cmmctrade-pressNewsThe Broadside3 min read

DOD to shift CMMC to NIST 800-171 Rev. 3 with expanded assessment scope

The control count drops from 110 to 97, but assessment objectives jump past 420 and new supply-chain risk management requirements push compliance beyond IT's walls.


TL;DR

DOD is planning an interim final rule to transition CMMC Level 2 compliance from NIST SP 800-171 Revision 2 to Revision 3, reducing controls from 110 to 97 while expanding assessment objectives from 320 to roughly 420 and adding supply-chain risk management requirements. Presenters at an Aug. 25 NDIA webinar warned that supply-chain risk management isn't an IT function and that contractors treating 800-171 compliance as a security-team problem will find Rev. 3 especially punishing. No effective date has been set; the CMMC Reform Task Force delivers recommendations in mid-September, and DOD must still issue guidance on organization-defined parameters before contractors can fully align.

DOD to shift CMMC to NIST 800-171 Rev. 3 with expanded assessment scope
Editorial illustration · drawn by The Broadside

The asymmetry is the story. DOD's planned transition of CMMC Level 2 from NIST SP 800-171 Revision 2 to Revision 3 shrinks the control count from 110 to 97, but the number of assessment objectives jumps from 320 to roughly 420, and the framework introduces supply-chain risk management requirements that can't be handled from inside the IT department. Fewer controls, more audit surface. That's the trade.

The department intends to issue an interim final rule to make the switch, according to an Aug. 25 NDIA webinar featuring Vincent Scott of the Defense Cybersecurity Group, Joe Devine of Axiotrop, and others. The IFR path means DOD can adopt Rev. 3 without the full notice-and-comment cycle, accelerating the timeline. But exactly when remains unclear: the CMMC Reform Task Force, stood up by DOD CIO Kirsten Davies in July, is expected to deliver recommendations in mid-September, and the program's phase-two rollout is paused until the review concludes.

Devine characterized Rev. 3 as "significantly more work and by design." The framework introduces organization-defined parameters (assessment criteria that individual agencies set for themselves) meaning DOD will need to publish its own ODP guidance before contractors can fully align. Scott flagged supply-chain risk management as the structural shift that catches organizations off guard. It's "not really a CISO function," he said, and treating 800-171 compliance as an IT problem "has always been a mistake, but that is even more true under revision three." The framing is enterprise risk, not server-room hygiene.

For contractors mid-certification, the webinar's practical advice was clear: don't stop working toward Rev. 2 to pivot early. "Work on Rev. 2, get through your certification assessment and then begin your transition process," Scott said. There's no effective date yet, and organizations that delay certification waiting for Rev. 3 could face contract-access gaps with nothing to show for the hesitation.

The transition also opens a harmonization question that extends beyond DOD. The FAR Council issued a proposed rule in June to standardize CUI protections across civilian agencies, aligned with Rev. 3. GSA updated its IT Security Procedural Guide in January to require Rev. 3 compliance for CUI. The Professional Services Council, in an Aug. 14 response to DOD's CMMC review RFI, urged the Pentagon and the FAR Council to "coordinate on a single Revision for use across the federal enterprise." If they do, Rev. 3 becomes the governmentwide CUI standard, not just a DOD requirement.

The Cyber AB's spinoff assessor-training body, the CAICO, is already building bridge courses so CMMC assessors certified under Rev. 2 can upgrade to Rev. 3, and vice versa. CAICO director Todd Gagnon said at an Aug. 25 town hall that release dates for those courses "will be finalized following the outcome of the Reform Task Force."

What's missing: an effective date, clarity on whether existing CMMC Level 2 certifications will require recertification, and DOD's ODP guidance. Until those land, the only safe posture is to pursue Rev. 2 certification and plan the Rev. 3 transition as a separate business initiative, one that reaches procurement, legal, and executive leadership, not just the security team.


Published ·Deep Fathom