DoD Specifies Implementation Requirements for NIST 800-171 Cyber Standard
Client Alert | 1 min read | 05.15.25
The Department of Defense (DoD) has released a memorandum establishing the DoD Organization-Defined Parameters (ODPs) for use in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision (Rev) 3. Currently, DoD’s cybersecurity regimes require government contractors to comply with NIST SP 800-171 Rev. 2. However, the release of this memorandum may indicate DoD’s intention to soon incorporate Rev. 3 into DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 7012) as well as the forthcoming Cybersecurity Maturity Model Certification (CMMC).
NIST SP 800-171 Rev. 3 was released in May 2024. Rev. 3 introduced new controls and control families, increased specificity for certain security requirements, and introduced Organization-Defined Parameters into 800-171. ODPs are “fill-in-the-blanks” to be filled by federal agencies to create tailored requirements for each agency’s specific needs.
DoD’s selected ODPs range from time-based requirements, such as requiring inactive user accounts to be terminated within 24 hours, to specific technical requirements, such as the use of Federal Information Processing Standard (FIPS) validated cryptography. The ODPs will also require flowing down certain protections to subcontracts, through requiring external service providers to meet NIST SP 800-171 Rev 2 and requiring integration of supply chain risk management into procurement policies.
The ODPs will not take immediate effect. Shortly after the release of NIST SP 800-171 Rev. 3, DoD issued a class deviation to clarify that NIST SP 800-171 Rev. 2 would continue to be used for the DFARS 7012 Safeguarding Clause. However, this new memorandum indicates that companies should begin preparing for Rev. 3, as it suggests that DoD is gearing up for Rev. 3 implementation in both the DFARS 7012 and CMMC requirements.
Recommendation
Companies should review the new security requirements and DoD-specific ODPs to determine what technical and administrative revisions would be required to meet these emerging requirements.
Contacts
Insights
Client Alert | 5 min read | 06.05.26
The Office of Management and Budget issued on May 29, 2026 a Proposed Rule that would significantly revise the Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) at 2 C.F.R. Part 200, potentially impacting the full lifecycle of federal grants, cooperative agreements and other forms of financial assistance, from pre-award merit review through post-award administration and termination. These proposed changes are designed to implement the President’s policy priorities, executive actions related to diversity, equity and inclusion (DEI) activities, and Executive Order No. 14332, Improving Oversight of Federal Grantmaking (EO 14332).
Client Alert | 5 min read | 06.04.26
EU Pay Transparency Directive: The Transposition Deadline is Looming — What Now?
Client Alert | 4 min read | 06.04.26
Surveillance Pricing Update: California’s Sweeping AB 2564 Passes Assembly and Heads to Senate
Client Alert | 4 min read | 06.04.26
USTR Proposes Sweeping Tariffs as Part of Section 301 Forced Labor Import Enforcement Investigation


