Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient - No AI Slop!
ComplianceForge

NIST 800-171 Rev 2 vs Rev 3 During the CMMC Pause: Which Version Should Your Self-Assessment Follow?

NIST 800-171
ComplianceForge Support
July 17, 2026
NIST 800-171 Rev 2 vs Rev 3 During the CMMC Pause: Which Version Should Your Self-Assessment Follow?

Editorial note: This article is informational, not legal or compliance advice. CMMC and DFARS requirements are changing after the Department of War suspended Phase II on July 13, 2026. The control counts below are drawn from NIST's published structure and should be verified against the primary NIST publications before you rely on them.

Here is the direct answer. The Department of War's interim guidance names NIST SP 800-171 Rev 2 as the standard it will enforce through self-assessment during the CMMC pause, so a self-assessment aimed at current DoD contract compliance should generally be built on Rev 2 today. At the same time, the underlying standard has already moved to NIST 800-171 Rev 3, and non DoD federal contracts may point to the current version, so the smart posture is to build on Rev 2 while being ready for Rev 3 rather than choosing one and ignoring the other.

This article explains the difference between the two revisions and how to make that call without redoing your program twice.

Key Takeaways

• The interim path after the CMMC Phase II suspension is keyed to NIST 800-171 Rev 2.

• NIST 800-171 Rev 3 is a substantial restructure, not a light edit.

• Rev 3 reorganizes the requirements into more control families and rebuilds the assessment objectives.

• Non DoD federal contracts may reference the current version, which is Rev 3.

• Building for both revisions at once avoids a costly rewrite when CMMC eventually catches up to Rev 3.

What Changed From Rev 2 to Rev 3

NIST 800-171 Rev 3 is not a version bump. Based on NIST's published structure, Rev 3 reorganizes the requirements into approximately 17 control families, up from the 14 families in Rev 2, and adds Planning and Supply Chain Risk Management as their own families. The requirement structure changed as well. Rev 3 is built around roughly 97 core requirements that expand into approximately 297 discrete requirements, assessed against roughly 510 Assessment Objectives in the companion publication NIST SP 800-171A Rev 3. Rev 2, by comparison, is generally described with 14 families, 110 controls and 320 assessment objectives.

Two other changes matter for your documentation. The Non-Federal Organization (NFO) controls that existed in Rev 2 were removed in Rev 3. And the addition of a Supply Chain Risk Management family brings a discipline into scope that goes beyond traditional IT and needs a mature risk management process behind it.

These figures are approximate and drawn from the published structure. Verify them against the primary NIST 800-171 Rev 3 and NIST 800-171A Rev 3 publications before making decisions, since exact counts and mappings should come from the source.

Why Rev 2 Is Still the Near Term Answer for DoD Work

There is a regulatory reason Rev 2 remains the working baseline for DoD contracts. DFARS 252.204-7012 is generally written to require the version of NIST 800-171 in effect at time of solicitation, which would point to Rev 3 today. To avoid forcing contractors onto Rev 3 while CMMC assessments still evaluated against Rev 2, the Department of Defense issued a class deviation in 2024 that allowed contractors to keep complying with Rev 2 for the time being.

The Department of War's July 2026 interim guidance is consistent with that. It names NIST SP 800-171 Rev 2 as the standard enforced through self-assessment during the review period. So for current DoD contract compliance, Rev 2 is the pragmatic baseline right now.

Why You Should Not Ignore Rev 3

Building only for Rev 2 is a shrinking window, not a stable resting place, for three reasons.

Non DoD federal agencies that require NIST 800-171 are not covered by the DoD's DFARS specific class deviation, and some federal solicitations may already reference the current version of the standard, which is Rev 3. If you sell outside DoD, Rev 2 only documentation can leave you unable to respond.

CMMC is widely expected to align with Rev 3 eventually. I do not have a verified source for the exact date of that transition, and you should verify current CMMC rulemaking before relying on any timeline. But when it happens, organizations sitting on Rev 2 only documentation will face a rewrite on the government's schedule rather than their own.

The rewrite is larger than it looks. Because Rev 3 restructured families, removed NFO controls and rebuilt assessment objectives, a Rev 2 document set cannot simply be patched. ComplianceForge's own published transition estimate is a useful gut check here. Its free NIST 800-171 Rev 2 to Rev 3 transition guide estimates that roughly a third of Assessment Objectives require minimal mapping effort, about a fifth require moderate effort, and roughly half require significant rework.

The Practical Answer: Build for Both

You do not have to choose one revision and gamble. The NIST 800-171 Compliance Program (NCP) ships three versions in a single purchase: a Rev 2 only version, a Rev 3 only version, and a combined Rev 2 and Rev 3 version for organizations addressing both during the transition. That means you can run your current self-assessment on Rev 2 and have the Rev 3 documentation ready when your contracts or CMMC move.

Because the NCP covers the Assessment Objectives from NIST 800-171A and has been used to pass DIBCAC and C3PAO assessments, it is written to the level real assessments evaluate, in whichever revision applies to you. For the deeper mapping detail, ComplianceForge also publishes a NIST SP 800-171 compliance resource page that walks through the Rev 3 structure.

To avoid buying your documentation twice, start with the NCP and use the version that matches each contract.

Frequently Asked Questions

Should I self-assess against Rev 2 or Rev 3 right now? For current DoD contract compliance during the CMMC pause, the interim guidance names Rev 2. If you hold non DoD federal contracts, check whether they reference the current version, which is Rev 3.

Is NIST 800-171 Rev 3 the current standard? Yes, Rev 3 is the current published revision of the standard. The DoD class deviation and the Department of War interim guidance are what keep Rev 2 in play for DoD contracts for now.

How different are Rev 2 and Rev 3 really? Different enough that a Rev 2 document set cannot be patched into a Rev 3 set. The families, the control structure and the assessment objectives all changed, and NFO controls were removed.

Sources: NIST SP 800-171 Rev 2, NIST SP 800-171 Rev 3 and NIST SP 800-171A Rev 3 for the control and objective structure. ComplianceForge NIST 800-171 Rev 2 to Rev 3 transition guide and NIST SP 800-171 compliance resource page. Department of War CMMC Phase II suspension release, July 13, 2026, at war.gov. Verify all counts and current requirements against the primary NIST and DFARS sources.