Skip to content
    August 22, 2026| Top Floor Team| 10 min read

    NIST 800-171 Rev 2 or Rev 3: Which One You Actually Owe

    As of August 2026 you owe Revision 2, and two separate instruments say so. 32 CFR 170.14(c)(3) states that "the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2", and DoD Class Deviation 2024-O0013, first issued May 2, 2024 and superseded by its own Revision 1 the same month, "requires contractors, who are subject to 252.204-7012, to comply with NIST SP 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer", and "remains in effect until rescinded". Revision 3 has been final since May 2024 (NIST), and the FAR Council's government-wide CUI rule is the instrument that would actually bring it to contractors, but neither of those has moved CMMC. Do not rebuild your program for Revision 3. Do build it so that moving is a delta rather than a rewrite.

    This article separates the two instruments that pin Revision 2, describes what Revision 3 changed, explains where Revision 3 is genuinely arriving from, and gives the small number of things worth doing now.

    Key takeaways

    • CMMC Level 2 is Revision 2 by regulation: 32 CFR 170.14(c)(3) says the requirements are identical to NIST SP 800-171 R2.
    • DFARS 252.204-7012 would otherwise follow the version in effect when a solicitation issues, or as authorized by the contracting officer; Class Deviation 2024-O0013 (May 2, 2024) pins it to Revision 2 until rescinded.
    • Revision 3 is a restructure, not a coat of paint, and its organization-defined parameters mean a mechanical crosswalk cannot finish the job.
    • Revision 3 is arriving through the FAR Council's CUI rule for federal contractors generally, which is still a proposed rule and not in force.
    • The right posture is Revision 2 compliance today, documented in a way that survives a parameter-driven standard tomorrow.

    Two instruments, one revision, and why people think otherwise

    The confusion here is structural, not anyone's fault. Two different rules govern what you implement, and they are pinned to Revision 2 by two different mechanisms, so a source that describes only one of them looks like it is describing the whole picture.

    The first is the CMMC program rule. 32 CFR Part 170 defines the levels, and 170.14(c)(3) fixes Level 2 to NIST SP 800-171 R2 by name. That is not a policy statement that could be reinterpreted; it is the operative text of the regulation, and Part 170 incorporates the referenced publications by reference under 170.2.

    The second is DFARS 252.204-7012, the safeguarding clause that has been in defense contracts since 2016 and that obliged 800-171 implementation years before CMMC existed. The clause as originally written points at the version of NIST SP 800-171 "in effect at the time the solicitation is issued or as authorized by the Contracting Officer" (DFARS 252.204-7012(b)(2)(i)). That drafting is what made Revision 3's publication a live problem: on the clause's own terms, a new revision would begin applying to new solicitations without any further rulemaking, unless a Contracting Officer authorized a different version for a given acquisition.

    Class Deviation 2024-O0013 closed that. Issued May 2, 2024, days before Revision 3 published, it replaces the floating reference with Revision 2 and stays in effect until rescinded. So the answer to "which revision does my contract require" is Revision 2 under both instruments, for two different reasons, and the deviation is the one with an expiry mechanism attached.

    Watch the deviation, not the news cycle. A rescission is the event that moves DFARS 7012, and it would be published rather than announced through vendor blogs.

    What Revision 3 changed

    Revision 3 is not a renumbering exercise. Three changes matter for planning.

    It restructured the families. The Revision 2 catalogue is 110 requirements in 14 families, which is the number underneath CMMC Level 2 and the number your Supplier Performance Risk System score is calculated from. Revision 3 reorganises that material and adds families that had no Revision 2 counterpart. Wiley's analysis of the release (a law firm, not a compliance vendor) describes the additions as Planning, System and Services Acquisition, and Supply Chain Risk Management, brought in to track the corresponding NIST SP 800-53 moderate baseline.

    It introduced organization-defined parameters. This is the change with the longest tail. Where Revision 2 stated a requirement, Revision 3 frequently states a requirement with a blank in it: a frequency, a duration, a threshold, or a scope that the organization (or the agency) fills in. That makes the standard more precise and considerably harder to crosswalk mechanically, because two organizations can implement the same requirement to genuinely different depths and both be conformant.

    It changed how the requirement count reads. Revision 3 consolidates some Revision 2 outcomes and separates others, so a headline count comparison between the revisions is misleading in both directions. Fewer numbered requirements does not mean less work when parameters have to be set, approved, and evidenced. We are deliberately not publishing a count here, because the counts in circulation vary by how withdrawn and consolidated items are treated, and a number we cannot source cleanly is worse than no number.

    Where Revision 3 is genuinely arriving from

    Not from CMMC. From the FAR.

    The FAR Council issued its Controlled Unclassified Information rule as a proposed rule in January 2025 (90 FR 4278, FAR Case 2017-016), and it would apply NIST SP 800-171 to CUI-handling contractors across the federal government rather than only in defense. That version was superseded on June 23, 2026 by a new proposal at 91 FR 37550, issued inside the broader FAR overhaul under its own docket, FAR Case 2026-001, and the revised rule "requires compliance with the newer Rev. 3" (Hunton). If you are tracking this, track 2026-001. The 2017-016 docket is the superseded one.

    Two things follow. First, this is still a proposed rule, so nothing in it obliges anyone today. Second, the direction of travel is real, and it is government-wide rather than defense-specific, which means a contractor with both defense and civilian federal work may eventually face two revisions at once until the instruments converge.

    That is the actual planning risk, and it is not the risk most vendors sell against. The risk is not that CMMC swaps revisions overnight. It is that you end up maintaining a Revision 2 program for defense contracts and a Revision 3 program for civilian ones, from the same control set, with the same team.

    The scoring problem nobody mentions

    There is a second, quieter reason CMMC cannot simply adopt Revision 3 by memo.

    Your SPRS score is not a percentage. It is calculated by the DoD Assessment Methodology, which starts at 110 and subtracts 1, 3, or 5 points per unimplemented requirement, keyed to Revision 2 requirement identifiers. We work through the mechanics in how to calculate your SPRS score. Change the underlying catalogue and every weight has to be reassigned, the maximum score changes, and historical scores stop being comparable to new ones for the same organization.

    Similarly, assessment procedures live in a companion publication, NIST SP 800-171A, and an assessor works to assessment objectives rather than to the requirement sentence. A revision change is therefore a change to the assessment guide, the scoring methodology, the SPRS submission form, and the training of every certified assessor, not just to the control list.

    None of that makes a transition impossible. It makes it slow, and it explains why the deviation and the program rule have both stayed where they are while the standard itself moved two years ago.

    Building Revision 3 tolerant without paying for Revision 3

    There is a narrow set of work that pays under either revision, and a wider set that does not. Do the narrow set.

    Write your parameters down even though Revision 2 does not ask for them. If your policy says accounts are reviewed periodically, change it to say quarterly, name who does it, and keep the records. Revision 3 will ask for the value; Revision 2 assessors already look for evidence that a frequency exists in practice. This is the single highest-value Revision-3-tolerant habit and it costs a policy edit.

    Keep the system security plan structured by requirement, not by narrative. A plan organised as one section per requirement, each with its implementation statement and its evidence pointer, can be re-keyed to a new catalogue. A twelve-page prose narrative cannot, and has to be rewritten.

    Do not restructure your control set to Revision 3 families. Your assessment, your score, and your affirmation are all Revision 2 artifacts today. Reorganising to a catalogue nobody assesses you against creates a translation problem in the direction that does not pay.

    Track the three triggers, and only those three. A rescission of Class Deviation 2024-O0013. A final FAR CUI rule. An amendment to 32 CFR 170.14. Everything else in this space is commentary. Our regulatory radar carries the entries as they move.

    When to ignore all of this

    If you have not yet implemented Revision 2, the revision debate is not your problem and reading about it is procrastination with a compliance flavour. The 110 requirements are contractually owed today under DFARS 7012, most first assessments fail on the same handful of them (multifactor authentication, encryption of CUI in transit and at rest, boundary protection, logging), and none of that changes under any revision.

    If you hold no federal contracts and no realistic pipeline, neither revision reaches you.

    And if a vendor is quoting you a Revision 3 migration project for a defense contract in 2026, ask them which instrument obliges it. The honest answer is none of them yet, and any proposal that cannot name the instrument is selling a calendar rather than a requirement. We would rather lose that engagement than run it.

    Where Top Floor fits

    Our CMMC practice works the 110 Revision 2 requirements at the assessment-objective level, and writes the system security plan in the structured, one-section-per-requirement form described above, because that is the form that survives a catalogue change. Where a client has both defense and civilian federal work, we build the control set once and map it twice rather than running two programs.

    For organizations carrying several frameworks at once, running them as a single program is usually cheaper than running each separately, which is what compliance as a service is for. The broader picture of what changed in the CMMC program is in our CMMC 2.0 guide.

    How to decide this week

    Confirm, in writing, which revision your current contracts reference. The answer should be Revision 2 under both the program rule and the deviation, and if a contract says something else, that is the thing to escalate.

    Take your three most parameter-shaped policies (access review frequency, log retention, password or authenticator lifetime) and write actual values into them. That is Revision 3 tolerance bought at the price of an afternoon.

    Look at your system security plan and ask one question: if the requirement catalogue were renumbered tomorrow, could you re-key this document, or would you rewrite it? If the answer is rewrite, restructure it now while the content is fresh, not later under a deadline.

    Set a calendar reminder against the three triggers above rather than following revision commentary. There will be a great deal of commentary.

    Frequently asked questions

    Which revision of NIST 800-171 does CMMC Level 2 use?

    Revision 2. 32 CFR 170.14(c)(3) states that "the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2", and Part 170 incorporates that publication by reference. That is the operative regulatory text rather than a policy preference, so CMMC Level 2 assessments, the 110-requirement count, and the scoring underneath a Supplier Performance Risk System submission all run on Revision 2 until the regulation itself is amended.

    Has the DoD class deviation on Revision 2 been rescinded?

    Not as of August 2026. Class Deviation 2024-O0013 was issued on May 2, 2024 and directs contractors subject to DFARS 252.204-7012 to comply with NIST SP 800-171 Revision 2 instead of the version in effect when the solicitation was issued or as authorized by the contracting officer. Its own terms keep it effective until it is rescinded, which makes rescission the specific event to watch: without the deviation, the clause's original drafting would begin pulling newer revisions into new solicitations without further rulemaking.

    Should we start implementing Revision 3 now?

    Not as a project. Nothing obliges Revision 3 in a defense contract today, and restructuring a control set to a catalogue no assessor scores you against creates translation work in the direction that does not pay. What does pay is the small set of habits that make a future transition a delta: write explicit values into policies that currently say "periodically", keep the system security plan organised one section per requirement with an evidence pointer, and preserve records that show frequencies being met.

    Does the FAR CUI rule apply to defense contractors too?

    It would, and that is why it matters here. The FAR Council's CUI rule was first proposed on January 15, 2025 as FAR Case 2017-016, and a revised proposal superseding it was published on June 23, 2026 inside the broader FAR overhaul under a new docket, FAR Case 2026-001 (91 FR 37550). It applies NIST SP 800-171 to CUI-handling contractors across the federal government rather than only in defense, and the revised version moves to Revision 3. It is not final and obliges nobody yet. Track FAR Case 2026-001 rather than 2017-016; the older docket no longer carries the live rule. The realistic exposure for a contractor with both defense and civilian federal work is a period where two revisions apply to different contracts at once.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.