CMMC Mandates a NIST Standard NIST Has Withdrawn
Quick answer: build to Revision 2, even though NIST withdrew it in 2024. CMMC incorporates Revision 2 by regulation, and a regulation does not update itself when a standards body moves on. This is one of the stranger facts in the programme and almost nobody states it plainly.
Which revision does CMMC actually require?
Revision 2, without ambiguity. 32 CFR 170.2 incorporates by reference "SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, Revision 2, February 2020 (includes updates as of January 28, 2021)," together with SP 800-171A of June 2018.
32 CFR 170.14(c)(3) says the same thing from the other side: "the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2."
No Revision 3 is incorporated anywhere in the rule.
Did NIST really withdraw Rev 2?
Yes. The NIST Computer Security Resource Center records SP 800-171 Revision 2 as withdrawn on May 14, 2024, superseded by Revision 3.
So the position today is that CMMC Level 2 mandates a publication its own author has formally retired. That is not a criticism of anyone. Incorporation by reference is how regulations achieve stability, and the alternative would be a standard that changes underneath contractors without notice. But it does mean the version on the NIST landing page is not the version you are assessed against.
Practically: keep a copy of Revision 2 and Revision A of the assessment guidance. Do not let a well-meaning consultant hand you Revision 3 controls because it is the current document.
Is Rev 3 coming to CMMC?
Eventually, almost certainly. On any near-term timeline, there is nothing to act on.
What is verifiable today is narrow. 32 CFR 170.2 still incorporates Revision 2. We found no published rule adopting Revision 3 into CMMC. Anything beyond that, including forecasts of a dual Revision 2 and Revision 3 reporting period in SPRS, is practitioner opinion rather than sourced fact, and should be labelled that way when you hear it.
The wider context points away from a near-term raise in the standard. The Department suspended the Phase 2 transition in July 2026 under memo 26-P-1023 and stood up a reform task force. A programme reviewing how to reduce compliance burden is not a programme about to adopt a larger control set. That reading is inference, not a sourced statement of intent.
What should you build to today?
Revision 2, with an eye on Revision 3 where the cost of alignment is zero.
For a Mac fleet this is a concrete choice rather than an abstract one. The macOS Security Compliance Project publishes both a baseline labelled CMMC that maps to 800-171 Revision 2 and a separate 800-171 Revision 3 baseline. Choosing the Revision 3 baseline because the number is higher means hardening against requirements the rule does not impose and creating evidence nobody asked for.
Pick the Revision 2 baseline. Where a Revision 3 practice is free to adopt and does not conflict, adopt it and note the decision. Where it costs real money, wait for a rule. We compared the baseline options in mSCP vs CIS vs STIG.
How do you keep documentation from going stale?
Version everything and date everything. 32 CFR 170.17(a)(1) has a C3PAO submit "the name, date, and version of the SSP" into the record, so your plan already needs a version identity whether or not you maintain one deliberately.
Three habits that survive a change of standard:
- Cite the revision explicitly. Write "NIST SP 800-171 Rev 2, requirement 3.4.1" rather than "800-171 3.4.1." When Revision 3 arrives, the ambiguous references are the ones you cannot triage.
- Separate the requirement from the implementation. If the citation and the narrative are tangled in one paragraph, a revision change means a rewrite instead of a remap.
- Keep a dated decision log. When you choose a baseline or set an organisation-defined value, record why and when. Assessors ask, and a year later you will not remember.
This is also why the Mac control map is worth keeping revision-tagged. Documentation that carries its own version metadata is the difference between a revision change costing a week and costing a quarter. That is the actual argument for maintained templates over a one-time write.
Sources
- 32 CFR 170.2, 170.14(c)(3), 170.17(a)(1)
- NIST CSRC publication record for SP 800-171 Rev 2, withdrawn May 14, 2024
- DoD CIO memo 26-P-1023, July 2026
- github.com/usnistgov/macos_security baseline list
Verified against primary sources on August 1, 2026. Forecasts about Revision 3 adoption are labelled as opinion where they appear. This is not legal advice.