EXECUTIVE BRIEF
Over the past two years, the National Institute of Standards and Technology (NIST) have released revised versions of Special Publications 800-171 and 800-172.
These standards are the basis for Levels 2 and 3 of the Cybersecurity Maturity Model Certification (CMMC). However, CMMC still requires contractors to implement Revision 2 instead of the most current Revision 3.
This blog provides contractors with:
Dig deeper and continue reading below!
If your company handles Controlled Unclassified Information (CUI) for the Department of Defense (DoD) (also known as the Department of War), National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 is your compliance baseline. Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 requires it. Cybersecurity Maturity Model Certification (CMMC) enforces it.
NIST published Revision 3 in May 2024. DoD's CMMC program, finalized in October 2024, still references Revision 2 and says so explicitly. That gap creates real confusion for contractors.
DFARS 252.204-7012 requires contractors to implement Rev2 on all covered information systems and flow those requirements down to subcontractors.
NIST overhauled the structure and tightened the requirements. Key changes:
DoD was direct about this in the final 32 Code of Federal Regulations (CFR) Part 170 rule:
If you're pursuing CMMC Level 2:
If you're preparing for the future:
|
|
Rev2 |
Rev3 |
|
Published |
Feb 2020 |
May 2024 |
|
Security requirement families |
14 |
17 |
|
Total security requirements |
110 |
91 (some added; some withdrawn or consolidated) |
|
Assessment objectives |
320 (per SP 800-171A Jun2018) |
422 (per SP 800-171Ar3) |
|
Basic/Derived split |
Yes |
No; all requirements treated uniformly |
|
ODPs |
No |
Yes; tailorable parameters in select requirements |
|
CMMC governing standard |
✅ Yes (CMMC Level 2) |
❌ Not yet; requires future rulemaking |
|
General Services Administration (GSA) requirement |
❌ |
✅ Rev3 required; GSA updated to R3 in Jan 2026; also adds selected SP 800-172r3 and SP 800-53 R5 privacy controls |
Rev3 is the direction the industry is heading. Rev2 is where compliance is measured today. Build your program to pass Rev2 assessments and architect it to absorb Rev3 when DoD makes it official.