Enterprise automation, designed, built and operated in the United States.

NIST SP 800-171 vs CMMC: What Applies to You

NIST SP 800-171 is the control set, DFARS is the contract clause that makes it binding, and CMMC is the mechanism that verifies you actually did it.

If you handle Controlled Unclassified Information for a federal or defense customer, you are not choosing between NIST SP 800-171 and CMMC. They are three layers of the same obligation. NIST SP 800-171 is the control catalog — the security requirements themselves. DFARS 252.204-7012 is the contract clause that makes those controls legally binding on you and flows them down to your subcontractors. CMMC is the verification program that decides whether you get to assert compliance yourself or whether a third party has to confirm it. A supplier that has done nothing yet does not need to pick one; it needs to implement 800-171, document the gaps honestly, post a score to SPRS, and close the gaps before an assessment becomes a condition of award.

What determines your specific obligation is the contract, not your company size or revenue. Look at the clauses in your existing awards and at the solicitations you intend to bid. If DFARS 252.204-7012 appears, you already owe 800-171 implementation and incident reporting, and that obligation has been in force for years regardless of CMMC's rollout schedule. If DFARS 252.204-7021 appears, a CMMC level is being applied to that contract, and the assessment type attached to that level becomes a condition of award. The practical driver of cost and effort is not the framework name — it is how much CUI actually touches your environment, how many systems it touches, and whether you have scoped it down or let it spread across every laptop and shared drive in the company.

What NIST SP 800-171 actually requires

SP 800-171 is a set of security requirements for protecting CUI in nonfederal systems, organized into families covering access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. Revision 3 restructured and consolidated parts of the earlier revision, so confirm which revision your contract cites before you build a control matrix against the wrong baseline.

Two artifacts carry the weight. The System Security Plan describes your environment, the boundary of the systems that handle CUI, and how each requirement is met. The Plan of Action and Milestones records the requirements you have not met, with owners and target dates. Assessors read the SSP first, and a vague or stale SSP is the single most common reason an otherwise reasonable program fails to demonstrate compliance. If your SSP does not match what a network diagram and a configuration export would show, you have a documentation problem that will surface as a finding.

DFARS 252.204-7012 and the clauses around it

DFARS 252.204-7012 is what converts 800-171 from a recommendation into a contractual duty. It requires adequate security on covered contractor information systems, rapid reporting of cyber incidents to DoD, preservation and submission of media and system images when an incident occurs, and flowdown to subcontractors whose performance involves covered defense information. That flowdown clause is why suppliers two and three tiers down from a prime find themselves in scope — the obligation travels with the information.

Two companion clauses matter. DFARS 252.204-7019 and 7020 govern the assessment methodology and the requirement to have a current score in the Supplier Performance Risk System before award. DFARS 252.204-7021 is the CMMC clause. As CMMC requirements phase into solicitations, 7021 is what tells you which level applies to a given procurement. Cloud service providers in scope face an additional condition under 7012: external cloud services used to store, process or transmit covered defense information must meet a FedRAMP Moderate equivalent baseline, which is a separate and often underestimated workstream.

CMMC 2.0 levels and who needs which

CMMC 2.0 has three levels. Level 1 covers basic safeguarding of Federal Contract Information and maps to the FAR 52.204-21 requirements. It is verified by annual self-assessment with an affirmation in SPRS by a senior company official. Level 2 covers CUI and maps directly to the NIST SP 800-171 requirements — no additional practices layered on top. Level 3 applies to a smaller set of programs handling CUI associated with the highest priority efforts, adds selected requirements drawn from NIST SP 800-172, and is assessed by the Defense Industrial Base Cybersecurity Assessment Center.

The important distinction inside Level 2 is the assessment type. Some Level 2 contracts permit self-assessment; others require a certification assessment by a CMMC Third-Party Assessment Organization. Which one applies is determined by the contract, driven by the sensitivity of the information involved. Do not assume the lighter path. Suppliers that plan for self-assessment and then encounter a C3PAO requirement mid-bid usually cannot close the gap inside the procurement timeline.

One more constraint shapes planning: CMMC limits what you can leave open on a POA&M. Certain requirements must be fully met at the time of assessment and cannot be deferred, and remaining items carry a closeout deadline. That changes the sequencing logic. Under 7012 alone, a POA&M was a reasonable way to show progress. Under CMMC, a POA&M carrying your highest-weighted gaps is a failed assessment waiting to happen.

The SPRS score and how it works

The SPRS score comes from the DoD Assessment Methodology. You start at a maximum and subtract weighted point values for each requirement not implemented, with the heaviest weights on the requirements whose absence most exposes CUI. The result can go negative, and negative scores are common for suppliers assessing themselves honestly for the first time. The score must be posted in SPRS along with the assessment date, the scope of the assessment, and the date by which you expect to reach full implementation.

Two things go wrong here repeatedly. First, suppliers post an optimistic score because a lower number feels like it will cost them work, then cannot substantiate it when a prime or an assessor asks for evidence. A knowingly inflated score in SPRS is a false statement to the government, and that is a materially different category of risk than being behind on controls. Second, suppliers post a score and never update it, so the record reflects an environment that no longer exists. Treat the score as a living artifact tied to your SSP.

The practical sequence if you have done nothing yet

Start with scope, because scope determines everything downstream. Identify what CUI or FCI you actually receive, where it enters the business, which systems and people touch it, and where it comes to rest. Most suppliers discover the footprint is wider than assumed — email, file shares, engineering workstations, a contract manufacturer, a backup vendor. Then deliberately narrow it. An enclave that isolates CUI handling from general corporate IT is usually cheaper to secure, cheaper to assess, and far easier to keep compliant than an attempt to bring the whole company up to the 800-171 baseline.

With scope fixed, run a gap assessment against the correct 800-171 revision and produce a real SSP describing the in-scope environment as it exists today. Score it under the DoD methodology, post to SPRS, and build a POA&M prioritized by point weight and by which requirements CMMC prohibits deferring. Then remediate — identity and access control, multifactor authentication, logging and monitoring, configuration baselines, media and mobile device handling, and incident response are where the bulk of the work usually sits. Collect evidence as you go rather than reconstructing it later; assessors examine artifacts, interview staff, and test controls, and evidence assembled retroactively tends to have gaps that show.

Alongside the technical work, handle the external dependencies. Get FedRAMP Moderate equivalence confirmed for any cloud service in scope. Flow requirements down to your own subcontractors in writing and verify rather than assume. If a C3PAO assessment applies, engage early — assessor capacity is a scheduling constraint, not a formality. Finally, re-score, update SPRS, and keep the SSP current as the environment changes.

Where we fit

We do assessment readiness, scoping and enclave design, gap analysis, SSP and POA&M development, remediation engineering and evidence preparation through our security and compliance assessments practice. We are not an accredited assessment body. Where an independent certification assessment is required, that work is delivered with accredited partners, and we keep our role on the readiness side so there is no conflict between preparing you and judging you.

If you are also evaluating automation or platform vendors who will touch your in-scope environment, the questions in our guide on security questions to ask an automation vendor will save you inheriting someone else's gaps. More background is in our guides library, and our own controls and posture are documented under security. To talk through where your contracts actually put you, get in touch.

Questions we get asked about this

No. NIST SP 800-171 is the set of security requirements for protecting CUI, while CMMC is the program that verifies whether you have implemented them. CMMC Level 2 maps directly to the 800-171 requirements without adding new practices. The difference is who checks your work and how.

The 7012 clause already obligates you to implement NIST SP 800-171 and report cyber incidents, independent of CMMC. CMMC requirements attach through DFARS 252.204-7021 as it appears in solicitations. Implementing 800-171 properly now is the work that satisfies both, so there is no reason to wait for a CMMC clause to show up.

It is determined by the contract, based on the information you handle. Level 1 covers Federal Contract Information, Level 2 covers CUI and maps to 800-171, and Level 3 applies to a limited set of high priority programs. Read the clauses in your awards and target solicitations rather than inferring a level from your company size.

Both paths exist within Level 2 and the contract decides which applies, based on the sensitivity of the information involved. Some Level 2 contracts permit annual self-assessment with a senior official affirmation; others require a certification assessment by a CMMC Third-Party Assessment Organization. Plan for the third-party path unless you have confirmed otherwise, because you cannot close that gap inside a bid window.

It is a score derived from the DoD Assessment Methodology, which subtracts weighted point values from a maximum for each NIST SP 800-171 requirement you have not implemented. Heavier weights sit on the requirements that matter most for protecting CUI, and the result can be negative. You post the score, the assessment date and scope, and your expected date of full implementation.

A negative score is common for suppliers assessing honestly for the first time and is not automatically disqualifying, though primes and contracting officers do look at it. The larger risk is posting an inflated score you cannot substantiate, which is a false statement to the government. Post an accurate score, pair it with a credible POA&M, and update it as you remediate.

Start by identifying exactly what CUI or FCI you receive and which systems and people touch it, then deliberately narrow that footprint. An isolated enclave for CUI handling is almost always cheaper to secure and assess than raising the whole company to the baseline. Once scope is fixed, run a gap assessment, write a real System Security Plan, score it, and remediate by point weight.

No. Under DFARS 252.204-7012, external cloud services that store, process or transmit covered defense information must meet a FedRAMP Moderate equivalent baseline, but that only covers the provider's side of the shared responsibility model. Your configuration, access control, logging and incident response within that service remain yours to implement and evidence.

Bring us the process you were reading this for

Confidential assessment led by senior engineers. No obligation.