NIST Publishes SP 800-171A Small-Business Primer
The assessment guide addresses Rev. 3 methodology directly, determination statements and security assessment plans have tripped up small contractors since the revision landed.
TL;DR
NIST released a small-business primer for SP 800-171A Revision 3, the companion assessment guide to the CUI security standard. The resource walks small contractors through assessment procedures, determination statements, and how to build a security assessment plan, areas where under-resourced firms have struggled since Rev. 3 was published. The primer also clarifies what roles different parties play in the CUI ecosystem and explicitly notes that CMMC remains pegged to SP 800-171 Revision 2, urging contractors to check their contracts for which version applies. NIST will host an Oct. 29 webinar on the primer.

NIST has been building out its small-business library for contractors who don't have dedicated compliance staff, and the new SP 800-171A primer is the latest piece, and the first to tackle the Rev. 3 assessment methodology head-on for this audience.
The primer doesn't replace SP 800-171A itself. It's a bridge. It explains how assessment procedures map to specific controls, what a determination statement actually is, and how to prepare a security assessment plan. Those are the components that send small firms into rework spirals when an assessor shows up and the documentation doesn't match the methodology.
Where the primer is unusually blunt is on the Rev. 2 vs. Rev. 3 question. Contractors have been asking which version governs their obligations, and the answer buried in the primer is the one they need to hear: CMMC is currently based on Revision 2, and you look to your contract (not the latest NIST publication) to tell you which version applies. That's the kind of clarity small firms can't get from reading the FAR.
The primer also includes a chart defining roles in the CUI ecosystem, something that helps a small subcontractor understand who's asking for what and why.
What's still missing is a comparable primer for SP 800-172, the enhanced security requirements that underpin CMMC Level 3. NIST's announcement frames this as "the first part of an effort to begin breaking down components of 800-171r3 for the small business community," but it's silent on whether 800-172 gets the same treatment. For the small contractors chasing Level 3 work, that gap matters.
Published ·Deep Fathom