The Short Answer
NIST SP 800-171 Rev 3 was finalized in May 2024. It replaces the 110-requirement, 14-family structure of Rev 2 with a 125-requirement framework organized across 17 families. Three families are new. The numbering scheme changed. The underlying security intent largely did not.
For CMMC Level 2 contractors, the practical urgency is limited right now. CMMC 2.0 remains anchored to Rev 2. C3PAO assessments are conducted against Rev 2's controls, and SPRS scores are calculated using the Rev 2 methodology. Rev 3 becomes operationally relevant when the DoD issues a CMMC rule revision that formally adopts it, and that update has not been finalized as of this writing.
That said, contractors who ignore Rev 3 entirely are taking a risk. The new requirements in the SR and SA families address supply chain and acquisition controls that assessors will eventually test. Organizations that begin gap analysis now will face a shorter remediation window when the transition arrives.
Structural Changes: What NIST Reorganized
Rev 2 organized its 110 requirements across 14 control families, each identified by a two-letter abbreviation. Rev 3 retains most of those families but adds three new ones and renames the numbering convention. The table below compares the two versions at the structural level.
| Attribute | Rev 2 | Rev 3 |
|---|---|---|
| Publication date | February 2020 | May 2024 |
| Total requirements | 110 | 125 |
| Control families | 14 | 17 |
| Numbering format | Domain.Sequence (e.g., 3.1.1) | Family prefix (e.g., AC.01) |
| NIST SP 800-53 alignment | Rev 4 | Rev 5 |
| CMMC Level 2 basis | Yes (current rule) | Not yet (pending DoD update) |
| SPRS scoring model | 110-requirement model, published | Not yet published |
| New control families | None | PL (Planning), SA (System and Services Acquisition), SR (Supply Chain Risk Management) |
Requirement Delta by Family
The 15 additional requirements in Rev 3 are not evenly distributed. The three new families account for most of the increase. Several existing families also saw requirements added or split into more granular controls. The table below shows the count change for each family, organized by Rev 2 family name where applicable.
| Code | Family | Rev 2 Count | Rev 3 Count |
|---|---|---|---|
| AC | Access Control | 22 | 25 |
| AT | Awareness and Training | 3 | 3 |
| AU | Audit and Accountability | 9 | 9 |
| CA | Assessment, Authorization, and Monitoring | 9 | 9 |
| CM | Configuration Management | 9 | 11 |
| IA | Identification and Authentication | 11 | 12 |
| IR | Incident Response | 3 | 3 |
| MA | Maintenance | 6 | 6 |
| MP | Media Protection | 9 | 8 |
| PE | Physical Protection | 6 | 6 |
| PL | Planning (new in Rev 3) | 0 | 2 |
| PS | Personnel Security | 2 | 2 |
| RA | Risk Assessment | 3 | 5 |
| SA | System and Services Acquisition (new in Rev 3) | 0 | 4 |
| SC | System and Communications Protection | 16 | 14 |
| SI | System and Information Integrity | 7 | 6 |
| SR | Supply Chain Risk Management (new in Rev 3) | 0 | 7 |
The Three New Families in Rev 3
The most substantive additions in Rev 3 are the three families that did not exist in Rev 2. Each addresses a gap that has grown more visible in DoD supply chain incidents over the past several years.
| Family | What It Covers | Assessment Relevance |
|---|---|---|
| PL Planning |
Requires a formal system security plan (SSP) and rules of behavior for users with access to CUI. Two requirements total. | Largely codifies what most contractors already produce for C3PAO assessments. The SSP requirement under PL maps to what was previously implicit in CA under Rev 2. |
| SA System and Services Acquisition |
Addresses security requirements in acquisitions, developer testing, and supply chain protection for software and services. Four requirements. | Contractors who purchase commercial software or outsource development will need documented security requirements for those vendors. This is a new documentation burden for many mid-sized prime contractors. |
| SR Supply Chain Risk Management |
Covers CUI protection in the supply chain, vendor risk assessment, and component authenticity. Seven requirements. The largest new family by count. | The SR family directly targets the risk that CUI flows to subcontractors who are not assessed. Primes with large sub-tier supplier networks face the heaviest lift here. |
What This Means for CMMC Level 2
CMMC 2.0 Level 2 currently requires compliance with all 110 requirements in NIST SP 800-171 Rev 2. That is the version your C3PAO assessor will test against. It is also the version that determines your SPRS score submitted in the Supplier Performance Risk System.
The DoD has publicly stated its intention to align a future CMMC revision to Rev 3, but the specific timeline and any transition provisions for contractors who achieved Rev 2 certification have not been released. Given that CMMC rulemaking moves slowly, most contractors pursuing certification in 2025 will be assessed against Rev 2 regardless of what Rev 3 adds.
One area where Rev 3 already matters: contract language. Some DoD agencies and a growing number of prime contractors are beginning to reference Rev 3 in their own security requirements clauses. If a contract clause cites Rev 3 explicitly, that version governs your obligations under that contract regardless of where the formal CMMC rule stands.
How to Prepare for the Transition
The gap between Rev 2 compliance and Rev 3 compliance is manageable with a structured approach. The organizations that will struggle are those that treat Rev 3 as a distant problem and make no effort to inventory the delta before the DoD transition date is announced.
| Action | What It Involves | Priority |
|---|---|---|
| Rev 2 certification first | Complete your CMMC Level 2 assessment or maintain your self-attestation. Rev 3 does not replace this obligation today. | Immediate |
| Gap analysis against SR family | Map your current supply chain security practices against the seven SR requirements. Most organizations have informal processes that do not yet produce documented artifacts. | High |
| Gap analysis against SA family | Review contracts with software vendors and development partners. Identify where you are not currently specifying security requirements in acquisition. | High |
| Renumber your SSP tracking | Build a crosswalk table mapping Rev 2 control numbers (3.x.x) to Rev 3 prefixes (XX.XX). Assessors will eventually expect this when the transition occurs. | Medium |
| Review modified AC and IA language | Even in families with unchanged counts, requirement text shifted toward outcomes-based language. Verify your implementation statements still satisfy the revised wording. | Medium |
| Monitor DoD CMMC updates | Watch for a CMMC rule revision that formally adopts Rev 3. The transition timeline will drive your implementation deadline. | Ongoing |
Tracking the Transition with 1TEN
Managing compliance across two active versions of 800-171 creates a real documentation problem. Your current SPRS score, your C3PAO artifacts, and your forward-looking Rev 3 gap analysis need to live in the same place without creating confusion about which version each control maps to. 1TEN is built for exactly this kind of structured compliance tracking. The platform maintains version-aware control libraries, flags gaps by domain and priority, and produces the artifact sets assessors expect. When the DoD formalizes the Rev 3 transition, the crosswalk is already built in.
Frequently Asked Questions
Not immediately. CMMC 2.0 Level 2 is currently anchored to NIST SP 800-171 Rev 2. The DoD has signaled that a future CMMC rule update will align to Rev 3, but no effective date has been finalized. Contractors assessed today are evaluated against Rev 2's 110 requirements.
Rev 3 increases the requirement count from 110 to 125. The additions are concentrated in areas such as supply chain risk management, planning, and system and services acquisition. Some Rev 2 requirements were also restructured or split into more granular controls.
Rev 3 reorganized and renumbered requirements rather than eliminating substantive security obligations. Some Rev 2 controls were consolidated, others were split. The net effect is a larger requirement set with clearer traceability back to NIST SP 800-53 Rev 5.
Rev 3 reorganizes the control families and introduces outcome-based language aligned to NIST SP 800-53 Rev 5. It also adds three new families not present in Rev 2: Planning (PL), System and Services Acquisition (SA), and Supply Chain Risk Management (SR). The numbering scheme changed from a domain.sequence format to a family-prefix format.
Gap analysis against Rev 3 is worthwhile today, particularly in the new SR and SA families. However, your SPRS score and C3PAO assessment remain tied to Rev 2 until the DoD formally updates the CMMC rule. Prioritize Rev 2 compliance first, then use Rev 3 as a roadmap for your next maturity cycle.
The current SPRS scoring methodology is based on Rev 2's 110 requirements. NIST and DoD have not published a Rev 3 scoring model. When the CMMC rule is updated to incorporate Rev 3, a revised scoring methodology is expected to follow. Scores submitted today use the Rev 2 framework.