMMC's Phase 2 suspension locked in by binding regulation (September 3, 2026)

Keep the proof, not just the plan.

Bedrock CMMC tracks every objective, links the evidence behind it, calculates the SPRS score and keeps the POA&M honest, in one package with a chain of custody an assessor can follow.