Get Demo
↑

NIST 800-171 Rev 3: What Changed from Rev 2 (and What CMMC Still Uses)

Rev 2 vs Rev 3 for CUI — 14 to 17 families, 97 requirements, ODPs, and why CMMC Level 2 still assesses against Rev 2's 110 requirements.

Published: September 2026 Compliance · NIST 8-12 min read

NIST SP 800-171 tells federal agencies what to require of nonfederal organizations that process, store, or transmit Controlled Unclassified Information (CUI). Revision 3 (final May 14, 2024) is the current NIST publication and organizes 97 security requirements into 17 families. CMMC Level 2 (32 CFR 170.14) still makes Level 2 identical to Revision 2 (110 requirements / 14 families) until rulemaking changes that baseline.

Related: NIST hub · 800-171 hub · CMMC vs 800-171.

What Changed from Rev 2 to Rev 3

Per NIST's Rev 3 FAQ and the final publication:

Final Rev 3 count: 97 active security requirements across 17 families (enumerated from the final May 2024 PDF).

Rev 3's 17 Security Requirement Families

Source: NIST SP 800-171 Rev 3, Table 1 / Section 3.

#
Family
ID
1
Access Control
AC
2
Awareness and Training
AT
3
Audit and Accountability
AU
4
Configuration Management
CM
5
Identification and Authentication
IA
6
Incident Response
IR
7
Maintenance
MA
8
Media Protection
MP
9
Personnel Security
PS
10
Physical Protection
PE
11
Risk Assessment
RA
12
Security Assessment and Monitoring
CA
13
System and Communications Protection
SC
14
System and Information Integrity
SI
15
Planning
PL
16
System and Services Acquisition
SA
17
Supply Chain Risk Management
SR

Not 800-171 requirement families (tailored out): Contingency Planning (CP), Program Management (PM), and PII Processing and Transparency (PT).

Why It Matters for DoD Suppliers

DoD suppliers must not “upgrade” CMMC Level 2 assessments to Rev 3 today. Keep SPRS scoring and SSP/POA&M evidence on Rev 2, while crosswalking early to Rev 3 for ODPs and SCRM readiness.

How CyberSilo Helps

Align Rev 2 Assessments with Rev 3 Readiness

Keep CMMC Level 2 evidence on Rev 2 while mapping ODPs and new families for the transition.

Frequently Asked Questions

Does CMMC Level 2 use 800-171 Rev 3?

No. Under 32 CFR 170.14, CMMC Level 2 security requirements are identical to NIST SP 800-171 Revision 2 until a published rule changes that baseline.

How many requirements are in final Rev 3?

97 active security requirements across 17 families, per the final May 2024 publication.

Who sets organization-defined parameters (ODPs)?

A federal agency or consortium may specify ODP values. If they do not, the nonfederal organization must assign values to complete the requirement. NIST does not assign ODP values.

NIST hub · What Is NIST CSF 2.0? · CSF Function Guides · 800-53 Rev 5 Families

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!