HomeBlogCompliance

CMMC vs NIST 800-171: The Requirements and the Program That Checks Them

Pixel-art illustration of a robot holding a tablet on a busy city sidewalk, with yellow taxis and pedestrians at a crosswalk behind it

NIST SP 800-171 is the standard: a NIST publication listing the security requirements for protecting controlled unclassified information (CUI) on a contractor's own systems. CMMC is the Defense Department program that checks whether contractors meet those requirements, and CMMC Level 2 uses exactly the 110 requirements of NIST SP 800-171 Revision 2. A defense contract that involves CUI asks for both: 800-171 is the work, and CMMC is how you prove it.

Our CMMC compliance services implement the 800-171 requirements and prepare the CMMC self-assessment; we are not a C3PAO. For a plain definition of the standard and its families, see our NIST SP 800-171 glossary entry. We checked the Department of War CIO's CMMC pages on October 10, 2026. This is general information, not legal advice.

What is the difference between CMMC and NIST 800-171?

One is a list of requirements; the other is a verification program with its own rules. NIST describes SP 800-171 as recommended requirements that federal agencies put into contracts and other agreements with nonfederal organizations. CMMC, codified at 32 CFR Part 170, decides which requirements a defense contract carries, how they are assessed and scored, who signs for them and how long the result lasts.

NIST SP 800-171CMMC
What it isA NIST publication of security requirements for protecting the confidentiality of CUI in nonfederal systemsA Defense Department program that verifies contractors meet the safeguards their contracts require
Where the obligation comes fromA contract clause; for defense work, DFARS 252.204-7012A contract that names a CMMC level and assessment type
What it contains110 requirements in 14 families (Rev. 2); 97 in 17 families (Rev. 3)Level 1: the 15 FAR 52.204-21 safeguards. Level 2: the 110 requirements of 800-171 Rev. 2. Level 3: 24 requirements selected from NIST SP 800-172
Information coveredCUIFCI at Level 1; CUI at Levels 2 and 3
How results are shownAssessed against the objectives in NIST SP 800-171AA scored assessment entered in SPRS, plus a senior official's affirmation every year
Version the Department enforcesRev. 2, although NIST withdrew it on May 14, 2024Rev. 2, incorporated by reference in 32 CFR Part 170
Status in October 2026DFARS 252.204-7012 remains in effectPhase II suspended since July 13, 2026; contracts may require only Level 1 (Self) or Level 2 (Self)

How does NIST 800-171 become a contract requirement?

Through the contract clause, not through NIST. DFARS 252.204-7012 makes a covered contractor information system subject to the NIST SP 800-171 requirements in effect when the solicitation was issued, or as the contracting officer authorizes. The same clause requires cyber incidents to be reported within 72 hours of discovery, requires cloud services that store covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline, and has to be included in subcontracts that involve covered defense information.

NIST wrote the publication for any federal agency to use, so 800-171 can show up in civilian contracts too. CMMC is specific to the Defense Department and the companies in its supply chain.

What does CMMC add on top of NIST 800-171?

CMMC keeps the 800-171 requirements and adds rules about proving them:

  • Scoring. 32 CFR 170.24 starts a Level 2 score at 110 and subtracts 5, 3 or 1 point for each requirement not met, with partial credit only in limited cases such as MFA.
  • Scoping. Assets fall into five categories, from CUI assets that are assessed against all 110 requirements to out-of-scope assets that must be separated from them.
  • Limits on open items. A conditional status needs a score of at least 88, open items worth 1 point each (non-FIPS encryption is the exception), none of six requirements that can never be deferred, and closure within 180 days.
  • Affirmations. A senior Affirming Official affirms compliance in SPRS after each assessment and every year, and the assessment lapses if an annual affirmation is missed.
  • Award conditions. A contract that requires a CMMC level needs the status and the affirmation in SPRS before award.
  • Records. Evidence is kept for six years from the status date.

CMMC also reaches below and above 800-171. Level 1 covers federal contract information (FCI) with the 15 FAR 52.204-21 safeguards, and Level 3 adds 24 enhanced requirements from NIST SP 800-172 for the most sensitive programs, assessed by the government's own DIBCAC team.

Which revision of NIST 800-171 does CMMC use?

Revision 2. NIST published SP 800-171 Revision 3 in May 2024 and withdrew Revision 2 on May 14, 2024, but the CMMC rule incorporates Revision 2 by reference, and both the About CMMC page and the July 13, 2026 suspension memo say the Department enforces Revision 2.

The revisions differ more than the number suggests. Revision 3 has 97 requirements in 17 families. NIST built it from the SP 800-53B moderate baseline, removing controls that are mainly the government's job or not about confidentiality, and it adds Planning, System and Services Acquisition, and Supply Chain Risk Management families. It also introduces organization-defined parameters: values such as time periods that an agency sets, or that you must set yourself if the agency does not.

For defense work, build and assess to Revision 2 and name the revision in your System Security Plan. The work carries forward: Revision 3 keeps the Revision 2 numbering and marks each withdrawn requirement with the requirement that absorbed it, so you can trace each Revision 2 requirement forward.

Is NIST 800-171 compliance enough without CMMC?

It depends on the contract. If a contract carries DFARS 252.204-7012 but no CMMC requirement, implementing 800-171 is the obligation. If it names a CMMC level, you also need the CMMC status and the affirmation in SPRS before award. During the Phase II suspension that means a Level 2 (Self) assessment at most: the memo bars new C3PAO and DIBCAC requirements and directs that existing ones come out of contracts at the next option period or administrative modification.

The reverse holds too: a CMMC status is only as good as the 800-171 work under it. The Department can still run government-led assessments, and under 32 CFR 170.16 a DIBCAC assessment that finds the requirements were not met takes precedence over the status you entered.

Which fits a small team: building to NIST 800-171 or preparing for CMMC?

For a defense supplier they are one project, and the order matters more than the label:

  1. Confirm the data. FCI only means FAR 52.204-21 and Level 1; CUI means 800-171 and Level 2.
  2. Shrink the scope. Keep CUI in an enclave so the 110 requirements apply to a few people and systems rather than the whole office.
  3. Build to Revision 2 and write the System Security Plan from what you actually deployed.
  4. Score it with the CMMC method, enter the result in SPRS and have the Affirming Official sign only after reviewing the evidence.

If you do no federal work and simply want a security baseline, neither is required of you. The NIST Cybersecurity Framework is usually the better starting point for a commercial business, while 800-171 stays a useful reference for how to protect sensitive files.

What drives the cost and effort?

We publish no prices, and no assessor fee applies while Phase II is suspended. The effort comes from the 800-171 work, and four factors move it most:

  • How much of the company touches CUI. Every CUI asset is assessed against all 110 requirements, so each extra system or person adds work.
  • Your current controls. MFA, device management, logging and backups that already run cut the project down.
  • Where CUI is stored. Cloud services that hold it must meet FedRAMP Moderate or an equivalent, which can change your Microsoft 365 licensing.
  • The paperwork. The System Security Plan, asset inventory, network diagram and six years of evidence take staff time every year.

Our guide to CMMC Level 2 requirements breaks the 110 requirements down by family, with the POA&M limits and a working sequence.

How does NetSys help with NIST 800-171 and CMMC?

We treat 800-171 and CMMC as one piece of work. It starts with a contract and flow-down review and a map of where CUI arrives, who opens it and where it goes. Then come an enclave boundary, a gap assessment against 800-171 with a scored plan, and the controls themselves in Microsoft 365, Entra ID and Intune: MFA, Conditional Access, encryption, logging and device baselines.

We write the System Security Plan from the configuration we deployed, keep any plan of action within the limits the rule allows, and prepare your self-assessment score and the annual affirmation package. We are not a C3PAO and certify no one; if third-party assessments return, the CMMC rule keeps members of the CMMC assessment ecosystem who consulted on your preparation within the previous three years out of your certification assessment. Our agreements run month to month.

Book a call with a NetSys engineer to go through the clauses in your contracts and where CUI sits today. We will show you which requirements apply and how much of your network they reach.

Frequently asked questions

Is CMMC the same as NIST 800-171?

No. NIST SP 800-171 is the set of security requirements for protecting CUI, and CMMC is the Defense Department program that checks whether a contractor meets them. CMMC Level 2 uses the same 110 requirements of Revision 2, then adds scoring rules, scoping rules, affirmations and limits on open items.

What is the difference between NIST and CMMC for a small contractor?

The NIST requirements are the work: MFA, logging, encryption, access control and the rest of the 110. CMMC is the paperwork and proof around that work: a scored self-assessment in SPRS and a senior official's affirmation every year. A small contractor needs both when a contract involves CUI and names a CMMC level.

Which fits a small team?

For defense work, both, done as one project. Keep CUI in an enclave, build to 800-171 Revision 2 inside it, and use the CMMC scoring method for the self-assessment. A business with no federal contracts is better served by the NIST Cybersecurity Framework.

What affects the cost, implementation and ongoing support?

The number of people and systems that touch CUI, the controls you already run, where CUI is stored and the documentation. Ongoing support covers monitoring, patching, keeping the System Security Plan current and the annual affirmation.

Does CMMC use NIST 800-171 Revision 3?

No. As of October 10, 2026, the CMMC rule incorporates Revision 2 by reference, and the Department enforces Revision 2. Revision 3 is NIST's current version, so watch for an announced change, but build defense work to Revision 2 today.

Do subcontractors need NIST 800-171 or CMMC?

Both flow down. DFARS 252.204-7012 must be included in subcontracts that involve covered defense information, and under 32 CFR 170.23 a subcontractor that handles CUI needs at least a Level 2 (Self) status.

CMMC 2.0 Compliance Services

Discuss cmmc 2.0 compliance services for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore CMMC 2.0 Compliance Services 845-203-3914