
NIST SP 800-171 Rev. 2 vs Rev. 3 for CMMC in 2026
Why NIST Rev. 3 is final while CMMC work can still depend on Rev. 2, and how to avoid mixing assessment baselines.
Read guide →Every NIST SP 800-171 guide on the site in one place — assessments, revisions, evidence, and the requirements that come up most in Level 2 self-assessments.

Why NIST Rev. 3 is final while CMMC work can still depend on Rev. 2, and how to avoid mixing assessment baselines.
Read guide →
A practical explanation of the current NIST SP 800-171 DoD Basic Assessment requirement, SPRS record, and three-year currency rule.
Read guide →A precise guide to NIST SP 800-171 Rev. 2 requirement 3.5.3 for CMMC Level 2, including privileged vs non-privileged access, local vs network access, common bypasses, and assessor-ready evidence.
Read guide →How CMMC Level 2 applies NIST SP 800-171 Rev. 2 least-privilege requirements to administrators, separate daily accounts, privileged functions, logging, approvals, and access reviews.
Read guide →How shared logins and service identities interact with CMMC requirements for identification, unique user traceability, least privilege, authentication, and assessor evidence.
Read guide →A practical guide to NIST SP 800-171 Rev. 2 audit requirements 3.3.1 through 3.3.9, including event selection, retention, user traceability, clock synchronization, log protection, failure alerts, and assessor evidence.
Read guide →How to implement NIST SP 800-171 Rev. 2 requirement 3.11.2 without inventing a quarterly rule: systems and applications, periodic scans, new-vulnerability triggers, missed devices, exclusions, and evidence.
Read guide →A focused guide to NIST SP 800-171 Rev. 2 requirement 3.14.1 and its relationship to vulnerability scanning and risk remediation, including patch SLAs, exceptions, emergency fixes, verification, and evidence.
Read guide →A precise guide to NIST SP 800-171 Rev. 2 requirements 3.13.16 and 3.13.11 for CUI at rest, covering endpoints, servers, backups, cloud storage, removable media, key handling, physical safeguards, and evidence.
Read guide →How to implement NIST SP 800-171 Rev. 2 requirements 3.13.8 and 3.13.11 for CUI in transit, including transfer-path inventory, alternative physical safeguards, FIPS-validated cryptography, TLS/VPN/SFTP configuration, and evidence.
Read guide →A focused guide to NIST SP 800-171 Rev. 2 media requirements for USB drives and portable storage, including 3.8.7, 3.8.8, transport accountability, encryption, approved-device models, technical enforcement, and evidence.
Read guide →
How to implement NIST SP 800-171 Rev. 2 media sanitization requirements for drives, SSDs, paper, printers, equipment sent for maintenance, reused devices, and destruction records without confusing decontrol with public release.
Read guide →How CMMC Level 2 applies NIST SP 800-171 Rev. 2 wireless requirements 3.1.16 and 3.1.17 to corporate Wi-Fi, guest networks, access points, rogue devices, remote sites, authentication, encryption, and assessment evidence.
Read guide →A practical guide to NIST SP 800-171 Rev. 2 requirements 3.1.18 and 3.1.19 for mobile devices, including connection control, CUI encryption, MDM, apps, screenshots, local downloads, cloud backup, loss, remote wipe, and assessor evidence.
Read guide →A detailed Level 2 tabletop guide for NIST SP 800-171 Rev. 2 incident response requirements 3.6.1–3.6.3, with scenarios, injects, roles, evidence, action tracking, DFARS 252.204-7012 reporting, and 90-day image preservation.
Read guide →