Skip to content
Foxx Cyberfoxxcyber/docs

Preparing for Revision 3

Plan and run a side-by-side migration of a package from NIST SP 800-171 Revision 2 to Revision 3.

CMMC assessments today use NIST SP 800-171 Revision 2. Revision 3 (final, May 2024) reorganizes the catalog into 97 requirements across 17 families and adds 88 organization-defined parameters (ODPs) you fill in yourself. Bedrock CMMC lets you prepare for Rev 3 without disturbing the package you are being assessed on.

Comparing revisions

With a package selected, the Controls page header shows the package's current revision (Rev 2) and two links:

  • Compare with Rev 3 — a read-only, side-by-side view of how each of your Rev 2 requirements maps onto Rev 3.
  • Prepare for Rev 3 — opens the migration wizard.

The migration wizard

The Prepare for Rev 3 page with the wizard steps, requirement counts, and the requirement dispositions bar

The wizard builds a migration plan and then creates a new, linked Rev 3 package beside your existing one. Your Rev 2 package is untouched — it stays fully assessable while you work through the transition.

The overview summarizes what the move involves for this package:

  • Requirements — how many Rev 2 requirements become how many Rev 3 requirements, with counts of new and retired items.
  • Carried by default — requirements whose statuses carry forward unchanged, plus those flagged for review or reset.
  • In scope to carry — the evidence links and POA&Ms that can move with the package.
  • ODPs to define — the organization-defined parameters you still need to fill in.
  • Requirement dispositions — a bar showing NIST's change analysis for your package: no significant change, minor change, significant change, new requirement, and withdrawn.

The steps run in order: Overview → Review mapping → ODP worksheet → Carry options → Dry run → Execute. Click Start migration plan to begin.

Nothing is copied without your consent. Carry-forward is overridable per requirement, evidence/POA&M/narrative carries are opt-in, and execution requires an explicit dry run and confirmation.

Last updated August 26, 2026