NIST finalized SP 800-171 Revision 3 in May 2024, and it is a genuine restructuring: three new requirement families, a lower headline count, and a new concept called organization-defined parameters. If you protect Controlled Unclassified Information for the Department of Defense, that news probably arrived with a question attached: does this change my CMMC assessment, and do I need to redo my work?
Short answer: not yet, and be careful about switching early. This article covers what Rev 3 actually changed, why CMMC is still assessed against Rev 2 today, what it means for your SPRS score, and how to prepare without wasting effort on a standard that is not yet the one you are measured against.
First, the answer you came for: CMMC is still on Rev 2
DFARS 252.204-7012 ties compliance to the version of NIST SP 800-171 in effect when the solicitation is issued. Once Rev 3 published, newly issued solicitations would have started pulling contractors toward Rev 3, while the CMMC program rule, drafted earlier, was still written around Rev 2. To avoid contractors implementing one revision while being assessed against another, the DoD issued a DFARS class deviation in May 2024 (Class Deviation 2024-O0013) directing contractors to keep complying with Rev 2. The deviation has no expiration date. Rev 2 remains the standard until DoD rescinds it.
One boundary to keep in mind: the class deviation governs contracts that carry the DFARS 252.204-7012 clause, meaning DoD contracts involving CUI. If your portfolio also includes non-DoD federal work, or a solicitation that specifically names Rev 3, check the clause language on each contract rather than assuming Rev 2 across the board.
The CMMC Program final rule (32 CFR Part 170, October 2024) is built on Rev 2 as well. So the number you self-assess and post to SPRS today, under DFARS 252.204-7019 and -7020, is scored against Rev 2's 110 requirements. As formal CMMC Level 2 assessments phase in, whether you self-assess or bring in a C3PAO, they are scored against Rev 2 too. Nothing about your current obligation changed when Rev 3 was published.
What actually changed in Rev 3
Rev 3 was not a light edit. NIST realigned the standard with the SP 800-53B moderate baseline, tightened the language, and reorganized how requirements are counted and assessed.
| Dimension | Rev 2 (2020) | Rev 3 (2024) |
|---|---|---|
| Requirement families | 14 | 17 (added PL, SA, SR) |
| Security requirements | 110 | 97 |
| Organization-defined parameters | None | Introduced (DoD sets the values) |
| Assessment objectives (800-171A) | 320 | 422 |
| Status for CMMC | In effect now | Future rulemaking |
The three new families are Planning (PL), System and Services Acquisition (SA), and Supply Chain Risk Management (SR). They pull in obligations that Rev 2 handled implicitly or not at all, and supply chain risk in particular is a meaningful new area for many contractors. Rev 3 also renamed the Security Assessment family to Security Assessment and Monitoring, folding in continuous monitoring, so the reorganization is not purely additive.
The biggest change: organization-defined parameters
The most consequential difference is not the family count, it is organization-defined parameters (ODPs). An ODP is the variable part of a requirement that receives a specific value during tailoring. Rev 2 leaned on vague words like "periodically." Rev 3 replaces that ambiguity with a parameter: instead of "review periodically," the requirement reads "review every [ODP] days," and someone has to fill in the number. In all, Rev 3 defines 88 organization-defined parameters across 49 of its 97 requirements.
Here is the part that matters for defense contractors: you do not choose your own ODP values. For federal CUI, the agency sets them. The DoD published its mandatory ODP values for Rev 3 in an April 2025 memo, so when Rev 3 does reach CMMC, the parameters are already defined and you implement to DoD's numbers, not your own preference. Those values are not contractually binding yet; they take force only when Rev 3 is incorporated through rulemaking, but they tell you exactly where the bar will land. On balance this is good, ambiguity is where audit findings live, but it also removes the wiggle room some organizations relied on.
What it means for your SPRS score
Today, nothing. Your SPRS score is a Rev 2 score: you start at 110 and subtract weighted point values for each unmet requirement under the DoD Assessment Methodology. (For the exact scoring mechanics, see our CMMC Level 2 and SPRS score walkthrough.)
Because Rev 3 changes the requirement set and adds ODPs, a revised assessment methodology and scoring approach will have to come with the transition. That methodology is not in effect for CMMC, so there is no official "Rev 3 SPRS score" to compute right now. The practical move is to keep your Rev 2 score current and accurate, since that is the number a contracting officer sees and an inflated score is False Claims Act exposure, not just a paperwork error.
How to prepare without wasting effort
Preparing for Rev 3 is worthwhile. Rebuilding for it today is not. The three new families are where most of the net-new work lives: Planning (PL) expects documented security and privacy plans and rules of behavior, System and Services Acquisition (SA) pushes security requirements into your acquisition process and software development lifecycle, and Supply Chain Risk Management (SR) expects a supply-chain risk management plan. SR usually carries the longest lead time, so it is the sensible place to start. The line between preparing and over-committing:
- Do read NIST's Rev 2-to-Rev 3 change analysis and the DoD's assigned ODP values, so you know where you will have to move and by how much.
- Do run a read-only Rev 3 gap assessment now, but do not re-score your SPRS against it. Map where you stand against the 97 requirements, prioritizing the new families, so the eventual transition is a checklist and not a scramble.
- Do not tear up your Rev 2 System Security Plan or re-baseline your program to Rev 3. You are assessed on Rev 2, and a premature switch creates the mismatch the class deviation exists to prevent.
- Watch the rulemaking. DoD has signaled a future amendment to 32 CFR Part 170 moving CMMC to Rev 3, but federal timelines slip, and the CMMC rule itself is phasing in over three years from its December 2024 effective date, so a Rev 3 amendment sits on top of that rather than arriving tomorrow. Act on what governs today, which is the class deviation keeping you on Rev 2.
Frequently asked questions
Is CMMC based on NIST SP 800-171 Rev 2 or Rev 3 right now?
Rev 2. In May 2024 the DoD issued a DFARS class deviation directing contractors under DFARS 252.204-7012 to keep complying with NIST SP 800-171 Revision 2 rather than the newer Revision 3. The deviation has no end date, and the CMMC Program final rule (32 CFR Part 170) is built on Rev 2, so a CMMC Level 2 assessment and your SPRS score are scored against Rev 2's 110 requirements today.
How many requirements are in NIST SP 800-171 Rev 3?
Rev 3 has 97 security requirements across 17 families, down from 110 requirements across 14 families in Rev 2. It added three families (Planning, System and Services Acquisition, and Supply Chain Risk Management) to realign with the SP 800-53B moderate baseline. The lower count is not less security: many Rev 2 requirements were withdrawn only because they were folded into other requirements or moved into the assessment procedures.
What is an organization-defined parameter (ODP)?
An ODP is the variable part of a requirement that gets a specific value assigned during tailoring, for example a review frequency or a threshold. Rev 3 replaced vague terms like "periodically" with ODPs to remove ambiguity. For defense contractors handling CUI, you do not choose your own values: the DoD published mandatory ODP values for Rev 3 in an April 2025 memo, so when Rev 3 reaches CMMC the parameters are already set.
Does Rev 3 change my SPRS score?
Not today. Your SPRS score is a Rev 2 score computed against 110 requirements under the DoD Assessment Methodology. Because Rev 3 changes the requirement set and adds ODPs, a revised scoring methodology will accompany the transition, but that is not in effect for CMMC yet. Keep your Rev 2 SPRS score current and accurate, since that is what is assessed and an inflated score carries False Claims Act exposure.
When will CMMC move to NIST SP 800-171 Rev 3?
Through future rulemaking. DoD has signaled an amendment to 32 CFR Part 170 that would move CMMC from Rev 2 to Rev 3, and it published the mandatory ODP values in April 2025 as a preparatory step. But federal rulemaking timelines routinely slip, so treat any specific date as provisional. What governs today is the May 2024 class deviation, which keeps CMMC on Rev 2 until it is rescinded.
Related reading
- CMMC Level 2: What It Demands and How to Know Where You Stand
- POA&M Template: The Fields That Matter (and a Free Tracker)
- System Security Plan (SSP) Template: Structure, Sections, and a Free Builder
- the free CMMC Level 2 SPRS calculator
References
- NIST SP 800-171 Rev 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (May 2024). doi.org/10.6028/NIST.SP.800-171r3
- NIST CSRC, Frequently Asked Questions: NIST SP 800-171 Rev. 3 and SP 800-171A Rev. 3 (family/requirement counts, assessment objectives). csrc.nist.gov
- DoD CIO, Organization-Defined Parameters for NIST SP 800-171 (April 2025). dodcio.defense.gov
- DoD Class Deviation 2024-O0013, continued use of NIST SP 800-171 Revision 2 (May 2024). acq.osd.mil
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program Final Rule (89 FR 83092, October 15, 2024). federalregister.gov