NIST 800-171 Rev 3 cut requirements from 110 to 97.

NIST 800-171 Rev 3 cut requirements from 110 to 97. Everyone relaxed.
Then assessment objectives jumped from 320 to 422 – a 32% increase hidden behind simplification headlines. Here's what actually broke.
Those 97 requirements decompose into 156 distinct security controls. Controls 3.4.1 and 3.4.2 now mandate "common secure configurations" – meaning STIG baselines aren't optional anymore. They're the expected compliance standard.
The scale problem nobody scoped:
67 active STIG baselines update quarterly. That's 268 discrete configuration changes per year. Add the 88-point SPRS minimum backed by False Claims Act exposure, and manual tracking simply collapses. The math doesn't work anymore.
You can't hand-track 422 verification objectives across 67 baselines when each updates every 90 days. Organizations that moved early are already reporting 70–90% effort reductions and compressing what used to be 6–12 month compliance timelines into just 100 days.
October 31, 2026: CMMC clauses become mandatory in all new DoD solicitations. By Q4, the organizations automating compliance now will own the advantage.
#CMMC2 #STIGs #DefenseCompliance #SecurityAutomation #CISO #AuditReadiness