Last updated: August 1, 2026
Important CMMC distinction
NIST published SP 800-171 Revision 3 in May 2024. Current CMMC Level 2 assessment requirements still reference the 110 requirements in Revision 2. CMMCPulsar treats Revision 3 as a separate readiness workspace so users do not mix control baselines or evidence.
What Revision 3 covers
NIST SP 800-171 Revision 3 applies to components of nonfederal systems that process, store, or transmit CUI, or that provide protection for those components. It establishes security requirements derived from the federal control catalog and tailored for protecting CUI.
17 control familiesRequirements are grouped by security capability and operating discipline.
System-focused scopeIdentify components that handle CUI or protect the environment that handles it.
Organization-defined parametersSome requirements require the organization to define values and frequencies.
Assessment companionSP 800-171A Revision 3 provides procedures for assessing each requirement.
The 17 control families
Access ControlAwareness and TrainingAudit and AccountabilityAssessment, Authorization, and MonitoringConfiguration ManagementIdentification and AuthenticationIncident ResponseMaintenanceMedia ProtectionPersonnel SecurityPhysical ProtectionPlanningProgram ManagementRisk AssessmentSystem and Services AcquisitionSystem and Communications ProtectionSystem and Information Integrity
Documentation and evidence that make the program usable
- A defined authorization boundary and inventory of covered components.
- A system security plan that describes how each requirement is implemented.
- Policies and procedures that match actual operating practices.
- Evidence with an owner, source, review date, and mapped requirement.
- Risk decisions, inherited protections, providers, and interconnections.
- Assessment results and remediation records that remain traceable over time.
A practical implementation sequence
1. ScopeFind CUI, covered components, external services, and protection assets.
2. DescribeDocument the current implementation before assigning a status.
3. MapConnect requirements, evidence, owners, providers, and architecture.
4. AssessUse the 800-171A procedures to test whether the requirement is satisfied.
5. RemediatePrioritize gaps by CUI exposure, likelihood, and operational impact.
6. MaintainRefresh evidence and reassess when systems, threats, or requirements change.