to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

3.5.10Never store or send passwords in the clear in Rev. 3

Withdrawn and incorporated elsewhere: 03.05.07 Password Management.

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

Side by side

Rev. 2 · in force 3.5.10 Cryptographically-Protected Passwords

Store and transmit only cryptographically-protected passwords.

Assessment objectives · 800-171A

  1. [a] passwords are cryptographically protected in storage
  2. [b] passwords are cryptographically protected in transit

Rev. 3 · not adopted 03.05.07 Password Management

a. Maintain a list of commonly-used, expected, or compromised passwords, and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised.

b. Verify that passwords are not found on the list of commonly used, expected, or compromised passwords when users create or update passwords.

c. Transmit passwords only over cryptographically protected channels.

d. Store passwords in a cryptographically protected form.

e. Select a new password upon first use after account recovery.

f. Enforce the following composition and complexity rules for passwords: [Assignment: organization-defined composition and complexity rules].

Determination statements · 800-171A Rev. 3

  1. 03.05.07.a[01] a list of commonly used, expected, or compromised passwords is maintained.
  2. 03.05.07.a[02] a list of commonly used, expected, or compromised passwords is updated <A.03.05.07.ODP[01]: frequency>.
  3. 03.05.07.a[03] a list of commonly used, expected, or compromised passwords is updated when organizational passwords are suspected to have been compromised.
  4. 03.05.07.b passwords are verified not to be found on the list of commonly used, expected, or compromised passwords when they are created or updated by users.
  5. 03.05.07.c passwords are only transmitted over cryptographically protected channels.
  6. 03.05.07.d passwords are stored in a cryptographically protected form.
  7. 03.05.07.e a new password is selected upon first use after account recovery.
  8. 03.05.07.f the following composition and complexity rules for passwords are enforced: <A.03.05.07.ODP[02]: rules>.

Organization-defined parameters

  • A.03.05.07.ODP[01] the frequency at which to update the list of commonly used, expected, or compromised passwords is defined.
  • A.03.05.07.ODP[02] password composition and complexity rules are defined.

Draws on Rev. 2 3.5.7, 3.5.10.

Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.

Word by word

The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.

removed in Rev. 3 added in Rev. 3

Rev. 2 3.5.10 → Rev. 3 03.05.07 Password Management

Store Maintain a list of commonly-used, expected, or compromised passwords, and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised. Verify that passwords are not found on the list of commonly used, expected, or compromised passwords when users create or update passwords. Transmit passwords only cryptographically-protected over cryptographically protected channels. Store passwords in a cryptographically protected form. Select a new password upon first use after account recovery. Enforce the following composition and complexity rules for passwords: [Assignment: organization-defined composition and complexity rules].

4 words kept, 2 removed, 83 added. Rev. 3 statement labels omitted for the comparison.

What NIST says changed

Rev. 3 withdraws this requirement as a separate item and folds it into another requirement. NIST's note: Incorporated into 03.05.07.

NIST's Rev. 3 discussion for 03.05.07

Password-based authentication applies to passwords used in single-factor or multi-factor authentication. Long passwords or passphrases are preferable to shorter passwords. Enforced composition rules provide marginal security benefits while decreasing usability. However, organizations may choose to establish and enforce certain rules for password generation (e.g., minimum character length) under certain circumstances. For example, account recovery can occur when a password is forgotten. Cryptographically protected passwords include salted one-way cryptographic hashes of passwords. The list of commonly used, compromised, or expected passwords includes passwords obtained from previous breach corpuses, dictionary words, and repetitive or sequential characters. The list includes context-specific words, such as the name of the service, username, and derivatives thereof. Changing temporary passwords to permanent passwords immediately after system logon ensures that the necessary strength of the authentication mechanism is implemented at the earliest opportunity and reduces susceptibility to authenticator compromises. Long passwords and passphrases can be used to increase the complexity of passwords.

What this means for you now

Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.5.10 as written in Rev. 2.

Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.

Back to the Rev. 2 vs Rev. 3 overview

Where this page's facts come from
Rev. 2 text and objectives
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
Mapping and change class
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
Rev. 3 03.05.07
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]