Want to learn more about services? Book a free introductory call - "Here"

NIST SP 800-171 Rev 3 Is Coming to CMMC

NIST published SP 800-171 Rev 3 in 2024, but DoD hasn't yet required it for CMMC. Here's what's confirmed, what's pending, and what to do now.

CMMC BLOG

Daniel McLain

8/28/20265 min read

NIST SP 800-171 Rev 3 Is Coming to CMMC: What It Changes and Why Waiting Is a Bad Idea

If you've seen headlines about "NIST 800-171 Revision 3 coming to CMMC" and assumed it's some new document about to drop on the Defense Industrial Base (DIB), here's the correction: it already exists. The National Institute of Standards and Technology (NIST) published the final version of Special Publication (SP) 800-171 Revision 3 on May 14, 2024. That's over two years ago as of this writing.

What's actually in motion right now isn't NIST writing a new standard. It's the Department of Defense (DoD) deciding when, and how, to require Revision 3 as the security baseline for Cybersecurity Maturity Model Certification (CMMC) Level 2, in place of the Revision 2 baseline contractors work against today. That's a separate process, it's still open, and it just got more uncertain because of a broader CMMC program review that started in July 2026. This article walks through what's settled, what's pending, and what you can reasonably do about it now.

Revision 3 already exists. Here's what NIST actually published

NIST SP 800-171 Revision 3 provides recommended security requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) on nonfederal systems. It's the document CMMC Level 2 practices are built on. NIST finalized it on May 14, 2024, alongside a companion document, NIST SP 800-171A Revision 3, which spells out the assessment procedures an examiner (or you, doing a self-assessment) would use to check each requirement.

The full text of SP 800-171 Rev 3 is public right now, free, and final. Nothing about the document itself is pending. What's pending is whether and when DoD makes it the mandatory standard for your contracts.

What changed from Revision 2 to Revision 3

Revision 2, the version currently required under CMMC Level 2, organizes 110 security requirements across 14 control families. Revision 3 restructures things:

  • Three new control families were added: Planning (PL), System and Services Acquisition (SA), and Supply Chain Risk Management (SR), bringing the total to 17 families.

  • The requirement count changed: Rev 3 consolidates and reorganizes down to 97 requirements, even with three new families added, largely because some Rev 2 requirements were merged or moved into assessment procedures rather than dropped as substance.

  • Organization-defined parameters (ODPs) were introduced. Instead of one fixed value for every requirement, certain controls now have a parameter that the requiring agency (DoD, for CMMC purposes) sets. NIST's final version settled on 49 ODPs after industry pushback trimmed an earlier draft's much larger count. In practice, this means DoD will need to publish its own values for those parameters before Rev 3 can function as a complete, assessable CMMC baseline. That hasn't happened yet.

If you're comparing your current Rev 2 System Security Plan (SSP) against Rev 3, expect more than a find-and-replace exercise. Some requirements moved families, some were reworded, and the ODPs mean a few controls won't have a final answer until DoD publishes its values.

What's actually pending: DoD adopting Rev 3, not NIST publishing it

Industry reporting has referenced a DoD interim final rule under regulatory identifier RIN 0790-AM01 that would establish transitional requirements between Revision 2 and Revision 3 for CMMC. As of late August 2026, that rule has not published. A target date of roughly July 2026 circulated in trade press earlier this summer, but that date came and went without a published rule, and DoD has not confirmed a new effective date. Treat any specific month you see quoted for Rev 3 adoption as reported and unconfirmed, not settled, until it appears in the Federal Register.

Right now, today, CMMC Level 2 self-assessments are still being conducted against NIST SP 800-171 Revision 2, not Revision 3. That hasn't changed and there's no indication it's changing on a specific date yet. (EnTech, "CMMC Phase II Is Paused, Phase I Is Not")

Why the timeline just got harder to predict: the Phase 2 pause

On July 13, 2026, DoD Chief Information Officer Kirsten Davies suspended CMMC Phase 2, the phase that would have required third-party certification assessments through a Certified Third-Party Assessment Organization (C3PAO) starting November 10, 2026. In the same memo, Davies launched a 60-day, cross-departmental "CMMC Reform Task Force" to reassess the program. (Federal News Network)

Phase 1 self-assessment obligations were not suspended and remain in effect. If you're a contractor handling CUI, you still owe DoD an accurate self-assessment against Rev 2, entered into the Supplier Performance Risk System (SPRS), with an annual affirmation from a named senior official. What's paused is the mandatory move to third-party certification.

We've covered the Phase 2 pause itself in more detail in a separate article on this site, so we won't re-walk all of it here. The relevant point for Rev 3 is this: the task force's 60-day window runs into mid-September 2026, and its recommendations could reshape parts of the CMMC framework, potentially including how and when a new NIST baseline gets folded in. That makes any Rev 3 rule timeline you see quoted right now, including the one referenced above, something to hold loosely. Nobody outside DoD currently knows how the reform review and the Rev 3 rulemaking will land relative to each other.

What this means for your organization right now

If you're preparing for a Phase 1 self-assessment today, your obligation is against Revision 2. Don't rebuild your SSP around Revision 3 language as if it's already required. It isn't. Doing that now, before DoD has published ODP values and finalized transition rules, risks you building documentation against a moving target.

That said, "it's not required yet" is different from "ignore it." A few things are worth doing now as a matter of good planning, separate from any compliance deadline:

  • Read SP 800-171A Revision 3 to understand how examiners would eventually check each Rev 3 requirement. It's public today, and understanding the assessment objectives now gives you a head start regardless of when the DoD rule lands.

  • Map your current controls against the three new families (Planning, System and Services Acquisition, Supply Chain Risk Management). These are the areas most likely to require net-new work rather than documentation tweaks, since Rev 2 didn't have dedicated families for them.

  • Flag Plan of Action and Milestones (POA&M) items that touch requirements likely to shift. If a control you're currently remediating under Rev 2 is one that Rev 3 restructures or reworks, it's worth noting so you don't finish work against language that's about to change.

This is a recommended practice for planning purposes, not a compliance requirement. Nothing here is a substitute for your actual Rev 2 self-assessment obligations, which are current and binding right now.

A small business example

Say you're a 40-person machine shop with a DFARS 252.204-7012 clause in your current contract, handling CUI design specs from a prime contractor. You did your Rev 2 self-assessment and submitted your SPRS score last year. Someone on your team reads a headline about "Rev 3 coming to CMMC" and asks whether you need to redo everything.

The honest answer: not yet, and there's no confirmed date telling you when. Your existing Rev 2 self-assessment and SPRS submission remain your operative compliance posture. What's reasonable is spending an afternoon skimming the three new Rev 3 control families against what you already have, so that if and when DoD's rule lands, you're not starting from zero. That's a planning head start, not a new obligation.

Official resources

A closing note, and where ICTS USA fits

This is general informational guidance based on publicly available sources as of August 28, 2026, not legal advice, and it isn't a substitute for consulting a Registered Practitioner Organization (RPO) or a C3PAO for a specific compliance determination or assessment. CMMC's Rev 3 timeline is genuinely unsettled right now, and anyone who tells you an exact effective date with confidence is guessing.

Before investing in tools, documentation, or a new assessment cycle built around Revision 3, make sure you understand what your current contract actually requires today, and which parts of your environment are in scope. ICTS USA can help you evaluate where you stand under the current Rev 2 baseline, get a practical read on how the Rev 3 transition and the CMMC Reform Task Force outcomes might affect your specific contracts, and figure out what's worth doing now versus what can reasonably wait.

Copyright © 2026 ICTS USA LLC - All Rights Reserved.