Skip to main content

NIST 800-171 Rev 3 Class Deviation for Controlled Unclassified Information

The National Institute of Standards and Technology published updated requirements for the handling of Controlled Unclassified Information. Contractors working with the Department of Defense, however, have been exempted from their application.

In early May 2024, the US DoD (Department of Defense) issued a class deviation that suspends the application of new cybersecurity requirements for Controlled Unclassified Information (CUI). The previous requirements will continue to apply until further communication.

The new security requirements for CUI

On May 14, 2024, the National Institute of Standards and Technology (NIST) published Revision 3 of Special Publication (SP) 800-171 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. SP 800-171 describes the controls that government contractors must put in place when processing, storing or transmitting CUI. The document is divided into areas, called families (for example Access Control, Incident Response and Risk Assessment), with several controls included in each family.

The emphasis of the publication is on digital data, although it also includes requirements for the protection of physical information, such as limiting access to systems and facilities to authorized individuals.

Some of the important changes introduced by Revision 3 are:

  • Three new families: Planning, System and Services Acquisition, and Supply Risk Management
  • 19 new requirements across ten families
  • Withdrawal or consolidation of 33 requirements
  • A more detailed description of each requirement, with the addition of references to support guidance
  • The introduction of organization-defined parameters (ODPs), which allow individual agencies to set their own criteria for identified controls.

Impact of Rev 3 on DIB contractors

The impact of Revision 3 is potentially significant for Defense Industrial Base (DIB) contractors, as they are required by the Defense Federal Acquisition Regulation Supplement (DFARS)to implement the SP 800-171 version that is currently “in effect at the time the solicitation is issued,” if they want to bid on a contract.

The recent class deviation provides a blanket exemption to that rule and confirms that Revision 2 remains the standard of reference for the time being. By suspending compliance to NIST 800-171 Revision 3, the DoD is allowing for a more gradual transition, while preventing conflicts with the upcoming Cybersecurity Maturity Model Certification (CMMC) program, which is aligned with NIST 800-171 Revision 2 and is expected to be effective in the coming months.

What does the DoD class deviation mean to your business?

The exemption granted by the DoD currently has no end date: Revision 2 will remain acceptable until “rescinded.” However, contractors within the DIB should continue to implement Revision 2 in order to comply with the upcoming CMMC framework and also be mindful that the implementation of Revision 3 has simply been postponed and will be required in the near future.

NSF-ISR's Security Gap Assessment

Information security is a concern for everyone, and we believe that all businesses can benefit from a comprehensive security assessment. Whether you're looking for a one-time audit or working toward certification, NSF-ISR's Basic Security Assessment is the starting point.

How NSF Can Help You

Get in touch to find out how we can help you and your business thrive.

What’s New with NSF

  • Information Systems Security Association (ISSA) Welcomes NSF’s Brian Schultz into the 2026 Hall of Fame

    September 10, 2026
    Lifetime achievement recognition honors exceptional leadership and lasting contributions to the cybersecurity profession.
    Read the Story
  • NSF Welcomes Nicole Parent Haughey to Board of Directors

    September 10, 2026
    NSF's appointment of Nicole supports the organization's continued focus on long-term growth and transformation.
    Read the Story
  • NSF Launches Independent Certification Standard for Compact Products

    August 25, 2026
    New third-party certification verifies products cutting materials and shipping impacts while maintaining safety and performance.
    Read the Story
  • NSF Achieves European Accreditation for Drinking Water Product Certification Ahead of 2027 EU Deadline

    July 22, 2026
    The ISO/IEC 17065 accreditation from BELAC complements NSF’s testing capacity, enabling end-to-end support for EU Drinking Water Directive (DWD) readiness ahead of the January 2027 deadline.
    Read the Story