Spring Has Sprung New Cyber Requirements: NIST Unveils Draft Revision 3 to NIST SP 800-171
Client Alert | 1 min read | 05.12.23
On May 10, 2023, the National Institute of Standards and Technology (NIST) released a draft of NIST Special Publication (SP) 800-171 Revision 3, containing new and revised cybersecurity controls that, when finalized, will be required for federal contractors handling Controlled Unclassified Information (CUI).
NIST proposed five key changes to NIST SP 800-171:
- New controls and control families. Like Revision 2, NIST SP 800-171 Revision 3 contains 110 total security controls. However, in Revision 3, NIST deleted or consolidated older controls to make way for 26 new controls, including 3 new control families.
- Introduction of organization-defined parameters (ODP). NIST introduced ODP in select security controls, increasing flexibility by allowing federal agencies to specify values for designated parameters as needed. For example, Control 3.5.12, “Authenticator Management,” now allows agencies to define the authenticator refreshment time period or, if the agency prefers, require refreshment when an agency-defined event occurs.
- Increased specificity for security requirements. Revision 3 incorporates nuanced security requirements for the majority of its controls. For example, to comply with Revision 3’s Control 3.1.4, “Separation of Duties,” contractors will need to demonstrate that they:
a. identify the duties of individuals requiring separation; and
b. define system access authorizations to support separation of duties. - Updated tailoring criteria. NIST reduced the number of non-federal organization (NFO) controls from Revision 2, as industry feedback revealed that many NFO controls (e.g. AC-1, “Policies and Procedures”) were not being implemented or assessed.
- A prototype CUI overlay. NIST provided a draft CUI overlay spreadsheet along with Revision 3. The overlay describes how each control and control item in the NIST SP 800-53 moderate baseline—essentially, NIST SP 800-171’s parent standard—is tailored to protect CUI in NIST SP 800-171.
NIST is soliciting comments on Revision 3 through July 14, 2023. Any interested parties may email their comments to 800-171comments@list.nist.gov.
Contacts
Insights
Client Alert | 3 min read | 06.12.26
DOJ Guidance Backs Away From Disparate Impact Liability
On June 9, 2026, the U.S. Department of Justice (DOJ) issued a formal opinion concluding that the Equal Opportunity Employment Commission’s (EEOC) existing interpretations of Title VII of the Civil Rights Act of 1964 (Title VII) disparate-impact liability, including the Uniform Guidelines on Employee Selection Procedures (UGESP), are unconstitutional. According to the opinion, EEOC’s prior interpretations contemplate liability based on disproportionately adverse effects alone, without regard to an employer’s likely intent, rather than treating disparate impact as an evidentiary mechanism to “smoke out” intentional discrimination. DOJ found that this approach functions as a “qualified racial-proportionality mandate” that places “a racial thumb on the scales, often requiring employers to evaluate the racial outcomes of their policies, and to make decisions based on (because of) those racial outcomes.” The opinion fulfills one mandate of Executive Order 14281, which rejected disparate-impact liability insofar as it “creates a near insurmountable presumption that unlawful discrimination exists wherever there are any differences in outcomes among different [demographic groups].”
Client Alert | 4 min read | 06.12.26
Auto Dealers: The FTC Is Back in the Driver’s Seat — Warning Letters Signal Renewed Federal Scrutiny
Client Alert | 13 min read | 06.12.26
Client Alert | 4 min read | 06.12.26


