NIST publishes SP 800-171 Revision 3; DoD contracts stay on Revision 2
On May 14, 2024, the National Institute of Standards and Technology (NIST) published the final Revision 3 of Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, together with the matching assessment guide, SP 800-171A Revision 3. It is the current NIST version of the requirements contractors implement to protect Controlled Unclassified Information (CUI).
This item was added to the change feed when the NIST SP 800-171 page launched on this site, so followers can see the kind of revision change a subscription covers. It is not a new announcement.
What changed
Revision 3 realigns SP 800-171 with NIST SP 800-53 Revision 5, the control catalog federal agencies use for their own systems. The 110 requirements in 14 families of Revision 2 became 97 requirements in 17 families, adding Planning, System and Services Acquisition, and Supply Chain Risk Management. Several Revision 2 requirements were merged into multi-part requirements, so the lower count does not mean less work.
The other structural change is organization-defined parameters (ODPs): blanks in certain requirements, such as how often to review accounts or how long to keep audit logs, that the imposing agency fills in. Revision 3 lists 49 of them in an appendix. Until an agency publishes its values, a contractor cannot fully assess itself against Revision 3.
What did not change for DoD contractors
On May 2, 2024, before Revision 3 was final, the Department of Defense issued Class Deviation 2024-O0013, directing contracting officers to require Revision 2 in DFARS 252.204-7012 contracts instead of “the version in effect at the time the solicitation is issued.” The Cybersecurity Maturity Model Certification (CMMC) program rule is also written against Revision 2. Both remain in effect, so defense contractors are still implemented, scored, and assessed against the 110 Revision 2 requirements.
Civilian agencies decide for themselves. The FAR Council’s June 2026 proposal for a government-wide CUI clause points to Revision 3; it is not yet final.
What to do now
- Read your contract clause and any deviation it cites to confirm which revision applies to you. For DoD work, assume Revision 2 until DoD says otherwise.
- Keep your System Security Plan (SSP) mapped to the revision your contract requires, and note the Revision 3 requirement numbers alongside so a future transition is a re-mapping, not a rewrite.
- If you sell to civilian agencies, review Revision 3 now: the new Planning, Acquisition, and Supply Chain families are where most gaps will appear.
- See the NIST SP 800-171 page for who is covered, how self-assessments and DoD assessments work, and what to ask your contracting officer or prime.
- Follow NIST SP 800-171 on this site for DoD’s Revision 3 transition decision and the outcome of the FAR CUI rulemaking.