to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

Rev. 2 versus Rev. 3: status, differences, and what to do

A reader who decides Rev. 3 applies to them today will spend real money for nothing. So the status comes first, the differences second, the advice third, and the full catalog comparison last.

1. Status: what your contract requires today

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

RevisionPublishedStatus in the Bedrock catalogWhat it means
NIST SP 800-171 Rev 2SP 800-171r2 (February 2020)activeThe revision DFARS 252.204-7012 and 32 CFR 170 point at. The one you are assessed against and score in SPRS.
NIST SP 800-171 Rev 3SP 800-171r3 (May 2024)previewPublished by NIST. Not adopted for contractual purposes. No DoD scoring model exists for it.

Where things stand, as of 2026-09-08

  • A DoD class deviation keeps Rev. 2 in force for contracts carrying DFARS 252.204-7012. Until that deviation changes, Rev. 2 is the assessed baseline.
  • The CMMC Phase 2 suspension of 13 July 2026 paused the expansion of third-party assessments and opened a program review. Interim guidance confirmed Rev. 2 as the active baseline for self-assessments and contract requirements. See the suspension page.
  • The Department has issued its Rev. 3 organization-defined parameter values. That is preparation for an eventual move, and it lets a contractor who wants to dual-track record the values now. It does not make Rev. 3 a requirement.
  • Outside DoD, the FAR CUI proposed rule (public comment closed 23 July 2026) points civilian agency contracts at Rev. 3. A contractor holding both civilian and defense CUI work may face two baselines once that rule is final. This site covers the defense side only.

Bedrock CMMC carries both revisions side by side and shows this comparison against your own package, with each requirement's current status beside its Rev. 3 successor; that is where the status above is read from.

2. What actually changed

Counts and classes are NIST's own, from its official Rev. 2 to Rev. 3 change analysis, as carried in the Bedrock mapping. Two workbook errata are corrected there and documented.

  • 18 No significant change · Carries as-is
  • 14 Minor change · Review
  • 46 Significant change · Rework
  • 19 New requirement · New
  • 32 Withdrawn · Retired

129 rows: the 110 Rev. 2 requirements plus the 19 requirements that are new in Rev. 3. The second label on each class is the planning bucket Bedrock uses: what a contractor would do with the requirement at adoption.

Structure

  • Rev. 2 has 110 requirements in 14 families. Rev. 3 has 97 active requirements in 17 families, with 33 numbered slots marked withdrawn.
  • Three families are new: PL Planning, SA System and Services Acquisition, SR Supply Chain Risk Management. Security Assessment becomes Security Assessment and Monitoring.
  • Rev. 3 breaks its requirements into 422 determination statements (assessment objectives) in NIST SP 800-171A Rev. 3.
  • Rev. 3 numbering is zero-padded (03.05.03 for 3.5.3) and a number can change meaning: 03.11.04 is a new requirement, Risk Response, not a renumbered 3.11.4. Never assume a match by number.

Organization-defined parameters

Rev. 3 introduces 88 organization-defined parameters: blanks such as a time period or a review frequency that the organization fills in. Each one is itself assessable in 800-171A Rev. 3, because defining the value is a determination. Rev. 2 has none. In the comparison below, rows that gain parameters carry an ODP marker, and each requirement's page shows the blanks highlighted in the Rev. 3 text.

The 6 Rev. 2 requirements with no Rev. 3 successor

3. What a contractor should do now

Durable regardless of adoption

  • Know your boundary. Where CUI lives does not change between revisions, and every reworded requirement still attaches to the same systems.
  • Keep the system security plan true. Rev. 3 keeps it (as 03.15.02) and adds a review frequency; a current, accurate plan carries over.
  • Collect evidence per assessment objective, not per requirement. Rev. 3 has more objectives, but they cover the same facts, and objective-level evidence re-maps; requirement-level narrative does not.
  • Close the five-point items. MFA for all users, FIPS-validated cryptography, logging, flaw remediation and incident response are the substance of both revisions, and they carry the same weight in the score you post today.
  • Note the choices Rev. 3 would ask you to make (its parameters) where you already make them: account inactivity periods, review frequencies, lockout thresholds. Writing down what you do now costs nothing and answers the question later.

Premature until adoption

  • Renumbering policies, procedures or the system security plan to Rev. 3 identifiers. Your assessor works from Rev. 2 and so does SPRS.
  • Re-scoring against Rev. 3. There is no DoD scoring model for it, so any number you produce is invented.
  • Buying tooling or services sold on Rev. 3 readiness as if it were a deadline. There is no deadline until a deviation or rule sets one.
  • Treating a withdrawn Rev. 2 requirement as gone. Until adoption it is still assessed.

4. Has anything else changed?

Readers who arrive here usually also want to know what the Phase 2 suspension did and did not change. That has its own page: the Phase 2 suspension. The short answer is the same as this page's: the clause, the standard, the score and the affirmation are where they were.

Catalog comparison, Rev. 2 → Rev. 3

Every Rev. 2 requirement beside its Rev. 3 successor, by family, with NIST's change class and Bedrock's planning bucket. Open a row for NIST's note, or the requirement for the full side-by-side and the word-level diff.

AC Access Control 6196
3.1.1 Know who and what is allowed on your systems 03.01.01 Account Management Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for account management
  • Added new ODP: time period to notify personnel/roles when accounts are no longer required
  • Added new ODP: time period to notify personnel/roles when users terminated/transferred
  • Added new ODP: time period to notify personnel/roles when system usage or need-to-know changes for an indivdual
  • Added new ODP: time period of inactivity or circumstances in which users are required to log out
  • Updated discussion differentiating 03.01.01 with 03.01.10

Side by side and word by word for 3.1.1

3.1.2 Limit what each person can do once inside 03.01.02 Access Enforcement Carries as-is
  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Rephrased for clarity; outcome remains unchanged

Side by side and word by word for 3.1.2

3.1.3 Control where CUI is allowed to travel 03.01.03 Information Flow Enforcement Carries as-is
  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Rephrased for clarity; outcome remains unchanged
  • Discussion updated to include additional guidance on the relationship between 03.01.03 and 03.12.05

Side by side and word by word for 3.1.3

3.1.4 Split duties so one person cannot do everything alone 03.01.04 Separation of Duties Carries as-is
  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Separated into two parts (a, b) needed for achieve outcome, rephrased for clarity; outcome remains unchanged

Side by side and word by word for 3.1.4

3.1.5 Give people the least access they need 03.01.05 Least Privilege Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks to implement least privilege
  • Added new ODP: security functions in which to authorize access
  • Added new ODP: security-relevant informationin which to authorize access
  • Added new ODP: frequency to review privileges assigned to roles/classes of users

Side by side and word by word for 3.1.5

3.1.6 Do ordinary work from ordinary accounts 03.01.06 Least Privilege – Privileged Accounts Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks to implement least privilege for privileged accounts
  • Added new ODP: personnel or roles to restrict privileged accounts to
  • Updated discussion for improved flow with requirement and clarity

Side by side and word by word for 3.1.6

3.1.7 Stop and log privileged actions by non-admins 03.01.07 Least Privilege – Privileged Functions Carries as-is
  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Separated into two parts (a, b) needed for achieve outcome, rephrased for clarity; outcome remains unchanged

Side by side and word by word for 3.1.7

3.1.8 Lock accounts after repeated failed logins 03.01.08 Unsuccessful Logon Attempts Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Added new ODP: number of consecutive invalid login attempts
  • Added new ODP: selection of one or more options (lock account/note for time period, lock account/note until released by administrator, delay next logon prompt, notify system administrator, take other action) when maximum number of unsuccesfful login attempts is exceeded
  • Discussion updated to clarify and provide guidance on other organizaiton-defined actions

Side by side and word by word for 3.1.8

3.1.9 Show a use notice at sign-in 03.01.09 System Use Notification Carries as-is
  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Rephrased for clarity; outcome remains unchanged
  • Discussion updated with minor clarifications, including scope/applicability

Side by side and word by word for 3.1.9

3.1.10 Lock idle screens 03.01.10 Device Lock Review ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks to implement device lock
  • Terminology changed from "session lock" to "device lock"
  • Added new ODP: select one or more ways to initiate device lock
  • Added new ODP: time period to initiate device lock (if selected)

Side by side and word by word for 3.1.10

3.1.11 End sessions automatically 03.01.11 Session Termination Carries as-is ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Added new ODP: conditions or trigger events for session termination

Side by side and word by word for 3.1.11

3.1.12 Watch and control remote access 03.01.12 Remote Access Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks to monitor and control remote access
  • Includes withdrawn requirements: 03.01.13, 03.01.14, 03.01.15
  • Updated discussion for clarity and flow of guidance

Side by side and word by word for 3.1.12

3.1.13 Encrypt remote access 03.13.08 Transmission and Storage Confidentiality Retired
  • Addressed by 03.13.08.

Incorporated into 03.13.08.

Side by side and word by word for 3.1.13

3.1.14 Funnel remote access through known entry points 03.01.12 Remote Access Retired
  • Incorporated into 03.01.12.

Incorporated into 03.01.12.

Side by side and word by word for 3.1.14

3.1.15 Approve remote admin work in advance 03.01.12 Remote Access Retired
  • Incorporated into 03.01.12.

Incorporated into 03.01.12.

Side by side and word by word for 3.1.15

3.1.16 Approve wireless before it connects 03.01.16 Wireless Access Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks to secure wireless access, including protecting wireless access using authentication and encryption
  • Includes withdrawn requirement: 03.01.17

Side by side and word by word for 3.1.16

3.1.17 Protect wireless with authentication and encryption 03.01.16 Wireless Access Retired
  • Incorporated into 03.01.16.

Incorporated into 03.01.16.

Side by side and word by word for 3.1.17

3.1.18 Control which mobile devices connect 03.01.18 Access Control for Mobile Devices Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks to implement access control for mobile devices
  • Includes withdrawn requirement: 03.01.19
  • Updated discussion to clarify "container-based encryption"

Side by side and word by word for 3.1.18

3.1.19 Encrypt CUI on mobile devices 03.01.18 Access Control for Mobile Devices Retired
  • Incorporated into 03.01.18.

Incorporated into 03.01.18.

Side by side and word by word for 3.1.19

3.1.20 Verify and limit outside systems 03.01.20 Use of External Systems Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks on use of external systems
  • Added new ODP: terms, conditions, and requirements to be satisfied on external systems
  • Includes withdrawn requirement: 03.01.21

Side by side and word by word for 3.1.20

3.1.21 Limit portable storage on outside systems 03.01.20 Use of External Systems Retired
  • Incorporated into 03.01.20.

Incorporated into 03.01.20.

Side by side and word by word for 3.1.21

3.1.22 Review what goes on public sites 03.01.22 Publicly Accessible Content Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks to manage publicly accessible content

Side by side and word by word for 3.1.22

AT Awareness and Training 21
3.2.1 Make sure people know the risks 03.02.01 Literacy Training and Awareness Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for literacy training and awareness
  • Added new ODP: frequency after intial training to provide security literacy training to users
  • Added new ODP: events that necessitate re-taking training
  • Added new ODP: frequency to update training content
  • Added new ODP: events that necessitate updating training
  • Includes withdrawn requirement: 03.02.01

Side by side and word by word for 3.2.1

3.2.2 Train people for the security duties they hold 03.02.02 Role-Based Training Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for role based training
  • Added new ODP: frequency to provide role-based training after initial training
  • Added new ODP: events that require providing role-based training
  • Added new ODP: frequency to update training
  • Added new ODP: events that necessitate updating training

Side by side and word by word for 3.2.2

3.2.3 Cover insider threat 03.02.01 Literacy Training and Awareness Retired
  • Incorporated into 03.02.01.

Incorporated into 03.02.01.

Side by side and word by word for 3.2.3

AU Audit and Accountability 81
3.3.1 Keep logs, and keep them long enough 03.03.01 Event Logging Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for event logging
  • Added new ODP: events types to log
  • Added new ODP: frequency to review and update event types selected for logging

Side by side and word by word for 3.3.1

3.3.2 Tie actions to individuals 03.03.02 Audit Record Content Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for audit record content

Side by side and word by word for 3.3.2

3.3.3 Revisit what you log 03.03.03 Audit Record Generation Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for audit records generation and retention

Side by side and word by word for 3.3.3

3.3.4 Get told when logging breaks 03.03.04 Response to Audit Logging Process Failures Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks to respond to audit logging failures
  • Added new ODP: time period to alert personnel/roles
  • Added new ODP: additional action(s) to take in the event of audit logging failure

Side by side and word by word for 3.3.4

3.3.5 Correlate logs across systems 03.03.05 Audit Record Review, Analysis, and Reporting Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for audit record review, analysis and reporting
  • Added new ODP: frequency to review and analyze system audit records

Side by side and word by word for 3.3.5

3.3.6 Be able to search and report on logs 03.03.06 Audit Record Reduction and Report Generation Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for audit record reduction and report generation

Side by side and word by word for 3.3.6

3.3.7 Synchronize clocks 03.03.07 Time Stamps Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for time stamps
  • Added new ODP: granularity of time measurement

Side by side and word by word for 3.3.7

3.3.8 Protect the logs themselves 03.03.08 Protection of Audit Information Rework
  • New security requirement title
  • Includes withdrawn requirement: 03.03.09

Side by side and word by word for 3.3.8

3.3.9 Restrict who manages logging 03.03.08 Protection of Audit Information Retired
  • Incorporated into 03.03.08.

Incorporated into 03.03.08.

Side by side and word by word for 3.3.9

CM Configuration Management 11532
3.4.1 Know what you have and how it is set up 03.04.01 Baseline Configuration Review ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for implementing a baseline configuration
  • Added new ODP: frequency to review and update baseline configuration

Side by side and word by word for 3.4.1

3.4.2 Enforce your settings 03.04.02 Configuration Settings Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for implementing configuration settings
  • Added new ODP: configuration settings

Side by side and word by word for 3.4.2

3.4.3 Track changes 03.04.03 Configuration Change Control Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for implementing configuration change control
  • Updated discussion to show relationship to 03.04.04

Side by side and word by word for 3.4.3

3.4.4 Think before you change 03.04.04 Impact Analyses Rework
  • New security requirement title
  • Added part b. to verify the security requirements continue to be satisfied.
  • Updated discussion to show relationship to 03.04.03

Side by side and word by word for 3.4.4

3.4.5 Restrict who can change what 03.04.05 Access Restrictions for Change Carries as-is
  • New security requirement title

Side by side and word by word for 3.4.5

3.4.6 Turn off what you do not need 03.04.06 Least Functionality Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for implementing least functionality
  • Added new ODP: prohibited or restricted functions, system ports, protocols, software, and/or services
  • Added new ODP: frequency to review system for unneccesary or nonsecure functions, ports, protocols, connections, and services
  • Includes withdrawn requirement: 03.04.07

Side by side and word by word for 3.4.6

3.4.7 Close unnecessary ports and services 03.04.06 Least Functionality
03.04.08 Authorized Software – Allow by Exception
Retired
  • Incorporated into 03.04.06 and 03.04.08.

Incorporated into 03.04.06, 03.04.08.

Side by side and word by word for 3.4.7

3.4.8 Decide what software may run 03.04.08 Authorized Software – Allow by Exception Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for implementing allow by exception policy for authorized software
  • Added new ODP: frequency to review and update authorized software programs

Side by side and word by word for 3.4.8

3.4.9 Control what users install 03.01.05 Least Privilege
03.01.06 Least Privilege – Privileged Accounts
03.01.07 Least Privilege – Privileged Functions
03.04.08 Authorized Software – Allow by Exception
03.12.03 Continuous Monitoring
Retired
  • Addressed by 03.01.05, 03.01.06, 03.01.07, 03.04.08, and 03.12.03.

Incorporated into 03.01.05, 03.01.06, 03.01.07, 03.04.08, 03.12.03.

Side by side and word by word for 3.4.9

03.04.10 System Component Inventory New ODP
  • New security requirement based on CM-08 and CM-08(01) (SP 800-53, Revision 5).
  • Added new ODP: frequency to review and update system component inventory

New in Rev. 3; no Rev. 2 counterpart to compare.

03.04.11 Information Location New
  • New security requirement based on CM-12 (SP 800-53, Revision 5) - newly added to the SP 800-53B moderate baseline

New in Rev. 3; no Rev. 2 counterpart to compare.

03.04.12 System and Component Configuration for High-Risk Areas New ODP
  • New security requirement based on CM-02(07) (SP 800-53, Revision 5).- newly added to the SP 800-53B moderate baseline

New in Rev. 3; no Rev. 2 counterpart to compare.

IA Identification and Authentication 22314
3.5.1 Give every user, process, and device an identity 03.05.01 User Identification and Authentication Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for user identification, authentication, and re-authentication
  • Added new ODP: circumstances or situations requiring re-authentication

Side by side and word by word for 3.5.1

3.5.2 Prove those identities 03.05.02 Device Identification and Authentication Review ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks device identification and authentication
  • Added new ODP: devices or types of devices to uniquely identify and authenticate

Side by side and word by word for 3.5.2

3.5.3 Require multi-factor authentication 03.05.03 Multi-Factor Authentication Review
  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Change in applicability to all system accounts

Side by side and word by word for 3.5.3

3.5.4 Use replay-resistant authentication 03.05.04 Replay-Resistant Authentication Carries as-is
  • New security requirement title
  • Aligned with SP 800-53, Rev 5

Side by side and word by word for 3.5.4

3.5.5 Do not recycle identifiers 03.05.05 Identifier Management Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for identifier management
  • Added new ODP: time period to prevent reuse of identifiers
  • Added new ODP: characteristic identifying individual status

Side by side and word by word for 3.5.5

3.5.6 Disable dormant accounts Retired, no successor Retired
  • Consistency with SP 800-53.

Side by side and word by word for 3.5.6

3.5.7 Set password rules 03.05.07 Password Management Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for password management
  • Incorporates withdrawn requirements: 03.05.07, 03.05.09, 03.05.10
  • Added new ODP: frequency to update list of commonly-used, expected, or compromised passwords
  • Added new ODP: composition and complexity rules

Side by side and word by word for 3.5.7

3.5.8 Block password reuse Retired, no successor Retired
  • Consistency with SP 800-53.

Side by side and word by word for 3.5.8

3.5.9 Force a change after a temporary password Retired, no successor Retired
  • Consistency with SP 800-53.

Side by side and word by word for 3.5.9

3.5.10 Never store or send passwords in the clear 03.05.07 Password Management Retired
  • Incorporated into 03.05.07.

Incorporated into 03.05.07.

Side by side and word by word for 3.5.10

3.5.11 Hide password entry 03.05.11 Authentication Feedback Carries as-is
  • New security requirement title

Side by side and word by word for 3.5.11

03.05.12 Authenticator Management New ODP
  • New security requirement based on IA-05(06) (SP 800-53, Revision 5).
  • Added new ODP: frequency to change or refresh authenticators
  • Added new ODP: events to require a change or refresh of authenticators

New in Rev. 3; no Rev. 2 counterpart to compare.

IR Incident Response 122
3.6.1 Have an incident response capability that works 03.06.01 Incident Handling Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for an incident response plan and handling
  • Addresses implementation of incident handling capability and development/update of the incident response plan

Side by side and word by word for 3.6.1

3.6.2 Track and report incidents 03.06.02 Incident Monitoring, Reporting, and Response Assistance Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for incident monitoring, reporting and response assistance
  • Added new ODP: authorities to report incident information to
  • Added requirement item for incident response support resource (part d)

Side by side and word by word for 3.6.2

3.6.3 Test the plan 03.06.03 Incident Response Testing Review ODP
  • New security requirement title
  • Added new ODP: frequency to test effectiveness of incident response capability

Side by side and word by word for 3.6.3

03.06.04 Incident Response Training New ODP
  • New security requirement based on IR-02 (SP 800-53, Revision 5).
  • Added new ODP: time period to provide incident response training for new role/access
  • Added new ODP: frequency to provide incident response training after initial training
  • Added new ODP: frequency to review and update training content
  • Added new ODP: events that require an update to incident response training content

New in Rev. 3; no Rev. 2 counterpart to compare.

03.06.05 Incident Response Plan New
  • New security requirement based on IR-08 (SP 800-53, Revision 5)

New in Rev. 3; no Rev. 2 counterpart to compare.

MA Maintenance 123
3.7.1 Maintain your systems Retired, no successor Retired
3.7.2 Control maintenance tools and who uses them 03.07.04 Maintenance Tools
03.07.06 Maintenance Personnel
Retired
  • Incorporated into 03.07.04 and 03.07.06.

Incorporated into 03.07.04, 03.07.06.

Side by side and word by word for 3.7.2

3.7.3 Wipe gear before it leaves 03.08.03 Media Sanitization Retired
  • Incorporated into 03.08.03.

Incorporated into 03.08.03.

Side by side and word by word for 3.7.3

3.7.4 Scan maintenance media 03.07.04 Maintenance Tools Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for maintenance tools
  • Includes withdrawn requirement: 03.07.02

Side by side and word by word for 3.7.4

3.7.5 Require MFA for remote maintenance, and hang up after 03.07.05 Nonlocal Maintenance Review
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for nonlocal maintenance

Side by side and word by word for 3.7.5

3.7.6 Escort uncleared maintenance staff 03.07.06 Maintenance Personnel Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for security related to maintenance personnel
  • Includes withdrawn requirement: 03.07.02

Side by side and word by word for 3.7.6

MP Media Protection 432
3.8.1 Protect media holding CUI 03.08.01 Media Storage Carries as-is
  • New security requirement title

Side by side and word by word for 3.8.1

3.8.2 Limit who can reach CUI on media 03.08.02 Media Access Carries as-is
  • New security requirement title

Side by side and word by word for 3.8.2

3.8.3 Destroy or wipe media properly 03.08.03 Media Sanitization Carries as-is
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for media access, but outcome and implementation unchanged
  • Incorporates withdrawn requirement: 03.07.03

Side by side and word by word for 3.8.3

3.8.4 Mark media 03.08.04 Media Marking Carries as-is
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for media marking

Side by side and word by word for 3.8.4

3.8.5 Control media in transit 03.08.05 Media Transport Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for media transport; adds new requirement item to document activities associated with the transport of system media that contains CUI

Side by side and word by word for 3.8.5

3.8.6 Encrypt media in transit 03.13.08 Transmission and Storage Confidentiality Retired
  • Incorporated into 03.13.08.

Incorporated into 03.13.08.

Side by side and word by word for 3.8.6

3.8.7 Control removable media 03.08.07 Media Use Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for media use
  • Added new ODP: removeable system media that are restricted or prohibited

Side by side and word by word for 3.8.7

3.8.8 No anonymous USB drives 03.08.07 Media Use Retired
  • Incorporated into 03.08.07.

Incorporated into 03.08.07.

Side by side and word by word for 3.8.8

3.8.9 Protect your backups 03.08.09 System Backup – Cryptographic Protection Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Added new foundational part of requirement to protect confidentiality of backup information (part a)

Side by side and word by word for 3.8.9

PS Personnel Security 11
3.9.1 Screen people before granting access 03.09.01 Personnel Screening Review ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to address rescreening individuals
  • Added new ODP: conditions requiring rescreening

Side by side and word by word for 3.9.1

3.9.2 Close accounts when people move or leave 03.09.02 Personnel Termination and Transfer Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for personnel termination and transfer
  • Added new ODP: time period to disable system access

Side by side and word by word for 3.9.2

PE Physical Protection 323
3.10.1 Limit physical access 03.10.01 Physical Access Authorizations Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for implementing physical access authorizations
  • Added new ODP: frequency to review facility access list

Side by side and word by word for 3.10.1

3.10.2 Protect and monitor the facility 03.10.02 Monitoring Physical Access Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for monitoring physical access
  • Added new ODP: frequency to review physical access logs
  • Added new ODP: events or potential indications of events to review physical access logs

Side by side and word by word for 3.10.2

3.10.3 Escort visitors 03.10.07 Physical Access Control Retired
  • Incorporated into 03.10.07.

Incorporated into 03.10.07.

Side by side and word by word for 3.10.3

3.10.4 Keep physical access logs 03.10.07 Physical Access Control Retired
  • Incorporated into 03.10.07.

Incorporated into 03.10.07.

Side by side and word by word for 3.10.4

3.10.5 Manage keys and badges 03.10.07 Physical Access Control Retired
  • Incorporated into 03.10.07.

Incorporated into 03.10.07.

Side by side and word by word for 3.10.5

3.10.6 Cover work-from-home 03.10.06 Alternate Work Site Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for alternate work site
  • Added new ODP: security requirements employed at alternate work sites

Side by side and word by word for 3.10.6

03.10.07 Physical Access Control New
  • New security requirement based on PE-03 (SP 800-53, Revision 5)
  • Added new ODP: circumstances requiring visitor escorts and control of visitor activity
  • Incorporates withdrawn requirements: 03.10.03, 03.10.04, 03.10.05

New in Rev. 3; no Rev. 2 counterpart to compare.

03.10.08 Access Control for Transmission New
  • New security requirement based on PE-04 (SP 800-53, Revision 5)

New in Rev. 3; no Rev. 2 counterpart to compare.

RA Risk Assessment 211
3.11.1 Assess your risk periodically 03.11.01 Risk Assessment Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for risk assessment; explicitly identifies supply chain risk as part of the risk assessment
  • Added new ODP: frequency to update risk assessments

Side by side and word by word for 3.11.1

3.11.2 Scan for vulnerabilities 03.11.02 Vulnerability Monitoring and Scanning Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for vulnerability monitoring and scanning
  • Added new ODP: frequency to monitor and scan system for vulnerabilities
  • Added new ODP: response time to remediate vulnerabilities
  • Added new ODP: frequency to update vulnerabilities to be scanned
  • Incorporates withdrawn requirement: 03.11.03

Side by side and word by word for 3.11.2

3.11.3 Fix what you find 03.11.02 Vulnerability Monitoring and Scanning Retired
  • Incorporated into 03.11.02.

Incorporated into 03.11.02.

Side by side and word by word for 3.11.3

03.11.04 Risk Response New
  • New security requirement based on RA-07 (SP 800-53, Revision 5)

New in Rev. 3; no Rev. 2 counterpart to compare.

CA Security Assessment 1211
3.12.1 Assess your own controls periodically 03.12.01 Security Assessment Carries as-is ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Added new ODP: frequency to determine if requirements have been satisfied

Side by side and word by word for 3.12.1

3.12.2 Write and work a POA&M 03.12.02 Plan of Action and Milestones Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for developing and maintaining a plan of action and milestones

Side by side and word by word for 3.12.2

3.12.3 Monitor controls continuously 03.12.03 Continuous Monitoring Review
  • New security requirement title
  • Aligned with SP 800-53, Rev 5; rephrased to provide more comprehensive detail on and foundational tasks for continuous monitoring; outcome unchanged

Side by side and word by word for 3.12.3

3.12.4 Keep a system security plan 03.15.02 System Security Plan Review ODP
  • Revised security requirement based on PL-02 (SP 800-53, Revision 5) to provide more comprehensive detail on and foundational tasks for system security plan
  • Added new ODP: frequency to review and update system security plan
  • Incorporates withdrawn requirement: 03.12.04

Side by side and word by word for 3.12.4

03.12.05 Information Exchange New ODP
  • New security requirement based on CA-02(01) (SP 800-53, Revision 5)
  • Added new ODP: selection of one or more (interconnection security agreements, information exchange agreements, memoranda of understanding or agreement, service-level agreements, user agreements, non-disclosure agreements, or other types of agreements)
  • Added new ODP: frequency to review and update agreements

New in Rev. 3; no Rev. 2 counterpart to compare.

SC System and Communications Protection 4426
3.13.1 Guard your boundaries 03.13.01 Boundary Protection Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for boundary protection

Side by side and word by word for 3.13.1

3.13.2 Design with security in mind Retired, no successor Retired
3.13.3 Separate admin interfaces from user interfaces 03.01.01 Account Management
03.01.02 Access Enforcement
03.01.03 Information Flow Enforcement
03.01.04 Separation of Duties
03.01.05 Least Privilege
03.01.06 Least Privilege – Privileged Accounts
03.01.07 Least Privilege – Privileged Functions
Retired
  • Addressed by 03.01.01, 03.01.02, 03.01.03, 03.01.04, 03.01.05, 03.01.06, and 03.01.07.

Incorporated into 03.01.01, 03.01.02, 03.01.03, 03.01.04, 03.01.05, 03.01.06, 03.01.07.

Side by side and word by word for 3.13.3

3.13.4 Prevent leakage through shared resources 03.13.04 Information in Shared System Resources Carries as-is
  • New security requirement title

Side by side and word by word for 3.13.4

3.13.5 Put public services in their own subnet 03.13.01 Boundary Protection Retired
  • Incorporated into 03.13.01.

Incorporated into 03.13.01.

Side by side and word by word for 3.13.5

3.13.6 Deny by default 03.13.06 Network Communications – Deny by Default – Allow by Exception Carries as-is
  • New security requirement title

Side by side and word by word for 3.13.6

3.13.7 Block split tunneling 03.01.12 Remote Access
03.04.02 Configuration Settings
03.04.06 Least Functionality
Retired
  • Addressed by 03.01.12, 03.04.02 and 03.04.06.

Incorporated into 03.01.12, 03.04.02, 03.04.06.

Side by side and word by word for 3.13.7

3.13.8 Encrypt CUI in transit 03.13.08 Transmission and Storage Confidentiality Carries as-is
  • New security requirement title
  • Incorporate withdrawn requirement: 3.13.16

Side by side and word by word for 3.13.8

3.13.9 Drop connections when sessions end 03.13.09 Network Disconnect Review ODP
  • New security requirement title
  • Added new ODP: time period of inactivity to terminate the network connection

Side by side and word by word for 3.13.9

3.13.10 Manage your encryption keys 03.13.10 Cryptographic Key Establishment and Management Review ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for cryptographic key establishment and management
  • Added new ODP: requirements for key generation, distribution, storage, access and destruction

Side by side and word by word for 3.13.10

3.13.11 Use FIPS-validated cryptography 03.13.11 Cryptographic Protection Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Added new ODP: types of cryptography used to protect confidentiality of CUI

Side by side and word by word for 3.13.11

3.13.12 Control cameras and microphones 03.13.12 Collaborative Computing Devices and Applications Review ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Added new ODP: exceptions where remote activation is allowed

Side by side and word by word for 3.13.12

3.13.13 Control mobile code 03.13.13 Mobile Code Review
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for use of mobile code

Side by side and word by word for 3.13.13

3.13.14 Control VoIP Retired, no successor Retired
3.13.15 Protect session authenticity 03.13.15 Session Authenticity Carries as-is
  • New security requirement title

Side by side and word by word for 3.13.15

3.13.16 Encrypt CUI at rest 03.13.08 Transmission and Storage Confidentiality Retired
  • Incorporated into 03.13.08.

Incorporated into 03.13.08.

Side by side and word by word for 3.13.16

SI System and Information Integrity 1313
3.14.1 Find and fix flaws on a clock 03.14.01 Flaw Remediation Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for flaw remediation
  • Added new ODP: time period to install security-relevant software and firmware updates

Side by side and word by word for 3.14.1

3.14.2 Run malware protection 03.14.02 Malicious Code Protection Rework ODP
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for malicious code protection
  • Incorporates withdrawn requirements: 03.14.04, 03.14.05
  • Added new ODP: frequency to perform system scans
  • Updated discussion to provide additional guidance on malicious code protection mechanisms.

Side by side and word by word for 3.14.2

3.14.3 Act on advisories 03.14.03 Security Alerts, Advisories, and Directives Rework
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for security alerts, advisories and directives

Side by side and word by word for 3.14.3

3.14.4 Keep malware definitions current 03.14.02 Malicious Code Protection Retired
  • Incorporated into 03.14.02.

Incorporated into 03.14.02.

Side by side and word by word for 3.14.4

3.14.5 Scan on schedule and in real time 03.14.02 Malicious Code Protection Retired
  • Addressed by 03.14.02.

Incorporated into 03.14.02.

Side by side and word by word for 3.14.5

3.14.6 Monitor traffic in and out 03.14.06 System Monitoring Review
  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for system monitoring
  • Incorporates withdrawn requirement: 03.14.07

Side by side and word by word for 3.14.6

3.14.7 Notice unauthorized use 03.14.06 System Monitoring Retired
  • Incorporated into 03.14.06.

Incorporated into 03.14.06.

Side by side and word by word for 3.14.7

03.14.08 Information Management and Retention New
  • New security requirement based on SI-08 (SP 800-53, Revision 5).

New in Rev. 3; no Rev. 2 counterpart to compare.

PL Planning New family 2
03.15.01 Policy and Procedures New ODP
  • New security requirement based on all-1 controls (SP 800-53, Rev 5) that were formerly tailored as "NFO"
  • Added new ODP: frequency to review and update policies and procedures

New in Rev. 3; no Rev. 2 counterpart to compare.

03.15.03 Rules of Behavior New ODP
  • New security requirement based on PL-4 (SP 800-53, Rev 5); formerly tailored as "NFO"
  • Added new ODP: frequency to review and update rules of behavior

New in Rev. 3; no Rev. 2 counterpart to compare.

SA System and Services Acquisition New family 3
03.16.01 Security Engineering Principles New ODP
  • New security requirement based on SA-08 (SP 800-53, Revision 5)
  • Added new ODP: system security engineering principles to apply

New in Rev. 3; no Rev. 2 counterpart to compare.

03.16.02 Unsupported System Components New
  • New security requirement based on SA-22 (SP 800-53, Rev 5); newly added to (SP 800-53B) moderate baseline

New in Rev. 3; no Rev. 2 counterpart to compare.

03.16.03 External System Services New ODP
  • New security requirement based on SA-09 (SP 800-53, Rev 5); formerly tailored as "NFO"
  • Added new ODP: security requirements for external system services to comply with

New in Rev. 3; no Rev. 2 counterpart to compare.

SR Supply Chain Risk Management New family 3
03.17.01 Supply Chain Risk Management Plan New ODP
  • New security requirement based on SR-02 (SP 800-53, Rev 5)
  • Added new ODP: frequency to review and update supply chain risk management plan

New in Rev. 3; no Rev. 2 counterpart to compare.

03.17.02 Acquisition Strategies, Tools, and Methods New
  • New security requirement based on SR-05 (SP 800-53, Rev 5); newly added to the (SP 800-53B) moderate baseline

New in Rev. 3; no Rev. 2 counterpart to compare.

03.17.03 Supply Chain Requirements and Processes New ODP
  • New security requirement based on SR-03 (SP 800-53, Rev 5); newly added to the (SP 800-53B) moderate baseline
  • Added new ODP: security requirement to enforce to protect against supply chain risks

New in Rev. 3; no Rev. 2 counterpart to compare.