03.11.04Risk Response in Rev. 3
New in Revision 3 — no Revision 2 equivalent. Nothing in NIST SP 800-171 Rev. 2 maps onto this number, so it has no Rev. 2 page and no side-by-side; the Rev. 3 text is below in full.
Status as of 2026-09-08
Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.
The requirement
Rev. 3 · not adopted 03.11.04 Risk Response
Respond to findings from security assessments, monitoring, and audits.
NIST SP 800-171 Rev. 3, verbatim, with organization-defined blanks highlighted. Rev. 2 has no counterpart to place beside it.
Determination statements
What an assessor would check under NIST SP 800-171A Rev. 3. 3 statements, each one answered yes or no.
- 03.11.04[01] findings from security assessments are responded to.
- 03.11.04[02] findings from security monitoring are responded to.
- 03.11.04[03] findings from security audits are responded to.
NIST SP 800-171A Rev. 3, verbatim.
What NIST says
- New security requirement based on RA-07 (SP 800-53, Revision 5)
NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “New requirement”. At adoption, Bedrock files this under “New”.
NIST's Rev. 3 discussion for 03.11.04
This requirement addresses the need to determine an appropriate response to risk before generating a plan of action and milestones (POAM) entry. It may be possible to mitigate the risk immediately so that a POAM entry is not needed. However, a POAM entry is generated if the risk response is to mitigate the identified risk and the mitigation cannot be completed immediately.
Risk Assessment in Rev. 3
The active RA requirements in Rev. 3. Those with a Rev. 2 predecessor link to that comparison; those marked new have their own page.
What this means for you now
Nothing. Until a class deviation or a published rule adopts Rev. 3, no assessor asks about 03.11.04 and SPRS has no score for it. If you already do what it describes, note where the evidence lives; that costs nothing and answers the question later.
Bedrock CMMC carries the Rev. 3 catalog beside your Rev. 2 package, so the day adoption lands the new requirements are a to-do list, not a surprise.
Where this page's facts come from
- Rev. 3 03.11.04 text, determination statements, parameters, class and note
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]