Skip to content
Foxx Cyberfoxxcyber/docs

Moving to NIST SP 800-171 Rev. 3

Compare a CMMC Level 2 client's answers with NIST's Rev. 2 to Rev. 3 change analysis, choose an action per practice, and copy the answers into NIST SP 800-171 Rev. 3 without touching CMMC Level 2.

CMMC Level 2 is built on NIST SP 800-171 Rev. 2, and it stays that way in Bedrock GRC: the catalog's CMMC Level 2 framework keeps Rev. 2's 110 practices, 320 objectives and SPRS weights. A client that wants to work on NIST SP 800-171 Rev. 3 as well can carry its CMMC Level 2 answers across in one step, guided by NIST's own analysis of what changed between the two revisions.

Open the comparison

On the client's Frameworks tab, open the CMMC Level 2 row's menu (the button with three dots) and choose Compare with SP 800-171 Rev 3. The client needs CMMC Level 2 adopted; it does not need Rev. 3 adopted yet.

The page is a comparison and changes nothing until you choose Move to Rev 3. At the top, four tiles sort the practices by what NIST's analysis says about them:

TileNIST's change classWhat the move does by default
Carry as isNo significant changeCopies the answer.
Carry, then reviewMinor changeCopies the answer, with NIST's summary of the change so a reviewer can see it.
ReworkSignificant changeCopies the narrative and evidence location as a starting point, but leaves the status not assessed and does not copy maturity.
New workNew requirement in Rev. 3Nothing to carry. The tile also counts the ODPs still to define.

A line under the tiles adds the rest: how many withdrawn practices merge into the requirements that absorbed them, how many are retired with no successor, how many carried practices are met or not applicable today, and how many Rev. 3 requirements already have an answer (those are kept).

Below that, every Rev. 3 family has a table with each CMMC Level 2 practice and the client's current answer, NIST's change class and summary, an ODP badge where Rev. 3 added an organization-defined parameter, the Rev. 3 requirement, and an Action.

Choose an action per practice

Each practice's Action starts at the default for its change class. Change any of them:

  • Carry as is: status, maturity, target maturity, narrative and evidence location are copied.
  • Carry, then review: the same, plus NIST's summary of the change.
  • Rework: the narrative and evidence location only, as a starting point.
  • Skip: nothing is copied.

Recalculate with these actions updates the tiles without moving anything.

Move to Rev 3

At the bottom of the page:

  • Link each practice's documents and evidence to its Rev 3 requirement too (on by default).
  • Link each practice's open roadmap items to its Rev 3 requirement too (on by default).
  • Make Rev 3 the client's primary framework (off by default; CMMC Level 2 stays primary).

Choose Move to Rev 3 and confirm. In one step:

  • NIST SP 800-171 Rev. 3 is adopted if the client has not adopted it.
  • CMMC Level 2 answers are never changed.
  • A Rev. 3 requirement that already has an answer is never overwritten. It is skipped and counted.
  • Practices that are still not assessed have nothing to carry and are left out.
  • Withdrawn practices merge into each requirement that absorbed them, and the weakest answer wins: not implemented, then partial, then implemented; not applicable only when every source is.
  • Every carried narrative says where it came from, for example "Carried from CMMC L2 AC.L2-3.1.1 (no significant change) on Oct 8, 2026. Review before relying on it."
  • Linked documents and open roadmap items follow, if you left those boxes ticked.

The Rev. 3 framework page then records the move, with the date and counts, and asks you to review each carried answer before relying on it. The move is written to the client's audit trail.

What the move does not do

  • Objective answers are not carried. Rev. 3's determination statements are new, so there is nothing to map them from. Answer them on the Rev. 3 control pages; see Objectives, one by one.
  • ODPs are answered like objectives. Rev. 3 has 88 organization-defined parameters; each is an objective on its requirement's page, and its note holds the value the client defined.
  • Snapshots are not copied. Rev. 3 starts its own posture history.
  • There is no SPRS score for Rev. 3. It is scored by coverage and maturity.
  • A second move is refused. After the move the comparison page stays available, read-only.
  • A move is refused while a partner firm holds either framework. When the firm holds the CMMC Level 2 framework, the page shows the comparison read-only. Assessors cannot open this page.

Last updated October 9, 2026