Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST 800-171 Rev 3 explained

NIST 800-171 Rev 3 vs Rev 2: 97 Requirements Explained (2026)

NIST 800-171 Rev 3 is the current NIST publication for protecting Controlled Unclassified Information in nonfederal systems — final since May 2024, superseding Revision 2, which NIST withdrew on 14 May 2024 — and it is also the revision most defense contractors must not build to yet. The two facts sit together because two different authorities are involved: NIST decides what the current standard is, and the regulation that binds you decides which revision it incorporates.

CMMC and DFARS 252.204-7012 remain on Revision 2 through a DoD class deviation; contracts and agreements outside that regime may name Revision 3. This guide sets out what changed between Rev 2 and Rev 3 — 110 requirements in 14 families became 97 in 17, with organization-defined parameters, three new families and a rewritten assessment companion — which revision applies to whom, how to tell Rev 2 and Rev 3 content apart, and how to run a program that satisfies the one you owe while staying ready for the other.

NIST 800-171 Rev 3 vs Rev 2: what changed
110 requirements in 14 families → 97 in 17; basic/derived distinction removed; 88 organization-defined parameters across 50 requirements; Planning, System and Services Acquisition and Supply Chain Risk Management added.

NIST 800-171 Rev 3 vs Rev 2 at a glance

Revision 2 (Feb 2020, updated Jan 2021) Revision 3 (May 2024)
Status at NIST Withdrawn 14 May 2024 Current; no Rev 4
Security requirements 110 across 14 families 97 across 17 families (130 identifiers, 33 marked withdrawn)
Structure of a requirement Basic requirements plus derived requirements Single requirements, many multi-part, aligned to SP 800-53 Rev 5 control language
Identifier format 3.1.1 03.01.01 (leading zeros, matching 800-171A)
Organization-defined parameters None 88 ODPs in 50 requirements; values set by the agency or, failing that, by the organization
Families added Planning (PL), System and Services Acquisition (SA), Supply Chain Risk Management (SR); Security Assessment renamed Security Assessment and Monitoring (CA)
Tailoring categories NCO, FED, NFO, CUI NCO, FED, ORC, N/A, CUI — NFO eliminated
Source baseline SP 800-53 Rev 4 moderate SP 800-53 Rev 5 / SP 800-53B moderate, with a published CUI overlay
Assessment companion SP 800-171A (June 2018), 320 objectives SP 800-171A Rev 3 (May 2024), procedures restructured to SP 800-53A syntax
Applies under CMMC / DFARS 7012 Yes — by class deviation and the CMMC rule No — “not currently applicable” per 32 CFR Part 170

What changed in NIST 800-171 Rev 3

NIST’s own FAQ on the revision lists the significant differences. Five of them change what an implementer actually does.

  1. The basic/derived distinction is gone. Rev 2 stated each family as a few high-level basic requirements drawn from FIPS 200 plus derived requirements from SP 800-53. Rev 3 recasts everything as single requirements written in SP 800-53 Rev 5 control language, with sub-parts (a, b, c) where the source control has them. The count fell from 110 to 97 not because protection was removed but because closely related requirements were consolidated — NIST notes that grouping into multi-part requirements “does not add to the total number of requirements”.
  2. Organization-defined parameters. Rev 2 said “limit unsuccessful logon attempts”; Rev 3 says limit them to an organization-defined number within an organization-defined time period, and lists all 88 such parameters in Appendix D. The federal agency may set the values; if it does not, the nonfederal organization must, and the values then become part of the requirement and are assessed as such. The 17 ODPs in Access Control alone cover session timeouts, account inactivity periods and lockout thresholds that Rev 2 left open.
  3. Three new families, one renamed. Planning brings the XX-1 policy-and-procedure controls in — NIST found that NFO-tailored controls such as AC-1 were simply not being implemented in nonfederal organizations, so the NFO category was eliminated. System and Services Acquisition adds acquisition and developer requirements; Supply Chain Risk Management adds a supply chain risk management plan, acquisition strategies and supplier controls.
  4. Increased specificity. Rev 2’s abstraction left assessors with different expectations; Rev 3 states more of the detail in the requirement, which narrows the solution space and makes assessments more consistent. Withdrawn Rev 2 requirements are listed with their disposition — incorporated into another requirement, or removed as outdated or redundant.
  5. The ISO 27001 mapping was removed. Rev 3’s mapping tables cover SP 800-53 only; NIST separately maintains an SP 800-53 Rev 5 to ISO/IEC 27001:2022 mapping.

The 17 families and their requirement counts

Family Rev 3 identifier Active requirements
Access Control 03.01 16
Awareness and Training 03.02 2
Audit and Accountability 03.03 8
Configuration Management 03.04 10
Identification and Authentication 03.05 8
Incident Response 03.06 5
Maintenance 03.07 3
Media Protection 03.08 7
Personnel Security 03.09 2
Physical Protection 03.10 5
Risk Assessment 03.11 3
Security Assessment and Monitoring 03.12 4
System and Communications Protection 03.13 10
System and Information Integrity 03.14 5
Planning (new) 03.15 3
System and Services Acquisition (new) 03.16 3
Supply Chain Risk Management (new) 03.17 3

Counts are of active requirements after the 33 withdrawn identifiers are excluded; Access Control, for example, runs 03.01.01 to 03.01.22 but six of those are marked withdrawn and incorporated elsewhere. Our guide to NIST 800-53 control families covers the parent catalog the families are drawn from.

Which revision applies to you

Your obligation Revision to implement Why
DFARS 252.204-7012 covered defense information Rev 2 DoD’s May 2024 class deviation holds 7012 at Rev 2; the September 2025 DFARS rule cites SP 800-171 without moving the revision
CMMC Level 2 (self-assessment, or a voluntary C3PAO assessment) Rev 2 32 CFR Part 170 assesses the 110 Rev 2 requirements and states Rev 3 is not currently applicable; Part 170 is unamended
SPRS score under the DoD Assessment Methodology Rev 2 The methodology scores 110 requirements from 110 down to −203
A civilian-agency contract or agreement that names SP 800-171 Whichever it names — increasingly Rev 3 Outside DFARS there is no deviation; read the clause
A commercial customer flowing down ‘NIST 800-171’ Ask Many mean Rev 2 because their own obligation is DFARS; some mean the current NIST publication
No contractual driver; using 800-171 as a voluntary baseline Rev 3 It is the current standard and the direction every regime will eventually move

The 13 July 2026 suspension of CMMC Phase 2 did not change any of this: DFARS 7012 and Phase 1 self-assessments continue, on Rev 2. Our guide to CMMC vs NIST 800-171 covers how the program layers on the standard.

Telling Rev 2 content from NIST 800-171 Rev 3 content

Because the two revisions are both in circulation, templates, SSPs and vendor documents get mislabelled — including, in our own experience, a pack whose content was Rev 2 under labels that said Rev 3. Three tells settle it without reading a requirement:

  • Identifier format. 3.1.1 is Rev 2; 03.01.01 is Rev 3.
  • Family count. Fourteen families ending at System and Information Integrity is Rev 2; seventeen ending at Supply Chain Risk Management is Rev 3.
  • Parameters. Any “[Assignment: organization-defined …]” or a table of values you set yourself is Rev 3; Rev 2 has none.

Our guide to NIST 800-171 templates applies the same tests to document sets.

Running a program that satisfies Rev 2 and is ready for NIST 800-171 Rev 3

  1. Implement and document the revision you owe. For DoD contractors that is Rev 2: 110 requirements, an SSP and POA&M keyed to 3.x.x identifiers, a SPRS score from the DoD methodology.
  2. Keep a Rev 3 crosswalk beside the SSP. NIST’s transition mapping tables show where each Rev 2 requirement went. A column in the SSP recording the Rev 3 identifier costs little now and turns the eventual transition into a documentation exercise.
  3. Set your ODP values now, in policy. Lockout thresholds, session timeouts, review frequencies and retention periods are decisions you have already made to satisfy Rev 2; writing them as Rev 3 parameter values means the Rev 3 requirement is met the day it applies.
  4. Close the three new families as good practice. A written security plan and policies (PL), acquisition requirements for system components (SA) and a supply chain risk plan (SR) are what a mature Rev 2 program has anyway.
  5. Do not re-baseline the SSP to Rev 3 for a DoD assessment. An assessor working from the Rev 2 catalog cannot map a Rev 3 document to the 110 requirements without doing your work again, and the score will suffer.

Frequently asked questions

Is NIST 800-171 Rev 3 mandatory?
It is the current NIST publication, but whether it binds you depends on the regulation or contract that incorporates SP 800-171. DFARS 252.204-7012 and CMMC remain on Rev 2 by DoD class deviation; other agreements may name Rev 3.

How many requirements are in Rev 3?
97 security requirements across 17 families, down from 110 in 14 families in Rev 2. The catalog has 130 identifiers, 33 of which are marked withdrawn and incorporated into other requirements.

What are organization-defined parameters?
Values the requirement leaves open — a number, a frequency, a time period — that the federal agency may set and that the organization must set if the agency does not. Rev 3 has 88 of them across 50 requirements, consolidated in Appendix D.

Is Rev 2 still available?
NIST withdrew it on 14 May 2024 but it remains published as a superseded document, and DoD requires it: the CMMC rule assesses Rev 2 and Part 170 has not been amended.

When will CMMC move to Rev 3?
No date has been set; the CMMC final rule states Rev 3 is not currently applicable, and the July 2026 suspension of Phase 2 has not changed the revision. Track the Federal Register for an amendment to 32 CFR Part 170 or a new DFARS deviation.

Where this leaves you

Treat NIST 800-171 Rev 3 as the destination and Rev 2 as the obligation: implement and score the 110 Rev 2 requirements for anything that runs through DFARS or CMMC, keep a crosswalk to the 97 Rev 3 requirements, set the 88 parameter values in policy now, and read every contract clause for the revision it actually names.

References

More on NIST SP 800-171

The System Security Plan, the POA&M, the control-family policies and procedures and the CUI scoping workbook — built to Revision 2 because that is what DFARS and CMMC assess — are in the NIST SP 800-171 CUI Protection Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.