3.5.4Use replay-resistant authentication in Rev. 3
No significant change: 03.05.04 Replay-Resistant Authentication.
Status as of 2026-09-08
Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.
Side by side
Rev. 2 · in force 3.5.4 Replay-Resistant Authentication
Assessment objectives · 800-171A
- [a] replay-resistant authentication mechanisms are implemented for network access to privileged accounts
- [b] replay-resistant authentication mechanisms are implemented for network access to non-privileged accounts
Rev. 3 · not adopted 03.05.04 Replay-Resistant Authentication
Implement replay-resistant authentication mechanisms for access to privileged and non-privileged accounts.
Determination statements · 800-171A Rev. 3
- 03.05.04[01] replay-resistant authentication mechanisms for access to privileged accounts are implemented.
- 03.05.04[02] replay-resistant authentication mechanisms for access to non-privileged accounts are implemented.
Draws on Rev. 2 3.5.4.
Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.
Word by word
The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.
removed in Rev. 3 added in Rev. 3
Rev. 2 3.5.4 → Rev. 3 03.05.04 Replay-Resistant Authentication
10 words kept, 2 removed, 1 added. Rev. 3 statement labels omitted for the comparison.
What NIST says changed
- New security requirement title
- Aligned with SP 800-53, Rev 5
NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “No significant change”. At adoption, Bedrock files this under “Carries as-is”.
NIST's Rev. 3 discussion for 03.05.04
Authentication processes resist replay attacks if it is impractical to successfully authenticate by recording or replaying previous authentication messages. Replay-resistant techniques include protocols that use nonces or challenges, such as time synchronous or challenge-response one-time authenticators.
What this means for you now
Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.5.4 as written in Rev. 2.
Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.
Where this page's facts come from
- Rev. 2 text and objectives
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
- Mapping and change class
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
- Rev. 3 03.05.04
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]