> ## Content Index
> Fetch the complete content index at: https://www.cmmcoperator.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CMMC Mandates a NIST Standard NIST Has Withdrawn
- URL: https://www.cmmcoperator.com/cmmc-mandates-a-nist-standard-nist-has-withdrawn/
- Published: 2026-08-21T14:00:00.000Z
- Updated: 2026-08-21T13:59:59.000Z
- Description: 32 CFR 170.2 incorporates NIST SP 800-171 Revision 2. NIST withdrew Revision 2 on May 14, 2024. What that means for which baseline a Mac fleet should actually harden to.
- Author: HydratedSec
- Tags: macOS CMMC

**Quick answer: build to Revision 2, even though NIST withdrew it in 2024.** CMMC incorporates Revision 2 by regulation, and a regulation does not update itself when a standards body moves on. This is one of the stranger facts in the programme and almost nobody states it plainly.

## Which revision does CMMC actually require?

Revision 2, without ambiguity. 32 CFR 170.2 incorporates by reference "SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, Revision 2, February 2020 (includes updates as of January 28, 2021)," together with SP 800-171A of June 2018.

32 CFR 170.14(c)(3) says the same thing from the other side: "the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2."

No Revision 3 is incorporated anywhere in the rule.

## Did NIST really withdraw Rev 2?

Yes. The NIST Computer Security Resource Center records SP 800-171 Revision 2 as withdrawn on May 14, 2024, superseded by Revision 3.

So the position today is that CMMC Level 2 mandates a publication its own author has formally retired. That is not a criticism of anyone. Incorporation by reference is how regulations achieve stability, and the alternative would be a standard that changes underneath contractors without notice. But it does mean the version on the NIST landing page is not the version you are assessed against.

Practically: keep a copy of Revision 2 and Revision A of the assessment guidance. Do not let a well-meaning consultant hand you Revision 3 controls because it is the current document.

## Is Rev 3 coming to CMMC?

Eventually, almost certainly. On any near-term timeline, there is nothing to act on.

What is verifiable today is narrow. 32 CFR 170.2 still incorporates Revision 2\. We found no published rule adopting Revision 3 into CMMC. Anything beyond that, including forecasts of a dual Revision 2 and Revision 3 reporting period in SPRS, is practitioner opinion rather than sourced fact, and should be labelled that way when you hear it.

The wider context points away from a near-term raise in the standard. The Department suspended the Phase 2 transition in July 2026 under memo 26-P-1023 and stood up a reform task force. A programme reviewing how to reduce compliance burden is not a programme about to adopt a larger control set. That reading is inference, not a sourced statement of intent.

## What should you build to today?

Revision 2, with an eye on Revision 3 where the cost of alignment is zero.

For a Mac fleet this is a concrete choice rather than an abstract one. The macOS Security Compliance Project publishes both a baseline labelled CMMC that maps to 800-171 Revision 2 and a separate 800-171 Revision 3 baseline. Choosing the Revision 3 baseline because the number is higher means hardening against requirements the rule does not impose and creating evidence nobody asked for.

Pick the Revision 2 baseline. Where a Revision 3 practice is free to adopt and does not conflict, adopt it and note the decision. Where it costs real money, wait for a rule. We compared the baseline options in [mSCP vs CIS vs STIG](https://www.cmmcoperator.com/mscp-vs-cis-stig-cmmc-mac-baseline/).

## How do you keep documentation from going stale?

Version everything and date everything. 32 CFR 170.17(a)(1) has a C3PAO submit "the name, date, and version of the SSP" into the record, so your plan already needs a version identity whether or not you maintain one deliberately.

Three habits that survive a change of standard:

- **Cite the revision explicitly.** Write "NIST SP 800-171 Rev 2, requirement 3.4.1" rather than "800-171 3.4.1." When Revision 3 arrives, the ambiguous references are the ones you cannot triage.
- **Separate the requirement from the implementation.** If the citation and the narrative are tangled in one paragraph, a revision change means a rewrite instead of a remap.
- **Keep a dated decision log.** When you choose a baseline or set an organisation-defined value, record why and when. Assessors ask, and a year later you will not remember.

This is also why the [Mac control map](https://www.cmmcoperator.com/cmmc-for-macos/) is worth keeping revision-tagged. Documentation that carries its own version metadata is the difference between a revision change costing a week and costing a quarter. That is the actual argument for maintained templates over a one-time write.

## Sources

- 32 CFR 170.2, 170.14(c)(3), 170.17(a)(1)
- NIST CSRC publication record for SP 800-171 Rev 2, withdrawn May 14, 2024
- DoD CIO memo 26-P-1023, July 2026
- github.com/usnistgov/macos\_security baseline list

*Verified against primary sources on August 1, 2026\. Forecasts about Revision 3 adoption are labelled as opinion where they appear. This is not legal advice.*