Linkedin
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Menu Categories
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Linkedin
Cart To use Cart please install WooCommerce plugin
Rev. 2 to Rev. 3: What Changes for a Small Enclave | Overwatch Tools
The Second Front · Part 3 of 4

Rev. 2 to Rev. 3: What Changes for a Small Enclave

The Department of War enforces one revision of NIST SP 800-171. The proposed FAR CUI rule reaches for the next one. If both touch your company, you don't get to pick.

By Rob Maupin, founder of Overwatch Tools and author of the CMMC Practical Guides series — Volume 1: CMMC Level 1 and Volume 2: CMMC Level 2.

Published September 7, 2026. This article describes a proposed rule published June 23, 2026 at 91 FR 37550, whose comment period closed July 23, 2026. Proposed language changes before it becomes final. It also reflects the Department of War announcement of July 13, 2026; the CMMC Reform Task Force is expected to deliver its recommendations to the Department of War CIO on or about September 13, 2026. The revision delta described here stands regardless of what those recommendations contain. We'll have our read on the report once it lands.

⚠ This rule is proposed, not final

Nothing here says you must implement NIST SP 800-171 Rev. 3 today. No contractor is currently required to. The FAR CUI rule is a proposal, and its obligations attach only when a final rule issues and the resulting clauses appear in your contracts. The revision number named in the final text could change. Read this as lead time, not urgency — the delta takes the same number of months to work whether a rule is pending or not, and only one of those schedules belongs to you.

Coverage of the proposed FAR CUI rule has focused on the parts that generate headlines: a new clause set, a new standard form, a 72-hour reporting window. Those are real. They are also the parts a competent contracts person absorbs in an afternoon.

The part with a long tail is a single reference buried in the clause text. Proposed FAR 52.240-7 would require contractor systems handling Controlled Unclassified Information — CUI — to meet the security requirements of NIST SP 800-171 Revision 3. The Department of War still enforces Revision 2, and the July 13 suspension of CMMC Phase II did nothing to change that.

Same standard. Different revision. Potentially both at one company. That is the most durable question in this series, because it outlives whatever happens to any particular rulemaking.

Why the two sides sit on different revisions

NIST published Revision 3 of SP 800-171 in May 2024. The gap that opened afterward isn't disagreement about security. It's a difference in what each side had to do to move.

Defense side — Rev. 2

  • 32 CFR Part 170 states that CMMC Level 2 security requirements are identical to NIST SP 800-171 Rev. 2
  • A Department class deviation pinned DFARS 252.204-7012 to Rev. 2 rather than the version in effect at solicitation
  • Moving to Rev. 3 requires rulemaking — an amendment to 32 CFR Part 170, a DFARS change, or a class deviation
  • The Phase II suspension of July 13, 2026 did not touch the underlying standard

Civilian side — proposed Rev. 3

  • Proposed FAR 52.240-7 would require systems handling CUI to meet NIST SP 800-171 Rev. 3
  • The January 2025 version of the rule named Rev. 2; the June 2026 rewrite raised it
  • Nothing to unwind — the Council was writing a new framework, so it started from the current publication
  • The Council expects to finalize the Overhaul rules before the end of 2026, with no anticipated phase-in

One further signal is worth knowing about precisely because it's easy to over-read. In 2025 the Department published its own set of organization-defined parameters for Rev. 3 — the values a contractor would fill in if Rev. 3 ever became the defense baseline. That changed nothing about what anyone owes today. What it tells you is that preparation for a revision change has been underway for a while, which is more useful than a prediction.

What would actually constitute a change

On the defense side: a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170. A memo changes discretion; a rule changes obligations. On the civilian side: a final rule in the Federal Register, then clauses in your solicitations. Until one of those happens, Rev. 2 is the defense baseline and the civilian requirement is a proposal. We won't speculate about outcomes, and you shouldn't budget against a forecast either.

What changed between the revisions — structurally

This article won't walk you through the differences requirement by requirement. That belongs in the standard itself, it would be stale within a year, and a blog post pretending to substitute for NIST SP 800-171 does you a disservice. What's worth understanding is the shape of the change, because the shape determines how much work the delta represents.

110 → 97 Security requirements — fewer, because many were consolidated rather than removed
14 → 17 Requirement families — Planning, System and Services Acquisition, and Supply Chain Risk Management were added
320 → 422 Determination statements in the companion assessment publication — the evidence bar rose while the requirement count fell

Four structural shifts matter more than any individual requirement:

The count went down; the work didn't

Roughly a third of the Rev. 2 requirement numbers are marked withdrawn in Rev. 3. Very few disappeared as obligations — most were absorbed into adjacent requirements or consolidated into broader ones. Reading “97 instead of 110” as a reduction in effort is the most common misread of this revision.

Organization-defined parameters arrived

Rev. 3 embeds bracketed values inside the requirement text — frequencies, thresholds, time periods — that the organization specifies. They appear in roughly half the 97 requirements. These are not configuration tasks. They are decisions, each needing a rationale, an approver, and a place to live in your documentation. For a small contractor without a security committee, this is the least technical and most underestimated part of the delta.

Assumed controls stopped being assumed

Rev. 2 leaned on a category of controls expected of any competent organization and therefore not spelled out. Rev. 3 largely drops that convenience, aligning to NIST SP 800-53 Rev. 5 as the single authoritative source and eliminating the old basic-versus-derived split. Practically: policy and planning documentation that used to be implied is now explicit — which is why the new Planning family shows up.

The assessment got more granular

The companion assessment publication grew from 320 determination statements to 422. Same broad control territory, finer-grained proof. An evidence set built to answer 320 questions will answer some of the 422 and not others.

What “working the delta” concretely involves

Here is what surprises people: at small-enclave scale, most of the delta is paperwork and decisions, not architecture. A contractor who built a properly scoped CUI enclave to Rev. 2 does not tear it down. The controls are recognizably the same controls. What changes is how they're described, parameterized, and proved.

1

Crosswalk before you touch anything

Map your existing Rev. 2 artifact set to the Rev. 3 requirement numbers. Most policies survive with a heading change and a renumbered reference. The output is a short list of genuine gaps — almost always shorter than people fear.

2

Decide your parameters and record who decided

Set a value for each organization-defined parameter and record the reasoning and the approving official. In a small business that's usually the owner or manager signing off on what the IT point person recommends. It's a sit-down-and-think exercise, not a console exercise, and it doesn't parallelize well.

3

Absorb the three new families at enclave scale

Planning, System and Services Acquisition, and Supply Chain Risk Management sound enterprise-sized. Inside a defined enclave with a handful of users, one platform, and a short vendor list, they mostly formalize what you already do informally: how you plan security for the enclave, how you evaluate what you buy for it, how you handle the suppliers who touch it. The families are new. At this scale, the underlying activity largely isn't.

4

Re-baseline the evidence, not the environment

Walk your evidence set against the finer-grained determination statements and find where a single screenshot or log export used to answer a question that is now three questions. This is unglamorous and it is where the hours actually go.

5

Rewrite the plan, keep the system

The system security plan gets restructured against the new family set; the environment it describes mostly stays put. That ordering — documentation follows architecture, not the reverse — is why a contractor who scoped well the first time gets off cheaply.

Scope decides how big the delta is

Every item on that list is priced per unit of scope. That is the whole argument.

Crosswalking artifacts, setting parameters, and re-baselining evidence all scale with the number of systems, users, and locations inside your protected boundary. A contractor who confined CUI to a defined enclave works the delta once, across a small footprint. A contractor who hardened the whole company for CUI living on one contract works the same delta across every laptop, mailbox, and file share in the business — and then, on a mixed portfolio, maintains two revision baselines across all of it.

That multiplication is the real cost of an unscoped posture, and it stays invisible until a revision changes. The proposal leans the same way: it clarifies that certain assets would sit outside scope, which only helps a contractor who drew a boundary in the first place. This is what Volume 2 of the CMMC Practical Guides spends its scoping chapters on — enclave scope is a decision you make once and collect on repeatedly, at every assessment, every platform change, and every revision of the standard. The 110 practices across 14 domains don't get easier. The surface you apply them to is the variable you control.

⚠ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO — a certified third-party assessor organization — are not in scope.

Find out how wide your delta actually is

A gap assessment against Rev. 3 is a scoping conversation before it's a technical one. Thirty minutes, no charge — we walk your boundary, your existing artifact set, and where the real gaps would land.

Book a 30-Minute Consultation → We provide templates, configuration guides, and consulting. Clients implement.

NIST SP 800-172, scoped accurately

One more publication belongs here, and it's routinely inflated in vendor marketing, so precision matters.

NIST SP 800-172 is a supplement to SP 800-171, not a replacement. It provides enhanced requirements aimed at advanced persistent threats, for CUI associated with a critical program or a high-value asset. NIST finalized Revision 3 of it in May 2026, expanding the objective from confidentiality alone to confidentiality, integrity, and availability.

The proposed rule contemplates that for contracts involving critical programs or high-value assets, an agency could layer selected 800-172 controls on top of the Rev. 3 baseline. That's the accurate statement. Four qualifiers keep it from becoming something it isn't:

  • It's selective, not wholesale. NIST is explicit that there's no expectation agencies will require all of the enhanced requirements; they're picked against mission risk.
  • It applies only when an agency invokes it. Nothing in 800-172 self-executes. It arrives in a contract or it doesn't exist for you.
  • The trigger is narrow. Critical programs and high-value assets are a small slice of federal work.
  • The defense analogue is tiny. Under 32 CFR Part 170 the Department selected a subset of the original 800-172 requirements as the basis for CMMC Level 3 — well under one percent of the defense industrial base, assessed by the government rather than by self-assessment.

If you're a five- to fifty-person contractor with limited CUI on a services contract, the honest expectation is that this never touches you. Know the term, recognize it in a solicitation, and don't budget for it on spec.

📚 The method behind the argument

This article covers one revision change. The full method — scoping the boundary, building the artifact set, and running the self-assessment — runs to two volumes.

Cover of CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors
CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors

All fifteen practices, FCI versus CUI, scoping, the system description, evidence, and the annual affirmation — written for the 5- to 50-employee contractor.

Cover of CMMC Level 2: A Practical Guide for Small to Medium GovCon Contractors
CMMC Level 2: A Practical Guide for Small to Medium GovCon Contractors

CUI enclave scoping, the 110 practices across 14 domains, the system security plan, POAM framework, and risk register — without assuming an enterprise IT department.

Overwatch Press. Kindle, paperback, and hardcover — Kindle from $12.99. See the series on Amazon →

Build once, map twice

The mixed-portfolio contractor — defense work under DFARS 252.204-7012 and civilian work that would fall under the proposed clauses — has the most interesting problem here. Two regimes, two revision numbers, one company.

The answer is not two enclaves. It's one enclave and a documentation set built to be mapped twice — a few habits that cost almost nothing adopted early and a great deal retrofitted:

  • Organize artifacts by what they do, not by the requirement number they satisfy. An access control policy is an access control policy. Filing it as “3.1.1” welds it to one revision's numbering.
  • Keep a crosswalk column. One spreadsheet column per applicable standard, mapping each artifact to the requirement it answers under each. When a revision changes, you update a column, not a library.
  • Write parameters as named values. Put your chosen frequencies and thresholds in one register that the procedures reference, rather than hardcoding numbers into a dozen documents.
  • Separate the description of the environment from the mapping. What your enclave is doesn't change when a revision does. Keep that description standalone so it survives.

None of this is exotic. It's the same discipline that lets a Level 1 system description survive a platform migration, applied one level up. Worth noting: the proposal would renumber the familiar FAR 52.204-21 basic safeguarding clause as well — another reason to anchor documentation to function rather than to citation.

Our Analysis — not a commitment

In our experience a contractor with a well-scoped enclave and a complete Rev. 2 artifact set works the delta in a fraction of the effort the original build took, and most of that effort lands on documentation and parameter decisions rather than configuration. We're deliberately not attaching a week count: the range is wide and moves with how complete your artifact set is, how many people sign off, and how much of your environment sits outside a defined boundary. That reflects what we typically see. It is not a guarantee and not a commitment.

What we will say with confidence: a contractor starting from a clean, scoped Rev. 2 baseline and one starting from an undocumented company-wide posture are not doing the same project.

⚠ Self-Assessment Programs Only. Our L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope. We provide templates, configuration guides, and consulting — clients implement. Level 2 always sits on top of Level 1: the enclave holds CUI, and the rest of your environment still holds Federal Contract Information and carries its own Level 1 obligation.

Why lead time is the right frame

Here is the asymmetry that makes this worth acting on even though the rule is only a proposal.

Running a gap assessment against Rev. 3 produces a document. If the rule shifts, changes revisions, or slips a year, you've spent modest effort and you own a current, honest picture of your environment — useful for the defense side, for a prime's questionnaire, and for your own risk decisions. There is no version of the future in which knowing your gaps is wasted.

If it finalizes roughly as written, the Council expects to complete the Overhaul rules before the end of 2026, with no anticipated phase-in once clauses are inserted into contracts. Under the proposal, an offeror who can't meet every requirement at proposal time would disclose the gaps and provide a POAM. Workable — and dramatically more workable when that POAM comes from an assessment you already ran rather than one you're drafting in the last week of a proposal.

That's the case. Cheap if nothing happens, months saved if something does. The work takes the same time either way; the only variable is whose calendar it runs on.

Start the delta on your schedule, not a clause's

Bring your current artifact set and your contract list. We'll tell you honestly whether the delta is a documentation project or something bigger — and if you aren't there yet, we'll say that too.

Schedule Your 30-Minute Call → Free Level 1 Gap Check The free tool covers all 15 CMMC Level 1 practices and returns a prioritized gap report in under 30 minutes — the right starting point if Federal Contract Information is where you are today. No credit card.

The Second Front — a four-part series

  1. The CMMC Pause Didn't Touch Your Civilian Contracts — one pause, two regimes, and who the FAR CUI rule reaches.
  2. Do You Actually Hold CUI on a Civilian Contract? — sensitive, proprietary, and export-controlled are not synonyms for CUI.
  3. Rev. 2 to Rev. 3: What Changes for a Small Enclave — you're here.
  4. One Enclave, Two Regimes — building a boundary once that answers to both sets of requirements.

About the author

Rob Maupin is the founder of Overwatch Tools, a CMMC compliance practice for small to medium defense contractors, and the author of the CMMC Practical Guides series from Overwatch Press: CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors and CMMC Level 2: A Practical Guide for Small to Medium GovCon Contractors. Both are available in Kindle, paperback, and hardcover — Kindle from $12.99. He works with 5- to 50-employee GovCon firms on right-sized compliance.

A guided documentation path for the L2 CUI Enclave Package is in development.

Sources

  • Federal Register — Revolutionary FAR Overhaul proposed rules, June 23, 2026 (91 FR 37550)
  • Federal Register — FAR Controlled Unclassified Information proposed rule, January 2025 (90 FR 4278, FAR Case 2017-016)
  • Hunton Andrews Kurth — analysis of the updated CUI proposed rule, June 30, 2026
  • NIST SP 800-171 — Protecting CUI in Nonfederal Systems and Organizations
  • NIST SP 800-172 Rev. 3 — Enhanced Security Requirements for Protecting CUI (final, May 2026)
  • NIST — release announcement for SP 800-172r3 and SP 800-172Ar3
  • Department of War — CMMC Phase II suspension release, July 13, 2026
  • SBA Office of Advocacy — CMMC Reform Task Force request for information

This article is general information about a proposed regulation, not legal advice. Contract interpretation and any question touching False Claims Act exposure should go to your attorney.

Tags: cmmc, FCI_vs_CUI, Google, L1, L2, Level 1, Level 2, MS365, NIST
Share Post
  • Twitter
  • Facebook
  • Pinterest
  • Linkedin
Do You Actually Hold CUI on a ...
Do You Actually Hold CUI on a Civilian Contract?
"Suspended" Is the Wrong Word. So Is "Cancelled."
“Suspended” Is the...

Related posts

Your Whole Office Doesn't Need to Be Level 2
Read more

Your Whole Office Doesn’t Need to Be Level 2

Your Whole Office Doesn’t Need to Be Level 2 | Overwatch Tools The Enclave Build · Part 1 of 6 Your Whole Office Doesn’t Need to Be Level 2 If your CUI lives on one or two contracts, a Level 1 workplace with a small Level 2 enclave is often the better build: easier to work in,... Continue reading
What a Task Force Report Can and Cannot Change
Read more

What a Task Force Report Can and Cannot Change

What a Task Force Report Can and Cannot Change | Overwatch Tools Reference · The Deviation, Part 3 What a Task Force Report Can and Cannot Change The report will be read as a verdict. It is closer to an opening argument. Here is how to read it when it arrives, and the three documents that actually... Continue reading
The Department Asked Seven Questions. Read Them Closely.
Read more

The Department Asked Seven Questions. Read Them Closely.

The Department Asked Seven Questions. Read Them Closely. | Overwatch Tools Analysis · The Deviation, Part 2 The Department Asked Seven Questions. Read Them Closely. The Task Force report isn’t public. The questions that shaped it have been public since July — and almost nobody has read them carefully. By Rob Maupin, Overwatch Tools — author of... Continue reading
"Suspended" Is the Wrong Word. So Is "Cancelled."
Read more

“Suspended” Is the Wrong Word. So Is “Cancelled.”

“Suspended” Is the Wrong Word. So Is “Cancelled.” | Overwatch Tools Industry Update · The Deviation, Part 1 “Suspended” Is the Wrong Word. So Is “Cancelled.” The CMMC pause stopped living in a memo in July. And the September document that half the industry read as the end of the program did not change the CMMC text... Continue reading
Do You Actually Hold CUI on a Civilian Contract?
Read more

Do You Actually Hold CUI on a Civilian Contract?

Do You Actually Hold CUI on a Civilian Contract? | Overwatch Tools The Second Front · Part 2 of 4 Do You Actually Hold CUI on a Civilian Contract? Sensitive, proprietary, and export-controlled are three different things. None of them is automatically Controlled Unclassified Information — and the difference decides your scope. By Rob Maupin, founder of... Continue reading

Comments are closed

Company Address

  • Overwatch Tools, Inc.
  • 300 Woodards Ford Road
  • Chesapeake Virginia 23322
  • E-Mail: info@overwatchtools.com
  • Outervision Capitol Company
  • Privacy Policy

,Copyright © 2025 Overwatch Tools, Inc.

Home
Shop
Contact us
More
More
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool