3.5.7Set password rules in Rev. 3
Reworded: 03.05.07 Password Management. Gains organization-defined parameters.
Status as of 2026-09-08
Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.
Side by side
Rev. 2 · in force 3.5.7 Password Complexity
Assessment objectives · 800-171A
- [a] password complexity requirements are defined
- [b] password change of character requirements are defined
- [c] minimum password complexity requirements as defined are enforced when new passwords are created
- [d] minimum password change of character requirements as defined are enforced when new passwords are created
Rev. 3 · not adopted 03.05.07 Password Management
a. Maintain a list of commonly-used, expected, or compromised passwords, and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised.
b. Verify that passwords are not found on the list of commonly used, expected, or compromised passwords when users create or update passwords.
c. Transmit passwords only over cryptographically protected channels.
d. Store passwords in a cryptographically protected form.
e. Select a new password upon first use after account recovery.
f. Enforce the following composition and complexity rules for passwords: [Assignment: organization-defined composition and complexity rules].
Determination statements · 800-171A Rev. 3
- 03.05.07.a[01] a list of commonly used, expected, or compromised passwords is maintained.
- 03.05.07.a[02] a list of commonly used, expected, or compromised passwords is updated <A.03.05.07.ODP[01]: frequency>.
- 03.05.07.a[03] a list of commonly used, expected, or compromised passwords is updated when organizational passwords are suspected to have been compromised.
- 03.05.07.b passwords are verified not to be found on the list of commonly used, expected, or compromised passwords when they are created or updated by users.
- 03.05.07.c passwords are only transmitted over cryptographically protected channels.
- 03.05.07.d passwords are stored in a cryptographically protected form.
- 03.05.07.e a new password is selected upon first use after account recovery.
- 03.05.07.f the following composition and complexity rules for passwords are enforced: <A.03.05.07.ODP[02]: rules>.
Organization-defined parameters
- A.03.05.07.ODP[01] the frequency at which to update the list of commonly used, expected, or compromised passwords is defined.
- A.03.05.07.ODP[02] password composition and complexity rules are defined.
Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.
Word by word
The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.
removed in Rev. 3 added in Rev. 3
Rev. 2 3.5.7 → Rev. 3 03.05.07 Password Management
6 words kept, 8 removed, 81 added. Rev. 3 statement labels omitted for the comparison.
What NIST says changed
- New security requirement title
- Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for password management
- Incorporates withdrawn requirements: 03.05.07, 03.05.09, 03.05.10
- Added new ODP: frequency to update list of commonly-used, expected, or compromised passwords
- Added new ODP: composition and complexity rules
NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “Significant change”. At adoption, Bedrock files this under “Rework”.
NIST's Rev. 3 discussion for 03.05.07
Password-based authentication applies to passwords used in single-factor or multi-factor authentication. Long passwords or passphrases are preferable to shorter passwords. Enforced composition rules provide marginal security benefits while decreasing usability. However, organizations may choose to establish and enforce certain rules for password generation (e.g., minimum character length) under certain circumstances. For example, account recovery can occur when a password is forgotten. Cryptographically protected passwords include salted one-way cryptographic hashes of passwords. The list of commonly used, compromised, or expected passwords includes passwords obtained from previous breach corpuses, dictionary words, and repetitive or sequential characters. The list includes context-specific words, such as the name of the service, username, and derivatives thereof. Changing temporary passwords to permanent passwords immediately after system logon ensures that the necessary strength of the authentication mechanism is implemented at the earliest opportunity and reduces susceptibility to authenticator compromises. Long passwords and passphrases can be used to increase the complexity of passwords.
What this means for you now
Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.5.7 as written in Rev. 2, and if you already choose a value for the parameters above in practice, write it down where your system security plan can find it.
Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.
Where this page's facts come from
- Rev. 2 text and objectives
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
- Mapping and change class
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
- Rev. 3 03.05.07
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]