NIST SP 800-171 Rev 3 ExplainedWhat Changed, and When It Applies to You

NIST 800-171 Rev 3 (NIST SP 800-171 Revision 3) is the current edition of the federal standard for protecting Controlled Unclassified Information (CUI) in nonfederal systems. NIST published it on May 14, 2024, reorganized the requirements into 17 families, reduced the count from 110 to 97, and introduced organization-defined parameters that let the agency that owns the CUI set specific values. For defense contractors the practical twist is that DFARS 252.204-7012 and CMMC Level 2 still assess against Revision 2 under a Department of Defense class deviation. This guide from Petronella Technology Group explains what actually changed, who has to care today, and how to prepare without breaking a Rev 2 program that already works.

CyberAB RPO #1449|BBB A+ Since 2003|Founded 2002|Raleigh, NC and Nationwide
Key Takeaways
  • Rev 3 is the published standard; Rev 2 is the contractual one. NIST withdrew Revision 2 on May 14, 2024, the same day it published Revision 3. The Department of Defense answered with Class Deviation 2024-O0013 on May 2, 2024, which pins DFARS 252.204-7012 to Revision 2 until the deviation is rescinded.
  • 97 requirements in 17 families replaces 110 in 14. Three families are new: Planning, System and Services Acquisition, and Supply Chain Risk Management. The lower count comes from consolidation, not from a lighter standard.
  • Organization-defined parameters (ODPs) are the biggest structural change. Rev 3 leaves values such as review frequencies and lockout thresholds blank for the federal agency to fill in. The Department of Defense issued its ODP values in a memorandum dated April 15, 2025.
  • CMMC Level 2 is still assessed against Rev 2. The CMMC program rule in 32 CFR Part 170 references Revision 2, and Phase 1 of CMMC enforcement began on November 10, 2025 on that basis.
  • Prepare in the System Security Plan, not the network. A Rev 2 program that is genuinely implemented already satisfies most of Rev 3. The work is a crosswalk, a set of new policies, and ODP values recorded in the SSP.
Definition

What Is NIST 800-171 Rev 3?

NIST Special Publication 800-171 Revision 3, titled "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations," is the third major edition of the standard that federal agencies use to tell contractors, universities, and other nonfederal organizations how to protect the confidentiality of CUI. Revision 3 was published as final on May 14, 2024, alongside its companion assessment guide, NIST SP 800-171A Revision 3. It supersedes Revision 2, which NIST marked withdrawn on the same date.

The standard exists because CUI leaves federal systems constantly. Engineering drawings, contract technical data, export-controlled specifications, and program information all end up on contractor networks. The agency that owns that information stays accountable for it, so it needs a common set of safeguards it can require by contract. NIST SP 800-171 is that set. When a federal contract cites it, the contractor takes on every requirement in the document for every system that stores, processes, or transmits CUI. Our guide to what counts as CUI covers the marking and handling side; this page covers the control side.

Revision 3 was NIST's answer to a problem that had grown for years: Revision 2 was written against SP 800-53 Revision 4, and the federal control catalog had since moved to Revision 5. Rev 3 realigns the CUI requirements with SP 800-53 Rev 5 and the moderate baseline in SP 800-53B, rewrites the requirements in the same structured, outcome-based style, and adds families that the older edition treated as assumed rather than required. Petronella Technology Group has implemented NIST SP 800-171 for defense suppliers since long before CMMC existed, and we operate as a CyberAB Registered Provider Organization (RPO #1449), so the questions below are the ones contractors actually ask us.

What Rev 3 Is
  • The current NIST edition of the CUI protection standard, final since May 14, 2024
  • 97 security requirements organized into 17 families, numbered 03.01.01 through 03.17.03
  • A standard built on organization-defined parameters that the CUI-owning agency fills in
  • Aligned with the SP 800-53 Rev 5 catalog and the SP 800-53B moderate baseline
  • Paired with SP 800-171A Rev 3, which defines the assessment objectives and methods
What Rev 3 Is Not
  • Not the version DFARS 252.204-7012 currently requires: Class Deviation 2024-O0013 holds that clause at Rev 2
  • Not the version a C3PAO assesses for CMMC Level 2, which 32 CFR Part 170 ties to Rev 2
  • Not a lighter standard because it has fewer numbered requirements; consolidation moved text, it did not remove obligations
  • Not a reason to rewrite a working Rev 2 program from scratch
  • Not self-scoring: the DoD Assessment Methodology and SPRS scoring remain built on Rev 2's 110 requirements
Side by Side

NIST 800-171 Rev 3 vs Rev 2 at a Glance

The two revisions protect the same information for the same reason. The differences are in structure, numbering, specificity, and the number of families. The table below is the comparison we walk through with every client who asks whether their SSP is "Rev 3 ready."

Attribute Revision 2 (February 2020, Update 1 January 2021) Revision 3 (May 14, 2024)
NIST status Withdrawn May 14, 2024 Current, final
Security requirements 110 97
Requirement families 14 17 (adds Planning, System and Services Acquisition, Supply Chain Risk Management)
Numbering 3.1.1 through 3.14.7 03.01.01 through 03.17.03, matching SP 800-53 identifiers
Basic and derived split Each family has basic requirements plus derived requirements Split removed; every requirement is a single structured statement with lettered sub-items
Specific values Mostly left to the contractor to define and defend Organization-defined parameters that the federal agency assigns; DoD published its values April 15, 2025
Source catalog SP 800-53 Rev 4 moderate baseline SP 800-53 Rev 5 and the SP 800-53B moderate baseline
Assessment guide SP 800-171A (2018) SP 800-171A Rev 3 (May 14, 2024)
DFARS 252.204-7012 today Required by Class Deviation 2024-O0013 Not yet required for DoD contracts
CMMC Level 2 today Assessment basis under 32 CFR Part 170 Not yet adopted; a future rulemaking would be needed

One number in that table causes more confusion than any other. Going from 110 requirements to 97 sounds like a reduction, and it is not. NIST consolidated requirements whose text overlapped, withdrew a handful it judged redundant, and folded their intent into neighboring requirements. Revision 2's 3.1.13, which called for cryptography on remote access sessions, is a good example: its substance now lives inside the communications protection requirement for CUI in transit. A contractor who drops the control because the number disappeared has created a gap, not saved effort. Our CMMC to NIST 800-171 mapping guide shows how the same problem plays out between frameworks.

New Families

The Three Families Rev 3 Adds

Revision 2 assumed that any organization protecting CUI already had planning, acquisition, and supply chain practices in place, so it did not spell them out. That assumption did not survive contact with the defense industrial base. Revision 3 makes all three explicit.

Planning (03.15)

Requires documented policies and procedures for every family, a System Security Plan that describes the boundary, the environment, and how each requirement is met, and rules of behavior that users acknowledge before they touch CUI. Most Rev 2 programs already have an SSP because 3.12.4 demanded one; far fewer have a complete policy set with a defined review cycle. Our free System Security Plan template is structured so the Rev 3 planning items are already headings.

System and Services Acquisition (03.16)

Brings in security engineering principles for system design, a requirement to manage unsupported system components (end-of-life software and hardware that no longer receives patches), and a requirement to govern external system services such as cloud providers and managed service providers. The unsupported-components item is the one we see contractors miss most, because the aging machine on the shop floor is rarely in the CUI inventory.

Supply Chain Risk Management (03.17)

Requires a supply chain risk management plan, acquisition strategies and tools that address supply chain risk, and processes for identifying and responding to weaknesses in the supply chain of the components and services that handle CUI. This family pulls the intent of NIST SP 800-161 down to the contractor level and connects directly to the flow-down obligations in DFARS 252.204-7012(m).

What Else Moved

Beyond the new families, Rev 3 adds or sharpens requirements inside existing ones. Configuration Management gains explicit system component inventory, information location, and configuration for high-risk areas such as travel. Risk Assessment gains a risk response requirement. System and Information Integrity gains information management and retention. The Assessment family was renamed Security Assessment and Monitoring and picks up information exchange agreements. None of these are exotic, but each one needs a sentence in the SSP and an artifact behind it.

Organization-Defined Parameters

What ODPs Are and Why They Matter More Than the New Families

An organization-defined parameter is a blank inside a requirement. Where Revision 2 said to lock an account after a number of failed attempts and left the number to the contractor, Revision 3 writes the requirement with a bracketed parameter and hands the pen to the federal agency that owns the CUI. The agency sets the value; the contractor implements it. Review frequencies, log retention periods, session timeout thresholds, lockout counts, and password rules are all ODPs.

The design borrows from SP 800-53 Rev 5, and it solves a real assessment problem. Under Rev 2, two contractors could implement the same requirement with wildly different values and both argue they were compliant, which made SPRS scores hard to compare. Under Rev 3, the agency's ODP values become part of the requirement, so an assessor checks against a known target. For the defense industrial base, that target arrived when the Department of Defense issued a memorandum on April 15, 2025 establishing its ODP values for NIST SP 800-171 Rev 3. DoD assigning values before it has adopted Rev 3 contractually is the clearest signal available that adoption is a matter of when, not whether.

How ODPs Change Your SSP

  • Every requirement with a parameter needs the assigned value recorded, with the source memo cited, so an assessor sees the number you implemented and where it came from
  • Where DoD's value is stricter than what you run today, the gap goes on a Plan of Action and Milestones with a date, not into a footnote
  • Where no agency value exists yet (non-DoD CUI), you define the value, defend it with a risk rationale, and document that it is contractor-defined
  • Technical controls that enforce the value (lockout policy, retention settings, timeout) should be exported as evidence next to the SSP statement

How ComplianceArmor® Handles Them

  • Our ComplianceArmor® platform generates the System Security Plan from a structured control inventory, so each parameter is a field rather than a sentence buried in prose
  • Gap analysis compares your implemented values against the assigned ODPs and flags every mismatch
  • Evidence collection attaches the configuration export to the requirement it satisfies, which is what SP 800-171A Rev 3 examine-and-interview methods look for
  • Continuous monitoring re-checks parameter-bound controls between assessments instead of the week before one
Applicability

Does Rev 3 Apply to You Right Now?

The honest answer depends on who put the CUI in your hands. For most readers of this page the answer is "not yet by contract, but plan for it." Here is the position for each population we work with.

DoD Contractors Under DFARS 252.204-7012

On May 2, 2024, twelve days before NIST published Rev 3, the Department of Defense issued Class Deviation 2024-O0013. It directs contracting officers to require compliance with NIST SP 800-171 Revision 2 rather than the version in effect when a solicitation is issued. The deviation stays in force until rescinded. Your DFARS 252.204-7012 obligation today is therefore Rev 2's 110 requirements, and your SPRS score is still calculated on the Rev 2 DoD Assessment Methodology.

Contractors Pursuing CMMC Level 2

The CMMC program rule in 32 CFR Part 170 references NIST SP 800-171 Revision 2 as the basis for Level 2, and the assessment guides a C3PAO uses are built on SP 800-171A's Rev 2 objectives. Phase 1 of the CMMC rollout began on November 10, 2025 on that footing. Moving Level 2 to Rev 3 would require DoD to amend the rule, so a Rev 3 assessment is not something you can request or be surprised by in the current phase. Our CMMC Level 2 guide covers the assessment as it stands.

Non-DoD Federal Contractors and Grantees

Outside the Department of Defense, the picture is agency by agency. Rev 3 is NIST's current publication and Rev 2 is withdrawn, so any new contract, grant, or agreement that cites "the current version" of SP 800-171 points to Rev 3 unless the agency says otherwise. Read the clause, ask the contracting officer in writing which revision governs, and keep the answer with your SSP. Where no ODP values have been assigned, you assign and defend them.

Universities and Research Organizations

Research institutions often hold CUI from several agencies at once, which means a single enclave can face Rev 2 language from one sponsor and Rev 3 language from another. The workable approach is to implement to the stricter interpretation, document both crosswalks in the SSP, and keep the boundary tight so the dual obligation covers as few systems as possible. Our enclave design guide explains the scoping mechanics.

A related question is what happens to the Rev 2 SPRS score once Rev 3 arrives contractually. Nobody outside DoD can answer that with certainty, and we do not promise dates that have not been published. What we can say is that the contractors who will move fastest are the ones whose Rev 2 program is real, documented, and evidenced today, because Rev 3's extra work is almost entirely paperwork on top of controls that already exist.

Transition

A Rev 2 Program Before and After Rev 3 Preparation

The difference between a contractor who is ready for Rev 3 and one who is not rarely shows up in the firewall rules. It shows up in the SSP, the policy binder, and the inventory.

Before

SSP written to 110 numbered controls

Every statement references a 3.x.y identifier. When an assessor or a customer asks about 03.17.01, nobody in the room can say which paragraph answers it.

Values chosen ad hoc

Lockout is set to whatever the domain default was in 2019. Log retention is whatever the disk allowed. None of it is written down as a deliberate decision.

Supply chain handled by a purchasing habit

Vendors are chosen on price and familiarity. There is no written plan for how a compromised component or provider would be found or replaced.

Unsupported systems invisible

The machine controller running an end-of-life operating system is not on the asset list because it is "not a computer."

After

SSP carries a Rev 2 to Rev 3 crosswalk

Each statement lists both identifiers. Consolidated requirements point to where the Rev 2 intent now lives, so nothing is silently dropped.

ODP values recorded with a source

Every parameter shows the DoD-assigned value from the April 15, 2025 memorandum or a documented contractor decision, and the technical setting that enforces it is exported as evidence.

Supply chain risk management plan on file

A short, real plan names the critical suppliers, the criteria for choosing them, and the process for responding when one of them has a problem.

Inventory includes every CUI-adjacent component

The asset inventory lists operational technology and end-of-life devices with a documented plan to isolate, replace, or accept the risk with a date.

Process

How Petronella Technology Group Prepares a Program for Rev 3

We do not tear down a Rev 2 program to get ready for Rev 3. We keep what is contractually required today, layer the Rev 3 structure over it, and produce a single SSP that answers both. The six steps below are the same ones we use for NIST SP 800-171 implementation generally, with the Rev 3 crosswalk added.

1

Scope Confirmation

We re-verify where CUI lives and which systems are in the boundary using the CMMC scoping categories, because every new Rev 3 requirement applies only to in-scope assets and a bloated boundary multiplies the work.

2

Rev 2 Baseline Assessment

A control-by-control review against the 110 Rev 2 requirements using the DoD Assessment Methodology, so the SPRS score you report is defensible and the program you are extending is real. Our SP 800-171A assessment service is this step on its own.

3

Rev 3 Crosswalk

Every Rev 2 statement is mapped to its Rev 3 identifier, consolidated requirements are traced to their new home, and the 97 requirements are checked for any with no existing coverage. The output is a gap list that is usually short and mostly documentation.

4

ODP Assignment

DoD's published values are recorded for each parameter, compared with what your systems enforce, and every mismatch becomes a POA&M item with an owner and a date. For non-DoD CUI we set and justify the value with you.

5

New Family Build-Out

Planning, acquisition, and supply chain artifacts are written: the policy set with review cycles, the rules of behavior, the unsupported-component register, the external services register, and the supply chain risk management plan. ComplianceArmor® generates the first drafts from your inventory.

6

Evidence and Continuous Monitoring

Each requirement gets its artifact attached, parameter-bound controls are re-checked on a schedule, and the SSP is versioned so the next assessor, under either revision, starts from a current document rather than a reconstruction.

Options

DIY Crosswalk vs RPO-Led Preparation vs Managed Compliance

Three ways contractors approach the Rev 3 question, and what each one actually costs in attention. There is no wrong answer; there is only the answer that matches your headcount and your contract timeline.

Consideration Do It Yourself RPO-Led Crosswalk and Gap Closure Managed Compliance with ComplianceArmor®
Who does the crosswalk Your IT lead, from the NIST documents and the DoD ODP memo A CMMC-RP certified consultant working from your existing SSP Our team, inside the platform, with the crosswalk maintained as NIST and DoD publish changes
Best fit A contractor with a dedicated compliance role and a clean Rev 2 program A contractor with a working IT team that needs the regulatory reading done for them A contractor with no internal compliance capacity, or several CUI sponsors with different revisions
Main risk Dropping a consolidated Rev 2 control because its number vanished Artifacts go stale between engagements if nobody owns the review cycle Higher recurring cost, offset by not staffing the role internally
Rev 2 obligations meanwhile Unchanged, and easy to neglect while chasing Rev 3 Verified first, so the SPRS score is defensible before anything new is added Continuously monitored alongside the Rev 3 items
Pricing Your staff time Scoped per engagement after a free consultation Scoped per engagement after a free consultation
Why Us

Why Contractors Bring the Rev 3 Question to Petronella Technology Group

Petronella Technology Group, Inc. was founded in Raleigh, North Carolina in 2002 and has held a BBB A+ rating since 2003. We are a CyberAB Registered Provider Organization (RPO #1449), and every member of our team holds the CMMC Registered Practitioner credential. Craig Petronella, our founder, is a CMMC-RP with more than 30 years in professional IT, holds CCNA and CWNE certifications, and wrote the CMMC 2.0 Certification Guide, which walks through all 110 NIST SP 800-171 controls, SPRS scoring, and C3PAO preparation. As Craig details in that guide, the contractors who struggle at assessment are almost never the ones with the weakest technology; they are the ones whose documentation cannot explain the technology they have. Rev 3 raises the bar on exactly that point.

What a Client Said

  • "Craig takes the time to understand our business model, not just our technology stack. It makes his recommendations more strategic and tailored to our actual goals." Daniel Lee, TrustIndex verified review
  • Rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews

What You Get

  • A single SSP that answers Rev 2 today and Rev 3 when it arrives, with the crosswalk built in
  • ODP values recorded from the DoD memorandum, with evidence exports attached
  • Planning, acquisition, and supply chain artifacts drafted from your real inventory, not a generic template
  • Raleigh-based consultants who serve the Triangle and defense suppliers nationwide
FAQ

NIST 800-171 Rev 3: Frequently Asked Questions

When was NIST SP 800-171 Rev 3 released?

NIST published the final version of SP 800-171 Revision 3 on May 14, 2024, together with SP 800-171A Revision 3, the companion assessment procedures. On the same date NIST marked Revision 2 as withdrawn and superseded by Revision 3. An HTML edition of Rev 3 followed in June 2024.

How many controls are in NIST 800-171 Rev 3?

Revision 3 contains 97 security requirements organized into 17 families, compared with 110 requirements in 14 families under Revision 2. The reduction comes from consolidating overlapping requirements and withdrawing a few NIST judged redundant; the underlying obligations were folded into neighboring requirements rather than removed.

What are the new families in Rev 3?

Three families are new: Planning (policies, the System Security Plan, and rules of behavior), System and Services Acquisition (security engineering, unsupported components, and external system services), and Supply Chain Risk Management (a supply chain risk plan, acquisition strategies, and processes for supply chain weaknesses). The former Security Assessment family was also renamed Security Assessment and Monitoring.

What is an organization-defined parameter in NIST 800-171?

An organization-defined parameter, or ODP, is a value inside a requirement that the standard leaves blank for the federal agency that owns the CUI to assign, such as a review frequency, a retention period, or a lockout threshold. Revision 3 uses ODPs throughout, following the SP 800-53 Rev 5 model. The Department of Defense issued its ODP values for Rev 3 in a memorandum dated April 15, 2025.

Does DFARS 252.204-7012 require Rev 2 or Rev 3?

Revision 2. DoD Class Deviation 2024-O0013, issued May 2, 2024, directs contracting officers to require NIST SP 800-171 Revision 2 rather than the version in effect at the time of the solicitation. The deviation remains in effect until DoD rescinds it. Read our DFARS 252.204-7012 guide for the full clause.

Does CMMC use NIST 800-171 Rev 3?

Not currently. The CMMC program rule in 32 CFR Part 170 bases Level 2 on NIST SP 800-171 Revision 2, and C3PAO assessments use the Rev 2 objectives. Phase 1 of the CMMC rollout began November 10, 2025 on that basis. Adopting Rev 3 for CMMC would require DoD rulemaking, so there is no Rev 3 CMMC assessment to prepare for today. See our CMMC compliance hub for the current program.

Should I update my System Security Plan to Rev 3 now?

Keep the Rev 2 SSP as the document of record, because that is what DFARS and CMMC assess, and add a Rev 3 crosswalk to it. The crosswalk maps each Rev 2 statement to its Rev 3 identifier, records the DoD ODP values, and adds the planning, acquisition, and supply chain artifacts. That way one document answers both revisions and nothing is dropped during the eventual switch.

Is Rev 3 easier because it has fewer requirements?

No. The 97 requirements are more specific than the 110 they replace, the ODP values remove the flexibility contractors used to have in choosing their own thresholds, and the three new families add documentation that many Rev 2 programs never produced. A contractor who treats the lower count as a reduction usually ends up with gaps that an assessor finds immediately.

Keep Reading

Related NIST and CMMC Resources

Last Updated: September 5, 2026. This page tracks NIST SP 800-171 Revision 3 (final, May 14, 2024), NIST SP 800-171A Revision 3, DoD Class Deviation 2024-O0013 (May 2, 2024), the DoD organization-defined parameters memorandum (April 15, 2025), and the CMMC program rule in 32 CFR Part 170. We update it when any of those sources change. For the wider security picture, download the free 2026 SMB Cybersecurity Survival Guide or browse Craig Petronella's published books.

Get a Rev 3 Crosswalk Without Disturbing the Rev 2 Program You Rely On

Petronella Technology Group has secured defense suppliers and regulated businesses since 2002, holds a BBB A+ rating dating to 2003, and operates as a CyberAB Registered Provider Organization (RPO #1449) with an entirely CMMC-RP certified team. Bring us your current System Security Plan and we will tell you, requirement by requirement, what Revision 3 adds, which DoD parameter values you already meet, and what belongs on a Plan of Action. Call 919-348-4912 or schedule a free consultation to start.