to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

3.13.2Design with security in mind in Rev. 3

Withdrawn with no successor.

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

Side by side

Rev. 2 · in force 3.13.2 Security Engineering

Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.

Assessment objectives · 800-171A

  1. [a] architectural designs that promote effective information security are identified
  2. [b] software development techniques that promote effective information security are identified
  3. [c] systems engineering principles that promote effective information security are identified
  4. [d] identified architectural designs that promote effective information security are employed
  5. [e] identified software development techniques that promote effective information security are employed
  6. [f] identified systems engineering principles that promote effective information security are employed

Rev. 3 · withdrawn

Rev. 3 withdraws this requirement and names no successor. NIST's stated reason: Recategorized as NCO.

Until Rev. 3 is adopted it is still assessed under Rev. 2.

Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.

What NIST says changed

Rev. 3 withdraws this requirement and names no successor. NIST's stated reason: Recategorized as NCO. Until Rev. 3 is adopted it is still assessed under Rev. 2.

What this means for you now

Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.13.2 as written in Rev. 2.

Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.

Back to the Rev. 2 vs Rev. 3 overview

Where this page's facts come from
Rev. 2 text and objectives
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
Mapping and change class
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3