CMMC 2.0 vs. NIST 800-171 – The Relationship Explained
There’s often confusion about CMMC 2.0 vs. NIST 800-171 — let’s take a look at the two to help understand the relationship.
The Cybersecurity Maturity Model Certification (CMMC) and the National Institute of Standards and Technology Special Publication 800-171 (NIST SP 800-171) are two important cybersecurity terms that are often confused and are related to cybersecurity and information safety for Controlled Unclassified Information (CUI).
CUI is information that is not classified but is of a highly confidential nature and must be guarded and protected from foreign entities and bad actors. CUI information is handled in one form or another by all Department of Defense (DoD) contractors and subcontractors, and their vendors and suppliers.
Understanding NIST 800-171
NIST SP 800-171 is a published standard of the National Institute of Standards and Technology (NIST), a non-regulatory government agency that develops all types of guidelines to promote measurements, standards, and technology, including cybersecurity. It provides system security requirements for protecting CUI and Federal Contract Information (FCI), which is any non-public government information held in nonfederal information systems or by contractors. NIST 800-171 outlines what organizations must do to protect CUI and FCI from unauthorized access and release.
First published in 2015, NIST 800-171 requires any non-federal organization handling CUI or other sensitive federal information to adhere to the guidelines outlined to fortify the federal supply chain and ultimately safeguard overall national security.
For organizations hoping to do business with the DoD, it takes around six months to fully execute NIST 800-171, which consists of 110 controls grouped into 14 control groups. It’s crucial to remember that there is no certification available to demonstrate adherence to this framework and compliance is communicated by submitting your ‘assessment score’ to the Supplier Performance Risk System (SPRS).
A Primer on CMMC 2.0
Think of CMMC as a framework designed to categorize different levels of cybersecurity readiness. Built on the foundations of NIST 800-171, CMMC Version 1.0 was originally developed in January 2020 in response to concerns that defense information was being leaked through vendor networks. The original CMMC 1.0 was comprised of 5 maturity levels that each built on the previous one, from Basic to Advanced.
As of November 2021, DoD contractors and subcontractors are required to adhere to a new set of cybersecurity requirements known as CMMC 2.0 (condensed into three levels) to reassure the DoD that they uphold the necessary cybersecurity framework standards. The new CMMC 2.0 architecture incorporates important DoD objectives, including cost reduction for smaller-sized businesses and clarification and alignment with cybersecurity standards that meet or exceed advancing technologies.
Why Was a New CMMC Standard and Program Required?
Many of the CMMC 1.0 cybersecurity standards that have been applied to the protection of sensitive information, up to now, have only seen patchy compliance. Through an advanced audit, the DoD recognized that some contractors and vendors were taking advantage of the ‘honor system’ and embellishing their results.
With the new CMMC 2.0 system, DoD subcontractors must at least be compliant with the Level 2 requirements. Results of the assessment are submitted to the DoD through the Supplier Performance Risk System (SPRS), either within parameters or with an accompanying Plan of Actions and Milestones (POAM) that has a rock-solid plan for full compliance, including a timeline for achievements.
Meeting the Fast Approaching Requirements Deadline
The DoD has disclosed its intention to publish a temporary regulation on the CMMC 2.0 framework by May 2023. If accepted, CMMC will start to be used in DoD contracts by July 2023, or around 60 days after the publication of the interim regulation.
These are tight timelines for many DoD subcontractors and vendors, which can impact future DoD contracting capabilities and revenue, but there is a solution.
Working with a managed services provider (MSP), like NIST Expert, allows a company to achieve its CMMC goals, while also establishing an ongoing compliance and maintenance system. When engaging an MSP, the process should include the following:
- An initial discovery audit to analyze the contractor’s environment, cybersecurity framework, and physical systems in detail.
- A Plan of Action and POAM that details CMMC 2.0 compliance and the required improvements necessary.
- SPRS Score submitted on the company’s behalf.
- Ongoing managed services to maintain compliance requirements and ensure documentation is updated, systems are upgraded, and the company is audit-ready at any time. These services ensure a company is well ahead of the threat from cyber criminals and bad actors.
Going Forward
While NIST 800-171 informs the DOD’s CMMC 2.0, meeting the CMMC certification obligations is the crucial component needed to maintain a company’s ability to submit/accept contract proposals in the future. This also includes all subcontractors and vendors doing business with direct contractors.
With deadlines fast approaching, NIST Expert is a cybersecurity expert that can equip your organization with the needed information security for compliance, plus ongoing managed services to keep you ahead of the competition.
To learn more or to schedule an assessment, contact a NIST Expert today.
Continue Reading
July 29, 2026
Five Takeaways from This Week’s CyberAB Town Hall
July 14, 2026
