CMMC Level 2 vs NIST 800-171 Rev 3: Contractor Essentials
CMMC Level 2. You keep hearing two messages at once: At the same time, the CMMC final rule is in place and showing up in real solicitations with award and assessment requirements for Level 2. No surprise that many defense contractors are asking a simple but urgent question: “Are we supposed to follow NIST 800-171 Rev 2 or Rev 3 for CMMC Level 2 right now?” If you guess wrong, you can end up with gaps in the version that assessors actually use, which can hurt both your SPRS score and your CMMC award eligibility. This post gives you a clear answer and a practical way forward. The confusion: two versions, one set of contracts Here is the situation in plain language: Recent articles aimed at defense contractors spell it out: So right away you can see the split: That is the source of the headache. What NIST 800-171 Rev 3 really changed NIST did not scrap Rev 2. It cleaned it up. Key points from NIST and expert explainers: DoD has also published Organization Defined Parameters (ODPs) for Rev 3 controls. These give concrete values for things like log retention, lockout thresholds, and other “tunable” settings in the new version. In other words, Rev 3 is the direction of travel for federal CUI protection, and DoD is already shaping how it will be used. But that still does not mean it is the CMMC Level 2 scoring baseline today. What CMMC Level 2 really checks today The CMMC final rule and most public mappings are still clear: Current guidance for contractors and MSPs still says: So if a C3PAO comes in to do a Level 2 assessment on a CMMC tagged contract: This is the part that “defense contractors must follow right now” for contract and award purposes. What defense contractors must follow right now Putting it together: So the practical answer: Right now, if you want to pass CMMC Level 2 and protect your DoD contract eligibility, you must be able to show a solid, evidence backed implementation of NIST 800-171 Rev 2 across your in scope systems. Rev 3 is “next”, not “instead of” Rev 2. How to use Rev 3 without breaking your CMMC audit You do not have to choose Rev 2 or Rev 3. The smart move is to use both in a controlled way. Step 1 – Lock in Rev 2 as your scored baseline This is the version that controls your SPRS score, DFARS 7012/7020/7021 posture, and CMMC assessment results today. Step 2 – Build a simple Rev 3 “overlay” instead of a rewrite For Rev 3: Then add a short overlay column to your internal tracking: This lets you prepare for the shift without throwing away the Rev 2 structure that CMMC Level 2 still uses. Step 3 – Use DoD’s ODP memo to tune settings, not to change your baseline DoD’s April 2025 memo sets Organization Defined Parameters for Rev 3. That gives you clear numbers for things like: You can borrow those values to sharpen your own settings even while your audit baseline is still Rev 2. This is a safe way to “future proof” your environment without stepping outside CMMC’s current scoring model. What this means for your next 12 months In the next year, most defense contractors will juggle three things at once: A simple way to talk about this with leadership: That is a very different message than “we have to start over for Rev 3.” Turning version confusion into a CMMC strength CMMC, NIST 800-171, and DFARS are not going to get simpler on their own. But this part can be clear: The contractors who stay ahead will be able to say: That is a strong, calm story to bring into both capture meetings and assessments. How Centrend can help your team right now Centrend can help defense contractors: If you want a focused working session, we can walk your team through a short Rev 2 vs Rev 3 CMMC Readiness Review and leave you with a practical action list for the next 90 days. Learn more about how Centrend’s Cybersecurity Services help defense contractors stay secure and CMMC ready.
CMMC Level 2 vs NIST 800-171 Rev 3: Contractor Essentials Read More »
