NIST SP 800-171 Rev 3, What Changed and What It Means for Your CMMC Timeline

In this article
Someone on your team downloads the current version of NIST SP 800-171 from the NIST website, opens it, and finds 97 requirements instead of the 110 you have been working with.
There are domains that you have never documented: Planning, System and Services Acquisition, and Supply Chain Risk Management.
Next, they find brackets associated with an Organizationally Defined Parameter (ODP) sitting inside the requirements themselves, waiting for someone to fill in a value.
This is Revision 3, which has been published since May 2024. Unfortunately, it is not what your current assessment is based on.
Here is what actually changed, what it will require, and why the answer is less urgent than that download makes it look.
What is NIST SP 800-171 Rev 3
NIST SP 800-171 Revision 3 is the current published version of the standard, released in May 2024. It replaces Revision 2 as the NIST standard for protecting Controlled Unclassified Information in nonfederal systems.
Published is not the same as required. NIST writes the standard. The agency buying from you decides when a standard applies to its contracts, and that decision happens through rulemaking, not through a publication date. Rev 3 has been sitting in that gap for over two years.
So you can download Rev 3 today, read every requirement in it, and still be assessed against Rev 2 tomorrow.
That gap is closing unevenly, which is the part most contractors miss. Defense contracts still run on Rev 2. Civilian and GSA work is a different answer (we will get to that below).
How Many Requirements are in NIST SP 800-171 Rev 3
Rev 3 has 97 security requirements across 17 families. Rev 2 has 110 across 14.
That reads like a reduction of 13. It is not.
NIST withdrew requirements that were redundant or not directly tied to protecting the confidentiality of CUI. Several Rev 3 requirements merge what Rev 2 treated as separate items. At the same time NIST added new requirements and introduced parameters that the organization defines. On the surface, that may seem like the Organization Seeking Assessment, but for Department of War (DoW) customers, they have been mostly defined for you. GSA has its own ODP list as well.
The count is a function of how the material was grouped. It is not a measure of how much work it represents.
This is the most common misreading we see. If your leadership hears 97 instead of 110 and concludes that Rev 3 is lighter, correct that early. The count is smaller. The scope is broader.
NIST SP 800-171 Rev 2 vs Rev 3, What Actually Changed
| Rev 2 | Rev 3 | |
|---|---|---|
| Requirements | 110 | 97 |
| Control families | 14 | 17 |
| Requirement structure | Basic and derived | Single tier |
| Parameter values | Left to the contractor to define | Organization-defined, with DoW and GSA setting most of them |
| Identifiers | Standalone numbering | Mapped to NIST SP 800-53 Rev 5 |
| CMMC status | Enforced standard | Not yet adopted |
| GSA CUI status | Superseded | Required since January 2026 |
Three of those rows carry most of the practical weight.
The basic and derived split is gone. Rev 2 divided each family into basic requirements and derived requirements. Rev 3 drops that structure entirely. Most SSPs list all the controls rather than organizing around that split, so for most contractors this changes the structure of the standard more than it changes the document.
Identifiers now map to NIST SP 800-53. If your organization also works with FedRAMP or FISMA standards, this reduces translation work between frameworks. If NIST SP 800-171 is the only standard you touch, it mostly means many of your requirement numbers stop matching and every cross-reference in your documentation needs rework.
Parameters are now defined, and often not by you. Under Rev 2 the parameters were genuinely individual and organization defined. Under Rev 3 they are organization-defined parameters, and for DoW and GSA customers the organization is the department. That one deserves its own section.
The 17 NIST SP 800-171 Rev 3 Control Families
Fourteen families carry over from Rev 2. Three are new. One was renamed.
| ID | Family | Status in Rev 3 |
|---|---|---|
| AC | Access Control | Carried over, expanded |
| AT | Awareness and Training | Carried over, broadened |
| AU | Audit and Accountability | Carried over, expanded |
| CA | Security Assessment and Monitoring | Renamed and broadened |
| CM | Configuration Management | Carried over, expanded |
| IA | Identification and Authentication | Carried over, expanded |
| IR | Incident Response | Carried over, broadened |
| MA | Maintenance | Carried over, clarified |
| MP | Media Protection | Carried over, clarified |
| PE | Physical Protection | Carried over, clarified |
| PS | Personnel Security | Carried over, clarified |
| RA | Risk Assessment | Carried over, expanded |
| SC | System and Communications Protection | Carried over |
| SI | System and Information Integrity | Carried over |
| PL | Planning | New |
| SA | System and Services Acquisition | New |
| SR | Supply Chain Risk Management | New |
Organization-Defined Parameters in NIST SP 800-171 Rev 3
Rev 2 requirements are prescriptive. The requirement exists or it does not, and you implement it. Rev 3 builds flexibility into many requirements by leaving a bracketed value to be chosen.
Instead of stating a fixed account lockout rule, a Rev 3 requirement reads more like this.
Enforce a limit of [ODP: number of consecutive invalid logon attempts] consecutive invalid logon attempts by a user during a [ODP: time period] time period.
You (or the government agency or department) pick the number and period, then both become part of your documented security program. Appendix D of NIST SP 800-171A Rev 3 lists all of the ODPs in one consolidated place.
Three obligations follow
Your System Security Plan has to record the specific value that applies, not just confirm the requirement is implemented. Your systems have to enforce that value exactly, so if the SSP says five failed attempts, the configuration says five. And an assessor working from NIST SP 800-171A Rev 3 checks both sides, comparing what you wrote against what your systems actually do.
A mismatch between the two is a finding, even when the implemented value is perfectly reasonable on its own.
Where the parameters cluster
| Family | What you define | Where it has to match |
|---|---|---|
| Access Control | Lockout threshold, lockout duration, session lock timeout, inactivity termination | Group Policy or device configuration profile |
| Identification and Authentication | Minimum password length, reuse restrictions, conditions that force a change | Password policy and authentication method settings |
| Audit and Accountability | Which events you are logged, retention period, review frequency | Log retention settings and your review records |
| Configuration Management | Baseline review frequency, approved software list scope | Change management records and baseline documents |
| Risk Assessment | Vulnerability scan frequency, remediation timelines by severity | Scanner schedule and POA&M |
The number that may apply to you depends on your environment and your scope. Treating these requirements as a fill-in-the-blank exercise is the fastest way to fail those objectives.
Keep a single parameter register. One table listing every value your organization has chosen, referenced from the SSP rather than buried in prose across forty documents. When a value changes, you update one row and you know exactly which configurations have to follow. The Kieri Compliance Documentation is built this way for exactly that reason.
The New Rev 3 Control Families: Planning, System and Services Acquisition, and Supply Chain Risk Management
Planning, System and Services Acquisition, and Supply Chain Risk Management have no Rev 2 equivalent. This could mean creating new documents instead of editing existing documentation.
Planning (PL)
PL makes security planning an explicit, auditable requirement rather than an assumed precondition. It covers the SSP, your policy documents, and rules of behavior, each as its own requirement:
- A formally structured SSP documenting your security architecture decisions, reviewed at defined intervals, with a defined process for updating it when your environment changes.
- Policy documents, updated under a requirement separate from the one covering the SSP.
- Rules of behavior your users have acknowledged, also a separate requirement.
Most organizations with a well maintained SSP already satisfy the intent. Rev 3 asks you to prove it.
System and Services Acquisition (SA)
SA covers systems engineering principles, replacing legacy hardware, and making sure external service providers, rather than every vendor you work with, meet certain security requirements. For DoW that means FedRAMP Moderate or equivalent for cloud service providers and NIST SP 800-171 for everyone else. It is not really a change from Rev 2, it just has a control spelled out for it now. You need criteria for assessing a service before you adopt it, security requirements written into external service provider contracts, and a process for revisiting those assessments when a provider’s posture changes. If you have already worked through the external service provider requirements in the CMMC Program Rule, there is meaningful overlap here, which could indicate that the work has already been done.
Supply Chain Risk Management (SR)
SR covers the plan to manage, mitigate and identify supply chain risk:
- A plan to manage supply chain risk, developed, reviewed, updated, and protected from unauthorized disclosure.
- Risk mitigation through acquisition strategies, tools and methods that identify, protect against and mitigate supply chain risks.
- Risk identification through a process to identify and address weaknesses and deficiencies, and to enforce the ODP supply chain risks.
The ODPs here are integrating supply chain risk management into procurement and defining the processes that make suppliers disclose significant vulnerabilities and incidents.
SR is the domain that people underestimate. It is not a setting you configure once. It involves purchasing and legal in addition to IT. Those conversations take longer than a technical change. If you are mapping your Rev 3 gap, start here.
Does CMMC Use NIST SP 800-171 Rev 2 or Rev 3
As of August 2026, Revision 2 is still used by CMMC.
The 32 CFR Part 170 CMMC Program Rule is written against NIST SP 800-171 Revision 2. Moving to Revision 3 is not a memo. It requires a rulemaking update that formally adopts Rev 3, updated assessment guidance, retrained assessors, revised SPRS scoring, and a defined transition period during which organizations can actually implement the changes.
None of those steps has a published date.
On July 13, 2026 the Department of War suspended CMMC Phase 2. This included the third-party certification milestone scheduled for November 10, 2026, and opened a review of the program. Phase 2 is only about the requirement for a third-party assessment, and Phase 3 is about CMMC being fully integrated into the contracting process. Neither one is a Rev 3 track.
Two things about that review matter here.
The first is what did not change:
- Phase 1 self-assessment remains enforced.
- DFARS 252.204-7012 remains enforced.
- NIST SP 800-171 Revision 2 remains the enforced standard.
The Department paused a verification mechanism. It did not pause the obligation to protect CUI.
The second is easy to miss: The Request for Information issued alongside the suspension asks which requirements deliver the most measurable risk reduction and which impose the greatest burden for the least benefit. That question reaches the requirement set itself, not only the assessment process. This means that the review may not just be about who verifies your compliance, but potentially the standards themselves.
Read all of that as extra allotted time to align on Rev 3, not as a reason to stop.
Where NIST SP 800-171 Rev 3 Is Already Required
This is the part that gets lost in the CMMC conversation. Rev 3 is not waiting everywhere. It is waiting on the Department of War.
GSA has already moved. Since January 5, 2026, GSA contractors handling CUI work to NIST SP 800-171 Rev 3 plus selected controls from 800-172, under GSA’s IT security procedural guides. That requirement carries an independent third-party assessment rather than self-attestation, a set of controls that must be in place before award, and a one hour incident reporting window instead of the 72 hours DFARS allows.
The FAR CUI rule points the same direction. The FAR Council published a revised proposed rule on June 23, 2026 that would require Rev 3 for any system holding CUI, and it applies to civilian and defense contractors alike. The Council has signaled it expects to finalize before the end of 2026 with no phase-in period.
So, the honest answer to “When do I need Rev 3?” depends on who you sell to. If your work is entirely DoW, you may have time. If you hold a GSA schedule or do civilian agency work, Rev 3 is either your standard today or close to it.
Check your contracts before you decide this is a next-year problem.
Does NIST SP 800-171 Rev 3 Change Your SPRS Score
Not today. SPRS scoring runs on the DoD Assessment Methodology, which is built around the 110 Rev 2 requirements and their point weights. A 97 requirement standard with different identifiers cannot drop into that scoring model unchanged.
Revised scoring is one of the steps that has to happen before Rev 3 applies to defense contracts, and it has not been published. Keep scoring and posting against Rev 2.
What Defense Contractors Should Do About Rev 3 Right Now
The answer depends on where you are.
If you are not yet compliant with Rev 2, work on Rev 2 and nothing else. Your SPRS score, your SSP, your POA&M, and any assessment in the near term are all measured against 110 requirements. Building toward a requirement set nobody is assessing produces documentation that will not match what an assessment asks for.
If you are already compliant or certified, start with the three new families. PL, SA, and SR are where your documentation says nothing at all, so that is where a few hours of review returns the most information. After that, review your existing requirements. If you work under DoW contracts, the DoW has already set almost all of the ODPs, so go through the newly added and significantly changed controls that appear throughout and make sure you are following them.
If you are mid-implementation, build with Rev 3 in mind wherever the extra effort is small. Structure your SSP so parameter values have a place to live. Keep a list of the sources where your evidence comes from rather than the old evidence itself, because most Rev 3 requirements map back to something you already do.
If you sell to civilian agencies or hold a GSA schedule, treat Rev 3 as current work rather than planning work, and read your contract language first.
What Carries Forward From Your Rev 2 Program
One thing worth saying plainly: Most of a solid Rev 2 program carries into Rev 3.
| Effort | Where it sits | What it takes |
|---|---|---|
| Review and extend | PL, SA, SR | New policies and procedures, plus purchasing and legal involvement for SR. Parts of all three pull from Rev 2 requirements |
| Extend what exists | AC, AU, CM, IA, RA, CA | Additional requirements plus documented parameter values |
| Review and update | Whole SSP | Go through the NIST SP 800-171A Rev 3 controls, update your SSP controls accordingly, and renumber cross-references to 800-53 identifiers |
| Limited changes | AT, MA, MP, PE, PS | Clarifications rather than substantive change |
| Maintain evidence process | Entire program | Screenshots, tickets, logs, and completed checklists stay valid |
Knowing where changes apply is the difference between extending a program and rebuilding one.
The contractors who will have the easiest Rev 3 transition are the ones with a working Rev 2 program and the habit of generating evidence as they operate. The ones who paused everything in July and will restart from a cold stop are the ones who will feel it.
NIST SP 800-171 Rev 3 FAQ
How many controls are in NIST SP 800-171 Rev 3
97 security requirements across 17 control families. Rev 2 has 110 across 14. The lower count comes from consolidating and withdrawing requirements, not from a reduced standard.
Is NIST SP 800-171 Rev 3 required right now
For DoW contracts, no, because Rev 2 is the enforced standard under DFARS 252.204-7012 and the CMMC Program Rule. For GSA contractors handling CUI, yes, since January 2026. The proposed FAR CUI rule would extend Rev 3 to civilian contractors as well.
What is the difference between NIST SP 800-171 Rev 2 and Rev 3
Rev 3 has three new families (Planning, System and Services Acquisition, Supply Chain Risk Management), drops the basic and derived requirement structure, maps identifiers to NIST SP 800-53 Rev 5, and introduces organization-defined parameters. If you are not supporting a DoW contract you set those values yourself. DoW and GSA each publish their own ODPs.
What are organization-defined parameters in NIST SP 800-171 Rev 3
Bracketed values inside a requirement, such as an account lockout threshold or an audit log retention period. For GSA and DoW, the organization that chooses them is the agency, not the organization seeking assessment. You record the value in your SSP, configure your systems to match it, and an assessor compares the two.
When will CMMC move to NIST SP 800-171 Rev 3
No date has been published. A move requires rulemaking that adopts Rev 3, updated assessment guidance, retrained assessors, revised SPRS scoring, and a transition period. The July 2026 suspension of CMMC Phase 2 is a separate track and does not set a Rev 3 date.
Do I need to rewrite my SSP for NIST SP 800-171 Rev 3
Update rather than rewrite. The content of a solid Rev 2 SSP mostly carries over. What changes is going through the NIST SP 800-171A Rev 3 controls and updating your SSP controls accordingly, the cross-references, since identifiers now map to 800-53, and the addition of your parameter values and three new families.
Does NIST SP 800-171 Rev 3 change my SPRS score
No. SPRS scoring uses the DoD Assessment Methodology built on the 110 Rev 2 requirements. Revised scoring for Rev 3 has not been published, so keep scoring and posting against Rev 2.
Does the FAR CUI rule use NIST SP 800-171 Rev 2 or Rev 3
Rev 3. The revised proposed rule published June 23, 2026 is built on NIST SP 800-171 Revision 3 and applies to civilian and defense contractors. The FAR Council expects to finalize before the end of 2026 with no phase-in period.
Get a Clear Read on Your NIST SP 800-171 Position
If you are not certain how your program measures against the 110 requirements that apply today, a CMMC gap analysis gives you a written answer with detailed findings for each assessment objective. Our assessors perform real CMMC Level 2 and NIST SP 800-171 assessments, so what comes back reflects what an assessment actually looks for rather than a checklist interpretation.
If what you need is the documentation itself, the Kieri Compliance Documentation covers both revisions, with policies, procedures, and a System Security Plan written out rather than left blank. It is the same set we used to pass our own CMMC Level 2 assessment. You can see a demo of the KCD before you decide anything.
We do not provide both consulting and formal CMMC assessments to the same clients. If you are considering Kieri Solutions for a future certification assessment, tell us up front and we will report findings without recommending fixes, which keeps our independence intact.
Schedule a call and we will talk through where you stand.
Related Reading on NIST SP 800-171 and CUI
For what comprises the documentation set, see CMMC compliance documentation templates, inside the KCD.
For a compliant Microsoft 365 environment built for CUI and ITAR, see the Kieri Reference Architecture.
For guides, checklists, and datasheets, see the Kieri resources center.
Evidence Review
Thorough examination of your compliance evidence. We verify documentation completeness.
Don't miss these
No one wants to start from blank templates.
No one wants to start from
blank templates.
Stop starting from blank templates. Get documentation proven through actual CMMC Level 2 assessment.


























































