Rev. 2 versus Rev. 3: status, differences, and what to do
A reader who decides Rev. 3 applies to them today will spend real money for nothing. So the status comes first, the differences second, the advice third, and the full catalog comparison last.
1. Status: what your contract requires today
Status as of 2026-09-08
Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.
| Revision | Published | Status in the Bedrock catalog | What it means |
|---|---|---|---|
| NIST SP 800-171 Rev 2 | SP 800-171r2 (February 2020) | active | The revision DFARS 252.204-7012 and 32 CFR 170 point at. The one you are assessed against and score in SPRS. |
| NIST SP 800-171 Rev 3 | SP 800-171r3 (May 2024) | preview | Published by NIST. Not adopted for contractual purposes. No DoD scoring model exists for it. |
Where things stand, as of 2026-09-08
- A DoD class deviation keeps Rev. 2 in force for contracts carrying DFARS 252.204-7012. Until that deviation changes, Rev. 2 is the assessed baseline.
- The CMMC Phase 2 suspension of 13 July 2026 paused the expansion of third-party assessments and opened a program review. Interim guidance confirmed Rev. 2 as the active baseline for self-assessments and contract requirements. See the suspension page.
- The Department has issued its Rev. 3 organization-defined parameter values. That is preparation for an eventual move, and it lets a contractor who wants to dual-track record the values now. It does not make Rev. 3 a requirement.
- Outside DoD, the FAR CUI proposed rule (public comment closed 23 July 2026) points civilian agency contracts at Rev. 3. A contractor holding both civilian and defense CUI work may face two baselines once that rule is final. This site covers the defense side only.
Bedrock CMMC carries both revisions side by side and shows this comparison against your own package, with each requirement's current status beside its Rev. 3 successor; that is where the status above is read from.
2. What actually changed
Counts and classes are NIST's own, from its official Rev. 2 to Rev. 3 change analysis, as carried in the Bedrock mapping. Two workbook errata are corrected there and documented.
- 18 No significant change · Carries as-is
- 14 Minor change · Review
- 46 Significant change · Rework
- 19 New requirement · New
- 32 Withdrawn · Retired
129 rows: the 110 Rev. 2 requirements plus the 19 requirements that are new in Rev. 3. The second label on each class is the planning bucket Bedrock uses: what a contractor would do with the requirement at adoption.
Structure
- Rev. 2 has 110 requirements in 14 families. Rev. 3 has 97 active requirements in 17 families, with 33 numbered slots marked withdrawn.
- Three families are new: PL Planning, SA System and Services Acquisition, SR Supply Chain Risk Management. Security Assessment becomes Security Assessment and Monitoring.
- Rev. 3 breaks its requirements into 422 determination statements (assessment objectives) in NIST SP 800-171A Rev. 3.
- Rev. 3 numbering is zero-padded (03.05.03 for 3.5.3) and a number can change meaning: 03.11.04 is a new requirement, Risk Response, not a renumbered 3.11.4. Never assume a match by number.
Organization-defined parameters
Rev. 3 introduces 88 organization-defined parameters: blanks such as a time period or a review frequency that the organization fills in. Each one is itself assessable in 800-171A Rev. 3, because defining the value is a determination. Rev. 2 has none. In the comparison below, rows that gain parameters carry an ODP marker, and each requirement's page shows the blanks highlighted in the Rev. 3 text.
The 6 Rev. 2 requirements with no Rev. 3 successor
3. What a contractor should do now
Durable regardless of adoption
- Know your boundary. Where CUI lives does not change between revisions, and every reworded requirement still attaches to the same systems.
- Keep the system security plan true. Rev. 3 keeps it (as 03.15.02) and adds a review frequency; a current, accurate plan carries over.
- Collect evidence per assessment objective, not per requirement. Rev. 3 has more objectives, but they cover the same facts, and objective-level evidence re-maps; requirement-level narrative does not.
- Close the five-point items. MFA for all users, FIPS-validated cryptography, logging, flaw remediation and incident response are the substance of both revisions, and they carry the same weight in the score you post today.
- Note the choices Rev. 3 would ask you to make (its parameters) where you already make them: account inactivity periods, review frequencies, lockout thresholds. Writing down what you do now costs nothing and answers the question later.
Premature until adoption
- Renumbering policies, procedures or the system security plan to Rev. 3 identifiers. Your assessor works from Rev. 2 and so does SPRS.
- Re-scoring against Rev. 3. There is no DoD scoring model for it, so any number you produce is invented.
- Buying tooling or services sold on Rev. 3 readiness as if it were a deadline. There is no deadline until a deviation or rule sets one.
- Treating a withdrawn Rev. 2 requirement as gone. Until adoption it is still assessed.
4. Has anything else changed?
Readers who arrive here usually also want to know what the Phase 2 suspension did and did not change. That has its own page: the Phase 2 suspension. The short answer is the same as this page's: the clause, the standard, the score and the affirmation are where they were.