NIST SP 800-171 & CMMC
What they are
Two linked standards for protecting Controlled Unclassified Information (CUI) in non-federal systems (i.e., contractors):
- NIST SP 800-171 — the control set (110 security requirements) for safeguarding CUI.
- CMMC — the Cybersecurity Maturity Model Certification, the DoD program that verifies contractors meet those requirements before they can win contracts.
Who it applies to
Contractors and subcontractors in the Defense Industrial Base (DIB) that handle FCI (Federal Contract Information) or CUI must comply. This is distinct from FedRAMP, which governs cloud services sold to agencies — CMMC governs the contractors those agencies work with.
Disclaimer. Not legal advice. CMMC is in phased rollout. Verified 2026-05-29.
The CMMC 2.0 levels
| Level | Name | Requirements | Assessment |
|---|---|---|---|
| Level 1 | Foundational | 15 requirements from FAR 52.204-21 (protects FCI) | Annual self-assessment |
| Level 2 | Advanced | 110 requirements of NIST SP 800-171 Rev 2 (protects CUI) | Self-assessment or third-party (C3PAO) assessment, by contract |
| Level 3 | Expert | Level 2 plus a subset of NIST SP 800-172 enhanced requirements | Government-led (DIBCAC) assessment |
Timeline (final rule)
- 32 CFR program rule effective December 16, 2024.
- 48 CFR acquisition rule (puts CMMC clauses in DoD contracts) effective November 10, 2025.
- Phased rollout: Phase 1 (Nov 2025, L1/L2 self-assessment) → Phase 2 (Nov 2026, L2 certification) → Phase 3 (Nov 2027, L3) → Phase 4 (Nov 2028, full).
Until your contract phase requires a C3PAO assessment, you typically attest via a SPRS score (Supplier Performance Risk System) derived from a self-assessment against 800-171. SPRS scores range from -203 to 110; a perfect score requires all 110 practices to be fully implemented.
Relationship to FedRAMP / 800-53
NIST 800-171’s 110 requirements are a tailored subset of NIST 800-53 aimed at non-federal systems. If you build to FedRAMP Moderate/High, you cover the large majority of 800-171 — but CMMC adds CUI-specific scoping, marking, and assessment obligations FedRAMP doesn’t address, so FedRAMP authorization is not a free pass to CMMC compliance.
Related resources
- NIST 800-53 — the broader catalog 800-171 derives from
- FedRAMP — the cloud-services analog
- Security Overview
Sources (verified 2026-05-29)
| Claim | Source |
|---|---|
| CMMC program, levels, assessment types | DoD CIO — CMMC |
| 32 CFR effective 2024-12-16; 48 CFR effective 2025-11-10; phased rollout | DoD final rules (Federal Register) |
| L1 = 15 FAR 52.204-21 reqs; L2 = 110 NIST 800-171 Rev 2 reqs | NIST SP 800-171 |
| L3 enhanced requirements | NIST SP 800-172 |