The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Independent research · authority and version guidance

NIST 800-171 Interim Baseline: Which Revision Actually Binds You Right Now

Last updated:

Last verified: against 32 CFR Part 170, DFARS, NIST, SPRS, Department implementation guidance, and related primary sources.

By The Defense Compliance Report Editorial TeamThe Defense Compliance Report is an independent trade publication on CMMC and Defense Industrial Base compliance.

Published: August 17, 2026 · Last reviewed: August 17, 2026 · Last verified: August 17, 2026

The NIST 800-171 interim baseline is not a separate federal standard. For CMMC Level 2, Revision 2 remains the controlling baseline today; the exact clause and written instrument determine the contractual obligation.

Educational research — not legal, contractual, or compliance advice. This article has not been reviewed by a published CMMC Subject Matter Advisor. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or Registered Provider Organization (RPO), and where contract interpretation is material, a qualified federal-contracts attorney. The written instrument governing your work and the information you actually handle set your requirement — not a checklist, and not this page. The Defense Compliance Report is not affiliated with the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.


The phrase NIST 800-171 interim baseline is not a defined term in 32 CFR Part 170, NIST SP 800-171, or the DFARS. It is shorthand — and it is shorthand for something real.

For CMMC Level 2 today, the controlling baseline is NIST SP 800-171 Revision 2: 110 security requirements across 14 families. Section 170.14 names that exact revision. Where a solicitation or award incorporates the deviation version of DFARS 252.204-7012 under Class Deviation 2024-O0013, Revision 1, that clause also requires Revision 2 instead of the version in effect when the solicitation was issued.

What can change that answer: the exact clause text in your solicitation, contract, subcontract, amendment, or modification; civilian-agency requirements that expressly name another revision; and a pending Department rule that has not published.

The original CMMC Phase 1 period began November 10, 2025 and was scheduled to run through November 9, 2026. The Department suspended the planned November 10, 2026 Phase 2 transition on July 13, 2026. That suspension changed which assessment designations may be placed in new procurement requirements. It did not replace Revision 2, cancel the Phase 1 self-assessment posture, or suspend DFARS 252.204-7012.

That is the verdict. The rest of this page shows the instrument, the dates, the two separate SPRS records people keep collapsing into one, and the three events that would make this answer change.

A note on Department names. Current Department web materials and the July 2026 memorandum use “Department of War” and “DoW.” The codified text of 32 CFR Part 170 and the DFARS still uses “Department of Defense” and “DoD.” We use the Department in our own prose and preserve each source’s exact name when identifying a rule, clause, or memorandum. The authority is the actual instrument, not the letterhead.


The NIST 800-171 interim baseline authority ledger

Several instruments can look like they answer the same question. They do not perform the same job. We built this ledger by asking one question of each source: what does this document actually control?

Instrument — What it actually controls — Answer on August 17, 2026 — What would change it
InstrumentWhat it actually controlsAnswer on August 17, 2026What would change it
NIST SP 800-171 Revision 2The 110-requirement, 14-family technical baseline incorporated into the current CMMC ruleWithdrawn at NIST, but still the CMMC Level 2 baselineAn effective rule or contract instrument adopting another revision
NIST SP 800-171 Revision 3NIST’s current 97-requirement, 17-family publicationFinal at NIST; not the CMMC-controlling Level 2 versionIncorporation through an effective rule, clause, amendment, or modification
32 CFR 170.14CMMC model requirementsLevel 2 uses Revision 2; Level 3 adds 24 selected requirements from NIST SP 800-172 February 2021An amendment to 32 CFR Part 170
Class Deviation 2024-O0013, Revision 1The deviation version of DFARS 252.204-7012 prescribed for covered Department solicitations and contractsNames Revision 2 and remains in effect until rescindedRescission, replacement, or different written clause text in the instrument
Codified DFARS 252.204-7012Safeguarding covered defense information and cyber incident reportingIts codified text points to the NIST SP 800-171 version in effect when the solicitation is issued, unless the contracting officer authorizes another versionThe deviation clause or other written direction incorporated into the award
DFARS 252.204-7019 and 252.204-7020The NIST SP 800-171 DoD Assessment score stream: Basic, Medium, and High AssessmentsThe codified clauses remain published; specific Department actions may use RFO-deviation text insteadThe clause and deviation text incorporated into the instrument
DFARS 252.204-7021 and 252.204-7025CMMC status, CMMC UID, self-assessment results, flow-down, and annual affirmationEffective; current contract eligibility depends on the designation in the written instrumentAmendment, modification, or a later acquisition rule
July 13, 2026 implementation memorandumDepartment implementation direction during the program reviewNew requirements packages may designate Level 1 (Self) or Level 2 (Self), not Level 2 (C3PAO) or Level 3 (DIBCAC); select Government-led assessments continueFurther Department direction after the review
RIN 0790-AM01A planned amendment transitioning CMMC from Revision 2 to Revision 3Final Rule Stage in the Unified Agenda, but unpublished and not effectivePublication of enforceable Federal Register text and its stated effective date
FAR Case 2026-001, 91 FR 37550A proposed government-wide CUI safeguarding frameworkProposed only; it does not control a contract unless and until final text or another written instrument makes it applicableA final rule or contract-specific requirement

Methodology note. This table separates publication status, program requirements, contract clauses, assessment records, and implementation direction. A government announcement does not automatically rewrite a solicitation, prime contract, or subcontract. Verify the operative written instrument and every amendment or modification.

Read the ledger sideways and the confusion finally makes sense

Four statements are true at the same time:

  1. NIST superseded Revision 2 with Revision 3 in May 2024.
  2. The CMMC Program Rule still incorporates Revision 2 for Level 2.
  3. The active 7012 class deviation directs use of Revision 2 where its clause is incorporated.
  4. The Department and FAR Council have rulemaking activity pointed toward Revision 3, but neither pending action has changed the current CMMC Level 2 baseline.

The instruments are answering different questions. NIST tells you what NIST currently publishes. The CFR tells you what CMMC presently uses. The clause in your award tells you what you promised. The memorandum tells contracting personnel what may be designated during the suspension. The Unified Agenda tells you what the Department plans to change next.

That is why “just tell me which version” has no honest one-word answer. It has a one-instrument answer.

Who this page is for

  • Compliance leads, IT directors, owners, and CISOs who need to state in writing which revision their program is built to and why.
  • Contractors whose prime or contracting officer asked which version they implement.
  • Teams that opened NIST’s Revision 2 page, saw “withdrawn,” and got a cold feeling.
  • Contractors deciding whether to fund a Revision 3 migration before the transition rule exists.
  • Companies trying to reconcile an SPRS score, a CMMC status, and a contract clause that do not appear to tell the same story.

Who should start somewhere else

  • You need to determine whether you handle FCI or CUI: start with the CMMC scoping guide.
  • You do not know whether Level 1, Level 2, or Level 3 applies: use the CMMC levels guide.
  • You need the technical Rev. 2-to-Rev. 3 comparison: use the dedicated NIST 800-171 Rev. 2 vs. Rev. 3 guide. That guide handles the technical comparison; this page stays on the authority question.
  • You need a legal determination on a specific award or flow-down: take the authority ledger and the actual instrument to qualified federal-contracts counsel.

What does “NIST 800-171 interim baseline” actually mean?

It is not a regulation, a NIST publication, or a reduced temporary control set. It is searcher shorthand for the current posture: the Department is in a temporary CMMC implementation review, while “baseline compliance with NIST SP 800-171 Rev. 2” continues through Level 1 and Level 2 self-assessments and select Government-led assessments.

The July memorandum uses those ideas separately: “during this suspension” and “baseline compliance with NIST SP 800-171 Rev. 2.” Our reading is that contractors combined the temporary implementation posture with the unchanged technical baseline and started calling the result an “interim baseline.” That explains the phrase. It does not turn the phrase into a defined term.

The distinction has money attached. If you hear “interim baseline” and assume there is a lighter 800-171 standard until Phase 2 restarts, you will under-build. There is no reduced interim set. For Level 2, there are still 110 Revision 2 requirements, and the assessment and scoring rules still operate against that set.

Five layers people are collapsing into one

Most arguments about “which baseline applies” are two people answering different layers:

  1. The security baseline — which revision and requirement set your controls are built to.
  2. The assessment designation — Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC), and which designation may be placed in a procurement during the suspension.
  3. The contractual instrument — the solicitation, prime contract, subcontract, purchase order, task order, amendment, or modification that reaches you.
  4. The record — the NIST SP 800-171 DoD Assessment score and the separate CMMC status, UID, scope, and affirmation data held in SPRS.
  5. The future transition — the planned move to Revision 3, which is real, not yet effective, and missing the one date everyone wants.

Layer 1 is what people usually mean by “baseline.” Layers 2 through 5 are where the expensive mistakes happen.

Which source should you read first?

This is a practical reading order, not a universal statement of legal precedence:

  1. Your operative solicitation, contract, subcontract, and every written amendment or modification. That is the document you need to explain.
  2. The incorporated regulation, clause, and class deviation. For this question, that usually means 32 CFR Part 170 and the relevant DFARS text.
  3. Current implementation direction. The July 2026 memorandum tells contracting personnel what may be designated during the suspension and how affected instruments should be changed.
  4. The technical standard and assessment process. NIST publications, the DoD Assessment Methodology, the CMMC assessment guides, and the Cyber AB’s current CMMC Assessment Process explain how the requirement is structured and assessed.
  5. Everything else. Trade publications, law-firm alerts, vendor pages, software mappings, and editorial frameworks — including ours.

Notice what is at the top. A press release does not amend your contract. A NIST publication page does not amend your contract. Your contract changes through written contract action.


Which NIST 800-171 revision binds you right now?

For CMMC Level 2, Revision 2. For DFARS 252.204-7012, read the exact clause version incorporated into your instrument. Those two answers usually align because Class Deviation 2024-O0013 directs contracting officers to use a Revision 2 version of 7012. They are not the same source of authority, and the distinction matters when the paperwork is wrong or incomplete.

Situation — Current baseline or requirement — Why
SituationCurrent baseline or requirementWhy
CMMC Level 1The 15 basic safeguarding requirements derived from FAR 52.204-21 — not NIST SP 800-17132 CFR 170.14(c)(2)
CMMC Level 2NIST SP 800-171 Revision 2, 110 requirements, 14 families32 CFR 170.14(c)(3)
CMMC Level 3Final Level 2 plus 24 selected enhanced requirements from NIST SP 800-172 February 202132 CFR 170.14(c)(4) and 170.18
Award with deviation 7012 clauseRevision 2Class Deviation 2024-O0013, Revision 1
Award with unmodified codified 7012 languageThe version in effect at solicitation, unless the contracting officer authorized anotherCodified DFARS 252.204-7012(b)(2)(i); verify in writing
Civilian-agency workWhatever the applicable contract and agency authority requireThe June 2026 government-wide Revision 3 rule is proposed, not final
Voluntary modernizationRevision 3 may be used as a secondary frameworkVoluntary implementation does not replace an existing Revision 2 obligation

Why NIST superseding Revision 2 did not move the CMMC baseline

The mechanism is incorporation by reference, and it does not float forward merely because the publisher releases a new edition.

32 CFR 170.14 states that CMMC Level 2 uses NIST SP 800-171 Revision 2. Section 170.2 identifies the dated NIST publications incorporated into the rule. When NIST published Revision 3, the CFR text did not change. CFR text changes through rulemaking.

That is the part that trips up good engineers. NIST’s website is the authority on what NIST published. It is not, standing alone, the authority on what your award requires.

NIST publishes. The Department regulates. The written instrument obligates.


What is Class Deviation 2024-O0013, and is it still in effect?

It is the Department’s deviation version of DFARS 252.204-7012 that names NIST SP 800-171 Revision 2 instead of using the codified clause’s floating “version in effect at the time the solicitation is issued” language. The current version is Revision 1, issued May 22, 2024. The deviation states that it remains in effect until rescinded.

If you take one artifact away from this page, take this one. It is the document that resolves the version mismatch where its clause is incorporated.

Why the deviation had to exist

The codified 7012 clause does not name a revision number. It requires the version of NIST SP 800-171 in effect when the solicitation is issued, unless the contracting officer authorizes another version.

NIST published Revision 3 on May 14, 2024. Without a deviation, new solicitations using that unmodified floating-version text could point to Revision 3 while the CMMC Program Rule still assessed Level 2 against Revision 2. Two control sets. One environment. No clean reconciliation.

The Department closed that path before Revision 3 published.

The twelve-day sequence

Date — Event — Consequence
DateEventConsequence
May 2, 2024Original Class Deviation 2024-O0013 issuedContracting officers were directed to use a 7012 clause naming Revision 2
May 14, 2024NIST published SP 800-171 Revision 3 and withdrew Revision 2 in its catalogNIST’s current publication changed; the prescribed deviation path was already pinned to Revision 2
May 22, 2024Revision 1 of the deviation issuedThe NIST and FedRAMP links were updated; the Revision 2 requirement and the clause’s existing FedRAMP Moderate-equivalent cloud condition remained
August 17, 2026Current checkThe active deviation remains listed, and 32 CFR Part 170 still names Revision 2

Twelve days. The Department acted before Revision 3 became the current NIST publication.

The reassuring conclusion needs one boundary around it: the Department closed its prescribed solicitation pathway before Revision 3 published, but your actual award still controls. Do not turn a class-deviation timeline into an assumption about a document you have not read.

If your award contains the deviation clause and you have been maintaining a Revision 2 SSP and evidence set, NIST’s publication of Revision 3 did not make that work obsolete. Keep it current. Do not relabel it.

The cloud requirement was already in 7012

Revision 1 did not invent a new FedRAMP Moderate baseline requirement. Codified DFARS 252.204-7012 already required an external cloud service provider storing, processing, or transmitting covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline and comply with the clause’s incident-reporting and forensic-support provisions. The May 2024 Revision 1 clause continues that cloud condition alongside the Revision 2 requirement.

That matters if you are standing up a CUI enclave, choosing a cloud environment, or evaluating an MSP or MSSP. The version question and the cloud question sit in the same clause, but they are separate obligations:

  • Revision question: which NIST SP 800-171 edition does the clause require?
  • Cloud question: does the external cloud offering meet the required authorization or equivalency condition, and are customer responsibilities documented?

For the cloud decision, use the GCC High cost and licensing guide and the CMMC scoping guide rather than assuming a brand or region solves the clause.

How to confirm which 7012 clause is in your instrument

Free, and it turns an assumption into a record:

  1. Open the solicitation, award, subcontract, or purchase order and search for 252.204-7012.
  2. Read the full clause title and every parenthetical. The deviation version identifies the deviation.
  3. Search for DEVIATION, REVISION 1, and MAY 2024.
  4. Read paragraph (b)(2)(i). Does it name Revision 2, or does it use “in effect at the time the solicitation is issued”?
  5. Record the clause version, instrument version, effective date, and date you checked.
  6. If the language is missing, unmodified, or conflicts with another requirement, ask for written clarification before making a representation.

Record the answer. You will be asked again, probably by a prime, probably at an inconvenient moment.

Decision Resolution Point #1

You now know which revision the current CMMC rule uses. The next question is whether your own paperwork agrees.

Reconstructing the answer mid-proposal — or the day a prime’s questionnaire lands — is how an unsupported answer gets put in writing.

Get the free 32-point CMMC Readiness Checklist — covering scope, SSP, SPRS, enclave, MSP/MSSP, and pre-assessment evidence. Delivered by email; no file uploads.

Do not submit CUI, drawings, contract numbers, system diagrams, credentials, or export-controlled information through any form on this site.


Did the July 2026 CMMC suspension change which revision applies?

No. The July 13, 2026 memorandum suspended the planned Phase 2 transition and restricted the designations that program managers and requiring activities may place in procurement requests and requirements documents. It did not replace Revision 2, suspend DFARS 252.204-7012, or erase Phase 1 self-assessment requirements.

The original schedule was:

  • Phase 1: November 10, 2025 through November 9, 2026.
  • Phase 2: originally scheduled to begin November 10, 2026.

The July 13 memorandum suspended that Phase 2 transition with no replacement date.

What changed

  • New procurement requests and requirements documents may designate Level 1 (Self) or Level 2 (Self).
  • They may not newly designate Level 2 (C3PAO) or Level 3 (DIBCAC) during the suspension.
  • Program offices were directed to amend affected active solicitations as soon as practicable.
  • Affected existing contracts or agreements are to be modified before the next option exercise or during the next scheduled administrative modification.
  • No CMMC waivers are to be processed during the review.

What did not change

  • NIST SP 800-171 Revision 2 as the CMMC Level 2 baseline.
  • The 110 Level 2 requirements and 14 families.
  • DFARS 252.204-7012, which the memorandum says remains in effect.
  • Level 1 and Level 2 self-assessment paths.
  • The requirement to enter applicable results and affirmations in SPRS.
  • Select Government-led assessments. The memorandum expressly preserves them as part of the baseline-enforcement posture; the suspension is not a universal stop-work order for every Government assessment.

The cleanest way to say it is this: the suspension changed the verification route available in new requirements packages. It did not reduce the standard.

There is a second-order effect worth naming. When a formal third-party designation is not in the procurement path, the contractor’s own scope, evidence, score, and affirmation carry more weight, not less. The standard did not get easier. The external checkpoint moved.

The full suspension analysis belongs on what the 2026 CMMC suspension actually changed. This page stays focused on the baseline.


Which document controls — the announcement, solicitation, contract, or subcontract?

The written instrument governing your work is the record you must be able to explain. The memorandum establishes implementation direction for Department personnel. It does not, by itself, replace the words in a signed prime contract or private subcontract. That is why the memorandum directs amendments and modifications.

This misunderstanding cuts both ways. A contractor can keep paying for a requirement that was removed by amendment. Another can cancel work based on a headline even though the operative instrument has not changed.

If you are looking at a new or active solicitation

Check the amendment list before the base document. Then confirm:

  • The CMMC level and assessment designation in the most recent amendment.
  • Every cybersecurity clause and deviation notation.
  • Whether the proposal deadline moved.
  • Whether the representations and certifications section still asks for something the amendment removed.
  • Whether a separate attachment or statement of work names a NIST revision.

Do not represent yourself as eligible based on an amendment you expect but have not received.

If you are looking at an existing prime contract

  • Look for an issued modification, not an announcement.
  • Identify the next option exercise and scheduled administrative modification.
  • Preserve written contracting-officer correspondence.
  • Reconcile any modification against the cybersecurity attachment, data-description documents, and flow-down schedule.
  • Before canceling an assessment or managed-service agreement, read its termination terms and get the requirement change in writing.

If you are a subcontractor

This is where relief does not automatically flow downhill.

The implementation memorandum directs Department personnel. It does not rewrite a private subcontract. DFARS 252.204-7021 requires the substance of the CMMC clause to flow down when the subcontract will involve FCI or CUI, and the prime must select the level appropriate to the information being flowed down. A prime may also impose a separate supplier-security condition through its own written agreement.

Those are different things. Ask the prime which written requirement controls your planning, and ask for the effective date. The CMMC for subcontractors guide covers the flow-down mechanics in full.

Clause and designation strings to search for

The 2026 FAR and DFARS overhaul deviations make this less tidy than it should be. Acquisition.gov still publishes the codified clauses, while specified Department actions may use deviation text and replacement numbering. Search both generations rather than assuming one set disappeared everywhere.

Search string — Why it matters
Search stringWhy it matters
252.204-7012Safeguarding covered defense information and cyber incident reporting; read the exact clause version
252.204-7019Codified notice of NIST SP 800-171 DoD Assessment requirements
252.204-7020Codified Basic, Medium, and High DoD Assessment requirements
252.240-7997RFO-deviation assessment clause used in specified newer or modified Department instruments
252.204-7021CMMC status, CMMC UID, affirmation, and flow-down clause
252.204-7025CMMC solicitation notice provision
52.204-21Codified basic safeguarding clause associated with the Level 1 requirement set
52.240-93RFO-deviation replacement basic-safeguarding clause used in specified actions
DEVIATIONIdentifies non-codified clause text
CMMC Level 1 (Self)Current permitted Phase 1 designation
CMMC Level 2 (Self)Current permitted Phase 1 designation
CMMC Level 2 (C3PAO)Certification-assessment designation suspended for new requirements packages
CMMC Level 3 (DIBCAC)Level 3 designation suspended for new requirements packages
NIST SP 800-171Find every revision reference, not just the clause heading
SPRSFind score, status, UID, and affirmation duties
annual affirmationFind the representation that must remain current

The February 1, 2026 overhaul deviations did not make the codified text vanish from existing instruments. They created another reason to read the actual document instead of relying on a memorized clause list.

The written question that ends the ambiguity

Send one email. Keep it short, non-sensitive, and in the file.

To a contracting officer:

Please confirm the current CMMC assessment designation and the applicable NIST SP 800-171 revision for [solicitation or contract identifier], including the controlling amendment or modification number and effective date. Please also confirm whether DFARS 252.204-7012 is incorporated under Class Deviation 2024-O0013, Revision 1. We are not transmitting CUI or controlled attachments with this request.

To a prime contractor:

Please confirm whether the CMMC and NIST SP 800-171 requirements in our current subcontract remain unchanged, will be amended, or reflect a separate supplier condition maintained by your organization. Please identify the effective written requirement, assessment designation, revision, and date we should use for planning. We are not transmitting CUI or sensitive system information with this request.

Copy the template, change the bracket, and send it. Guessing on a proposal is worse for everyone.

Decision Resolution Point #2

You know the revision and the document that proves it. What you may not know is whether your scope is right — and scope is what makes a correct baseline succeed or fail.

A correct requirement set applied to the wrong boundary is still an expensive mistake.

Read the CMMC scoping guide — how the CUI boundary, External Service Providers, specialized assets, and enclave strategy change what you actually have to secure.

See who to hire first for CMMC — the decision order before you buy a platform, managed service, enclave, or assessment.


Has the Revision 3 CMMC rule published?

Not as of August 17, 2026. The rulemaking is real. It is tracked as RIN 0790-AM01, and the Unified Agenda lists it at Final Rule Stage. But there is no published Federal Register rule text amending 32 CFR Part 170, so the planned transition does not bind anyone today.

What the official agenda record actually says

The agenda entry says the Department plans to define a deadline and transition period from Revision 2 to Revision 3. It identifies added specificity and organization-defined parameters as material changes, and it estimates that roughly 20% fewer total companies would be affected by Part 170 based on a newer estimate of the size of the Defense Industrial Base.

It also lists an interim final rule target of July 2026. That target has passed.

Two details keep the record honest:

  • The Unified Agenda is a planning document, not enforceable rule text.
  • The entry states “Regulatory Flexibility Analysis Required: No” and “RIN Data Printed in the FR: No.” The agenda does not support a claim that the Department made a formal finding that this rule will have a significant economic impact on a substantial number of small entities.

The 20% figure is an agency estimate about the affected population in the agenda entry. It is not a 20% reduction in requirements, not a promise that any individual contractor leaves scope, and not an effective eligibility rule.

What “Final Rule Stage” does and does not tell you

It tells you the agency’s planned next action is a final action rather than another proposed rule. The timetable says “Interim Final Rule.” It does not tell you:

  • the final transition date;
  • whether existing Revision 2 CMMC statuses receive credit;
  • whether the rule takes effect on publication or on a later date;
  • how current POA&Ms and affirmations transition;
  • which assessment and scoring materials will be designated;
  • whether the July 2026 suspension changes the rollout structure written into the rule.

An interim final rule can issue without a prior proposed rule. The Federal Register document itself will set the effective date and any post-publication comment process. Until that document exists, do not manufacture a deadline from the agenda.

The one honest thing we cannot give you

Here is the part we would rather not write:

We cannot tell you the Revision 3 CMMC transition date because no enforceable source has published one. We also cannot tell you whether an existing Revision 2 certification, self-assessment status, or voluntarily completed assessment will receive transition credit.

Nobody has a private effective date hidden in a webinar. Confidence is not a source.

The three events that move the current answer

Event — What to watch — Where to verify
EventWhat to watchWhere to verify
A rule under RIN 0790-AM01 publishesFederal Register text, effective date, transition instructions, and amended incorporated publicationsReginfo RIN entry and Federal Register
Class Deviation 2024-O0013 is rescinded or supersededA new 7012 deviation or changed clause text in new solicitationsDepartment class deviations and your instrument
32 CFR Part 170 changesRevision references in sections 170.2 and 170.14, plus assessment, scoring, and transition provisionsCurrent eCFR Part 170

Put those three on a recurring calendar item. Fifteen minutes a month is cheaper than rebuilding a program around a date that never existed.


Should you start building to Revision 3 now?

Not as a replacement for the Revision 2 program you are currently measured against. A Revision 3 crosswalk is useful. A premature migration that breaks Revision 2 traceability is not.

Revision 3 is a real structural change: 97 top-level requirements across 17 families, three additional families, and organization-defined parameters. It is not simply Revision 2 with new numbers. The full requirement-level comparison, NIST transition-workbook analysis, and ODP count reconciliation are on the dedicated Rev. 2 vs. Rev. 3 page. Reproducing all of that here would blur this page’s job.

The dual-track approach we would actually use

This is editorial judgment, not a regulatory requirement:

  • Keep the Revision 2 SSP, scope, evidence index, and score support intact and current. That is the CMMC Level 2 baseline today.
  • Build a separate Revision 2-to-Revision 3 crosswalk. Label it future-state planning, not current compliance.
  • Preserve requirement-level traceability. Do not overwrite Revision 2 identifiers with Revision 3 identifiers in the only evidence system you have.
  • Start governance work for Planning, System and Services Acquisition, and Supply Chain Risk Management. Documentation ownership and decision records take time even when technology does not change.
  • Record the parameter values you already use. Owner, value, rationale, approval date, and evidence source. That strengthens Revision 2 evidence and prepares you for Revision 3 ODP governance.
  • Do not submit a Revision 3-based score as the score required by the current Revision 2 methodology.
  • Do not fund a transition date nobody has published.

For the current 110-requirement set, point values, and POA&M limits, use the NIST 800-171 requirements checklist.


What does the interim baseline mean for your SPRS score and affirmation?

It means you must keep two different SPRS concepts separate. Both involve Revision 2. They are not the same record.

SPRS stream — Governing authority — What is recorded — Core cadence
SPRS streamGoverning authorityWhat is recordedCore cadence
NIST SP 800-171 DoD AssessmentDFARS 252.204-7019 and 252.204-7020, or applicable deviation textBasic, Medium, or High Assessment summary score and related assessment informationA current assessment as required by the instrument; the codified award condition generally uses a three-year window unless a shorter period is stated
CMMC status and affirmation32 CFR Part 170, DFARS 252.204-7021, and 252.204-7025CMMC level, status, scope, CMMC UID, self-assessment result where applicable, and affirmation of continuous complianceSelf-assessment/status cadence by level, plus annual affirmation

A company can have a DoD Assessment score and a CMMC status in the same system. One does not become the other merely because both are in SPRS.

The Revision 2 score mechanics that matter

  • The NIST SP 800-171 DoD Assessment Methodology runs from 110 down to −203.
  • Each unmet Revision 2 requirement subtracts its assigned value from the maximum score.
  • A negative score is possible and is not, by itself, proof of fraud or a CMMC status determination.
  • For Conditional Level 2 under 32 CFR 170.21, the score must be at least 88 of 110.
  • Requirements worth more than one point generally may not remain on the POA&M, except the narrow encryption condition stated in the rule.
  • Six named one-point requirements are also barred from the POA&M.
  • Eligible items must be closed and confirmed within 180 days, or the Conditional status expires.
  • Level 1 permits no POA&M. All 15 requirements must be met.

Here is the counterintuitive consequence: a score of 105 with one unmet five-point requirement cannot qualify for Conditional Level 2. A lower score may qualify only when every remaining gap is POA&M-eligible. Score alone does not tell you whether there is a Conditional path.

The SPRS score guide breaks down the arithmetic and the difference between “high score” and “eligible score.”

Why “self-assessment” is not permission to guess

The suspension changed new assessment designations. It did not remove consequences for unsupported representations.

In June 2026, the Department of Justice announced a $507,144 settlement with LOGZONE, Inc. resolving False Claims Act allegations related to cybersecurity representations. The settlement agreement says the company posted a NIST SP 800-171 DoD self-assessment score of 110 in SPRS in October 2021, while a later DCMA DIBCAC Medium Assessment produced −170 on the same −203-to-110 scale. The agreement resolved allegations and was not a determination of liability.

This was a DFARS 252.204-7019/7020 DoD Assessment score matter, not a CMMC certification case. That distinction matters. So does the comparison: 110 and −170 were both Revision 2 numbers. The version was not the problem. The evidence was.

One case does not establish a typical outcome. It does establish a public, primary-sourced example of the distance between a number posted in SPRS and a number the Government can reproduce from the system, SSP, scope, and artifacts.

Before the next assessment or affirmation, reconcile these against each other:

  • Current CUI boundary and system description.
  • SSP version and approval date.
  • Evidence for every requirement marked MET.
  • Assessment date, type, scope, and methodology.
  • DoD Assessment score in SPRS, where applicable.
  • CMMC status, UID, scope, and self-assessment result, where applicable.
  • Every open POA&M item, eligibility basis, and closeout date.
  • Affirming official and actual authority to affirm.
  • Material changes since the assessment.

If those records do not tell the same story, fix the record before anyone signs it. The CMMC non-compliance penalties guide covers the enforcement landscape without turning one settlement into a guarantee of what happens next.


Does NIST SP 800-172 Revision 3 control CMMC Level 3?

No. Not under the current CMMC rule. This is the Level 3 version trap hiding behind the Level 2 version trap.

NIST finalized SP 800-172 Revision 3 in May 2026 and superseded the February 2021 publication in NIST’s catalog. But 32 CFR Part 170 still incorporates NIST SP 800-172 February 2021 for CMMC Level 3 and identifies 24 selected enhanced requirements. The current rule’s Level 3 assessment procedures use NIST SP 800-171A June 2018 and NIST SP 800-172A March 2022.

So the same discipline applies twice:

  • NIST’s current SP 800-171 publication is Revision 3; CMMC Level 2 still uses Revision 2.
  • NIST’s current SP 800-172 publication is Revision 3; CMMC Level 3 still uses the selected February 2021 requirements.

Level 3 also does not replace Level 2. Under the current rule, the organization must hold a Final Level 2 status for the same CMMC assessment scope before the Level 3 process proceeds.

During the July 2026 suspension, program managers and requiring activities may not newly designate Level 3 (DIBCAC) in procurement requests and requirements documents. The memorandum still preserves select Government-led assessments as part of the enforcement posture. Do not read the suspension as an amendment to the 24 enhanced requirements.

For the boundary between the two publications, use NIST 800-171 vs. 800-172 and the CMMC levels guide.


Is “Brilliant at the Basics” the new NIST 800-171 baseline?

No. Brilliant at the Basics is Department guidance and enablement material for prioritizing foundational cybersecurity practices. It is not a replacement compliance baseline.

It does not:

  • reduce the 110 Revision 2 requirements;
  • change a DFARS clause;
  • select your CMMC level;
  • create a different SPRS scoring method;
  • replace an assessment or affirmation;
  • adopt Revision 3;
  • create a waiver.

What it is useful for: sequencing work, explaining priorities to leadership, and getting a team out of pure documentation mode and into actual risk reduction.

Use it to decide what to do first. Do not use it to decide what to stop doing.

If a provider presents “Brilliant at the Basics” as a new reduced CMMC baseline, treat that as a provider-selection signal. That is our editorial judgment, not a finding made by the Department.


What if you also hold civilian-agency contracts?

Then you may end up managing two baselines on two clocks. A proposed government-wide rule would use NIST SP 800-171 Revision 3 for covered CUI contracts and add a 72-hour cyber-incident reporting requirement. It is proposed, not final.

The proposal is FAR Case 2026-001, published at 91 FR 37550 on June 23, 2026. The comment period closed July 23, 2026.

Place the two current facts next to each other:

  • The CMMC Program Rule and the 7012 deviation still point the Department’s Level 2 posture to Revision 2.
  • The FAR Council has proposed a government-wide CUI framework built around Revision 3.

If you sell only into the Department, the FAR proposal is a watch item. If you sell to the Department and civilian agencies, it is a design constraint. A system can support both baselines, but your records must say which obligation each control, parameter, score, and representation is intended to satisfy.

This is the strongest practical argument for the dual-track approach: keep Revision 2 operational, keep the Revision 3 crosswalk current, and do not tear down a working evidence chain while two rulemaking tracks are moving in different directions.


Which CMMC provider category resolves a baseline problem?

It depends on which layer is unresolved. A revision question can be a contract question, a scoping question, an implementation question, an evidence question, or an assessment question. Calling the wrong category first is how a narrow ambiguity turns into a broad engagement.

This is The CMMC Path Framework: required level, FCI or CUI handling, assessment type, environment, and timeline determine the provider category worth investigating first. It routes to a category, not a certification prediction, ranking, or legal conclusion.

Your unresolved layer — Start with — Not the right first call — Ask before you engage
Your unresolved layerStart withNot the right first callAsk before you engage
Which revision and clause apply to our written instruments?RPO/RP; qualified federal-contracts counsel where interpretation is disputedAssessment-only providerWill the deliverable name the clause, deviation, revision, instrument, effective date, and unresolved assumptions?
We do not know whether we hold CUI or what is in scopeRPO/RP or qualified CMMC scoping adviserGRC software purchaseWhat is your boundary-definition process, and what written scope artifact will we own?
Controls exist on paper but are not operatedCMMC-focused MSP/MSSPC3PAOWill you provide a Customer Responsibility Matrix and recurring evidence the organization can retain?
SSP, evidence, POA&M, and ownership are unmanagedGRC platform plus implementation supportGRC platform aloneCan we export our evidence, retain it after termination, and map Revision 2 now with a separate Revision 3 crosswalk?
The CUI boundary is unnecessarily broadCUI enclave or secure-cloud specialistFull-company migration by defaultWhat data and users stay outside the enclave, and how are FedRAMP authorization/equivalency and customer responsibilities documented?
A formal Level 2 certification assessment is actually requiredA current authorized or accredited C3PAOThe consultant that prepared the organizationWhat is your current Cyber AB status, CAP version, conflict analysis, assessment-team composition, and cancellation policy?
We do not know which category fitsFind My CMMC PathA named-provider sales call as the first step

Readiness and certification assessment must stay separate

Under 32 CFR 170.8(b)(17), CMMC Ecosystem members may not participate in a Level 2 certification assessment for an assessment where they served as a consultant preparing that organization for any CMMC assessment within the prior three years. The rule also requires conflict-of-interest controls, accurate representation of credentials and status, and honest, factual conduct.

The regulation defines a C3PAO as a CMMC Third-Party Assessment Organization. Before engagement:

  • verify the organization’s current status in the Cyber AB Marketplace;
  • confirm the current CMMC Assessment Process release the assessment will use;
  • ask for the conflict analysis in writing;
  • distinguish “authorized” from “accredited” rather than letting a sales page blur the status;
  • reject any promise that a provider can guarantee certification.

A readiness provider can help you prepare. A C3PAO can conduct an authorized Level 2 certification assessment when that assessment is required and permitted. Neither can promise the result before testing the evidence.

Software alone does not satisfy CMMC

A GRC platform can be a strong system of record. It does not implement controls, classify information, correct a boundary, authorize a cloud service, or create evidence that never existed. Buying it before ownership and scope are defined often produces a clean dashboard over an unresolved environment.

The full comparison is on the provider categories page, and the pricing tradeoffs are on the CMMC Level 2 cost guide.

Decision Resolution Point #3

You know the baseline, the instrument, the suspension posture, the SPRS distinction, and the provider category that fits each gap. The last step is routing the problem before you collect quotes.

Find My CMMC Path — answer non-sensitive questions about level, scope, assessment type, environment, and timeline, and get the provider category to investigate first.

Already know the category and need options? Request a CMMC quote or match.

Do not submit CUI, drawings, controlled attachments, credentials, contract numbers, system diagrams, SSPs, or export-controlled information.

Disclosure: The Defense Compliance Report may receive compensation for disclosed qualified introductions, sponsorships, or partner referrals. Compensation does not control our regulatory analysis, category framework, Cyber AB status checks, or corrections process.


Your next 48 hours: write a baseline determination someone else can verify

Do not start by buying or canceling anything. Start by writing down the instrument, revision, designation, record, and date you verified each. A dated determination memo turns “we think we are on Revision 2” into a document a CFO, prime, contracting officer, adviser, or assessor can challenge line by line.

Seven steps. Start with a first pass, then send the one written question the record cannot answer.

1. Identify the governing instrument

Solicitation, prime contract, subcontract, purchase order, task order, delivery order — plus every amendment and modification. Write down which one governs the work in question.

2. Identify the information involved

No federal information, FCI only, CUI, or uncertain. If uncertain, that is the first unresolved decision. Do not upload the data to a public checklist or describe it casually in a lead form.

3. Record the exact clause and deviation text

Use the search table above. Copy the full title, date, deviation notation, and revision language into the memo. Do not record only the clause number.

4. Record the assessment designation and phase posture

Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), Level 3 (DIBCAC), or none found. Note whether an amendment or modification issued after July 13, 2026 changed it.

5. Reconcile the two SPRS streams

Where applicable, record the DoD Assessment score and date separately from the CMMC status, UID, scope, result, and affirmation date. Do not put both under a single label called “the SPRS score.”

6. Send one written question

Use the contracting-officer or prime template above. Keep the reply with the memo and record who supplied it.

7. Choose the provider category after you know the gap

Contract interpretation, scope, implementation, evidence management, enclave design, or formal assessment. Pick the category that resolves the gap you found, not the most expensive category available.

Write the result at the top of the memo:

As of [date], the governing instrument is [identifier and version]. The current CMMC designation is [designation]. The applicable NIST baseline is [revision], based on [specific clause, deviation, or regulation]. The relevant SPRS records are [records and dates]. The open questions are [questions].

That document is worth more than a dashboard with no authority chain. It is also the document you will be glad exists when the Revision 3 rule publishes, because it tells you exactly what must be re-examined.


What we actually verified

A page making a current baseline claim should show its work.

Read directly on August 17, 2026

What we did not verify and will not claim

  • A restart date for Phase 2.
  • A Revision 3 CMMC effective date.
  • Transition credit for an existing Revision 2 certification, self-assessment status, or voluntary assessment.
  • The exact assessment and scoring method the unpublished Revision 3 rule will designate.
  • Whether a specific prime will change a supplier condition.
  • Whether a specific environment contains CUI.
  • That any provider can guarantee a CMMC result.
  • A current named-provider Marketplace status on this page. No provider is named here.

How this page was produced

The Defense Compliance Report Editorial Team classified each source by the function it performs: publication, regulation, contract clause, assessment record, implementation direction, or future rulemaking. We then tested each source against one question: does this instrument set the reader’s baseline today, or does it merely describe a future state?

We publish our Methodology, Editorial Standards, Editorial & Advertising Policy, and Corrections Policy. If a controlling source changes or you find an error, we want the record corrected.


Frequently asked questions

Is there an official NIST 800-171 interim baseline?

No. The phrase is not defined in 32 CFR Part 170, NIST SP 800-171, or the DFARS. It is shorthand for the current posture: CMMC implementation is under review, while Revision 2 remains the Level 2 baseline and Level 1/Level 2 self-assessment designations continue.

Is NIST SP 800-171 Revision 2 or Revision 3 required right now?

Revision 2 is the current CMMC Level 2 baseline. A contract can expressly impose another requirement, so read the actual clause, amendment, modification, and flow-down rather than relying on the NIST publication page alone.

Why is Revision 2 still used if NIST withdrew it?

Because 32 CFR Part 170 incorporates a specific dated edition. NIST’s publication status did not amend the regulation. The Department must change the rule for CMMC to move to Revision 3.

What is Class Deviation 2024-O0013?

It is the Department’s deviation version of DFARS 252.204-7012 that names NIST SP 800-171 Revision 2 instead of using the codified clause’s version-in-effect-at-solicitation language. Revision 1 was issued May 22, 2024 and remains in effect until rescinded.

Did Revision 1 create the FedRAMP Moderate requirement?

No. The external-cloud FedRAMP Moderate-equivalent requirement already existed in 7012. The May 2024 Revision 1 clause continues that cloud condition alongside the Revision 2 requirement.

Did any Department contract automatically switch to Revision 3?

Do not make that conclusion without the instrument. The Department issued the original Revision 2 deviation twelve days before NIST published Revision 3, closing the prescribed floating-version path for solicitations using the deviation clause. Verify the clause actually incorporated into your award.

Did the July 2026 suspension change the required revision?

No. It suspended the planned Phase 2 transition and restricted new procurement designations to Level 1 (Self) and Level 2 (Self). The memorandum states that Level 2 remains aligned with Revision 2 and that 7012 remains in effect.

Is Phase 1 still in effect?

The original Phase 1 period began November 10, 2025 and was scheduled through November 9, 2026. The Department suspended the planned November 10, 2026 Phase 2 transition and left Phase 1 self-assessment requirements in place pending further direction.

Are all Government-led assessments suspended?

No. The memorandum prohibits new Level 3 (DIBCAC) designations in procurement requests during the suspension but separately states that select Government-led assessments remain part of baseline enforcement.

Has the Revision 3 CMMC rule published?

Not as of August 17, 2026. RIN 0790-AM01 is at Final Rule Stage in the Unified Agenda, but no enforceable Federal Register rule text amending Part 170 has published.

When will Revision 3 become the CMMC baseline?

No verified effective date exists. Watch for the rule under RIN 0790-AM01, replacement or rescission of Class Deviation 2024-O0013, and amended Revision references in 32 CFR Part 170.

Should we build to Revision 3 now?

Use it as a parallel crosswalk, not as a replacement for the current Revision 2 evidence chain. Keep Revision 2 as the primary map wherever it is the controlling obligation.

Which revision does SPRS score against?

The current NIST SP 800-171 DoD Assessment Methodology uses Revision 2 and a range from 110 to −203. CMMC self-assessment results, CMMC status, UID, scope, and annual affirmation are a separate SPRS record stream under Part 170 and DFARS 252.204-7021.

Can we use a POA&M during the suspension?

Where the applicable Level 2 status permits it, yes. Conditional Level 2 requires at least 88 of 110, only eligible requirements may remain open, and closeout must occur within 180 days. Level 1 permits no POA&M.

Does NIST SP 800-172 Revision 3 control CMMC Level 3?

No. The current CMMC rule still incorporates 24 selected requirements from the February 2021 SP 800-172 publication and uses the assessment publications named in Part 170. NIST’s May 2026 Revision 3 publication did not amend the rule.

Is “Brilliant at the Basics” a new reduced baseline?

No. It is prioritization and enablement guidance. It does not remove requirements, change a clause, create a CMMC status, or replace evidence.

What happened to DFARS 252.204-7019 and 252.204-7020 under the 2026 overhaul?

The codified clauses remain published on Acquisition.gov. Department RFO class deviations direct use of replacement text and numbering in specified actions, including 252.240-7997 for the assessment clause. Search the codified and deviation numbers in the actual instrument instead of assuming a universal repeal.

Can a prime require more than the current Department designation posture?

A prime’s private supplier requirements depend on the written subcontract and supplier terms. The Department memorandum does not automatically rewrite those documents. Ask the prime to identify the controlling written condition and effective date.

Can the same company prepare us and conduct our Level 2 certification assessment?

Not for the same assessment where the three-year prior-consultant prohibition applies. Section 170.8 bars CMMC Ecosystem members from participating in a Level 2 certification assessment for an organization they served as a consultant to prepare for any CMMC assessment within the prior three years. Get the conflict analysis in writing.

Is this legal or compliance advice?

No. This is educational research. Confirm applicability and scope with a qualified RP/RPO, and use federal-contracts counsel where contract interpretation or a material representation is at stake.


The bottom line

There is no NIST 800-171 interim baseline as a separate standard. There is a current CMMC Level 2 baseline — Revision 2, 110 requirements, 14 families — and there are specific instruments that keep it there while the implementation schedule and future rulemaking move around it.

Name the instrument. Date the determination. Separate the two SPRS records. Watch the three triggers. That is the discipline.

Revision 3 is coming through a real rulemaking track. The agenda target has already slipped, and the transition details do not exist in enforceable form. The contractors who absorb that change with the least waste will be the ones who kept Revision 2 clean, maintained a separate crosswalk, and can explain in one sentence what their baseline was and why.

Need help deciding which type of CMMC provider fits the gap you found?

Find My CMMC Path

Free. Non-sensitive scope answers only. Do not submit CUI, drawings, controlled attachments, credentials, contract numbers, system diagrams, SSPs, or export-controlled information.

Not ready to be matched? Start with the free CMMC Readiness Checklist or compare CMMC provider categories.


This article was researched and written by The Defense Compliance Report Editorial Team. The Defense Compliance Report is an independent trade publication on CMMC and Defense Industrial Base compliance.

Published: August 17, 2026 · Last reviewed: August 17, 2026 · Last verified: August 17, 2026 · Next scheduled re-verification: September 2026

See our Methodology, Editorial Standards, Editorial & Advertising Policy, and Corrections Policy. The Defense Compliance Report is not affiliated with the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.

Related guides