Quick Answer: NIST 800-171 Rev 3 assessment objectives are the specific, testable statements an assessor uses to decide whether each security requirement is met. They come from NIST SP 800-171A Rev 3. Each objective is checked with one or more methods (e.g., examine, interview, test), and a requirement is satisfied only when all of its objectives are satisfied.
NIST SP 800-171 Rev 3 contains 97 security requirements organized into 17 families. A requirement such as account management covers several distinct ideas, so NIST SP 800-171A breaks each requirement into determination statements, called assessment objectives. Each one describes a single thing the assessor must confirm.
ComplianceForge has published a page for every Rev 3 requirement. For example, the 03.01.01 Account Management page lists the requirement, its assessment objectives and practical implementation guidance.
Assessors choose methods based on the objective. A documentation objective may need only examination. A technical objective usually needs a test, and interviews confirm the process is understood and followed.
Rev 3 introduced Organization-Defined Parameters (ODPs), placeholders such as review frequencies or time periods that the organization must set. An objective that includes an ODP cannot be assessed until the value is defined and documented. Record every ODP value in your standards so assessors can see it in one place.
Work requirement by requirement and objective by objective:
This mapping is where documentation gaps appear. A requirement can look complete in an SSP while one objective has no procedure or evidence behind it. Reviewing each objective with the control owner, before the assessor does, is the quickest way to find those gaps and close them while there is still time. The NIST 800-171 Compliance Program (NCP) provides editable policies, standards and procedures built for this level of traceability, and it maps to the Secure Controls Framework.
Start with the families that changed most and with the new ODPs, then work through the remaining objectives. The NIST 800-171 Rev 3 transition guide summarizes the differences, and the NIST SP 800-171 Rev 3 compliance resource center collects related resources.
NIST SP 800-171A Rev 3 is the companion assessment publication to NIST SP 800-171 Rev 3. It defines assessment procedures, including assessment objectives and methods, for determining whether each security requirement is satisfied.
Examine, interview and test. Examine reviews documents and records, interview talks with the people responsible, and test exercises mechanisms or activities to see how they behave.
A requirement is generally treated as satisfied only when all of its assessment objectives are satisfied. One unmet objective can make the whole requirement other than satisfied, so each objective needs evidence.
Not at this time, as far as we know. CMMC Level 2 has been tied to NIST SP 800-171 Rev 2. Many DIB contractors are still preparing for Rev 3 now.