
Compliance Pulse | Inaugural Edition
COMPLIANCE PULSE| Inaugural Edition
NIST 800-171 Rev. 3 Is Here — But Who’s Actually Enforcing It?
Most defense contractors are laser-focused on CMMC and Rev. 2 compliance right now. That’s the right call — for DoD work. But if you think NIST 800-171 Revision 3 is just a future concern, one agency just moved the timeline forward.
DoD: Rev. 2 Still Required — But Rev. 3 Is Being Staged
DoD’s May 2024 Class Deviation 2024-O0013 locked DFARS 252.204-7012 compliance to Rev. 2. All active CMMC Level 2 assessments still run against the 110 controls in Rev. 2, and that’s not changing imminently.
But DoD is clearly staging the transition. In April 2025, DoD released official Organizationally Defined Parameter (ODP) values for Rev. 3 controls — the fill-in-the-blank variables that replace hardcoded requirements from Rev. 2. Publishing those values is the preparatory step before Rev. 3 moves into DFARS rulemaking, expected between late 2026 and early 2027.
Bottom line for DIB: Stay the course on Rev. 2 and CMMC. But start mapping your ODP values now so the transition doesn’t blindside you.
GSA: Rev. 3 Is Already Enforceable — Right Now
This is the development most practitioners missed. On January 5, 2026, the General Services Administration quietly published its IT Security Procedural Guide, “Protecting CUI in Nonfederal Systems and Organizations Process.” NIST SP 800-171 Revision 3 is now the required CUI protection baseline for GSA contractors.
Key facts:
•No formal phase-in period — requirements can be incorporated into new solicitations at contracting officer discretion immediately
•This is the first significant CUI enforcement expansion beyond the DoD ecosystem
•Civilian agency contractors could previously self-attest against just 17 of the 110 Rev. 2 controls under FAR 52.204-21 — that bar just got dramatically higher
•If you’re pursuing a GSA MAS contract or hold one, Rev. 3 compliance is no longer optional
DoJ: Enforcement Is Active, Regardless of Revision
The Department of Justice’s Civil Cyber-Fraud Initiative continues pursuing contractors who misrepresent NIST 800-171 compliance under the False Claims Act. The Georgia Tech case — where the institution faces legal action for allegedly falsifying its SPRS score — is the clearest warning that self-attestation without substantive compliance is a liability, not a checkbox.
What This Means for GRC and Compliance Practitioners
The compliance landscape is fragmenting across revision levels by agency:
•DoD contracts: NIST 800-171 Rev. 2 (110 controls) + CMMC
•GSA contracts: NIST 800-171 Rev. 3 (97 requirements, ODP-based) effective now
•Other civilian agencies: Likely to follow GSA’s lead — watch for FAR rulemaking in 2026
If you’re advising clients who hold both DoD and civilian agency contracts, you may be managing dual compliance postures simultaneously. Build that into your scoping conversations now.
Are you tracking your Rev. 3 readiness alongside your CMMC posture? Drop a comment or DM me — this is exactly the kind of dual-framework advisory work we’re doing with clients right now.
#CompliancePulse #NIST800171 #CMMC #CUI #GRC #CybersecurityCompliance #DIB #MaritimeCyber #FederalContracting #vCISO
Craig Wood, CISM | CCA Lead Assessor | ISO 27001 Lead Auditor|PSY Logistics Technology Partners