Defense contractors navigating DFARS obligations face a critical reality: NIST SP 800-171 Revision 2 remains the binding standard for protecting Controlled Unclassified Information even after NIST withdrew the publication. Lazarus Alliance audit teams observe that DoD Class Deviation requirements lock in the original 110 controls for all DFARS 252.204-7012 contracts, creating both stability and strategic planning challenges for organizations preparing CMMC Level 2 self-assessments.
NIST 800-171 Rev 2 Retention Under Current DFARS Mandates
DoD procurement rules explicitly retain the 110 security requirements from NIST SP 800-171 Revision 2 for all applicable contracts. This retention occurs despite broader NIST framework updates, ensuring contractors continue implementing the same access control, audit, and incident response measures. Lazarus Alliance compliance audits verify that organizations map these controls directly to system security plans without substituting newer revision language.
Impact of CMMC Phase 2 Suspension on Rev 2 Obligations
The Department of War suspension of CMMC Phase 2 advancement leaves Phase 1 self-assessments and DFARS 252.204-7012 requirements fully intact. Contractors must still demonstrate full implementation of the 110 Rev 2 controls during annual assessments. Federal News Network, CMMC updates confirm that third-party certification language has been removed from solicitations via Class Deviation 2026-O0025 Revision 3, yet the underlying control set stays unchanged.
Technical Control Implementation Details for Rev 2 Compliance
Rev 2 control 3.1.1 requires limiting system access to authorized users, a requirement Lazarus Alliance auditors test through role-based access reviews and privileged account inventories. Organizations frequently overlook the linkage between this control and 3.1.2, which mandates transaction and file access monitoring. Effective implementation includes automated logging that feeds directly into incident response workflows required under control 3.6.1.
Common Audit Findings in DFARS Environments
Evidence collection gaps appear most often around media sanitization (3.7.9) and physical access controls (3.10.1). Contractors relying on cloud service providers must obtain specific attestations confirming Rev 2 alignment rather than generic SOC 2 reports. Lazarus Alliance recommends maintaining a crosswalk matrix that ties each of the 110 controls to current policies, procedures, and technical evidence artifacts.
Strategic Governance Considerations for Long-Term Rev 2 Retention
Executive leadership must treat Rev 2 retention as a multi-year governance commitment rather than a temporary measure. This includes updating risk assessments to reflect the five-tier vulnerability remediation model introduced in CISA Binding Operational Directive 26-04, which applies risk variables to DFARS-covered systems. CISA, BOD 26-04 guidance integrates directly with Rev 2 audit and accountability controls.
Cross-Framework Alignment Opportunities
Organizations already maintaining ISO 27001:2022 or SOC 2 Trust Services Criteria can leverage overlapping controls to reduce audit burden. However, the 110 Rev 2 requirements contain defense-specific nuances around CUI marking and flow-down to subcontractors that demand dedicated attention. Lazarus Alliance assessments routinely identify where existing ISO Annex A controls satisfy Rev 2 but require supplemental evidence for DFARS-specific clauses.
Actionable Implementation Roadmap
- Conduct a gap analysis mapping current policies against all 110 Rev 2 controls with documented evidence references.
- Update system security plans to reference the retained revision explicitly rather than generic NIST SP 800-171 language.
- Integrate CISA BOD 26-04 risk tiers into existing vulnerability management procedures tied to control 3.11.2.
- Establish quarterly governance reviews that include DFARS flow-down verification to prime and sub-tier contractors.
Lazarus Alliance recommends embedding these steps into existing compliance calendars to avoid last-minute evidence collection during contract award periods. This approach transforms regulatory retention into a competitive advantage for winning and maintaining defense contracts.
Sources and References
- Federal News Network, CMMC Phase 2 updates September 2026
- CISA, Binding Operational Directive 26-04
- DoD Class Deviation references for DFARS 252.204-7012
About Lazarus Alliance
To learn more about how Lazarus Alliance can help, contact us.
- FedRAMP
- GovRAMP
- NIST 800-53
- DFARS NIST 800-171
- CMMC
- SOC 1 & SOC 2
- C5
- HIPAA, HITECH, & Meaningful Use
- PCI DSS RoC & SAQ
- IRS 1075 & 4812
- CJIS
- LA DMF
- ISO 27001, ISO 27002, ISO 27005, ISO 27017, ISO 27018, ISO 27701, ISO 22301, ISO 17020, ISO 17021, ISO 17025, ISO 17065, ISO 9001, & ISO 90003
- And dozens more!




Related Posts