In this blog, Rob Teague, VP of CMMC Services and Lead CMMC Assessor, and Dr. Thomas Graham, CISO and Lead CMMC Assessor for Redspin, revisit the shift from NIST 800,171 Rev. 2 to NIST 800,171 Rev. 3, now that the Department of War (formerly DoD) has published a formal rulemaking timeline for the transition. This blog highlights the key updates and what they mean for Organizations Seeking Certification (OSCs).
Where Things Stand Today
CMMC Level 2 began November 2025, and Phase 2 of the rollout begins November 10, 2026. Right now, every CMMC assessment is still benchmarked against NIST 800,171 Rev. 2.
That said, the transition to Rev. 3 is no longer just a future possibility. A recent DoD Unified Agenda filing formally confirmed the department is defining a transition period from Rev. 2 to Rev. 3, targeting an Interim Final Rule around July 2026. Based on how DoD has handled prior transitions, expect a formal announcement with 12 to 24 months of advance notice once that rule finalizes, putting realistic enforcement somewhere in the late 2026 to 2027 window.
One additional detail from that filing worth noting. DoD’s updated cost-benefit analysis now estimates roughly 20% fewer total companies will be affected by CMMC than earlier projections assumed, reflecting a more current count of the Defense Industrial Base.
Bottom line for OSCs: Rev. 2 is your assessment baseline today, but start mapping now.
NFOs, ODPs and FIPS:
One of the more structural changes in Rev. 3 is that most of the NFO (non federal organization) controls, previously tucked into Appendix E under Rev. 2, are now built directly into the body of the NIST 800,171 practices. This brings more clarity and less ambiguity to what was previously an assumed, rather than explicitly stated, requirement.
Rev. 3 also introduces 88 Organizationally Defined Parameters (ODPs) across the practices, things like password length, session timeout duration, or account inactivity thresholds, that were previously left vague with language like “periodically” or “as needed.” NIST’s framework leaves agencies room to set these values. For CMMC purposes, DoD has already published its own defined ODP values that contractors will need to meet once Rev. 3 is formally adopted. In other words, ODPs are not simply an internal federal agency matter. They will directly shape what OSCs are required to document and implement.
For DoD organizations concerned about the removal of explicit FIPS 140.2 references in Rev. 3, that concern can largely be set aside. While specific citations to FIPS 140,2 were removed from the text, cryptographic requirements in Rev. 3 can still be satisfied through FIPS or NSA approved standards. DoD organizations should expect FIPS 140,2 validated cryptographic solutions to remain a practical requirement.
Objectives and Assessments:
Rev. 3 is structured differently than Rev. 2, and it is worth being precise here since the numbers matter for assessment planning. Rev. 2 organized 110 security requirements around 320 assessment objectives in NIST 800.171A. Rev. 3 reduces the top line requirement count to 97, but that is not the full picture. Many withdrawn Rev. 2 requirements were folded into other requirements rather than eliminated, and the corresponding 800.171A determination statements actually increased by roughly 32% to 422. In practical terms, Rev. 3 assessments will likely involve more, not fewer, points of verification.
CMMC’s assessment methodology will need to be formally updated to align once Rev. 3 is adopted. Exactly how that reshapes assessment length, cost, or C3PAO scoping is still being finalized.
Language Shift and Expansion to Other Agencies:
Rev. 3 also reflects a broader shift in language, moving from a DoD centric framing toward a more standardized, agency neutral document. This may signal eventual expansion of NIST 800.171 style requirements into other federal departments, such as Energy or Health and Human Services, in pursuit of more consistent CUI protection standards across government.
What OSCs Should Do Now:
- Keep your SSP, POA&M, and assessment evidence aligned to Rev. 2. That remains the standard C3PAOs assess against today.
- Start a Rev. 3 crosswalk in parallel. Map your current Rev. 2 controls to their Rev. 3 equivalents so the eventual transition is a translation exercise, not a rebuild.
- Watch for the Interim Final Rule. Once DoD’s rulemaking clears, a firmer enforcement date and updated assessment guidance will follow.
- Do not wait to start your CMMC journey. Organizations still working toward initial Rev. 2 compliance should keep moving. A Rev. 3 transition on the horizon does not pause today’s requirements.
Summary:
The formal DoD filing on the Rev. 2 to Rev. 3 transition confirms this shift is now a matter of when, not if. Rev. 3 brings more structure, more explicit parameters, and, in practice, more rigorous assessment criteria than the reduced requirement count might suggest. While Rev. 3 is not yet a CMMC requirement, organizations should treat this as the moment to begin preparing in parallel with their Rev. 2 obligations, rather than waiting for a mandate to force a scramble.
How Redspin can help >>
We are already consulting clients on Rev. 3. If you have questions about any aspect of CMMC compliance, or would like a more detailed conversation with a CMMC assessor about third-party providers, readiness, documentation, or training, contact us.
Book a meeting to tackle CMMC with Redspin: