Analysis

NIST SP 800-171 Rev 2 vs Rev 3: What Changed and What It Means for Your Assessment

Last updated: 2025-06-15

AC CA CM IA RA SC SI
Overview Structural Changes Requirement Delta New Families CMMC Impact Preparing Now FAQ

The Short Answer

NIST SP 800-171 Rev 3 was finalized in May 2024. It replaces the 110-requirement, 14-family structure of Rev 2 with a 125-requirement framework organized across 17 families. Three families are new. The numbering scheme changed. The underlying security intent largely did not.

For CMMC Level 2 contractors, the practical urgency is limited right now. CMMC 2.0 remains anchored to Rev 2. C3PAO assessments are conducted against Rev 2's controls, and SPRS scores are calculated using the Rev 2 methodology. Rev 3 becomes operationally relevant when the DoD issues a CMMC rule revision that formally adopts it, and that update has not been finalized as of this writing.

That said, contractors who ignore Rev 3 entirely are taking a risk. The new requirements in the SR and SA families address supply chain and acquisition controls that assessors will eventually test. Organizations that begin gap analysis now will face a shorter remediation window when the transition arrives.

Structural Changes: What NIST Reorganized

Rev 2 organized its 110 requirements across 14 control families, each identified by a two-letter abbreviation. Rev 3 retains most of those families but adds three new ones and renames the numbering convention. The table below compares the two versions at the structural level.

Attribute Rev 2 Rev 3
Publication date February 2020 May 2024
Total requirements 110 125
Control families 14 17
Numbering format Domain.Sequence (e.g., 3.1.1) Family prefix (e.g., AC.01)
NIST SP 800-53 alignment Rev 4 Rev 5
CMMC Level 2 basis Yes (current rule) Not yet (pending DoD update)
SPRS scoring model 110-requirement model, published Not yet published
New control families None PL (Planning), SA (System and Services Acquisition), SR (Supply Chain Risk Management)
Numbering Scheme Change
Rev 2 used a three-digit decimal format tied to the domain number (e.g., 3.1.1 for the first Access Control requirement). Rev 3 uses a family-prefix format (e.g., AC.01). If your SSP, POA&M, or internal tracking tools reference Rev 2 control numbers, they will need remapping when your organization transitions.

Requirement Delta by Family

The 15 additional requirements in Rev 3 are not evenly distributed. The three new families account for most of the increase. Several existing families also saw requirements added or split into more granular controls. The table below shows the count change for each family, organized by Rev 2 family name where applicable.

Code Family Rev 2 Count Rev 3 Count
AC Access Control 22 25
AT Awareness and Training 3 3
AU Audit and Accountability 9 9
CA Assessment, Authorization, and Monitoring 9 9
CM Configuration Management 9 11
IA Identification and Authentication 11 12
IR Incident Response 3 3
MA Maintenance 6 6
MP Media Protection 9 8
PE Physical Protection 6 6
PL Planning (new in Rev 3) 0 2
PS Personnel Security 2 2
RA Risk Assessment 3 5
SA System and Services Acquisition (new in Rev 3) 0 4
SC System and Communications Protection 16 14
SI System and Information Integrity 7 6
SR Supply Chain Risk Management (new in Rev 3) 0 7
Net Change Is Not the Whole Story
Several families with unchanged counts still have modified requirement language. AC and IA requirements were reworded in Rev 3 to align with SP 800-53 Rev 5 outcomes-based language. If you are tracking compliance at the requirement-text level, a direct comparison is worth conducting even in families where the total count stayed the same.

The Three New Families in Rev 3

The most substantive additions in Rev 3 are the three families that did not exist in Rev 2. Each addresses a gap that has grown more visible in DoD supply chain incidents over the past several years.

Family What It Covers Assessment Relevance
PL
Planning
Requires a formal system security plan (SSP) and rules of behavior for users with access to CUI. Two requirements total. Largely codifies what most contractors already produce for C3PAO assessments. The SSP requirement under PL maps to what was previously implicit in CA under Rev 2.
SA
System and Services Acquisition
Addresses security requirements in acquisitions, developer testing, and supply chain protection for software and services. Four requirements. Contractors who purchase commercial software or outsource development will need documented security requirements for those vendors. This is a new documentation burden for many mid-sized prime contractors.
SR
Supply Chain Risk Management
Covers CUI protection in the supply chain, vendor risk assessment, and component authenticity. Seven requirements. The largest new family by count. The SR family directly targets the risk that CUI flows to subcontractors who are not assessed. Primes with large sub-tier supplier networks face the heaviest lift here.
SR Is the Highest-Risk New Family
Seven requirements across Supply Chain Risk Management is not a small addition. Organizations that treat their CUI boundary as ending at their own systems will face findings in this family. SR requires documented processes for managing the security of components acquired from suppliers, including verification of component authenticity.

What This Means for CMMC Level 2

CMMC 2.0 Level 2 currently requires compliance with all 110 requirements in NIST SP 800-171 Rev 2. That is the version your C3PAO assessor will test against. It is also the version that determines your SPRS score submitted in the Supplier Performance Risk System.

The DoD has publicly stated its intention to align a future CMMC revision to Rev 3, but the specific timeline and any transition provisions for contractors who achieved Rev 2 certification have not been released. Given that CMMC rulemaking moves slowly, most contractors pursuing certification in 2025 will be assessed against Rev 2 regardless of what Rev 3 adds.

Two Separate Clocks
Your CMMC assessment clock (tied to Rev 2) and your internal maturity roadmap (which should account for Rev 3) are two different timelines. Conflating them creates either unnecessary urgency around Rev 3 controls during your assessment window, or false confidence that Rev 2 compliance is a permanent destination.

One area where Rev 3 already matters: contract language. Some DoD agencies and a growing number of prime contractors are beginning to reference Rev 3 in their own security requirements clauses. If a contract clause cites Rev 3 explicitly, that version governs your obligations under that contract regardless of where the formal CMMC rule stands.

How to Prepare for the Transition

The gap between Rev 2 compliance and Rev 3 compliance is manageable with a structured approach. The organizations that will struggle are those that treat Rev 3 as a distant problem and make no effort to inventory the delta before the DoD transition date is announced.

Action What It Involves Priority
Rev 2 certification first Complete your CMMC Level 2 assessment or maintain your self-attestation. Rev 3 does not replace this obligation today. Immediate
Gap analysis against SR family Map your current supply chain security practices against the seven SR requirements. Most organizations have informal processes that do not yet produce documented artifacts. High
Gap analysis against SA family Review contracts with software vendors and development partners. Identify where you are not currently specifying security requirements in acquisition. High
Renumber your SSP tracking Build a crosswalk table mapping Rev 2 control numbers (3.x.x) to Rev 3 prefixes (XX.XX). Assessors will eventually expect this when the transition occurs. Medium
Review modified AC and IA language Even in families with unchanged counts, requirement text shifted toward outcomes-based language. Verify your implementation statements still satisfy the revised wording. Medium
Monitor DoD CMMC updates Watch for a CMMC rule revision that formally adopts Rev 3. The transition timeline will drive your implementation deadline. Ongoing

Tracking the Transition with 1TEN

Managing compliance across two active versions of 800-171 creates a real documentation problem. Your current SPRS score, your C3PAO artifacts, and your forward-looking Rev 3 gap analysis need to live in the same place without creating confusion about which version each control maps to. 1TEN is built for exactly this kind of structured compliance tracking. The platform maintains version-aware control libraries, flags gaps by domain and priority, and produces the artifact sets assessors expect. When the DoD formalizes the Rev 3 transition, the crosswalk is already built in.

Frequently Asked Questions

Not immediately. CMMC 2.0 Level 2 is currently anchored to NIST SP 800-171 Rev 2. The DoD has signaled that a future CMMC rule update will align to Rev 3, but no effective date has been finalized. Contractors assessed today are evaluated against Rev 2's 110 requirements.

Rev 3 increases the requirement count from 110 to 125. The additions are concentrated in areas such as supply chain risk management, planning, and system and services acquisition. Some Rev 2 requirements were also restructured or split into more granular controls.

Rev 3 reorganized and renumbered requirements rather than eliminating substantive security obligations. Some Rev 2 controls were consolidated, others were split. The net effect is a larger requirement set with clearer traceability back to NIST SP 800-53 Rev 5.

Rev 3 reorganizes the control families and introduces outcome-based language aligned to NIST SP 800-53 Rev 5. It also adds three new families not present in Rev 2: Planning (PL), System and Services Acquisition (SA), and Supply Chain Risk Management (SR). The numbering scheme changed from a domain.sequence format to a family-prefix format.

Gap analysis against Rev 3 is worthwhile today, particularly in the new SR and SA families. However, your SPRS score and C3PAO assessment remain tied to Rev 2 until the DoD formally updates the CMMC rule. Prioritize Rev 2 compliance first, then use Rev 3 as a roadmap for your next maturity cycle.

The current SPRS scoring methodology is based on Rev 2's 110 requirements. NIST and DoD have not published a Rev 3 scoring model. When the CMMC rule is updated to incorporate Rev 3, a revised scoring methodology is expected to follow. Scores submitted today use the Rev 2 framework.

Your SSP. Not a template.

1TEN generates your System Security Plan from your actual documented control implementations. C3PAO-ready.

Request a Demo