NIST 800-171 Rev. 3: What to Update First

NIST 800-171 Rev. 3: What to Update First

NIST SP 800-171 Rev. 3 introduces important changes for defense contractors protecting Controlled Unclassified Information (CUI).

If your organization has already built its security program around Rev. 2, you have a foundation to work from. The challenge is figuring out which parts of that foundation need to change, which can stay largely the same, and where Rev. 3 introduces new decisions.

There is an important distinction for defense contractors: NIST finalized Rev. 3 in May 2024, but current DoD CMMC implementation continues to use Rev. 2. The Department has said it plans to incorporate Rev. 3 through future rulemaking.

That means preparing for Rev. 3 is not about throwing out your existing program. It is about understanding the differences, identifying what applies to your environment, and deciding where to incorporate changes into the security work you are already doing.

For most defense contractors, the best approach is not to update everything at once.

Start with the areas that affect your CUI environment, security practices, documentation, and risk management. Then work from there.

What Changed in NIST SP 800-171 Rev. 3?

The NIST SP 800-171 Rev. 3 revision restructures and updates the security requirements, aligns their structure and language with NIST SP 800-53 Rev. 5, introduces organization-defined parameters (ODPs), and provides additional specificity and outcome-oriented guidance.

Some of the changes that may have the biggest impact on defense contractors include:

  • Organization-defined parameters (ODPs) which force organizations to establish certain specific values, frequencies, thresholds, and other parameters to be established based on organizational needs

  • Updates to security requirements and their structure

  • Changes to tailoring criteria

  • Greater specificity intended to reduce ambiguity

If you want a broader look at what changed between revisions, RAMPQuest's NIST SP 800-171 Rev. 3 overview provides more background on the transition and what contractors should be considering.

What Should Defense Contractors Update First for Rev. 3?

You don't necessarily need to rebuild your entire security program to begin preparing for Rev. 3.

Instead, start with the areas that can influence the rest of your program. That gives you a clearer picture of what needs to change before you start rewriting policies or updating individual requirements.

 

1. Start With Your CUI Environment and System Boundaries

Before updating individual security requirements, take a close look at where CUI resides, how it moves through the environment, and which systems and processes protect it.

This gives you the context needed to determine how Rev. 3 changes may affect your organization.

Review areas such as:

  • Systems or components that process, store, or transmit CUI

  • CUI data flows

  • System boundaries

  • Users and roles with access to CUI

  • Cloud services and other technology supporting the CUI environment

  • Third-party systems and vendors

  • Changes to the environment since your last assessment

This step is easy to overlook when the focus is on comparing one requirement list to another.

But a control-by-control comparison doesn't tell the whole story.

A change to your environment can affect how a requirement is implemented, what documentation supports it, and what evidence you need to maintain.

That's why understanding your current environment should come before making large-scale updates.

 

2. Identify Which ODPs Apply to Your Organization

Organization-defined parameters are one of the most important changes to understand in Rev. 3.

The inclusion of organization-defined parameters (ODPs), allows organizations to tailor select security controls to specific security requirements, as determined by unique organizational risk management strategies. NIST explains that these values can be informed by laws, regulations, policies, standards, guidance, and an organization's mission and business needs.

For defense contractors, that means Rev. 3 can involve more than simply asking, “Do we meet this security requirement?”

You may also need to ask:

  • What value or parameter applies to our environment?

  • Who is responsible for making that decision?

  • What business or security considerations should inform it?

  • Where should the decision be documented?

  • What policies, procedures, or technical configurations need to reflect it?

  • How will the organization demonstrate the requirement is met?

Don't treat ODPs as a documentation exercise.

The decisions behind them can affect implementation and maintenance.

 

3. Review Your System Security Plan (SSP)

Once you understand the changes and determine which requirements and ODPs affect your environment, look at the documentation that supports your security program.

This is where many organizations find gaps.

A security practice may be working as intended, but the documentation describing it may no longer reflect the environment.

Review items such as:

  • SSP

  • Policies and procedures

  • Roles and responsibilities

  • Security configurations and processes

  • Supporting documentation

  • Assessment evidence

Your documentation should describe how your organization actually protects CUI. Not how the environment looked during the last assessment.

This is especially important when systems, personnel, vendors, or processes have changed.

For Rev. 3 preparation, think about the connection between your environment, your practices, your documentation, and your evidence. If one changes, the others may need to change with it.

 

4. Look at Risk Management, Assessment, and Monitoring

Rev. 3 also puts greater emphasis on areas such as risk management, assessment, authorization, and monitoring.

That makes this a good time to look beyond individual requirements and ask how your organization manages its security program over time.

For example:

  • How are security risks identified and prioritized?

  • How are findings tracked through remediation?

  • How do you verify that security practices continue to operate as intended?

  • How often are changes to the environment reviewed?

  • Who is responsible for ongoing monitoring?

  • How are changes reflected in documentation and evidence?

These questions matter because CUI protection isn't a one-time project.

Systems change. Employees change roles. New technologies and vendors are introduced. Security responsibilities shift.

Your security program needs a way to keep up.

 

5. Review Supply Chain Risk

Finally, take a closer look at supply chain risk management.

Defense contractors rarely operate in isolation. Vendors, suppliers, cloud services, and other third parties all play a role in how CUI is protected.

Consider reviewing:

  • Vendors with access to systems or information

  • Third-party services supporting the CUI environment

  • Supplier security requirements

  • Vendor risk assessment processes

  • Third-party access

  • Dependencies that could affect the security of the CUI environment

Start by identifying where your existing supply chain practices align with Rev. 3 and where additional work may be needed.

How Should Contractors Approach the Rev. 3 Transition?

Once you've worked through these areas, the next step is to turn what you found into an actionable plan.

A simple approach is:

incorp

 

Assess

Look at your current environment and security program.

Ask:

  • What systems and processes are in scope?

  • How are you currently protecting CUI?

  • What security practices and documentation are already in place?

  • What resources, time, and costs could be involved in addressing identified gaps?

If your organization is currently operating under Rev. 2 requirements, document that baseline before deciding what needs to change for Rev. 3.

 

Identify

Compare your current program against the applicable Rev. 3 requirements.

Look for:

  • New or changed requirements

  • Applicable ODPs

  • Documentation gaps

  • Changes to security practices

  • Areas where existing processes may need to be strengthened

For contractors currently operating under CMMC requirements based on Rev. 2, this comparison should also identify differences that could affect future Rev. 3 implementation. DoD has specifically noted that organizations implementing Rev. 3 need to account for gaps between Rev. 2 and Rev. 3 while Rev. 2 remains the current CMMC assessment standard.

 

Prioritize

Not every Rev. 3 change will have the same impact on your organization.

Give greater attention to changes that:

  • Directly affect CUI protection

  • Change how a security requirement is implemented

  • Require an organization-specific decision

  • Create gaps in policies, procedures, or evidence

  • Introduce or expose risks

This is where gap analysis is useful. Instead of treating every change as an immediate remediation item, use the results to separate what needs attention now from what can be incorporated into planned security work.

 

Incorporate

Finally, look for opportunities to build Rev. 3 preparation into work your organization is already doing.

If you're already updating policies, reviewing access controls, improving monitoring, assessing vendors, updating system documentation, or addressing security findings, consider those efforts through a Rev. 3 lens.

That can help contractors prepare for future requirements without creating an entirely separate compliance project.

Do You Need to Replace Your Rev. 2 Program?

For contractors, preparing for Rev. 3 does not mean abandoning requirements that currently apply to your organization.

Your current contractual and regulatory obligations still matter. For CMMC, the Department currently identifies NIST SP 800-171 Rev. 2 as the standard while it works toward incorporating Rev. 3 through future rulemaking.

That means you can use your existing Rev. 2 program as a starting point while identifying where Rev. 3 changes may require updates.

The goal is not to maintain two separate security programs. It is to understand where the programs differ, address important gaps, and incorporate future-facing improvements into the security program you already maintain.

How RAMPQuest Can Help

Preparing for NIST SP 800-171 Rev. 3 can raise questions that don't have simple checklist answers.

  • Which requirements affect your environment?

  • What should you update first?

  • Which documentation needs to change?

  • How should you approach ODPs?

  • Which gaps should receive attention now, and which can be incorporated into ongoing security work?

RAMPQuest helps defense contractors evaluate those questions in the context of their existing security program.

Our approach can help you understand your current environment, identify Rev. 3 gaps and dependencies, review documentation and evidence, prioritize remediation, and determine how to incorporate changes without creating unnecessary duplicate work.

For organizations still operating against Rev. 2 requirements, that can also mean identifying where Rev. 2 and Rev. 3 differ so you can prepare for future requirements while continuing to address what applies today.

The goal is to help you understand what needs to change, prioritize the work, and build those improvements into the security program you already have.

For defense contractors preparing for the next phase of NIST 800-171 implementation, the first step is not updating everything. It is understanding what applies to your environment and where your existing program needs to evolve.