to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

3.14.6Monitor traffic in and out in Rev. 3

Reworded: 03.14.06 System Monitoring.

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

Side by side

Rev. 2 · in force 3.14.6 Monitor Communications for Attacks

Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.

Assessment objectives · 800-171A

  1. [a] inbound communications traffic is monitored to detect attacks and indicators of potential attacks
  2. [b] outbound communications traffic is monitored to detect attacks and indicators of potential attacks

Rev. 3 · not adopted 03.14.06 System Monitoring

a. Monitor the system to detect:

01. Attacks and indicators of potential attacks and

02. Unauthorized connections.

b. Identify unauthorized use of the system.

c. Monitor inbound and outbound communications traffic to detect unusual or unauthorized activities or conditions.

Determination statements · 800-171A Rev. 3

  1. 03.14.06.a.01[01] the system is monitored to detect attacks.
  2. 03.14.06.a.01[02] the system is monitored to detect indicators of potential attacks.
  3. 03.14.06.a.02 the system is monitored to detect unauthorized connections.
  4. 03.14.06.b unauthorized use of the system is identified.
  5. 03.14.06.c[01] inbound communications traffic is monitored to detect unusual or unauthorized activities or conditions.
  6. 03.14.06.c[02] outbound communications traffic is monitored to detect unusual or unauthorized activities or conditions.

Draws on Rev. 2 3.14.6, 3.14.7.

Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.

Word by word

The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.

removed in Rev. 3 added in Rev. 3

Rev. 2 3.14.6 → Rev. 3 03.14.06 System Monitoring

Monitor organizational systems, including inbound and outbound communications traffic, the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monitor inbound and outbound communications traffic to detect unusual or unauthorized activities or conditions.

9 words kept, 8 removed, 25 added. Rev. 3 statement labels omitted for the comparison.

What NIST says changed

  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for system monitoring
  • Incorporates withdrawn requirement: 03.14.07

NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “Minor change”. At adoption, Bedrock files this under “Review”.

NIST's Rev. 3 discussion for 03.14.06

System monitoring involves external and internal monitoring. Internal monitoring includes the observation of events that occur within the system. External monitoring includes the observation of events that occur at the system boundary. Organizations can monitor the system by observing audit record activities in real time or by observing other system aspects, such as access patterns, characteristics of access, and other actions. The monitoring objectives may guide determination of the events. A system monitoring capability is achieved through a variety of tools and techniques (e.g., audit record monitoring software, intrusion detection systems, intrusion prevention systems, malicious code protection software, scanning tools, network monitoring software). Strategic locations for monitoring devices include selected perimeter locations and near server farms that support critical applications with such devices being employed at managed system interfaces. The granularity of monitoring the information collected is based on organizational monitoring objectives and the capability of the system to support such objectives. Systems connections can be network, remote, or local. A network connection is any connection with a device that communicates through a network (e.g., local area network, the internet). A remote connection is any connection with a device that communicates through an external network (e.g., the internet). Network, remote, and local connections can be either wired or wireless. Unusual or unauthorized activities or conditions related to inbound and outbound communications traffic include internal traffic that indicates the presence of malicious code in the system or propagating among system components, the unauthorized export of information, or signaling to external systems. Evidence of malicious code is used to identify a potentially compromised system. System monitoring requirements, including the need for types of system monitoring, may be referenced in other requirements.

What this means for you now

Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.14.6 as written in Rev. 2.

Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.

Back to the Rev. 2 vs Rev. 3 overview

Where this page's facts come from
Rev. 2 text and objectives
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
Mapping and change class
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
Rev. 3 03.14.06
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]