Skip to main content
Rule Updates

NIST Just Published an Assessment Primer for Small Contractors — and Confirmed CMMC Still Runs on Revision 2

NIST's new SP 1352 walks small contractors through how a CUI security assessment actually works - and states expressly that CMMC still leverages SP 800-171 Revision 2 and SP 800-171A Revision 2, not Revision 3.

Brandon Hancock, J.D., CMMC-RPPublished September 19, 2026Updated September 19, 20267 min read

On September 16, 2026, NIST published Special Publication 1352, Assessing Security Requirements for Controlled Unclassified Information (CUI): NIST SP 800-171A, Revision 3 Small Business Primer, a plain-language walkthrough of how a CUI security assessment actually works. The primer is aimed squarely at "business leaders or employees who are new to SP 800-171A and who are tasked with managing the implementation of SP 800-171, including conducting self-assessments or preparing to work with external assessors." It is a companion to the SP 800-171r3 implementation primer NIST released in August 2025 — that one covered what to build, this one covers how it gets graded.

The revision question, answered by NIST itself

The most consequential paragraph in the document is an FAQ. NIST states that at the time of publication, "the Department of War's Cybersecurity Maturity Model Certification (CMMC) Program leverages the requirements and assessment procedures in SP 800-171r2 (Revision 2) and SP 800-171Ar2." A second FAQ repeats the point: "CMMC is currently based on SP 800-171, Revision 2. Contractors should check for specific requirements in their contracts to understand which version they are required to use."

That matters because the primer itself is written against Revision 3. A contractor reading it for assessment mechanics is reading Revision 3 procedures while operating, in most DoD contracts, under a Revision 2 obligation. NIST points readers to its published change analysis between the two revisions to decide which fits their current and future needs — but the contract, not the newest publication, sets the requirement. We covered the practical mechanics of that gap in our guide to the SPRS score and DFARS 252.204-7019/-7020.

NIST is also unusually direct about the boundary of its own role: it develops the technical guidelines, but "NIST does not have a role in DOW's implementation of its programs," and it "is not involved in the design, development, or implementation of the CMMC model, accreditation body, or certification process." If you want to know what you owe, read the clause and ask the contracting officer. NIST writes the ruler; the contract decides what gets measured.

What an assessment procedure actually contains

The primer breaks the SP 800-171A structure into three parts that are worth memorizing before any assessor arrives:

Assessment objective — the security requirement decomposed into individual determination statements, each beginning with "A" and the requirement identifier (for example, A.03.01.10.a). Every determination statement within an objective must be satisfied for the requirement to be considered fully implemented. Partial credit is not a concept here.

Assessment methods — examine (reviewing policies, procedures, the system security plan), interview (discussions with personnel), and test (evaluating whether controls behave as expected). Not all three are required for every procedure.

Assessment objects — specifications (plans, policies, architectures), mechanisms (hardware, software, firmware), activities (backups, incident-response exercises, traffic monitoring), and individuals (the people doing the above).

Findings come back as one of two words: satisfied or other than satisfied. NIST notes that "other than satisfied" also covers the case where the assessor could not obtain enough information to make the determination — which means missing evidence is scored the same as a missing control. That is the single most expensive lesson in the document. For what your evidence file should look like, see what your contract requires you to log.

The four-phase process, and the two phases contractors skip

The primer maps assessment to four phases: prepare, develop the assessment plan, conduct the assessment, and document/analyze/report results. Most contractors show up for phase three.

Phase one is scoping. NIST is explicit that the SP 800-171 requirements apply "only to components of nonfederal systems that process, store, or transmit CUI or that provide protection for such components," and that scope can be limited by isolating those components into a separate security domain using subnetworks, firewalls, or other boundary protection — physical separation, logical separation, or both. Scoping is a protection-investment decision, not paperwork. Our CMMC Level 2 scoping and asset categories piece covers how that maps to the DoD asset framework.

Phase two is the assessment plan, and NIST includes a point primes and subs both under-read: review the contracts or agreements governing external systems that create, store, or transmit CUI, because the organization "does not always have direct control over the security requirements used in external systems," and tailor the procedures accordingly. That is a flowdown problem disguised as a planning step — see cybersecurity flowdown obligations.

Phase four turns findings into a Plan of Action and Milestones and, usually, revisions to the system security plan. NIST's framing is that gaps surface when "what is documented in the System Security Plan might not actually be what is happening in practice." That mismatch — plan versus practice — is precisely the theory behind the government's cyber False Claims Act cases collected on our enforcement page.

What this changes, and what it does not

Nothing. SP 1352 is an awareness document, not a requirement. It creates no new obligation, alters no clause, and does not shift any CMMC date. Its value is that it is a free, government-authored explanation of the assessment process written for someone who does not speak cybersecurity — which is most of the small-business defense industrial base. NIST also notes it does not endorse vendors, while pointing to the CyberAB Marketplace as one place to evaluate consultants.

Read against the current moment, the timing is useful. With CMMC Phase 2 suspended pending the Department of War's reform review, the self-assessment path is the one most contractors are on right now — and self-assessment is exactly what this primer is built to prepare you for. Start with Find My Requirements to confirm which obligations your contracts actually carry.

Key Takeaways

  • NIST confirmed in writing that CMMC still runs on SP 800-171 Revision 2 and SP 800-171A Revision 2 — the new primer explains Revision 3 procedures, so check your clause before assuming the newest publication governs your contract.
  • "Other than satisfied" includes evidence you could not produce. An assessor who cannot verify a control scores it the same as a control you never implemented; every determination statement in an objective must be satisfied for the requirement to count.
  • Scoping and external-system contract review happen before the assessment, not during it. Isolating CUI components into a separate security domain limits scope legitimately, and reviewing agreements for external systems that touch CUI is a planning obligation NIST calls out directly.

---

This article is educational information about government contracting and cybersecurity requirements. It is not legal advice and does not create an attorney-client relationship. Contractors should review their specific contract terms and consult counsel on their particular obligations.

Primary source: NIST Special Publication 1352, Assessing Security Requirements for Controlled Unclassified Information (CUI): NIST SP 800-171A, Revision 3 Small Business Primer (September 2026), https://doi.org/10.6028/NIST.SP.1352 — publication page · full text (PDF) · NIST announcement, Sept. 16, 2026

Share
BH

Brandon Hancock

J.D. · CMMC Registered Practitioner (RP)

Brandon is the founder and principal advisor of GovConCyber. His advisory approach is shaped by roughly six years as a U.S. Army human intelligence collector, where information accuracy, source protection, classification discipline, need-to-know access, and controlled reporting were daily requirements. He brings that information-discipline mindset to GovConCyber's work helping government contractors understand and comply with federal cybersecurity obligations.

Was this post helpful?

Keep reading

Rule UpdatesA New Supply-Chain Prohibition Regime Just Opened Its Comment Window — and a FAR Rule Is Already ScheduledMost contractors read "bulk-power system" and stop. That is a mistake. The executive order behind this rulemaking defines "procurement" in federal-acquisition terms, tasks the FAR Council with a rule, and reaches installation services — which is to say, it reaches contractors.September 10, 2026 · 7 min readRule UpdatesMaryland Just Widened Which State Contracts Carry Cyber and Privacy Clauses — Effective October 1The Maryland Data Privacy and Protection Act of 2026 (Chapter 435, House Bill 264) takes effect October 1, 2026 and rewrites State Finance and Procurement § 13-115. Collecting, storing, or processing personal information is now an independent trigger for mandatory security, data collection, and privacy requirements in Maryland State contracts — no connection to a State system required — and the statutory definition of personal information expanded at the same time.August 31, 2026 · 7 min readRule UpdatesCISA Published the Logging Reference Architecture — and Contractor-Operated Systems Are In ScopeCISA published the Logging Reference Architecture on August 20, 2026, implementing OMB Memorandum M-26-14, which rescinded M-21-31 and put federal civilian agencies on a maturity clock for how they log, retain, and produce network data. The memorandum reaches systems operated “by third parties on the agency’s behalf” — so contractor-run systems are inside the agency’s plan, and the obligation will arrive through contract terms rather than the memo itself.August 27, 2026 · 7 min read