3.1.21Limit portable storage on outside systems in Rev. 3
Withdrawn and incorporated elsewhere: 03.01.20 Use of External Systems.
Status as of 2026-09-08
Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.
Side by side
Rev. 2 · in force 3.1.21 Portable Storage Use
Assessment objectives · 800-171A
- [a] the use of portable storage devices containing CUI on external systems is identified
- [b] limits on the use of portable storage devices containing CUI on external systems are defined
- [c] the use of portable storage devices containing CUI on external systems is limited as defined
Rev. 3 · not adopted 03.01.20 Use of External Systems
a. Prohibit the use of external systems unless the systems are specifically authorized.
b. Establish the following security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: [Assignment: organization-defined security requirements].
c. Permit authorized individuals to use external systems to access the organizational system or to process, store, or transmit CUI only after:
01. Verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied and
02. Retaining approved system connection or processing agreements with the organizational entities hosting the external systems.
d. Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems.
Determination statements · 800-171A Rev. 3
- 03.01.20.a the use of external systems is prohibited unless the systems are specifically authorized.
- 03.01.20.b the following security requirements to be satisfied on external systems prior to allowing the use of or access to those systems by authorized individuals are established: <A.03.01.20.ODP[01]: security requirements>.
- 03.01.20.c.01 authorized individuals are permitted to use external systems to access the organizational system or to process, store, or transmit CUI only after verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied.
- 03.01.20.c.02 authorized individuals are permitted to use external systems to access the organizational system or to process, store, or transmit CUI only after retaining approved system connection or processing agreements with the organizational entity hosting the external systems.
- 03.01.20.d the use of organization-controlled portable storage devices by authorized individuals on external systems is restricted.
Organization-defined parameters
- A.03.01.20.ODP[01] security requirements to be satisfied on external systems prior to allowing the use of or access to those systems by authorized individuals are defined.
Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.
Word by word
The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.
removed in Rev. 3 added in Rev. 3
Rev. 2 3.1.21 → Rev. 3 03.01.20 Use of External Systems
8 words kept, 1 removed, 103 added. Rev. 3 statement labels omitted for the comparison.
What NIST says changed
Rev. 3 withdraws this requirement as a separate item and folds it into another requirement. NIST's note: Incorporated into 03.01.20.
NIST's Rev. 3 discussion for 03.01.20
External systems are systems that are used by but are not part of the organization. These systems include personally owned systems, system components, or devices; privately owned computing and communication devices in commercial or public facilities; systems owned or controlled by nonfederal organizations; and systems managed by contractors. Organizations have the option to prohibit the use of any type of external system or specified types of external systems (e.g., prohibit the use of external systems that are not organizationally owned). Terms and conditions are consistent with the trust relationships established with the entities that own, operate, or maintain external systems and include descriptions of shared responsibilities. Authorized individuals include organizational personnel, contractors, or other individuals with authorized access to the organizational system and over whom organizations have the authority to impose specific rules of behavior regarding system access. Restrictions that organizations impose on authorized individuals may vary depending on the trust relationships between organizations. Organizations need assurance that external systems satisfy the necessary security requirements so as not to compromise, damage, or harm the system. This requirement is related to <a href="#/cprt/framework/version/SP_800_171_3_0_0/home?element=03.16.03">03.16.03</a>.
What this means for you now
Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.1.21 as written in Rev. 2.
Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.
Where this page's facts come from
- Rev. 2 text and objectives
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
- Mapping and change class
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
- Rev. 3 03.01.20
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]