3.12.4Keep a system security plan in Rev. 3
Reworded: 03.15.02 System Security Plan. Gains organization-defined parameters.
Status as of 2026-09-08
Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.
Side by side
Rev. 2 · in force 3.12.4 System Security Plan
Assessment objectives · 800-171A
- [a] a system security plan is developed
- [b] the system boundary is described and documented in the system security plan
- [c] the system environment of operation is described and documented in the system security plan
- [d] the security requirements identified and approved by the designated authority as non-applicable are identified
- [e] the method of security requirement implementation is described and documented in the system security plan
- [f] the relationship with or connection to other systems is described and documented in the system security plan
- [g] the frequency to update the system security plan is defined
- [h] system security plan is updated with the defined frequency
Rev. 3 · not adopted 03.15.02 System Security Plan
a. Develop a system security plan that:
01. Defines the constituent system components;
02. Identifies the information types processed, stored, and transmitted by the system;
03. Describes specific threats to the system that are of concern to the organization;
04. Describes the operational environment for the system and any dependencies on or connections to other systems or system components;
05. Provides an overview of the security requirements for the system;
06. Describes the safeguards in place or planned for meeting the security requirements;
07. Identifies individuals that fulfill system roles and responsibilities; and
08. Includes other relevant information necessary for the protection of CUI.
b. Review and update the system security plan [Assignment: organization-defined frequency].
c. Protect the system security plan from unauthorized disclosure.
Determination statements · 800-171A Rev. 3
- 03.15.02.a.01 a system security plan that defines the constituent system components is developed.
- 03.15.02.a.02 a system security plan that identifies the information types processed, stored, and transmitted by the system is developed.
- 03.15.02.a.03 a system security plan that describes specific threats to the system that are of concern to the organization is developed.
- 03.15.02.a.04 a system security plan that describes the operational environment for the system and any dependencies on or connections to other systems or system components is developed.
- 03.15.02.a.05 a system security plan that provides an overview of the security requirements for the system is developed.
- 03.15.02.a.06 a system security plan that describes the safeguards in place or planned for meeting the security requirements is developed.
- 03.15.02.a.07 a system security plan that identifies individuals that fulfill system roles and responsibilities is developed.
- 03.15.02.a.08 a system security plan that includes other relevant information necessary for the protection of CUI is developed.
- 03.15.02.b[01] the system security plan is reviewed <A.03.15.02.ODP[01]: frequency>.
- 03.15.02.b[02] the system security plan is updated <A.03.15.02.ODP[01]: frequency>.
- 03.15.02.c the system security plan is protected from unauthorized disclosure.
Organization-defined parameters
- A.03.15.02.ODP[01] the frequency at which the system security plan is reviewed and updated is defined.
Draws on Rev. 2 3.12.4.
Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.
Word by word
The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.
removed in Rev. 3 added in Rev. 3
Rev. 2 3.12.4 → Rev. 3 03.15.02 System Security Plan
13 words kept, 17 removed, 100 added. Rev. 3 statement labels omitted for the comparison.
What NIST says changed
- Revised security requirement based on PL-02 (SP 800-53, Revision 5) to provide more comprehensive detail on and foundational tasks for system security plan
- Added new ODP: frequency to review and update system security plan
- Incorporates withdrawn requirement: 03.12.04
NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “Minor change”. At adoption, Bedrock files this under “Review”.
NIST's Rev. 3 discussion for 03.15.02
System security plans provide key characteristics of the system that is processing, storing, and transmitting CUI and how the system and information are protected. System security plans contain sufficient information to enable a design and implementation that are unambiguously compliant with the intent of the plans and the subsequent determinations of risk if the plan is implemented as intended. System security plans can be a collection of documents, including documents that already exist. Effective system security plans reference policies, procedures, and documents (e.g., design specifications) that provide additional detailed information. This reduces the documentation requirements associated with security programs and maintains security information in other established management or operational areas related to enterprise architecture, the system development life cycle, systems engineering, and acquisition.
What this means for you now
Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.12.4 as written in Rev. 2, and if you already choose a value for the parameters above in practice, write it down where your system security plan can find it.
Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.
Where this page's facts come from
- Rev. 2 text and objectives
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
- Mapping and change class
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
- Rev. 3 03.15.02
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]