Platform Update

NIST SP 800-171 Rev 3
Coming to 1TEN by July 31, 2026

We are actively building out support for the updated NIST SP 800-171 Revision 3 requirements inside the 1TEN platform. The rollout will be complete and fully available to customers by July 31, 2026.

Published: January 18, 2026

Updated: March 15, 2026

What's Happening

NIST published Revision 3 of SP 800-171 in May 2024. The updated standard expands and restructures the CUI protection requirements that underpin CMMC Level 2 — and while the DoD has not yet formally mandated Rev 3 for active CMMC assessments, the transition is coming. Defense contractors who build their compliance programs on Rev 2 alone will need to close the gap when the mandate arrives.

We started planning for this the day Rev 3 dropped. Our goal is to make the Rev 3 transition invisible to 1TEN customers — you shouldn't have to re-document your entire program from scratch because NIST restructured requirement numbering. Our job is to handle the mapping, flag what genuinely changed, and surface only the real gaps that require your attention.

Target Date
Full NIST SP 800-171 Rev 3 support in 1TEN will be available by July 31, 2026. This includes updated requirement mappings, revised assessment questions, updated SSP templates, and a Rev 2 → Rev 3 gap analysis tool built into the platform.

What Changed in Rev 3

Revision 3 is a meaningful update — not a cosmetic refresh. The headline changes that affect DIB companies:

Requirement Count Decreased — But the Burden Didn't

Rev 3 contains 97 requirements, down from 110 in Rev 2. That reduction is real but misleading. NIST consolidated many Rev 2 requirements into broader, more comprehensive controls rather than eliminating them — 33 requirements were "withdrawn" but their substance was absorbed into surviving requirements. The net effect: fewer line items, but more detailed implementation expectations. The total number of assessment determination statements actually increased by approximately 22%, from 320 in Rev 2 to 392 in Rev 3. Rev 3 also eliminates the Rev 2 distinction between "basic" and "derived" requirements, replacing it with a single unified requirement structure derived entirely from NIST SP 800-53.

Three New Requirement Families

Rev 3 adds three security requirement families with no Rev 2 equivalent: Planning (PL), System and Services Acquisition (SA), and Supply Chain Risk Management (SR). These nine net-new requirements align Rev 3 with the SP 800-53 moderate control baseline and represent genuine gaps for most DIB companies — areas where Rev 2 documentation provides no coverage.

Restructured Numbering System

Rev 3 renumbers requirements across domains. A requirement that carried a specific identifier in Rev 2 may now appear under a different number — or have been consolidated into a different control entirely. Organizations that have built their SSP documentation around Rev 2 numbering will need cross-reference mapping to avoid assessment confusion. 1TEN will handle this automatically.

Organization-Defined Parameters (ODPs)

Rev 3 introduces 49 ODPs — specific configurable values within requirements that organizations must explicitly document. Rather than implementing a general control, you must define and record the exact parameter value your organization has chosen: the maximum failed login attempts before lockout, the minimum password length, the session timeout threshold. As of April 2025, DoD has published its own ODP values establishing the minimum acceptable settings for defense contractors, which removes ambiguity but also creates a compliance floor your configurations must meet.

Assessment Impact
When DoD formally adopts Rev 3 for CMMC assessments, C3PAO assessors will assess against Rev 3 requirements and verify ODP values against DoD's published minimums. Organizations that have only documented Rev 2 compliance will need to address the three new requirement families and document all applicable ODPs before their assessment.

What 1TEN Is Building for Rev 3

Our Rev 3 rollout isn't a content swap — it's a full platform update designed to protect the investment our customers have already made in their Rev 2 compliance documentation.

Platform Update What It Delivers
Updated requirement library All 97 Rev 3 requirements mapped into the platform with domain structure, requirement text, and assessment objectives — including the three new families (PL, SA, SR) with no Rev 2 equivalent.
Rev 2 → Rev 3 gap analysis A built-in tool that cross-references your existing Rev 2 documentation against Rev 3 and surfaces only the requirements that represent a genuine new gap — not a full re-documentation exercise.
ODP documentation interface Guided input fields for all 49 organization-defined parameters, pre-loaded with DoD's published minimum values, with validation to ensure your configured settings meet the floor.
Revised SSP templates Updated System Security Plan output that reflects Rev 3 requirement numbering and ODP documentation requirements — exportable in C3PAO-ready format.
Updated SPRS framework When DoD publishes updated scoring guidance for Rev 3, 1TEN will implement the revised point weights immediately — no manual recalculation required.
Assessor question updates All built-in C3PAO assessment preparation questions updated to reflect Rev 3 assessment objectives, so your interview prep stays current with what assessors are actually testing.

What This Means for Your Program

If you are currently working toward CMMC certification under Rev 2, the most important thing to understand is that Rev 2 remains the operative standard for active assessments until DoD formally transitions. You should not pause your current certification effort waiting for Rev 3.

If your assessment is scheduled before the DoD Rev 3 mandate takes effect, proceed on Rev 2. If your assessment window falls after that mandate, or if you're planning a program now that will mature into an assessment 12–18 months from now, you should be building awareness of the Rev 3 changes into your planning.

1TEN will publish additional guidance on the DoD transition timeline as it becomes clearer. We'll also notify all customers when the Rev 3 update goes live in the platform and provide specific guidance on what actions — if any — you need to take based on your current compliance posture.

For Companies Starting Now
If you're beginning a CMMC compliance program today, 1TEN will guide you through Rev 2 requirements — which remain current — while flagging areas where Rev 3 introduces new obligations. By the time your assessment date arrives, you'll be prepared for whichever revision the assessor is operating under.

Frequently Asked Questions

DoD has not yet published a formal transition date. Rev 2 remains the operative standard for current CMMC assessments. We expect DoD to publish transition guidance once the CMMC rule implementation matures and assessment volume increases. 1TEN will communicate directly with customers when that timeline is confirmed.
Most of it, yes. The majority of Rev 2 requirements map directly to Rev 3 equivalents — you're not starting over. The 1TEN gap analysis tool will identify exactly which of your existing implementation statements satisfy Rev 3 requirements as-is, and which require supplementation to address the new ODPs or the three net-new requirement families.
ODPs are specific configurable values within a requirement — for example, the maximum number of failed login attempts before account lockout, or the minimum password length. Rev 3 has 49 ODPs. DoD published its minimum ODP values in April 2025, so the floor is now defined. You must document your chosen values in your SSP and assessors will verify they meet or exceed DoD's minimums.
The current SPRS methodology is built around Rev 2's 110 requirements and the associated point weights. DoD will need to publish updated SPRS scoring guidance that reflects Rev 3's restructured requirement set. 1TEN will implement those updates immediately when published.
Based on the current DoD implementation pace, we believe yes — July 31 positions our customers well ahead of any likely formal mandate. That said, we're tracking the regulatory timeline closely and will accelerate our rollout if needed. If you have specific assessment timing concerns, contact us directly.

Prepare for assessment.

1TEN structures your compliance posture across all 14 CMMC domains and produces the evidence package your C3PAO will request.

Request a Demo