DIB & Federal Compliance
Does CMMC Level 2 Use NIST SP 800-171 Revision 2 or Revision 3?
Revision 3 is the current NIST publication, and a civilian-agency rule already points to it. CMMC Level 2 does not — and the reason is a standing DoD deviation, not an oversight.
NIST finalized SP 800-171 Revision 3 in May 2024. Revision 2 has been formally withdrawn. Yet if you are a defense contractor working toward CMMC Level 2, you are still building your System Security Plan against the 110 requirements of Revision 2 — and you will be for a while longer. A separate proposed rule for civilian agencies already requires Revision 3. Here is what changed in the new standard, why the Defense Department has not adopted it for CMMC, and what actually deserves your attention this quarter.
The short answer: CMMC Level 2 still runs on Revision 2
Two weeks before NIST finalized Revision 3, the Department of Defense issued Class Deviation 2024-O0013, dated May 2, 2024, which explicitly ties DFARS clause 252.204-7012 and the CMMC program to Revision 2. That deviation has no expiration date and remains in effect today. CMMC Level 2, codified at 32 CFR Part 170, assesses contractors against Revision 2’s 110 security requirements, and the Supplier Performance Risk System (SPRS) is built to score against that same baseline — it does not accept a Revision 3-based self-assessment. If your assessor, your C3PAO, or your compliance vendor tells you otherwise, ask them to point to the rule that changed it, because as of this writing none has (Crowell & Moring).
That is a deliberate, durable decision, not an oversight. It exists because moving 90,000-plus defense contractors to a new control set mid-stream, while SPRS scoring and thousands of System Security Plans are built on the old one, is not something DoD is willing to do without a rulemaking. Which raises the obvious question: what is actually different in Revision 3, and is it worth planning around before you are required to?
What actually changed between Revision 2 and Revision 3
NIST did not add complexity for its own sake. Revision 3 consolidates and modernizes the control set, built entirely on NIST SP 800-53 Revision 5 as its single authoritative source rather than the patchwork of basic and derived requirements Revision 2 inherited from the original 800-53 catalog. The headline numbers:
- Requirement count: 110 requirements across 14 families (Revision 2) drops to 97 requirements across 17 families (Revision 3), per NIST’s own change analysis.
- New families: Planning (PL), System and Services Acquisition (SA), and Supply Chain Risk Management (SR) — three domains Revision 2 never addressed directly (Crowell & Moring).
- Organization-defined parameters (ODPs): Revision 2 had none. Revision 3 embeds 88 ODPs across 49 of its 97 requirements — bracketed values such as account lockout thresholds, password length, and vulnerability remediation windows that an organization (or, for DoD contracts, the Department itself) must fill in before the requirement is complete (Government Contracts Law Blog). DoD has not waited to answer these: it published specific required values for all 88 ODPs in an April 2025 memorandum, so the values that would apply on Day One of a DoD transition are already public.
- Assessment objectives: the companion assessment procedures document, NIST SP 800-171A, expands from 320 determination statements under Revision 2 to 422 under Revision 3 — a heavier evidentiary lift per requirement, even with fewer requirements overall (Summit 7).
Net effect: fewer numbered requirements, but each one is more precisely defined, more consistently testable, and in several cases folds in controls that Revision 2 had relegated to its non-mandatory Appendix E “NFO” list. A lower requirement count is not a lighter compliance lift.
The transition rule that has not shown up yet
DoD has told the public it intends to move CMMC to Revision 3 eventually — it just has not published the rule that does it. The Department’s own regulatory agenda lists RIN 0790-AM01, an interim final rule that would amend 32 CFR Part 170 to define the transition timeline from Revision 2 to Revision 3 and formally incorporate the DoD-set ODP values, at the Final Rule Stage with a placeholder target of July 2026. As of mid-September 2026, that rule has not appeared in the Federal Register, 32 CFR Part 170 has not been amended, and no new class deviation has superseded 2024-O0013. Until one of those three things happens, Revision 2 is the enforced baseline for every CMMC Level 2 assessment, full stop.
A second complication: the CMMC Phase 2 suspension
The Revision 3 question does not exist in isolation. On July 13, 2026, the Department of War immediately suspended CMMC Phase 2 — the third-party (C3PAO) certification tier that was set to become a solicitation requirement on November 10, 2026 — and launched a CMMC Reform Task Force to run a comprehensive review, under Department CIO Kirsten Davies. During the review, DoD is enforcing cybersecurity compliance through Revision 2 self-assessments and select government-led (DIBCAC) assessments; CMMC Phase 1 self-assessments and the underlying DFARS 252.204-7012 obligation are unaffected and remain fully in force. A companion memorandum limits new procurement documents to Level 1 or Level 2 self-assessment designations only for the duration of the suspension — no new C3PAO or DIBCAC designations, and no waivers, according to legal analyses from Latham & Watkins and Crowell & Moring.
The Task Force’s review window was scoped to roughly 60 days from the July 13 order — putting its internal deadline around mid-September 2026, right now, as this post publishes. No public recommendations report has been released as of this writing. Until one is, treat any specific relaunch date, phased rollout plan, or Revision 3 timeline you see circulating as speculation, not policy. The suspension itself, and the DFARS 7012 / Revision 2 baseline underneath it, are the only parts of this story that are settled.
A third complication: civilian agencies are already moving to Revision 3
Here is the part that trips up contractors who serve both defense and civilian federal customers. On June 23, 2026, the FAR Council published a revised proposed rule — FAR Case 2026-001, the CUI provisions of the broader “Revolutionary FAR Overhaul” — that would require any federal contractor whose contract involves Controlled Unclassified Information to implement NIST SP 800-171 Revision 3, using DoD’s published ODP values, through a new FAR 52.240-7 clause. The comment period closed July 23, 2026, and the rule is not yet final, but its direction is clear and corroborated across multiple independent legal analyses (Mayer Brown, Hunton).
That sets up a real divergence: a contractor holding both a DoD contract and a GSA or civilian-agency contract that each involve CUI could, once both rules are in force, need to satisfy Revision 2 on one side of the business and Revision 3 on the other — under a single security program. GSA’s own January 2026 CUI guidance already requires Revision 3 for the nonfederal systems it approves. None of this changes what CMMC Level 2 requires today, but it is the strongest signal yet that Revision 3 is not a hypothetical future state to defer indefinitely — it is already load-bearing somewhere in the federal contracting landscape, just not yet on the DFARS side.
What DIB contractors should actually do right now
- Keep building to Revision 2. Your System Security Plan, POA&Ms, and SPRS score should be built against the current 110-requirement baseline. Nothing in this post changes that today.
- Do not let a C3PAO, assessor, or vendor sell you a Revision 3 assessment as your CMMC path. It will not satisfy 32 CFR Part 170 or score in SPRS until DoD formally adopts it.
- If you also hold civilian-agency contracts involving CUI, start tracking FAR Case 2026-001 separately. A GSA or civilian contract could require Revision 3 controls before your DoD contracts do, and the control sets are not identical.
- Map your current controls to the new family structure now, even without a deadline. The three new families — Planning, System and Services Acquisition, and Supply Chain Risk Management — are areas most mid-market DIB programs under-document today regardless of which revision eventually governs them.
- Watch for two specific triggers, not rumors: a Federal Register publication under RIN 0790-AM01, or a public CMMC Reform Task Force report. Either one will tell you the real timeline; nothing published before that does.
- If you run your own compliance program without a dedicated GRC or vCISO function, this is a reasonable point to have someone stress-test your Revision 2 evidence base before Phase 2 resumes, whenever that turns out to be.
Frequently asked questions
Does CMMC Level 2 require NIST SP 800-171 Revision 3?
No. CMMC Level 2, under 32 CFR Part 170, is assessed against Revision 2’s 110 security requirements. DoD Class Deviation 2024-O0013 ties DFARS 252.204-7012 to Revision 2 with no expiration date, and SPRS scoring is built on the same baseline.
What is NIST SP 800-171 Revision 3?
Revision 3 is NIST’s current, finalized update (published May 2024) to the security requirements for protecting Controlled Unclassified Information on nonfederal systems. It reorganizes the control set into 97 requirements across 17 families and is built on NIST SP 800-53 Revision 5.
How many requirements does Revision 3 have compared to Revision 2?
Revision 2 has 110 requirements across 14 families. Revision 3 has 97 requirements across 17 families, adding Planning, System and Services Acquisition, and Supply Chain Risk Management as new families.
When will CMMC move to Revision 3?
There is no confirmed date. DoD’s regulatory agenda lists an interim final rule (RIN 0790-AM01) at the Final Rule Stage with a placeholder target of July 2026, but as of mid-September 2026 it has not published, and 32 CFR Part 170 has not been amended.
What is the CMMC Reform Task Force?
It is the review body the Department of War created on July 13, 2026, when it suspended CMMC Phase 2 (third-party certification), tasked with a comprehensive review of the CMMC program. Its internal review window ran roughly 60 days from that order; no public recommendations report has been released as of this writing.
What are organization-defined parameters (ODPs) in Revision 3?
ODPs are bracketed values inside a requirement — such as a time period, threshold, or frequency — that must be specified before the requirement is complete. Revision 3 has 88 ODPs across 49 of its 97 requirements, and DoD has already published its required values for all 88 in an April 2025 memorandum.
Should contractors start preparing for Revision 3 now, even though CMMC still uses Revision 2?
It is reasonable to map current controls to the new family structure and review DoD’s published ODP values, since that work is not wasted regardless of the eventual transition date. It is not reasonable to substitute a Revision 3 assessment for a required Revision 2 CMMC assessment today.
Does the FAR CUI rule use Revision 2 or Revision 3?
The FAR Council’s proposed CUI rule (FAR Case 2026-001, published June 23, 2026) would require Revision 3 for civilian-agency contractors handling CUI — diverging from DFARS 252.204-7012 and CMMC, which remain on Revision 2. The rule is not yet final.
Cyberuptive tracks CMMC and NIST SP 800-171 rulemaking as part of our CMMC compliance advisory work for defense contractors and subcontractors. For related reading, see our coverage of DFARS 252.204-7012 flow-down obligations, the CMMC Phase 2 suspension, and the enhanced-requirement companion standard, NIST SP 800-172r3. If your organization supports both defense and civilian federal customers, our defense contractor security programs are built to handle exactly this kind of dual-track compliance exposure.