3.13.6Deny by default in Rev. 3
No significant change: 03.13.06 Network Communications – Deny by Default – Allow by Exception.
Status as of 2026-09-08
Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.
Side by side
Rev. 2 · in force 3.13.6 Network Communication by Exception
Assessment objectives · 800-171A
- [a] network communications traffic is denied by default
- [b] network communications traffic is allowed by exception
Rev. 3 · not adopted 03.13.06 Network Communications – Deny by Default – Allow by Exception
Deny network communications traffic by default, and allow network communications traffic by exception.
Determination statements · 800-171A Rev. 3
- 03.13.06[01] network communications traffic is denied by default.
- 03.13.06[02] network communications traffic is allowed by exception.
Draws on Rev. 2 3.13.6.
Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.
Word by word
The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.
removed in Rev. 3 added in Rev. 3
Rev. 2 3.13.6 → Rev. 3 03.13.06 Network Communications – Deny by Default – Allow by Exception
13 words kept, 6 removed, 0 added. Rev. 3 statement labels omitted for the comparison.
What NIST says changed
- New security requirement title
NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “No significant change”. At adoption, Bedrock files this under “Carries as-is”.
NIST's Rev. 3 discussion for 03.13.06
This requirement applies to inbound and outbound network communications traffic at the system boundary and at identified points within the system. A deny-all, allow-by-exception network communications traffic policy ensures that only essential and approved connections are allowed.
What this means for you now
Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.13.6 as written in Rev. 2.
Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.
Where this page's facts come from
- Rev. 2 text and objectives
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
- Mapping and change class
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
- Rev. 3 03.13.06
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]