Rev 2 is the operative standard · Rev 3 is not adopted

What actually changes in 800-171 Rev 3

Revision 3 is published. It is not what DFARS pins you to, and no adoption date has been announced — least of all now, with CMMC Phase 2 suspended and under review. But it is the clearest signal available of where the standard is heading, and it is worth knowing before someone sells you a scramble. Every one of the 110 Rev 2 requirements below is tagged with what Revision 3 does to it, in NIST's own words, alongside the 19 requirements that are new in Rev 3 and have no Rev 2 counterpart at all. Nothing you do here leaves your browser.

Your searches never leave your browser. This page has no backend. The full dataset is embedded in the HTML, every filter and export runs locally, and there is no analytics on what you look up. It works offline once loaded. Open your network tab and check — that is rather the point.
Read this first

Rev 3 is not your requirement today

Revision 2 is the operative standard for DoD contractors. DoD Class Deviation 2024-O0013 hard-codes SP 800-171 Rev 2 into DFARS 252.204-7012 and states it stays in effect until rescinded, which overrides the clause's usual version-in-effect-at-solicitation language. Revision 3 has been published by NIST since May 2024, but it has not been adopted into DFARS or CMMC, and there is no announced date for that.

With CMMC Phase 2 suspended in July 2026 and the program under a reform review, the honest answer about Rev 3 adoption is that nobody outside the review knows. Treat everything on this page as planning context. Your self-assessment, your SPRS score, and your SSP are still built on Rev 2 today — do not renumber anything on the strength of this page.

What this is useful for. Seeing which parts of your program are stable and which are likely to move, so you can avoid over-investing in something Rev 3 withdraws, and so you are not blindsided by the ODP work if adoption does come. It is also a straight answer to hand anyone who tells you that you need to "get ready for Rev 3" right now.

Looking for how a requirement maps across frameworks rather than what changed? Use the 800-171 to 800-53 to CMMC crosswalk. For where the program itself stands, see the CMMC reform tracker.

Provenance

Where this data comes from

Every classification and change summary on this page is NIST's own, read directly out of NIST's published change-analysis workbook. Nothing here is our interpretation of what changed.

  • Change classifications and summaries — NIST SP 800-171 R2-to-R3 Change Analysis workbook, the "Change Analysis" sheet. The significant, minor, no-significant-change, new-ODP, new-requirement, and withdrawn tags are NIST's columns, not ours. XLSX
  • The 110 Rev 2 requirements — NIST SP 800-171 Rev 2 (upd1) machine-readable requirements file, used to verify that exactly the official 110 appear here. Publication · CSV
  • Rev 3 requirement identifiers and family structure — NIST SP 800-171 Rev 3 OSCAL catalog, published by the NIST OSCAL Program. Publication · OSCAL
One correction we made, and why we are telling you. NIST's workbook contains 130 analysis rows. One of them lists its Rev 2 identifier as 3.11.4, which is not a real Rev 2 requirement — the Risk Assessment family ends at 3.11.3. Its requirement text is verbatim the system security plan requirement, 3.12.4, and it records the vacated Rev 3 slot 03.12.04 as withdrawn, because in Rev 3 the SSP requirement moves to Planning at 03.15.02. It is a typo in the source, and it double-counts one requirement. We drop that row, which is why this page shows 129 rows and 32 withdrawn rather than 130 and 33. Removing it makes the Rev 2 side reconcile to exactly the official 110. We would rather show you the seam than quietly publish a number that does not add up.

NIST publications are US Government works in the public domain. BASTION is not affiliated with NIST, DoD, or the Cyber AB, and nothing here is an endorsement by them. This is a planning reference, not legal advice, and not a substitute for reading the standard.

Questions

Common questions

Is Rev 3 required for CMMC?

No. Revision 2 is the operative standard, fixed in place by DoD Class Deviation 2024-O0013 until it is rescinded. Revision 3 is published but not adopted into DFARS or CMMC, and no adoption date has been announced.

What is an ODP, and why do 49 requirements have one?

An organization-defined parameter is a value Revision 3 leaves for you to set and document — a time period, a frequency, a threshold — where Revision 2 usually fixed it in the text. That is the single largest practical shift in Rev 3: less prescription, more of your own documented judgment, which an assessor can then question. If adoption comes, the ODP work is the part most people will underestimate.

Does Rev 3 add supply chain requirements?

Yes. Revision 3 adds a Supply Chain Risk Management family at 03.17 with three requirements, drawn from SR-02, SR-03, and SR-05 in SP 800-53 Rev 5. Revision 2 has no SR family, which is exactly why CMMC Level 2 contains no scored supply-chain requirement today. Your supply-chain obligations currently come from elsewhere — Section 889, FASCSA orders, and DFARS 7012 flow-down.

Thirty-two requirements are withdrawn. Can I stop doing them?

No. Revision 2 is what you are assessed against, so all 110 still apply to your self-assessment and your SPRS score. Withdrawn is forward-looking information about where the standard is going, not permission to stop. What it is genuinely useful for is deciding where not to spend money on heavy new tooling right now.

Does this tool send my data anywhere?

No. Everything runs in your browser. There are no accounts, nothing to submit, and no analytics on what you search or export. The dataset is embedded in the page, so it works offline once loaded. Open your network tab while you use it and confirm for yourself.

Free checklist

The vendor vetting checklist

The 15-minute pre-purchase check to run before you buy any tool or piece of hardware — the six government lists to screen against, and what actually disqualifies a vendor. Plus practical CMMC guidance as the reform review develops.

We collect your email address, nothing else. No spam. Unsubscribe anytime.