Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
NIST SP 800-171 is the cybersecurity standard that defines the 110 security requirements defense contractors must implement to protect controlled unclassified information in their systems. CMMC 2.0 is the enforcement framework that determines whether those requirements are actually in place — through annual self-assessment at Level 1 and independent third-party verification at Level 2. For defense subcontractors, the relationship is direct: NIST 800-171 is what you implement; CMMC is how the DoD verifies you implemented it.
Most contractors who encounter both terms assume they are two names for the same thing, or that CMMC replaced NIST. Neither is accurate.
NIST SP 800-171 is a technical standard published by the National Institute of Standards and Technology. It defines what security controls must be in place to protect CUI. It has been a contractual requirement for defense contractors since 2017 under DFARS 252.204-7012, which required compliance without any formal verification mechanism. Organizations self-assessed against the 110 requirements, submitted a score to the Supplier Performance Risk System, and that was largely the extent of enforcement.
CMMC 2.0 is the DoD’s answer to that verification gap. It is not a separate set of security requirements. It is a certification framework that uses existing NIST standards as its technical foundation and adds structured assessment to confirm compliance is real rather than self-reported.
That distinction — requirements that exist versus requirements that are verified — is the core of what contractors need to understand when they encounter both terms.
NIST SP 800-171 was developed to define the baseline security requirements for protecting controlled unclassified information in non-federal information systems — the servers, workstations, and networks operated by contractors, not federal agencies.
That distinction matters for one common point of confusion: NIST SP 800-53 is the parallel standard for federal agencies themselves, covering a much broader set of controls for government information systems. If you are a defense contractor, 800-53 is not your standard — 800-171 is. The two share a common NIST lineage but serve different audiences and carry different scope.
NIST SP 800-171 contains 110 security requirements organized across 14 control families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
Together these requirements establish a comprehensive security baseline for protecting CUI. They address who can access your systems, how incidents are detected and handled, whether configurations are managed and documented, and whether your environment is monitored over time.
The version that governs CMMC assessments is NIST SP 800-171 Revision 2. Revision 3 was published in May 2024 but has not yet been incorporated into the CMMC framework through formal rulemaking. Until that changes, C3PAO assessments evaluate compliance against Revision 2.
The Cybersecurity Maturity Model Certification program was developed by the Department of Defense to close the enforcement gap that existed under DFARS alone. Before CMMC, contractors were expected to comply with NIST SP 800-171, self-score their implementation, and report that score to SPRS. Without independent verification, compliance was inconsistent. Controls were frequently documented on paper rather than implemented in practice.
CMMC 2.0 does not introduce new technical requirements. It takes the NIST standards that already applied and adds the accountability structure that was missing. For most organizations handling CUI, that means a formal assessment by a certified C3PAO — a CMMC Third Party Assessment Organization — rather than self-certification. The CMMC 2.0 Program Rule took effect December 2024. The DFARS Acquisition Rule went live November 2025, placing active CMMC requirements into DoD solicitations. Phase 2 — which makes third-party C3PAO assessments mandatory for most contracts involving CUI — begins November 10, 2026.
CMMC 2.0 has three certification levels. Each maps to a different NIST standard and corresponds to the type of federal information the organization handles.
Level 1 applies to organizations that handle Federal Contract Information but not CUI. It requires the 15 security requirements specified in FAR clause 52.204-21 and is assessed through annual self-assessment with an annual affirmation submitted to SPRS. These are basic safeguarding requirements covering access control, limited user permissions, device protection, and similar foundational controls. Level 1 represents the compliance floor for any organization in the defense supply chain.
Level 2 is where the full NIST SP 800-171 mapping lives. It requires implementation of all 110 security requirements from NIST SP 800-171 Revision 2 across all 14 control families. For the majority of organizations handling CUI, it requires a formal assessment by a certified C3PAO rather than self-assessment.
This is the level most defense subcontractors are working toward. The 110 requirements are not new to CMMC — they were already required under DFARS 252.204-7012. What CMMC Level 2 adds is the verification layer that DFARS alone never provided.
Level 3 applies to a smaller set of organizations supporting the most sensitive DoD programs. It builds on the Level 2 baseline and adds 24 additional requirements from NIST SP 800-172, which addresses enhanced protections against advanced persistent threats. Level 3 assessments are government-led rather than C3PAO-conducted. Most small and mid-sized defense subcontractors will not encounter Level 3 requirements.
The table below shows how each of the 14 NIST SP 800-171 control families maps to CMMC Level 2. The mapping is one-to-one — every control family is fully adopted into Level 2 with no omissions.
| NIST SP 800-171 Control Family | CMMC Level 2 Mapping |
| Access Control | Fully mapped |
| Awareness and Training | Fully mapped |
| Audit and Accountability | Fully mapped |
| Configuration Management | Fully mapped |
| Identification and Authentication | Fully mapped |
| Incident Response | Fully mapped |
| Maintenance | Fully mapped |
| Media Protection | Fully mapped |
| Personnel Security | Fully mapped |
| Physical Protection | Fully mapped |
| Risk Assessment | Fully mapped |
| Security Assessment | Fully mapped |
| System and Communications Protection | Fully mapped |
| System and Information Integrity | Fully mapped |
There are no NIST SP 800-171 control families absent from CMMC Level 2 and no Level 2 requirements outside the 800-171 framework. Organizations that achieve CMMC Level 2 certification have met the full NIST SP 800-171 Revision 2 standard — independently verified.
The technical requirements at Level 2 are identical. The differences lie in how compliance is established, demonstrated, and maintained.
Assessment type. Under the pre-CMMC model, organizations self-scored their NIST SP 800-171 compliance and reported to SPRS. CMMC Level 2 replaces self-certification with independent C3PAO assessment for most CUI-handling organizations. The assessor examines implemented controls, tests configurations, reviews documentation, and interviews personnel. Implementation gaps cannot be attested away.
POAM governance. CMMC 2.0 introduced formal rules governing Plans of Action and Milestones. Certain lower-risk controls may be temporarily deferred via POAM, but high-priority requirements — including multi-factor authentication — must be fully implemented before an assessment can proceed. NIST SP 800-171 itself does not regulate POAM usage at this level of specificity.
Certification cycle. CMMC Level 2 certification is valid for three years, with annual affirmations of continued compliance required in between. Controls must remain implemented and documented throughout the cycle — not just at the point of assessment.
Contract eligibility. Before CMMC, failing to comply with NIST SP 800-171 was a contractual violation that was rarely enforced. Under CMMC, the inability to demonstrate the required certification level means ineligibility for contracts that require it. The connection between security posture and contract access is direct.
Phase 1 is active. CMMC requirements are appearing in DoD solicitations now, and the compliance clock for Phase 2 ends November 10, 2026.
For defense subcontractors that have been operating under DFARS 252.204-7012 for years, the NIST SP 800-171 requirements were already legally in effect. What changes under CMMC is not the substance of the obligation — it is the verification. Organizations that have genuinely built and documented their security controls against the 110 requirements are in a substantially better position than those that scored a self-assessment without following through on implementation.
The starting point is an honest evaluation of your current environment against the NIST SP 800-171 requirements — not an estimate, but an actual gap count mapped to the specific controls that are in place versus those that are not. That gap picture drives the remediation roadmap, which in turn determines how realistic the Phase 2 timeline is for your organization.
Right Hand Technology Group offers CMMC compliance services for defense subcontractors navigating this process — from gap assessment through remediation planning and C3PAO preparation. Start by scheduling a call with our CMMC experts to get a clear picture of where you stand before Phase 2 makes that question unavoidable.
No. NIST SP 800-171 is the cybersecurity standard — 110 security requirements for protecting CUI in non-federal systems. CMMC is the enforcement mechanism. CMMC Level 2 maps directly to NIST SP 800-171 Revision 2, but meeting the technical requirements alone does not produce CMMC certification. CMMC adds independent verification: for most organizations handling CUI, compliance must be assessed by a certified C3PAO, not self-reported. NIST defines what you need to implement; CMMC determines whether you can prove you implemented it.
CMMC Level 2 maps directly to NIST SP 800-171 Revision 2 — all 110 requirements across 14 control families. Level 1 is based on 15 separate requirements from FAR clause 52.204-21 for organizations handling FCI rather than CUI. Level 3 builds on Level 2 and adds 24 requirements from NIST SP 800-172. For most defense subcontractors handling CUI, Level 2 is the applicable target and NIST SP 800-171 Revision 2 is the technical standard behind it.
Not entirely. Any organization in the DoD supply chain that handles Federal Contract Information is subject to CMMC Level 1 requirements, regardless of whether CUI is involved. Level 2 applies to organizations that handle CUI. The type of information flowing into your organization — from customers tied to DoD programs — determines your applicable level. Subcontractors and lower-tier vendors who receive FCI or CUI through the supply chain are in scope even without a direct DoD contract.
IT support for manufacturing is the ongoing technical assistance, monitoring, and cybersecurity management that keeps…
IT solutions for manufacturing are the combination of managed services, cybersecurity tools, and infrastructure…
Managed IT services for small businesses typically run between $100 and $200 per user…