to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

3.1.9Show a use notice at sign-in in Rev. 3

No significant change: 03.01.09 System Use Notification.

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

Side by side

Rev. 2 · in force 3.1.9 Privacy & Security Notices

Provide privacy and security notices consistent with applicable CUI rules.

Assessment objectives · 800-171A

  1. [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category
  2. [b] privacy and security notices are displayed

Rev. 3 · not adopted 03.01.09 System Use Notification

Display a system use notification message with privacy and security notices consistent with applicable CUI rules before granting access to the system.

Determination statements · 800-171A Rev. 3

  1. 03.01.09 a system use notification message with privacy and security notices consistent with applicable CUI rules is displayed before granting access to the system.

Draws on Rev. 2 3.1.9.

Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.

Word by word

The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.

removed in Rev. 3 added in Rev. 3

Rev. 2 3.1.9 → Rev. 3 03.01.09 System Use Notification

Provide Display a system use notification message with privacy and security notices consistent with applicable CUI rules before granting access to the system.

9 words kept, 1 removed, 13 added. Rev. 3 statement labels omitted for the comparison.

What NIST says changed

  • New security requirement title
  • Aligned with SP 800-53, Rev 5
  • Rephrased for clarity; outcome remains unchanged
  • Discussion updated with minor clarifications, including scope/applicability

NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “No significant change”. At adoption, Bedrock files this under “Carries as-is”.

NIST's Rev. 3 discussion for 03.01.09

System use notifications can be implemented using messages or warning banners. The messages or warning banners are displayed before individuals log in to a system that processes, stores, or transmits CUI. System use notifications are used for access via logon interfaces with human users and are not required when human interfaces do not exist. Organizations consider whether a secondary use notification is needed to access applications or other system resources after the initial network logon. Posters or other printed materials may be used in lieu of an automated system message. This requirement is related to <a href="#/cprt/framework/version/SP_800_171_3_0_0/home?element=03.15.03">03.15.03</a>.

What this means for you now

Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.1.9 as written in Rev. 2.

Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.

Back to the Rev. 2 vs Rev. 3 overview

Where this page's facts come from
Rev. 2 text and objectives
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
Mapping and change class
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
Rev. 3 03.01.09
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]