DBITDefenseCMMC Level 2 · Readiness
Standards · NIST · April 18, 2026

NIST SP 800-171: Rev. 2 vs Rev. 3.

NIST published Revision 3 of SP 800-171 in May 2024. The CMMC Program rule (32 CFR Part 170) currently references Revision 2 as the underlying control catalog. Both documents are publicly available from NIST.

Published April 18, 2026South Florida · Palm Beach · Broward · Miami-Dade
(561) 887-5470
Tag
Standards
Citations
3
Type
Plain summary
Original
no control interpretation
No. 01

Summary and dates.

Publication dates

Feb 2020
NIST SP 800-171 Rev. 2 published (with update 1 in 2021).
NIST CSRC
May 2024
NIST SP 800-171 Rev. 3 published.
NIST CSRC

Which version CMMC currently references

32 CFR Part 170, as published in the Federal Register, references NIST SP 800-171 Rev. 2 as the control catalog for CMMC Level 2. Any transition to Rev. 3 would require an amendment to the CMMC Program rule.

Structural changes in Rev. 3 (factual)

NIST has published a public mapping between Rev. 2 and Rev. 3. The total control count, the family structure, and the wording of several requirements changed between revisions. Refer to NIST CSRC for the full mapping document.

No. 02

Sources and citations.

Primary references

DBIT Defense does not interpret control intent or republish substantive control text. All claims above link to primary sources for verification.

No. 03

Related insights.

Know where you stand
before the requirement
reaches the contract.

Start with a focused CMMC readiness assessment. We will send a written scoping summary within two business days, or a candid recommendation if it is not the right fit.

Or call directly (561) 887-5470Mon–Fri · 9am – 6pm ET · South Florida

Request a readiness assessment