Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
REV. 3 WATCH

NIST SP 800-171 Rev. 3 and CMMC: What Changes When (and If) the Program Adopts It

NIST SP 800-171 Rev. 3 is final, but current CMMC implementation remains anchored to Rev. 2; prepare for transition without claiming Rev. 3 is today's baseline.

NIST finalized SP 800-171 Rev. 3 and 800-171A Rev. 3 in May 2024, but that publication did not automatically change CMMC's contractual baseline. The current DoD class deviation continues to direct contractors subject to DFARS 252.204-7012 to Rev. 2 until the deviation is rescinded or replaced.

Status note: reviewed September 4, 2026. Phase II is suspended, Phase I remains in force, and the Department of War's CMMC Reform Task Force review is still open. Re-check the official CMMC page before publication if this article is published after that date.

The rule in plain English

Rev. 3 reorganizes requirements, adds families such as Planning, System and Services Acquisition, and Supply Chain Risk Management, and introduces organization-defined parameters. A future CMMC transition would therefore require more than renumbering a checklist.

Do not mix Rev. 3 assessment objectives into a Rev. 2 CMMC claim unless the contract or program source explicitly adopts them.

How to implement it without overbuilding

Maintain a Rev. 2 authoritative control matrix for current obligations and a separate Rev. 2-to-Rev. 3 transition crosswalk for planning.

Use the transition work to identify policy owners, ODP decisions, new-family gaps, and evidence that can be reused without prematurely changing the compliance claim.

What evidence to keep

Keep both source versions, the crosswalk, Rev. 3 gap notes, ODP decisions, and a dated statement of which baseline governs each contract/environment.

Version discipline matters because NIST marks Rev. 2 withdrawn as a publication even while DoD contract language can still require it.

Where teams get into trouble

The common mistake is equating 'NIST superseded Rev. 2' with 'DoD contracts now require Rev. 3.' Publication status and contractual adoption are separate events.

Rev. 3 publication did not automatically switch the CMMC baseline

NIST finalized SP 800-171 Rev. 3 and SP 800-171A Rev. 3 in May 2024, but DoD contracting requirements are not changed merely because NIST supersedes a publication. Class Deviation 2024-O0013 Revision 1 directs contracting officers to use a version of DFARS 252.204-7012 that requires NIST SP 800-171 Rev. 2 and states that the deviation remains in effect until rescinded. That is the reason this site should continue to label Rev. 2 as the current contractual/CMMC baseline as reviewed September 4, 2026.

This distinction also prevents a common evidence mistake: replacing the active 110-requirement control matrix with a Rev. 3 matrix before the contract or CMMC program adopts it. The organization can plan for Rev. 3, but its current self-assessment and CMMC claims should map to the baseline actually incorporated by the governing acquisition source.

What is materially different in Rev. 3 planning

Rev. 3 is not a simple renumbering exercise. It reorganizes requirements, adds new families such as Planning, System and Services Acquisition, and Supply Chain Risk Management, and uses organization-defined parameters in places where Rev. 2 was less explicit about values the organization must choose. A future transition therefore affects governance, evidence mapping, policy ownership, and assessment procedures as well as control numbers.

For a small contractor, the most useful preparation is a two-column program: keep the Rev. 2 production control matrix authoritative, and maintain a separate Rev. 2-to-Rev. 3 transition register. The transition register should identify requirements that map cleanly, requirements whose evidence can be reused, new decision points, new owners, and architecture work that would be expensive to postpone.

  • Do not relabel current Rev. 2 evidence as Rev. 3 compliance.
  • Identify Rev. 3 ODP decisions and who has authority to set them.
  • Map new-family responsibilities before buying new tools.
  • Watch for DoD rulemaking or a replacement/rescission of the class deviation.

How to avoid a double-documentation project

Reuse facts, not unsupported conclusions. An asset inventory, network diagram, access review, training record, risk assessment, or incident log can remain useful under a future revision because it describes the environment. The control mapping and sufficiency judgment may change. Store evidence once, with metadata showing system, owner, date, and source, then map that evidence to the applicable baseline.

The transition trigger should be authoritative adoption, not a vendor dashboard changing its default framework. When DoD changes the baseline, archive the final Rev. 2 mapping, record the effective date for the new requirement set, and run a controlled gap review rather than silently overwriting the evidence history.

A practical Rev. 3 transition workbook for a small contractor

Build the transition workbook around decisions rather than a giant side-by-side text dump. For each Rev. 3 requirement, record the closest Rev. 2 source, whether the existing implementation is reusable, whether new policy language is needed, whether a new technical capability is needed, the proposed owner, and any organization-defined parameter that must be chosen. Mark items as 'planning only' until an authoritative DoD source adopts the new baseline for the relevant contract.

Pay special attention to requirements that move responsibility into procurement, planning, and supply-chain functions. Those are easy to miss when the CMMC program has historically been run almost entirely by IT. A future Rev. 3 transition can therefore fail organizationally even when the contractor already has strong endpoint and network controls.

  • Map reusable evidence separately from control-number mapping.
  • Identify new business owners outside IT.
  • List ODPs that require an explicit organizational choice.
  • Flag long-lead architecture or supplier changes.
  • Do not retire the Rev. 2 matrix until the contractual trigger changes.
WORKING CHECKLIST

A short working check

  • Keep Rev. 2 as the current contract baseline where required.
  • Build a separate Rev. 3 gap map.
  • Track new families.
  • Identify ODP decisions.
  • Watch DoD rule/deviation changes.
  • Update claims only after adoption.

Common questions

Is Rev. 3 the current CMMC Level 2 baseline?

No, not under the current DoD class deviation reviewed September 4, 2026; Rev. 2 remains the contractual baseline.

Why does NIST call Rev. 2 withdrawn?

NIST superseded its publication with Rev. 3, but DoD can contractually require an older revision through acquisition rules or deviations.

Should we ignore Rev. 3?

No. It is sensible transition planning, especially for governance or architecture changes with long lead times.

What are ODPs?

Organization-Defined Parameters are values defined for certain Rev. 3 requirements and are part of the new structure future adoption would need to address.

What should be re-checked immediately before using this guide for a contract decision?

Re-open the controlling government source, confirm the solicitation or contract language for the specific information system, and verify that the provider or program status cited here has not changed since September 4, 2026.

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.