NIST 800-171 Rev 3 finalized in May 2024 with 97 requirements and ODPs, but the Department of War's class deviation keeps CMMC on Rev 2. Here's what to do now.
Short version: NIST SP 800-171 Revision 3 was finalized in May 2024. It cuts the requirement count from 110 to 97, reorganizes controls into 17 families, and introduces Organization-Defined Parameters (ODPs). NIST now lists Rev 2 as superseded, but the Department of War (DoW) has not adopted Rev 3 for assessments, and DoW assesses against Rev 2. Class Deviation 2024-O0013, issued in May 2024, ties DFARS 252.204-7012 to Revision 2 until it is rescinded, the Department's September 3, 2026 class deviation keeps Rev 2, and every CMMC Level 2 assessment today still uses Rev 2. The right move now is to keep your Rev 2 controls in place, stay Rev 2-aligned for CMMC, track the ODP values DoW published in April 2025, and prepare a Rev 2 to Rev 3 crosswalk so you are not scrambling when the transition rule lands.
This post covers what actually changed, why the DoW split matters, and a concrete action list for contractors caught between two revisions.
Two things are true at the same time, and holding both is the whole game:
The gap exists because moving DoW contracts to a new NIST revision takes rulemaking, and NIST cannot make that change on its own. As preparation, the Department published Organization-Defined Parameter (ODP) values in April 2025, the specific values that fill in Rev 3's flexible requirements. That memo signaled intent, but it set no effective date.
The rule that matters today: If a page tells you "CMMC Level 2 is 97 controls," it is wrong as of September 2026. CMMC Level 2 is 110 requirements mapped to Rev 2. Rev 3's 97 requirements are the likely future baseline, and DoW has not adopted them.
For the full picture of how these requirements roll up into a CMMC assessment, see our NIST 800-171 compliance guide and CMMC levels breakdown.
Three structural shifts define Rev 3. None of them are cosmetic.
NIST withdrew, consolidated, or absorbed a number of Rev 2 controls. Some were merged into broader requirements; a handful were dropped as redundant with other language. The headline "13 fewer controls" undersells it — the mapping is not a clean subtraction. A single Rev 2 requirement can split across two Rev 3 requirements, and vice versa. That is exactly why a crosswalk matters (more below).
Rev 3 reorganized the control families to align more closely with the NIST SP 800-53B moderate baseline. It added three families, contributing nine new controls:
Supply Chain Risk Management is the one most contractors underestimate. If your Rev 2 program never formally addressed supplier risk, that is net-new work under Rev 3.
This is the biggest conceptual change. In Rev 2, a requirement such as 3.1.8, "limit unsuccessful logon attempts," left the actual limit to interpretation. Rev 3 makes values like that explicitly settable by the organization or by the agency that requires compliance, as an ODP. The Department's April 2025 memo assigns values to the ODPs in Rev 3, so when DoW adopts Rev 3, that memo tells you which values you will be held to (for example, a specific number of days or a specific threshold). That leaves less "we interpreted it as X" ambiguity and less room to argue with an assessor.
| Dimension | Rev 2 (current DoW baseline) | Rev 3 (final, not yet adopted by DoW) |
|---|---|---|
| Total requirements | 110 | 97 |
| Control families | 14 | 17 |
| New families | — | Planning (PL), System & Services Acquisition (SA), Supply Chain Risk Management (SR) |
| Parameters | Fixed / interpreted | Organization-Defined Parameters (ODPs), with DoW values published April 2025 |
| Aligned to | 800-53 (older mapping) | 800-53B moderate baseline |
| Companion assessment guide | 800-171A (June 2018) | 800-171A Rev 3 |
| Used by CMMC / DFARS 7012 today | Yes | No — pending DoW rulemaking |
Source: NIST SP 800-171 Rev 3 and NIST SP 800-171A Rev 3 (csrc.nist.gov); DoD Class Deviation 2024-O0013 to DFARS 252.204-7012.
The Department has not announced a date, so do not plan around one. DoW has signaled intent, which is what the April 2025 ODP values were about. The Unified Agenda listed an interim final rule to move from Rev 2 to Rev 3 (RIN 0790-AM01) with a July 2026 target, and as of September 23, 2026 that rule has not been published. Treat any vendor claiming a firm Rev 3 effective date as ahead of the facts.
Watch the Federal Register for that rule. An interim final rule can take effect as soon as it is published, with public comment afterward, so the lead time may be shorter than a proposed rule with a comment period would give you. The contractors who get hurt are the ones who read "Rev 3 is final" in 2024, assumed it applied to them, and either wasted effort re-baselining early or ignored it entirely.
Here is the practitioner playbook for the in-between period.
1. Stay Rev 2-aligned for CMMC — do not re-baseline early. Your SPRS score, your System Security Plan, and your CMMC Level 2 assessment all key off Rev 2's 110 requirements. Rebuilding your control set to 97 requirements today gets you assessed against a standard the Department is not using. Keep executing Rev 2.
2. Track the ODP values. Pull the Department's April 2025 ODP memo and note where your current Rev 2 implementations would or would not satisfy the Rev 3 parameters. If Rev 3 will require, say, a specific password-rotation or session-timeout value, knowing that now lets you set your configurations to satisfy both revisions with one setting.
3. Build the crosswalk before you need it. Map each of your Rev 2 requirements to its Rev 3 counterpart(s), and flag the nine net-new controls in PL, SA, and SR. This is the single highest-leverage prep task. When the transition rule lands, a maintained crosswalk turns a re-assessment scramble into a gap-closure sprint. Compli.ai carries the Rev 2 catalog DoW assesses against today, and when the Department changes the baseline, the updated catalog reaches every tenant through a normal upgrade that leaves your statuses, notes, and POA&Ms in place.
4. Watch the three new families specifically. Planning, System & Services Acquisition, and especially Supply Chain Risk Management are where Rev 2-mature contractors have the most exposure. Start informal work here even under Rev 2 — good supplier-risk hygiene helps your DFARS 7012 flow-down obligations today regardless.
5. Do not touch your POA&M discipline. Rev 3 or not, open items still have to close. See how to manage a POA&M for the closure rules that matter for CMMC conditional status.
How do I become NIST 800-171 compliant right now — Rev 2 or Rev 3? Rev 2. The Department's class deviation directs contractors to NIST SP 800-171 Rev 2, and CMMC Level 2 is assessed against Rev 2's 110 requirements. Implement Rev 2, document it in an SSP, and post your self-assessment score to SPRS. Treat Rev 3 as preparation, not the current bar.
How many controls are in NIST 800-171? It depends on the revision. Rev 2, the version the Department assesses against, has 110 requirements across 14 families. Rev 3, finalized May 2024 but not yet adopted by DoW, has 97 requirements across 17 families. For any contract or CMMC purpose today, use 110.
What is the difference between CMMC and NIST 800-171? NIST 800-171 is the underlying set of security requirements for protecting Controlled Unclassified Information (CUI). CMMC is DoW's program that verifies you have implemented them, through self-assessment or a third-party (C3PAO) assessment depending on the contract. The Department has suspended CMMC Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program. Phase 1 remains in effect, so contracts can still require Level 1 and Level 2 self-assessments with affirmations in SPRS. CMMC Level 2 maps 1:1 to NIST 800-171 Rev 2.
Do I need to redo my assessment when Rev 3 is adopted? Almost certainly you will need to re-baseline against the new requirements, but the Department has not set a date and the lead time is unknown. A maintained Rev 2 → Rev 3 crosswalk turns that re-baseline into a planned project.
Is NIST 800-171A Rev 3 out? Yes. NIST released the companion assessment guide, SP 800-171A Rev 3, alongside the Rev 3 requirements in May 2024. It defines the assessment objectives for the 97 requirements. DoW assessors still use the June 2018 edition of 800-171A, with its 320 objectives, for CMMC today.
The Rev 2 to Rev 3 shift rewards contractors who prepare quietly and punishes the ones who either panic early or ignore it. The right posture is steady: keep executing Rev 2, track the ODPs, and maintain a crosswalk so the eventual transition is a planned sprint.
If you would rather not track the transition in a spreadsheet, book a demo and we will show you how Compli.ai keeps your Rev 2 program, SSP implementation statements, and SPRS score current inside your own Microsoft 365 tenant, and how a catalog update reaches your tenant without overwriting the work you have recorded. It is built by people who have run these assessments. If you want to compare doing this in-house versus with help, our CMMC compliance software overview lays out the trade-offs. To see where your Rev 2 posture stands today, run a self-assessment and see how many of the 110 you actually meet.