r/NISTControls • u/ElectricalEinstein • 8d ago
800-171 C3PAO goes away, but NIST 800-171 requirements still apply… for now anyway.
From the various press releases, it looks to me that (at least until the 60day review period is up) that 800-171 requirements are still in place. But the Phase 2 (Nov 10th deadline) for C3PAO goes away.
\- Press release calls out “It is critical to note that this action does not eliminate the requirement for companies to protect federal data. All defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012”
\- “[the number of available assessors is not large enough to conduct all the evaluations needed in time for the upcoming November deadline.](https://www.war.gov/News/News-Stories/Article/Article/4542849/war-department-changes-cybersecurity-maturity-model-certification-requirements/)”
\- L2 C3PAO deadline & listing have been removed from the [Overview of Assessments](https://dodcio.defense.gov/CMMC/About/)
I am getting employees stoked that all the controls will be pulled, but I don’t see that as the outcome here.
We still need data security, this just gives some breathing room while standards are re-evaluated.

