What's Happening
NIST published Revision 3 of SP 800-171 in May 2024. The updated standard expands and restructures the CUI protection requirements that underpin CMMC Level 2 — and while the DoD has not yet formally mandated Rev 3 for active CMMC assessments, the transition is coming. Defense contractors who build their compliance programs on Rev 2 alone will need to close the gap when the mandate arrives.
We started planning for this the day Rev 3 dropped. Our goal is to make the Rev 3 transition invisible to 1TEN customers — you shouldn't have to re-document your entire program from scratch because NIST restructured requirement numbering. Our job is to handle the mapping, flag what genuinely changed, and surface only the real gaps that require your attention.
What Changed in Rev 3
Revision 3 is a meaningful update — not a cosmetic refresh. The headline changes that affect DIB companies:
Requirement Count Decreased — But the Burden Didn't
Rev 3 contains 97 requirements, down from 110 in Rev 2. That reduction is real but misleading. NIST consolidated many Rev 2 requirements into broader, more comprehensive controls rather than eliminating them — 33 requirements were "withdrawn" but their substance was absorbed into surviving requirements. The net effect: fewer line items, but more detailed implementation expectations. The total number of assessment determination statements actually increased by approximately 22%, from 320 in Rev 2 to 392 in Rev 3. Rev 3 also eliminates the Rev 2 distinction between "basic" and "derived" requirements, replacing it with a single unified requirement structure derived entirely from NIST SP 800-53.
Three New Requirement Families
Rev 3 adds three security requirement families with no Rev 2 equivalent: Planning (PL), System and Services Acquisition (SA), and Supply Chain Risk Management (SR). These nine net-new requirements align Rev 3 with the SP 800-53 moderate control baseline and represent genuine gaps for most DIB companies — areas where Rev 2 documentation provides no coverage.
Restructured Numbering System
Rev 3 renumbers requirements across domains. A requirement that carried a specific identifier in Rev 2 may now appear under a different number — or have been consolidated into a different control entirely. Organizations that have built their SSP documentation around Rev 2 numbering will need cross-reference mapping to avoid assessment confusion. 1TEN will handle this automatically.
Organization-Defined Parameters (ODPs)
Rev 3 introduces 49 ODPs — specific configurable values within requirements that organizations must explicitly document. Rather than implementing a general control, you must define and record the exact parameter value your organization has chosen: the maximum failed login attempts before lockout, the minimum password length, the session timeout threshold. As of April 2025, DoD has published its own ODP values establishing the minimum acceptable settings for defense contractors, which removes ambiguity but also creates a compliance floor your configurations must meet.
What 1TEN Is Building for Rev 3
Our Rev 3 rollout isn't a content swap — it's a full platform update designed to protect the investment our customers have already made in their Rev 2 compliance documentation.
| Platform Update | What It Delivers |
|---|---|
| Updated requirement library | All 97 Rev 3 requirements mapped into the platform with domain structure, requirement text, and assessment objectives — including the three new families (PL, SA, SR) with no Rev 2 equivalent. |
| Rev 2 → Rev 3 gap analysis | A built-in tool that cross-references your existing Rev 2 documentation against Rev 3 and surfaces only the requirements that represent a genuine new gap — not a full re-documentation exercise. |
| ODP documentation interface | Guided input fields for all 49 organization-defined parameters, pre-loaded with DoD's published minimum values, with validation to ensure your configured settings meet the floor. |
| Revised SSP templates | Updated System Security Plan output that reflects Rev 3 requirement numbering and ODP documentation requirements — exportable in C3PAO-ready format. |
| Updated SPRS framework | When DoD publishes updated scoring guidance for Rev 3, 1TEN will implement the revised point weights immediately — no manual recalculation required. |
| Assessor question updates | All built-in C3PAO assessment preparation questions updated to reflect Rev 3 assessment objectives, so your interview prep stays current with what assessors are actually testing. |
What This Means for Your Program
If you are currently working toward CMMC certification under Rev 2, the most important thing to understand is that Rev 2 remains the operative standard for active assessments until DoD formally transitions. You should not pause your current certification effort waiting for Rev 3.
If your assessment is scheduled before the DoD Rev 3 mandate takes effect, proceed on Rev 2. If your assessment window falls after that mandate, or if you're planning a program now that will mature into an assessment 12–18 months from now, you should be building awareness of the Rev 3 changes into your planning.
1TEN will publish additional guidance on the DoD transition timeline as it becomes clearer. We'll also notify all customers when the Rev 3 update goes live in the platform and provide specific guidance on what actions — if any — you need to take based on your current compliance posture.