Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
KNOWLEDGE BASECompliance FrameworksEDITOR REVIEWED

CMMC vs. NIST SP 800-171: What’s the Difference?

They share the same 110 controls, so why do you keep hearing both names? One is the rulebook. The other is the referee.

TL;DR

NIST SP 800-171 is the rulebook — 110 security requirements for protecting Controlled Unclassified Information (CUI). CMMC (Cybersecurity Maturity Model Certification) is the referee — the DoD program, codified at 32 CFR Part 170, that verifies you actually implemented those requirements. CMMC Level 2 is literally the same 110 controls from 800-171 Rev 2. What changed is accountability: instead of self-attesting a score into SPRS, many contracts now require a third-party assessment by a C3PAO. Same rulebook, stricter enforcement.

The short answer

If you handle Controlled Unclassified Information (CUI) for the Department of Defense, you will hear “NIST 800-171” and “CMMC” used almost interchangeably. They are not the same thing, but they are deeply connected:

  • NIST SP 800-171 is the *control set* — 110 security requirements that tell you what protections to put in place.
  • CMMC is the *verification program* — the DoD mechanism that checks whether you actually did it, and how you prove it.
800-171 is the rulebook. CMMC is the referee. Level 2 CMMC is the same 110 rules — the difference is who blows the whistle.

What NIST SP 800-171 is

NIST SP 800-171 — “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations” — is a publication from the National Institute of Standards and Technology. It defines security requirements across 14 families (access control, audit, incident response, identification and authentication, and so on).

The current baseline for defense contracts is Rev 2, which contains 110 requirements. (Rev 3, published in 2024, reorganized and adjusted the controls, but the DoD’s move to Rev 3 is tied to future updates of the DFARS clause — always confirm which revision your specific contract cites.)

On its own, 800-171 is a NIST document, not a law. It becomes contractually binding through the DFARS clause 252.204-7012, which requires contractors handling Covered Defense Information to implement 800-171. For years, compliance was self-attested: you scored yourself against a 110-point methodology and posted the result to the government’s Supplier Performance Risk System (SPRS).

What CMMC is

CMMC — Cybersecurity Maturity Model Certification — is a DoD program, formally established by the final rule at 32 CFR Part 170, published in October 2024. It exists because self-attestation alone proved unreliable: too many contractors claimed compliance they had not achieved.

CMMC does not invent a new set of controls for Level 2. It reuses NIST SP 800-171 and adds an enforcement layer: defined assessment levels, third-party assessors, affirmations by a senior official, and formal certification. In short, CMMC is how DoD turns “trust me” into “show me.”

The three CMMC levels

LevelProtectsRequirementsHow it’s assessed
Level 1Federal Contract Information (FCI)15 requirements from FAR 52.204-21Annual self-assessment; no POA&Ms permitted
Level 2Controlled Unclassified Information (CUI)110 requirements from NIST SP 800-171 Rev 2Self-assessment or C3PAO third-party assessment (every 3 years), depending on the contract
Level 3CUI on the highest-priority programsLevel 2 plus 24 requirements from NIST SP 800-172Assessed by the government (DCMA DIBCAC)

Most Defense Industrial Base companies that touch CUI are aiming at Level 2 — which is exactly the 110 controls of NIST SP 800-171.

How they connect: the DFARS thread

The two frameworks are stitched together by DFARS clauses in your contract:

  • DFARS 252.204-7012 — requires you to implement NIST SP 800-171 and to report cyber incidents.
  • DFARS 252.204-7019 / -7020 — require you to have a current 800-171 self-assessment score posted in SPRS.
  • DFARS 252.204-7021 — the CMMC requirement that phases in third-party certification as a condition of award.

When a C3PAO completes a Level 2 assessment, the results flow through the CMMC system into SPRS, where your official CMMC status lives. Limited POA&Ms (Plans of Action and Milestones) are allowed at Level 2 under specific conditions — a minimum score, certain controls that can never be deferred, and a 180-day window to close them — but you cannot POA&M your way to a passing grade indefinitely.

What contractors should actually do

  1. Scope your CUI. Identify where CUI lives, flows, and is processed. This defines your assessment boundary — get it wrong and everything downstream is wrong.
  2. Assess against the 110. Do an honest gap assessment against NIST SP 800-171 Rev 2. The controls are identical whether you call it “800-171” or “CMMC Level 2.”
  3. Write the SSP and POA&M. A System Security Plan documenting how each control is met is mandatory — its absence is itself a finding.
  4. Score and post to SPRS. Use the DoD Assessment Methodology to calculate your score and keep it current.
  5. Close gaps, then get assessed. Remediate, then schedule your C3PAO assessment if your contract requires certification.
Common misconception

“We’re NIST 800-171 compliant, so CMMC doesn’t apply.” The controls are the same, but self-attesting a score is not the same as passing a third-party assessment. CMMC raises the evidentiary bar — documentation and proof that would survive an outside assessor, not just an internal checklist.

Key takeaways

  • 800-171 is the control set; CMMC is the verification program. Different roles, same underlying requirements.
  • CMMC Level 2 = the 110 requirements of NIST SP 800-171 Rev 2. No new controls at Level 2 — new *accountability*.
  • The three levels protect FCI (L1, 15 reqs), CUI (L2, 110 reqs), and high-priority CUI (L3, +24 from 800-172).
  • DFARS clauses (7012, 7019/7020, 7021) are what make both contractually binding, with your status recorded in SPRS.
  • The work is the same either way: scope your CUI, implement the 110 controls, document them in an SSP, and be ready to prove it.

Sources

Cloud consoles and federal guidance change; confirm control text and clause language against the official publication that applies to your contract. This article is independent education and does not by itself establish compliance or confer CMMC certification.

← Back to the knowledge base