Skip to main content
Rule Updates

NIST SP 800-171 Rev 3: What Changed and What to Do

Revision 3 restructured the CUI standard. Here's what changed, why DoD contracts still use Rev 2, and how to prepare.

Brandon Hancock, J.D., CMMC-RPPublished April 22, 2026Updated July 10, 20266 min read

NIST SP 800-171 Revision 3 is finalized and published — but if you're a DoD contractor, you may still be required to comply with Revision 2. That apparent contradiction trips up a lot of teams. Here's what actually changed and how to plan.

Why There Are Two Live Versions

NIST published Revision 3 in 2024 to modernize the CUI protection standard. But contractual requirements don't change just because NIST updates a document — they change when the contract clause points to the new version. As of 2026, DoD has kept DFARS 252.204-7012 tied to Revision 2 (110 controls) through a class deviation, while issuing organization-defined parameters (ODPs) that prepare the ground for a Rev 3 transition. Translation: comply with Rev 2 today; get ready for Rev 3.

What Changed in Revision 3

The revision was more than cosmetic. Key shifts include:

  • Restructured control families and requirements, with some consolidation and re-organization versus Rev 2's 110 controls.
  • Organization-Defined Parameters (ODPs) — places where the standard lets the agency (here, DoD) specify values like password length or timeout periods, rather than baking them in. This is why DoD's ODP publication matters: it pre-fills those blanks for the eventual transition.
  • Updated and withdrawn requirements to reflect current threats and to better align with NIST SP 800-53.
  • Clarified language intended to reduce ambiguity in assessments.

What This Means for You

  • Don't re-baseline prematurely. If your contract references Rev 2, your assessment, SPRS score, and POA&M should be against Rev 2's 110 controls.
  • Track the transition. Watch for contract modifications, new solicitations, and CMMC guidance adopting Rev 3. The move is a question of when, not if.
  • Build transition-friendly. Where Rev 3 and DoD's ODPs are stricter or clearer, implementing to that standard now can reduce future rework — just keep your formal compliance evidence mapped to the version your contract requires.
Update (July 2026): DoD has now put a specific regulatory vehicle behind this transition — RIN 0790-AM01, an interim final rule targeted for July 2026 that would formally set the Rev. 2-to-Rev. 3 transition deadline. See DoD Puts a Date on the CMMC Rev. 3 Transition for the full breakdown.

A Practical Preparation Checklist

1. Confirm which revision each of your contracts references. 2. Keep your current Rev 2 assessment and SPRS score honest and within the three-year window. 3. Review DoD's ODPs and note where they tighten Rev 2 expectations. 4. Map your existing controls to Rev 3 so a future transition is an update, not a rebuild.

Key Takeaways

  • Rev 3 is published, but DoD contracts still run on Rev 2 for now.
  • The headline change is ODPs — agency-set parameters DoD has begun to define.
  • Comply to your contract's version, and prepare for the Rev 3 move in parallel.

Compare the standards on the Frameworks page, or score yourself with the Self-Assessment Checklists.

Share
BH

Brandon Hancock

J.D. · CMMC Registered Practitioner (RP)

Brandon is the founder and principal advisor of GovConCyber. His advisory approach is shaped by roughly six years as a U.S. Army human intelligence collector, where information accuracy, source protection, classification discipline, need-to-know access, and controlled reporting were daily requirements. He brings that information-discipline mindset to GovConCyber's work helping government contractors understand and comply with federal cybersecurity obligations.

Was this post helpful?

Keep reading

Rule UpdatesMaryland Just Widened Which State Contracts Carry Cyber and Privacy Clauses — Effective October 1The Maryland Data Privacy and Protection Act of 2026 (Chapter 435, House Bill 264) takes effect October 1, 2026 and rewrites State Finance and Procurement § 13-115. Collecting, storing, or processing personal information is now an independent trigger for mandatory security, data collection, and privacy requirements in Maryland State contracts — no connection to a State system required — and the statutory definition of personal information expanded at the same time.August 31, 2026 · 7 min readRule UpdatesCISA Published the Logging Reference Architecture — and Contractor-Operated Systems Are In ScopeCISA published the Logging Reference Architecture on August 20, 2026, implementing OMB Memorandum M-26-14, which rescinded M-21-31 and put federal civilian agencies on a maturity clock for how they log, retain, and produce network data. The memorandum reaches systems operated “by third parties on the agency’s behalf” — so contractor-run systems are inside the agency’s plan, and the obligation will arrive through contract terms rather than the memo itself.August 27, 2026 · 7 min readRule UpdatesOMB Rescinded the Governmentwide Software Attestation Mandate — Now Each Agency Sets Its Own TermsFor two years, software producers selling to the federal government worked from a single assumption: sign the CISA Common Form or the agency cannot use your product. That assumption is no longer correct — and the replacement is harder to track, not easier.August 18, 2026 · 6 min read