Revision 3 is published. It is not what DFARS pins you to, and no adoption date has been announced — least of all now, with CMMC Phase 2 suspended and under review. But it is the clearest signal available of where the standard is heading, and it is worth knowing before someone sells you a scramble. Every one of the 110 Rev 2 requirements below is tagged with what Revision 3 does to it, in NIST's own words, alongside the 19 requirements that are new in Rev 3 and have no Rev 2 counterpart at all. Nothing you do here leaves your browser.
Revision 2 is the operative standard for DoD contractors. DoD Class Deviation 2024-O0013 hard-codes SP 800-171 Rev 2 into DFARS 252.204-7012 and states it stays in effect until rescinded, which overrides the clause's usual version-in-effect-at-solicitation language. Revision 3 has been published by NIST since May 2024, but it has not been adopted into DFARS or CMMC, and there is no announced date for that.
With CMMC Phase 2 suspended in July 2026 and the program under a reform review, the honest answer about Rev 3 adoption is that nobody outside the review knows. Treat everything on this page as planning context. Your self-assessment, your SPRS score, and your SSP are still built on Rev 2 today — do not renumber anything on the strength of this page.
Looking for how a requirement maps across frameworks rather than what changed? Use the 800-171 to 800-53 to CMMC crosswalk. For where the program itself stands, see the CMMC reform tracker.
Every classification and change summary on this page is NIST's own, read directly out of NIST's published change-analysis workbook. Nothing here is our interpretation of what changed.
NIST publications are US Government works in the public domain. BASTION is not affiliated with NIST, DoD, or the Cyber AB, and nothing here is an endorsement by them. This is a planning reference, not legal advice, and not a substitute for reading the standard.
No. Revision 2 is the operative standard, fixed in place by DoD Class Deviation 2024-O0013 until it is rescinded. Revision 3 is published but not adopted into DFARS or CMMC, and no adoption date has been announced.
An organization-defined parameter is a value Revision 3 leaves for you to set and document — a time period, a frequency, a threshold — where Revision 2 usually fixed it in the text. That is the single largest practical shift in Rev 3: less prescription, more of your own documented judgment, which an assessor can then question. If adoption comes, the ODP work is the part most people will underestimate.
Yes. Revision 3 adds a Supply Chain Risk Management family at 03.17 with three requirements, drawn from SR-02, SR-03, and SR-05 in SP 800-53 Rev 5. Revision 2 has no SR family, which is exactly why CMMC Level 2 contains no scored supply-chain requirement today. Your supply-chain obligations currently come from elsewhere — Section 889, FASCSA orders, and DFARS 7012 flow-down.
No. Revision 2 is what you are assessed against, so all 110 still apply to your self-assessment and your SPRS score. Withdrawn is forward-looking information about where the standard is going, not permission to stop. What it is genuinely useful for is deciding where not to spend money on heavy new tooling right now.
No. Everything runs in your browser. There are no accounts, nothing to submit, and no analytics on what you search or export. The dataset is embedded in the page, so it works offline once loaded. Open your network tab while you use it and confirm for yourself.
The 15-minute pre-purchase check to run before you buy any tool or piece of hardware — the six government lists to screen against, and what actually disqualifies a vendor. Plus practical CMMC guidance as the reform review develops.
We collect your email address, nothing else. No spam. Unsubscribe anytime.