WHITEPAPER: Preparing for the Transition to NIST SP 800-171 Revision 3

Aligning CMMC Level 2, DFARS, and the Proposed FAR CUI Rule for Long-Term Federal Compliance

By Asher Glasgow, KLC Consulting; LCCA

Executive Summary

Federal cybersecurity requirements are entering another period of significant change. As the federal government moves toward NIST Special Publication (SP) 800-171 Revision 3 (Rev. 3) as the long-term baseline for protecting Controlled Unclassified Information (CUI) must prepare for evolving expectations while continuing to satisfy today’s contractual obligations.

The proposed Federal Acquisition Regulation (FAR) Controlled Unclassified Information (CUI) Rule would establish standardized CUI protection requirements across civilian federal agencies, while the Department of Defense (DoD) is preparing to transition the Cybersecurity Maturity Model Certification (CMMC) program from NIST SP 800-171 Revision 2 (Rev. 2) to Rev. 3 through future rulemaking. Together, these initiatives reflect a broader federal effort to harmonize cybersecurity requirements for protecting Controlled Unclassified Information across federal acquisitions.

For organizations beginning or advancing their CMMC Level 2 journey, the question is not whether to implement Rev. 2 or Rev. 3, it is how to meet today’s contractual requirements while building a cybersecurity program capable of adapting to tomorrow’s expectations.

This paper examines how the proposed FAR CUI Rule, DFARS, and CMMC fit together, highlights the most significant changes introduced by Rev. 3, and provides practical recommendations to help organizations reduce future transition costs while strengthening long-term cybersecurity maturity.

The Federal Cybersecurity Landscape is Converging

For years, cybersecurity requirements for protecting Controlled Unclassified Information (CUI) were driven primarily through Department of Defense (DoD) contracts and the Defense Federal Acquisition Regulation Supplement (DFARS). Contractors supporting civilian agencies often encounter varying cybersecurity requirements depending on the agency and contract.

That landscape is changing.

Federal agencies are increasingly aligning cybersecurity expectations around common standards to improve the protection of CUI throughout the federal acquisition community. Rather than developing agency-specific cybersecurity frameworks, the federal government is moving toward standardized implementation of the National Archives and Records Administration (NARA) CUI Program and NIST SP 800-171 Revision 3.

This convergence reflects a broader effort to reduce inconsistencies across the federal acquisition environment. Historically, the Department of Defense (DoD) has driven many cybersecurity requirements through DFARS, while civilian agencies often implemented agency-specific contract language. Increasingly, agencies such as NASA, the General Services Administration (GSA), and others participating in the Federal Acquisition Regulation (FAR) process are aligning around common cybersecurity expectations for protecting CUI. Although agencies may continue to publish supplemental guidance based on their individual missions, the long-term trend is toward greater consistency in cybersecurity requirements across the federal government.

One of the most significant steps in this evolution is the proposed FAR CUI Rule (FAR Case 2026-001), including proposed FAR clause 52.240-7. If finalized, the rule would establish consistent CUI protection requirements across civilian agencies such as the Department of Energy (DOE), Department of Justice (DOJ), Department of Veterans Affairs (VA), Department of Health and Human Services (HHS), NASA, the General Services Administration (GSA), and numerous agencies.

The proposed FAR clause would require contractors to:

  • Identify and effectively manage Controlled Unclassified Information throughout its lifecycle.
  • Protect systems processing CUI using NIST SP 800-171 Revision 3.
  • Train personnel who create, process, or access CUI.
  • Maintain appropriate cybersecurity safeguards throughout contract performance.
  • Demonstrate continued protection of CUI through documented policies, procedures, and supporting evidence.

While the FAR CUI Rule has not yet been finalized, it provides valuable insight into the federal government’s long-term direction. Organizations that understand this path today can better position themselves for future compliance while minimizing costly program redesigns.

Understanding FAR, DFARS, and CMMC

FAR, DFARS, and CMMC work together within the federal cybersecurity ecosystem, but each serves a different purpose:

RequirementPurposeApplies To
FAR CUI Rule (Proposed)Establishes government-wide CUI protection expectations using Rev3Federal contractors supporting applicable agencies
DFARS 252.204-7012Establishes DoD cybersecurity and incident reporting requirementsDoD contractors handling CUI
CMMC 2.0Verifies implementation of required cybersecurity practicesDoD contractors handling FCI or CUI

In simple terms:

  • DFARS establishes the cybersecurity requirements for DoD contractors.
  • CMMC verifies implementation of those requirements.
  • The proposed FAR rule expands similar CUI protection expectations across the federal government.

The Transition to NIST SP 800-171 Revision 3

The most significant shift in the federal cybersecurity landscape is the transition from NIST SP 800-171 Revision 2 (Rev. 2) to Revision 3 (Rev. 3). While current CMMC Level 2 assessments remain based on Revision 2, both the proposed FAR CUI Rule and the Department of Defense’s stated intent to update CMMC through future revisions to 32 CFR Part 170 indicate that Revision 3 is expected to become the long-term cybersecurity baseline for protecting Controlled Unclassified Information (CUI).

Revision 3 represents more than a routine update to security controls. It reflects NIST’s broader shift toward outcome-based cybersecurity, emphasizing governance, enterprise risk management, supply chain security, and organizational accountability. While many familiar technical safeguards remain unchanged, organizations should expect greater emphasis on demonstrating that security practices are effectively managed, documented, and sustained over time.

For organizations with mature cybersecurity programs, the transition will primarily involve refining policies, strengthening governance, updating documentation, and expanding assessment evidence. Organizations that are just beginning their compliance journey have an opportunity to build with Revision 3 in mind, reducing the effort required during future regulatory transitions.

Revision 3 is expected to affect several key areas, while placing greater emphasis on demonstrating that cybersecurity is governed as an ongoing business process rather than simply a collection of technical controls. Although many organizations will find that their existing technical safeguards remain applicable, they should anticipate increased effort associated with governance, documented organizational decisions, executive oversight, assessment evidence, and continuous risk management.

Revision 2 vs. Revision 3: What Has Changed?

Although many foundational cybersecurity controls remain familiar, Revision 3 expands both the breadth and depth of cybersecurity expectations. The transition reflects a greater emphasis on organizational governance, documented decision-making, and continuous risk management.

TopicRevision 2Revision 3Organizational Impact
Security Domains14 control families17 control familiesBroader cybersecurity governance
Assessment ObjectivesApproximately 320Approximately 422Increased assessment effort and evidence collection
Organizationally Defined Parameters (ODPs)LimitedWidely incorporatedMore documented organizational decisions
GovernancePrimarily control implementationGreater executive oversight and accountabilityIncreased leadership involvement
Risk ManagementSecurity-focusedEnterprise-wide, continuous risk managementStronger governance processes
Supply Chain Risk ManagementLimited emphasisExpanded requirementsGreater oversight of third-party vendors
DocumentationSSPs, policies, POA&MsExpanded documentation and supporting evidenceMore comprehensive assessment preparation

These changes should not be viewed as a complete redesign of existing cybersecurity programs. Organizations that have implemented Revision 2 effectively already possess much of the technical foundation needed for Revision 3. The primary effort will involve expanding governance, documentation, and organizational processes rather than replacing technical security controls.

Organizationally Defined Parameters (ODPs)

One of the most notable additions in Revision 3 is the expanded use of Organizationally Defined Parameters (ODPs).

Rather than prescribing a single value for certain security settings, Revision 3 requires organizations to define, document, and justify security decisions based on their operational environment and risk tolerance. These documented decisions become part of the organization’s cybersecurity baseline and must be consistently implemented and maintained.

Examples of ODPs may include:

  • Audit log retention periods
  • Session timeout values
  • Frequency of security reviews
  • Authentication parameters
  • Configuration management timelines
  • Vulnerability remediation timeframes

The increased reliance on ODPs places greater importance on cybersecurity governance. Organizations must establish repeatable processes for approving, documenting, reviewing, and updating these parameters as risks evolve.

For contractors supporting multiple federal agencies, this becomes even more significant. Different agencies may publish supplemental guidance or establish agency-specific implementation expectations. Rather than maintaining multiple security baselines, organizations should evaluate applicable requirements and adopt the most stringent—or highest watermark—where practical. A standardized governance approach can simplify compliance while reducing operational complexity across multiple federal contracts.

Supply Chain Risk Management
Under Revision 3

Another significant enhancement in Revision 3 is the increased emphasis on Supply Chain Risk Management (SCRM).

Cybersecurity risk no longer resides solely within an organization’s own systems. Managed service providers, cloud service providers, software vendors, subcontractors, consultants, and other third parties frequently process, store, or support systems containing Controlled Unclassified Information. As a result, organizations are expected to understand and manage the cybersecurity risks introduced throughout their supply chain.

An effective Supply Chain Risk Management program extends beyond contractual requirements. Organizations should establish policies and processes to:

  • Identify third parties that access or support CUI.
  • Classify vendors according to business and cybersecurity risk.
  • Evaluate supplier security practices before engagement.
  • Continuously monitor higher-risk suppliers.
  • Reassess vendor risk periodically throughout the relationship.
  • Document risk acceptance decisions and mitigation activities.

Revision 3 reinforces the principle that organizations remain responsible for protecting CUI even when portions of their operations are supported by external service providers.

Organizations that establish mature SCRM programs will not only improve compliance readiness but also strengthen operational resilience against increasingly sophisticated supply chain threats.

A Risk-Based Approach to Third-Party Assessments

Not every supplier presents the same level of cybersecurity risk. Applying identical assessment requirements to every vendor is often inefficient and resource-intensive. Instead, organizations should adopt a risk-based methodology that aligns assessment rigor with the sensitivity of the services provided.

Vendor Risk Level Typical Assessment Approach
Low RiskAutomated security monitoring, vendor questionnaires, and annual reviews.
Moderate RiskDocumentation reviews, targeted security assessments, and validation of key cybersecurity controls.
High RiskComprehensive assessments including interviews, evidence reviews, technical validation, and ongoing monitoring for vendors supporting critical systems or handling CUI.

A tiered assessment methodology enables organizations to focus resources where risk is greatest while maintaining appropriate oversight across the broader supplier ecosystem. Combining automated monitoring tools with documented governance processes provides a scalable approach to managing third-party cybersecurity risks and supports the risk-based philosophy reflected throughout Revision 3.

Current Status and Transition to Revision 3

The proposed FAR CUI Rule and the Department of Defense’s transition of CMMC toward NIST SP 800-171 Revision 3 will occur through formal rulemaking and phased implementation. Until those changes are finalized and become effective:

  • Existing contractual cybersecurity requirements remain in place.
  • DoD contractors must continue meeting applicable DFARS requirements.
  • CMMC Level 2 assessments continue under the currently approved assessment criteria.
  • Civilian agencies will continue using existing contract provisions until updated FAR requirements are adopted.

Organizations should not wait for final implementation before preparing. While the specific implementation schedule and any grandfathering provisions will ultimately be determined through future rulemaking, organizations should expect a structured transition period rather than an immediate compliance deadline. Existing certifications and contractual obligations are unlikely to become obsolete overnight; however, organizations that delay planning may ultimately face more significant remediation efforts as future requirements are adopted. Preparing early allows organizations to spread implementation activities over time instead of compressing them into a short compliance window

The most effective approach is to maintain compliance with current requirements while gradually aligning cybersecurity programs with Revision 3 expectations. Organizations that begin preparation early can reduce future transition costs, avoid unnecessary redesign efforts, and strengthen their overall cybersecurity maturity.

A Practical Path Forward

Organizations beginning or advancing their CMMC Level 2 journey should focus on meeting current contractual obligations while building cybersecurity programs that can adapt to future federal requirements.

The goal is not to choose between Revision 2 and Revision 3. The goal is to establish a sustainable cybersecurity program that satisfies current assessment requirements while preparing for the federal government’s long-term direction.

Organizations should consider the following approach:

Build the Current Cybersecurity Foundation

Implement the technical controls, policies, and documentation necessary to meet current CMMC Level 2 requirements, including:

  • Access control
  • Multi-factor authentication
  • Encryption
  • Incident response
  • Logging and monitoring
  • Vulnerability management
  • Configuration management
  • Security awareness training
  • System Security Plans (SSPs)
  • Risk assessments
  • Supplier cybersecurity management

These capabilities remain foundational under both Revision 2 and Revision 3.

Incorporate Revision 3 Concepts Early

Organizations should integrate Revision 3 considerations into existing cybersecurity initiatives, including:

  • Stronger governance processes
  • Organizationally Defined Parameters (ODPs)
  • Supply Chain Risk Management (SCRM)
  • Enhanced documentation practices
  • Improved evidence collection
  • Clear control ownership

Building these practices into current programs reduces future transition effort and supports long-term cybersecurity maturity.

Develop a Rev. 2 to Rev. 3 Transition Roadmap

Organizations should conduct a structured Gap Assessment to identify:

  • Requirements that remain unchanged.
  • Areas requiring additional governance or documentation.
  • New cybersecurity expectations introduced by Revision 3.
  • Future investments needed to support compliance.
  • Assess anticipated increases in governance responsibilities, assessment evidence, executive oversight, and supplier risk management activities.

A phased transition roadmap allows organizations to prioritize improvements based on risk, resources, and business objectives.

Recommended Strategy by Organization Maturity

Organization StatusRecommended Strategy
Already CMMC Level 2 CertifiedMaintain current compliance, monitor regulatory developments, perform a Rev. 2 to Rev. 3 Gap Assessment, and begin transition planning.
Currently Implementing CMMC Level 2Meet current requirements while designing policies, documentation, and governance processes with Revision 3 expectations in mind.
No Formal Cybersecurity ProgramEstablish a NIST-aligned cybersecurity foundation while incorporating Revision 3 planning from the beginning.

What DIB Organizations Should Do Now

The transition to Revision 3 should not be treated as a separate compliance initiative. Organizations should build upon the cybersecurity investments already being made for CMMC and NIST SP 800-171.

Key priorities include:

Strengthen Governance: Establish executive ownership, define cybersecurity responsibilities, and implement governance processes that support ongoing risk management and documented security decisions.

Understand the CUI Environment: Identify where CUI is stored, processed, and transmitted, define system boundaries, validate data flows, and reduce unnecessary exposure.

Maintain Strong Technical Controls: Continue implementing foundational safeguards such as multi-factor authentication, encryption, access control, vulnerability management, logging, monitoring, and incident response.

Keep Documentation Assessment Ready: Maintain current System Security Plans (SSPs), policies, procedures, risk assessments, Plans of Action and Milestones (POA&Ms), training records, and supporting evidence.

Develop a Revision 3 Roadmap: Evaluate Rev. 2 to Rev. 3 gaps, prioritize governance improvements, assess ODP requirements, and strengthen Supply Chain Risk Management processes.

Organizations that begin planning now will be better positioned to navigate future regulatory changes while maintaining compliance and minimizing transition costs.

How KLC Consulting Can Help

As federal cybersecurity requirements continue to evolve, organizations need practical guidance that connects regulatory expectations with operational cybersecurity improvements. KLC Consulting helps organizations understand emerging requirements, evaluate current readiness, and develop transition strategies that support both immediate compliance needs and long-term cybersecurity maturity.

KLC Consulting’s consultants bring experience designing and assessing cybersecurity and third-party risk management programs across highly regulated industries. That experience helps organizations translate evolving federal cybersecurity requirements into practical, risk-based implementation strategies that support both compliance and operational resilience.

We supports organizations through:

NIST SP 800-171 and CMMC readiness assessments

Evaluating current cybersecurity practices, identifying gaps, and developing actionable remediation plans aligned with assessment requirements.

Rev. 2 to Rev. 3 transition planning

Performing Gap Assessments to identify changes in governance, documentation, assessment evidence, Organizationally Defined Parameters (ODPs), and security processes.

Cross-agency cybersecurity alignment reviews

Helping organizations evaluate applicable federal requirements and develop cybersecurity strategies capable of supporting multiple government customers through a consistent, risk-based approach.

Supply Chain Risk Management (SCRM) assessments

Helping organizations establish risk-based supplier evaluation processes, assess third-party cybersecurity risks, and improve oversight of vendors that support critical business functions or handle sensitive information.

CUI identification and system boundary reviews

Evaluating where CUI exists within an organization’s environment, validating system boundaries, and improving protection strategies.

System Security Plan (SSP), policy, and documentation development

Creating and improving documentation needed to demonstrate cybersecurity maturity and assessment readiness.

Executive cybersecurity advisory services

Providing leadership with practical guidance to understand regulatory changes, prioritize investments, and establish sustainable cybersecurity programs.

For organizations that have already invested in CMMC Level 2 preparation, Rev. 3 should be viewed as an evolution rather than a restart. The foundation created through current compliance efforts provides a strong starting point for future improvements.

Conclusion

Federal cybersecurity requirements are converging around a common objective: protecting Controlled Unclassified Information through mature, risk-based cybersecurity practices.

The transition to Rev. 3 represents more than an increase in assessment objectives or control families. It reflects a broader evolution toward stronger governance, organizational accountability, executive involvement, supply chain oversight, and continuous enterprise risk management. Organizations that build these capabilities now will be better positioned to adapt as federal cybersecurity requirements continue to mature.

Organizations should continue meeting current contractual requirements while preparing for the direction federal cybersecurity requirements are moving. By incorporating Rev. 3 considerations into existing CMMC efforts, organizations can reduce future transition costs, minimize compliance disruption, and build cybersecurity programs that are more resilient and adaptable.

The organizations best positioned for this transition will be those that begin preparing before requirements become mandatory. A proactive approach allows companies to strengthen security practices, improve operational maturity, and remain competitive in an increasingly security-focused federal marketplace.

KLC Consulting helps organizations navigate this evolving environment by translating regulatory changes into practical cybersecurity strategies that support current compliance obligations while preparing for future federal requirements.

Disclaimer
This paper is provided for informational purposes only and does not constitute legal, regulatory, or contractual advice. Organizations should consult qualified compliance professionals when making cybersecurity and compliance decisions. Information is current as of August 2026.

References

  • National Archives and Records Administration (NARA). Controlled Unclassified Information (CUI) Program. 32 CFR Part 2002.
  • Office of Information and Regulatory Affairs (OIRA). Cybersecurity Maturity Model Certification (CMMC) Program. Regulatory Information Number (RIN) 0790-AM01, Unified Agenda of Federal Regulatory and Deregulatory Actions. RegInfo.gov. https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0790-AM01
  • U.S. Department of Defense. Cybersecurity Maturity Model Certification (CMMC) Program. 32 CFR Part 170.
  • U.S. Department of Defense. Defense Federal Acquisition Regulation Supplement (DFARS) Clause 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident Reporting.
  • U.S. Department of Defense. Cybersecurity Maturity Model Certification (CMMC) Acquisition Rule. 48 CFR Parts 204 and 252.
  • U.S. General Services Administration, Department of Defense, and National Aeronautics and Space Administration. Federal Acquisition Regulation (FAR) Case 2026-001: Controlled Unclassified Information (CUI). Proposed Rule.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name
Email*
Want to keep up-to-date with our latest news and announcements?

Psssst. We’re cybersecurity professionals and dedicated privacy advocates. Rest assured, the confidentiality of your information is our top priority!

Check out our YouTube channel and LinkedIn pages for the latest informational and educational resources for Cybersecurity Maturity Model Certification.

Scroll to Top