to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

3.5.5Do not recycle identifiers in Rev. 3

Reworded: 03.05.05 Identifier Management. Gains organization-defined parameters.

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

Side by side

Rev. 2 · in force 3.5.5 Identifier Reuse

Prevent reuse of identifiers for a defined period.

Assessment objectives · 800-171A

  1. [a] a time period within which identifiers cannot be reused is defined
  2. [b] reuse of identifiers is prevented within the defined time period

Rev. 3 · not adopted 03.05.05 Identifier Management

a. Receive authorization from organizational personnel or roles to assign an individual, group, role, service, or device identifier.

b. Select and assign an identifier that identifies an individual, group, role, service, or device.

c. Prevent the reuse of identifiers for [Assignment: organization-defined time period].

d. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status].

Determination statements · 800-171A Rev. 3

  1. 03.05.05.a authorization is received from organizational personnel or roles to assign an individual, group, role, service, or device identifier.
  2. 03.05.05.b[01] an identifier that identifies an individual, group, role, service, or device is selected.
  3. 03.05.05.b[02] an identifier that identifies an individual, group, role, service, or device is assigned.
  4. 03.05.05.c the reuse of identifiers for <A.03.05.05.ODP[01]: time period> is prevented.
  5. 03.05.05.d individual identifiers are managed by uniquely identifying each individual as <A.03.05.05.ODP[02]: characteristic>.

Organization-defined parameters

  • A.03.05.05.ODP[01] the time period for preventing the reuse of identifiers is defined.
  • A.03.05.05.ODP[02] characteristic used to identify individual status are defined.

Draws on Rev. 2 3.5.5.

Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.

Word by word

The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.

removed in Rev. 3 added in Rev. 3

Rev. 2 3.5.5 → Rev. 3 03.05.05 Identifier Management

Receive authorization from organizational personnel or roles to assign an individual, group, role, service, or device identifier. Select and assign an identifier that identifies an individual, group, role, service, or device. Prevent the reuse of identifiers for a defined [Assignment: organization-defined time period]. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status].

6 words kept, 2 removed, 50 added. Rev. 3 statement labels omitted for the comparison.

What NIST says changed

  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for identifier management
  • Added new ODP: time period to prevent reuse of identifiers
  • Added new ODP: characteristic identifying individual status

NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “Significant change”. At adoption, Bedrock files this under “Rework”.

NIST's Rev. 3 discussion for 03.05.05

Identifiers are provided for users, processes acting on behalf of users, and devices. Prohibiting the reuse of identifiers prevents the assignment of previously used individual, group, role, service, or device identifiers to different individuals, groups, roles, services, or devices. Characteristics that identify the status of individuals include contractors, foreign nationals, and non-organizational users. Identifying the status of individuals by these characteristics provides information about the people with whom organizational personnel are communicating. For example, it is useful for an employee to know that one of the individuals on an email message is a contractor.

What this means for you now

Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.5.5 as written in Rev. 2, and if you already choose a value for the parameters above in practice, write it down where your system security plan can find it.

Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.

Back to the Rev. 2 vs Rev. 3 overview

Where this page's facts come from
Rev. 2 text and objectives
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
Mapping and change class
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
Rev. 3 03.05.05
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]