Nexeris

CMMC vs. NIST 800-171: What Is the Difference?

Organizations in the defense industrial base often hear CMMC and NIST SP 800-171 discussed together. That can make the two seem interchangeable, but they serve different purposes. NIST SP 800-171 establishes cybersecurity requirements for protecting Controlled Unclassified Information in applicable nonfederal systems. CMMC builds on those requirements by creating a framework for assessing, verifying, documenting, and reporting whether applicable defense contractors have actually implemented the required safeguards. Understanding the difference matters even more in 2026 because NIST has published Revision 3 of SP 800-171 while the current CMMC Level 2 framework continues to use Revision 2. At the same time, the planned CMMC Phase II rollout was suspended in July 2026, creating new questions about what contractors are still required to do.

CMMC vs. NIST 800-171: What Is the Difference?

NIST SP 800-171 defines security requirements for protecting Controlled Unclassified Information, while CMMC provides the Department’s assessment and verification framework for determining whether applicable contractors have implemented required safeguards. CMMC Level 2 currently uses all 110 security requirements from NIST SP 800-171 Revision 2 as its cybersecurity baseline. In simple terms, NIST tells an organization what security requirements must be implemented, while CMMC establishes how implementation is demonstrated and assessed for applicable defense contracts.

CMMC vs. NIST 800-171 at a Glance

Area NIST SP 800-171 CMMC
What it is Cybersecurity security requirements for protecting CUI in applicable nonfederal systems DoD cybersecurity assessment and verification program
Governing organization National Institute of Standards and Technology Department of Defense cybersecurity acquisition program
Information protected Controlled Unclassified Information FCI at Level 1 and CUI at Levels 2 and 3
Applicability Applies when incorporated through a contract, regulation, agreement, or other requirement Applies when a CMMC level is required by an applicable DoD solicitation or contract
Requirements Rev. 2 contains 110 security requirements Level 1 has 15 FAR safeguards; Level 2 uses 110 NIST Rev. 2 requirements; Level 3 adds 24 enhanced requirements
Levels No CMMC-style levels Levels 1, 2, and 3
Assessment method Self-assessment procedures may be used to evaluate implementation; DoD contracts may separately require NIST assessments Self-assessment, C3PAO assessment, or DIBCAC assessment depending on level, contract, and current implementation phase
Certification/status NIST itself does not issue a certification Produces defined CMMC status
Assessment frequency Determined by applicable contractual or regulatory requirements Level 1 self-assessment annually with annual affirmation; Level 2 assessment generally every three years with annual affirmation; Level 3 framework uses a three-year government assessment cycle with annual affirmation.
POA&M rules POA&Ms can document unresolved requirements, subject to applicable contractual rules POA&M use is specifically limited, and conditional Level 2 or 3 items generally must be closed within 180 days
SPRS requirements Applicable DoD NIST assessment scores are reported in SPRS Applicable CMMC self-assessment information, statuses, and affirmations are recorded through government systems including SPRS
Contractual connection Frequently incorporated through clauses such as DFARS 252.204-7012 CMMC requirements are incorporated into applicable defense solicitations and contracts

The current CMMC model continues to identify Level 2 with the 110 requirements in NIST SP 800-171 Rev. 2. Phase II expansion of third-party assessment requirements is currently suspended, but Phase I self-assessment requirements remain in place.

What Is NIST SP 800-171?

NIST Special Publication 800-171 provides cybersecurity requirements intended to protect the confidentiality of Controlled Unclassified Information when that information resides in applicable nonfederal systems and organizations. It is particularly important to government contractors because federal agencies can incorporate the publication into contracts or other agreements that require contractors to safeguard CUI.

What Does NIST 800-171 Protect?

NIST SP 800-171 focuses on Controlled Unclassified Information, commonly called CUI. CUI is government information that is not classified but still requires safeguarding or dissemination controls under applicable laws, regulations, or government-wide policies. The requirements apply to system components that process, store, or transmit CUI, as well as components that provide security protection for those systems. For a contractor, this can include endpoints, servers, applications, identity systems, security tools, cloud environments, network infrastructure, and other technology involved in the CUI environment.

Who Is Required to Follow NIST 800-171?

NIST does not independently impose requirements on every private business. Applicability normally comes from a contract, regulation, solicitation, agreement, or other federal requirement. For defense contractors, one of the most important contractual connections is DFARS 252.204-7012, which requires covered contractor information systems handling covered defense information to meet applicable NIST SP 800-171 requirements. Prime contractors also need to understand when requirements flow down to subcontractors whose work involves covered defense information.

What Are the NIST 800-171 Security Requirements?

The CMMC-relevant baseline is NIST SP 800-171 Revision 2, which contains 110 security requirements organized into 14 security requirement families. Those families address areas such as:

  • Access control
  • Awareness and training
  • Audit and accountability
  • Configuration management
  • Identification and authentication
  • Incident response
  • Maintenance
  • Media protection
  • Personnel security
  • Physical protection
  • Risk assessment
  • Security assessment
  • System and communications protection
  • System and information integrity

The requirements collectively cover the people, technology, processes, documentation, and security practices needed to protect CUI.

What Is CMMC?

The Cybersecurity Maturity Model Certification program is designed to give the Department greater assurance that contractors and subcontractors have implemented cybersecurity requirements associated with the information they handle. Rather than creating an entirely separate set of Level 2 cybersecurity controls, CMMC uses existing federal requirements and adds an assessment, reporting, evidence, and accountability framework.

Why Did the DoD Create CMMC?

Before CMMC, much of the defense industrial base relied heavily on contractor self-assessment to determine whether cybersecurity requirements had been implemented. The challenge was that stating compliance and demonstrating compliance are not always the same thing. CMMC was created to strengthen verification. Depending on the applicable level, acquisition requirement, and implementation phase, organizations may need to conduct a self-assessment or undergo an independent or government-led assessment. The goal is greater confidence that required security safeguards are operating in the actual contractor environment rather than existing only in policies or plans.

What Information Does CMMC Protect?

CMMC distinguishes between two important types of federal information. Federal Contract Information, or FCI, generally includes nonpublic information provided by or generated for the government under a contract to develop or deliver a product or service. Controlled Unclassified Information, or CUI, requires additional safeguarding because laws, regulations, or government-wide policies require or permit specific handling controls. Level 1 focuses on basic protection of FCI. Levels 2 and 3 focus on stronger protection of CUI.

What Are the Three CMMC Levels?

CMMC contains three cybersecurity levels. Level 1 focuses on basic safeguarding of FCI and incorporates the 15 safeguarding requirements associated with FAR 52.204-21. Level 2 focuses on broad protection of CUI and aligns with all 110 security requirements in NIST SP 800-171 Revision 2. Level 3 is intended for higher-priority programs requiring greater protection against advanced threats. It builds on Level 2 and adds 24 selected enhanced security requirements from NIST SP 800-172. For a broader explanation of the framework, levels, assessments, and contractor responsibilities, see these CMMC compliance requirements.

The relationship between CMMC and NIST SP 800-171 is easiest to understand by thinking of NIST as the cybersecurity baseline and CMMC as the mechanism used to verify implementation for applicable defense work.

Why CMMC Level 2 Is Based on NIST SP 800-171

CMMC Level 2 incorporates all 110 security requirements from NIST SP 800-171 Revision 2. That means organizations preparing for Level 2 are not learning a completely unrelated collection of cybersecurity requirements. Their technical foundation is NIST SP 800-171 Rev. 2. What changes under CMMC is the level of assessment discipline surrounding those requirements, including scoping, evidence, assessment procedures, reporting, affirmation, and status.

Does CMMC Replace NIST 800-171?

No. CMMC does not replace NIST SP 800-171. NIST SP 800-171 continues to provide the underlying security requirements used to protect CUI. CMMC builds an assessment and accountability structure around applicable requirements so the Department can determine whether organizations have implemented them at the required level. For Level 2, the relationship can be summarized as: NIST SP 800-171 Rev. 2 requirements + CMMC assessment framework = CMMC Level 2 implementation and verification.

Does NIST 800-171 Compliance Mean You Are CMMC Compliant?

Not automatically. An organization may believe it has implemented the 110 NIST requirements but still have CMMC readiness gaps. CMMC preparation also requires attention to areas such as:

  • CUI and assessment scoping
  • Asset identification
  • An accurate System Security Plan
  • Objective evidence
  • Assessment procedures
  • POA&M restrictions
  • SPRS information
  • Required affirmations
  • CMMC status requirements

Implementation remains the foundation, but the organization must also be capable of demonstrating that implementation.

What Are the Key Differences Between CMMC and NIST 800-171?

Security Standard vs. Assessment and Verification Program

This is the most important distinction in the CMMC vs NIST 800-171 comparison. NIST SP 800-171 establishes security requirements. CMMC establishes a structured process for determining whether applicable defense contractors meet the cybersecurity requirements associated with their required CMMC level. NIST answers: What security outcomes must we achieve? CMMC additionally asks: Can we demonstrate that those outcomes have been implemented within the correct assessment scope?

Scope and Information Protected

NIST SP 800-171 specifically focuses on protecting CUI. CMMC has a broader three-level structure. Level 1 addresses FCI using safeguards from FAR 52.204-21. Level 2 addresses CUI using NIST SP 800-171 Rev. 2. Level 3 adds enhanced protections for applicable high-priority CUI environments.

Self-Assessment vs. CMMC Assessment Requirements

It is incorrect to say that every organization requiring CMMC Level 2 must currently undergo a C3PAO assessment. Under the CMMC framework, Level 2 can involve either a self-assessment or a C3PAO certification assessment depending on the applicable acquisition requirement. The distinction is particularly important in 2026 because Phase II, which would have expanded Level 2 third-party certification requirements, was suspended on July 13, 2026. The program is currently paused in Phase I, where applicable Level 1 and Level 2 self-assessments remain the primary mechanism.

CMMC Levels vs. a Single NIST Security Baseline

NIST SP 800-171 is not organized into CMMC-style maturity levels. CMMC uses three levels because contractors handle different types of government information and different levels of cybersecurity risk. A company handling only FCI may have a Level 1 requirement. A contractor processing CUI may require Level 2. Selected high-priority programs may ultimately require Level 3 protections.

Evidence, Documentation and Assessment Readiness

CMMC requires more than having cybersecurity policies in a shared folder. An assessment can examine whether requirements are implemented through evidence such as:

  • System configurations
  • Security settings
  • Policies and procedures
  • Logs
  • Access records
  • Training records
  • Asset inventories
  • Network diagrams
  • Technical documentation
  • Interviews with responsible personnel
  • Demonstration or testing of security processes

The Level 2 assessment methodology is designed to verify that required practices are actually implemented within the defined assessment scope. A written statement saying that multifactor authentication is required, for example, is different from demonstrating that MFA is configured and enforced on the systems where it is required.

POA&M and Remediation Requirements

A Plan of Action and Milestones, or POA&M, documents requirements that have not yet been fully implemented and describes how the organization plans to correct them. POA&Ms have historically played an important role in NIST SP 800-171 implementation. Under CMMC, their use is more restricted. Level 1 does not permit POA&Ms for achieving the required status. Level 2 and Level 3 permit limited use under defined conditions, and a conditional status requires successful POA&M closeout within 180 days. Certain critical deficiencies cannot simply be deferred through a POA&M.

How Do CMMC Levels Map to NIST Requirements?

CMMC Level 1 and FAR 52.204-21

CMMC Level 1 does not require implementation of all 110 NIST SP 800-171 requirements. Instead, Level 1 incorporates the 15 basic safeguarding requirements from FAR 52.204-21. It is designed primarily for organizations that process, store, or transmit FCI but do not handle CUI requiring the Level 2 baseline.

CMMC Level 2 and NIST SP 800-171 Rev. 2

CMMC Level 2 aligns directly with the 110 security requirements in NIST SP 800-171 Revision 2. This is why a thorough NIST 800-171 gap assessment is one of the most important starting points for Level 2 preparation. The requirements themselves are not merely a reference point. They form the cybersecurity baseline against which Level 2 implementation is evaluated.

CMMC Level 3 and NIST SP 800-172

Level 3 builds on Level 2. An organization pursuing Level 3 must first satisfy the Level 2 baseline, then meet 24 selected enhanced security requirements derived from NIST SP 800-172. These enhanced requirements are intended to help applicable high-priority programs defend CUI against more sophisticated adversaries and advanced persistent threats. The current CMMC model describes Level 3 as 134 requirements in total: 110 Level 2 requirements plus 24 selected NIST SP 800-172 requirements.

Does CMMC Use NIST SP 800-171 Rev. 2 or Rev. 3?

Which NIST 800-171 Revision Applies to CMMC in 2026?

CMMC Level 2 currently uses NIST SP 800-171 Revision 2. This is one of the most important distinctions for contractors in 2026. NIST has already published Revision 3 and identifies it as the successor to Revision 2. However, the current CMMC framework specifically incorporates the 110 requirements from Revision 2. Contractors should therefore avoid assuming that NIST’s publication of a newer revision automatically changes the CMMC Level 2 baseline.

What Changed With NIST SP 800-171 Rev. 3?

NIST finalized SP 800-171 Revision 3 in May 2024. The revision substantially updates the structure and presentation of the CUI security requirements. Major changes include:

  • Greater alignment with NIST SP 800-53 Revision 5
  • Restructured security requirements
  • Organization-defined parameters
  • Updated tailoring criteria
  • New and revised security requirements
  • Removal or consolidation of some older requirements
  • Changes to security requirement families
  • More outcome-focused requirement language

Revision 3 also introduces new mechanisms intended to improve flexibility, reduce ambiguity, and better connect CUI requirements to the wider NIST security control ecosystem.

Should Contractors Prepare for Rev. 3 Now?

Contractors should understand Rev. 3 and monitor how federal agencies incorporate it into future requirements. However, organizations preparing for the current CMMC Level 2 requirements should not substitute Revision 3 for Revision 2. CMMC Level 2 remains tied to Rev. 2 unless the applicable regulatory and contractual framework is formally changed. A sensible approach is to maintain current Rev. 2 compliance while evaluating Rev. 3 so future changes do not come as a surprise.

How Do DFARS, NIST 800-171 and CMMC Work Together?

Defense cybersecurity requirements can feel complicated because several rules and frameworks operate together. Each serves a different role.

DFARS Establishes Contractual Cybersecurity Obligations

For applicable DoD contracts, DFARS 252.204-7012 establishes requirements for safeguarding covered defense information and reporting cyber incidents. For qualifying covered contractor information systems, the clause requires implementation of applicable NIST SP 800-171 security requirements. Other DFARS provisions and clauses, including 252.204-7019 and 252.204-7020, establish requirements surrounding NIST SP 800-171 DoD assessments.

NIST 800-171 Defines the Security Requirements

NIST SP 800-171 provides the cybersecurity requirements used to safeguard CUI in applicable nonfederal systems. For current CMMC Level 2 purposes, the applicable baseline is Revision 2.

CMMC Provides the Assessment and Verification Framework

CMMC adds a structured method for demonstrating implementation. Depending on the required level and current acquisition rules, that can involve:

  • Defining an assessment scope
  • Performing an assessment
  • Providing objective evidence
  • Reporting results
  • Maintaining a CMMC status
  • Completing required affirmations
  • Closing eligible POA&M items

This helps move cybersecurity compliance from a statement of intent toward demonstrable implementation.

Where Does SPRS Fit Into the Process?

The Supplier Performance Risk System, or SPRS, provides the government with visibility into applicable contractor cybersecurity assessment information. Under DFARS 252.204-7019, an offeror required to implement NIST SP 800-171 generally needs a current applicable assessment before award. Applicable NIST assessment results and scores are maintained through SPRS. CMMC also relies on SPRS for applicable self-assessment information, CMMC statuses, unique identifiers, and affirmations. A useful way to remember the relationship is: DFARS = contractual obligation → NIST SP 800-171 = security requirements → CMMC = assessment and verification

Do DoD Contractors Need Both CMMC and NIST 800-171?

Potentially, yes, but the answer depends on what information the organization handles and what its contracts require.

Contractors That Handle CUI

Organizations handling CUI under applicable defense contracts may already be required to implement NIST SP 800-171 through DFARS 252.204-7012. They may also face CMMC Level 2 requirements when the relevant solicitation or contract includes them. In that situation, NIST SP 800-171 provides the cybersecurity baseline while CMMC establishes the assessment and verification obligations.

Contractors That Handle Only FCI

Organizations that handle FCI but not CUI may fall under CMMC Level 1 rather than Level 2. Level 1 uses the 15 safeguarding requirements from FAR 52.204-21 rather than all 110 NIST SP 800-171 Rev. 2 requirements. This is why correctly identifying the information received and generated under a contract is essential before determining the organization’s CMMC scope.

What About Federal Contractors Outside the DoD?

NIST SP 800-171 is not exclusive to the Department of Defense. Federal agencies can incorporate NIST SP 800-171 requirements into contractual vehicles and other agreements when CUI must be protected in nonfederal systems. CMMC, however, is specifically a defense cybersecurity assessment program. A civilian federal contractor could therefore have NIST SP 800-171 obligations without having CMMC requirements.

Do Subcontractors Need CMMC and NIST 800-171?

They can. Cybersecurity requirements do not necessarily stop with the prime contractor. If a subcontractor will process, store, transmit, or otherwise handle information that requires specific safeguards, applicable requirements can flow down through the defense supply chain. Prime contractors should identify what information subcontractors actually need, determine the corresponding protection requirements, and ensure applicable contractual obligations are properly flowed down. Our guide to CMMC flow-down requirements explains how these responsibilities can affect primes and subcontractors.

Is NIST 800-171 Compliance Enough for CMMC Level 2?

Implementing all applicable NIST SP 800-171 Rev. 2 security requirements is the technical foundation of CMMC Level 2, but implementation alone does not automatically mean an organization is fully prepared for the CMMC assessment framework. Contractors also need to demonstrate what they have implemented.

Define the CMMC Assessment Scope

One of the first steps is understanding exactly what belongs inside the CMMC assessment boundary. Organizations need to identify the systems, users, applications, services, assets, and security technologies involved in processing, storing, transmitting, or protecting CUI. CMMC Level 2 scoping guidance categorizes assets based on how they interact with CUI or provide protection to the CUI environment. Poor scoping can create serious problems. A scope that is too broad can unnecessarily increase compliance cost and complexity. A scope that is too narrow can leave relevant CUI assets or security dependencies outside the assessment.

Maintain an Accurate System Security Plan

The System Security Plan should describe the organization’s real environment. It should explain system boundaries, operational environments, how security requirements are implemented, and how relevant components work together to protect CUI. Generic statements copied from policies are not enough. The SSP should correspond to actual technologies, configurations, responsibilities, and processes.

Collect Objective Evidence for Each Requirement

A strong CMMC readiness program maps evidence to applicable assessment objectives. Evidence might include:

  • Policies and procedures
  • Screenshots
  • Technical configurations
  • System settings
  • Access records
  • Logs
  • Tickets
  • Asset inventories
  • Network diagrams
  • Training documentation
  • Incident response records
  • Change-management records
  • Security monitoring outputs

The goal is not to produce paperwork for its own sake. It is to demonstrate that a requirement is implemented and operating as described.

Address Gaps and POA&M Items

Organizations should identify unresolved requirements well before an assessment. Not every deficiency can remain open indefinitely. CMMC places specific restrictions on POA&M use and establishes deadlines for closing eligible items when an organization receives conditional status. Treating the POA&M as a permanent list of unfinished cybersecurity projects is therefore a risky strategy.

Validate Assessment Readiness

Before an organization enters a formal assessment process, it should test whether its scope, SSP, evidence, policies, technical safeguards, and personnel can collectively support each requirement. A structured readiness review can uncover situations where a control exists technically but documentation is inaccurate, evidence is incomplete, or responsible personnel cannot demonstrate the process. Organizations that need support aligning requirements, evidence, documentation, and the CUI environment can use CMMC compliance consulting to prepare for the assessment process.

How Does the 2026 CMMC Phase II Suspension Affect NIST 800-171 Requirements?

The July 2026 CMMC announcement changed the planned assessment rollout, but it did not eliminate contractors’ underlying cybersecurity responsibilities.

What Was Suspended in July 2026?

On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II requirements, which had originally been scheduled to begin November 10, 2026. Phase II would have expanded requirements involving Level 2 C3PAO assessments. The Department also began a broader review of the CMMC program. Current official guidance states that CMMC implementation is paused in Phase I.

What CMMC Requirements Remain in Effect?

The suspension did not eliminate Phase I. Applicable Phase I self-assessment requirements remain in place. Current Department guidance states that the program, while paused in Phase I, may require Level 1 and Level 2 self-assessments, along with the associated affirmation and reporting requirements. Contractors should therefore avoid interpreting the suspension as the cancellation of CMMC.

Does the Suspension Remove NIST 800-171 Obligations?

No. The Phase II suspension does not eliminate applicable requirements to safeguard CUI under existing contract clauses. For contractors subject to DFARS 252.204-7012, applicable NIST SP 800-171 requirements continue to matter. Official guidance specifically states that the Phase II suspension does not eliminate the requirement for companies to protect applicable information under DFARS 252.204-7012 and that NIST SP 800-171 Rev. 2 compliance continues to be enforced through self-assessments and selected government-led assessments. For a more detailed explanation of what changed and what did not, see our overview of the CMMC Phase 2 suspension.

What Should Contractors Do If They Already Follow NIST 800-171?

Organizations that have previously implemented NIST SP 800-171 should not assume that old compliance work automatically makes them ready for current requirements. Cybersecurity environments change constantly.

Confirm Which Requirements Apply to Your Contracts

Review applicable:

  • Solicitations
  • Prime contracts
  • Subcontracts
  • DFARS clauses
  • Flow-down provisions
  • CUI requirements
  • CMMC level designations
  • Assessment requirements

Contract language ultimately determines many of the organization’s obligations.

Verify Your NIST 800-171 Rev. 2 Implementation

Perform a requirement-by-requirement review. Do not rely solely on an assessment completed several years ago. Systems may have changed, employees may have left, vendors may have been replaced, cloud platforms may have been added, and security configurations may no longer match the original SSP.

Review Your CUI Environment and Assessment Scope

Follow the CUI lifecycle. Determine:

  1. Where CUI enters the organization.
  2. Who can access it.
  3. Which systems process it.
  4. Where it is stored.
  5. How it is transmitted.
  6. Which security services protect it.
  7. Whether third parties receive it.
  8. How it is retained and destroyed.

This exercise often identifies unexpected systems or services that should be considered during scoping.

Update Your SSP, POA&M and Supporting Evidence

Documentation should reflect today’s environment, not last year’s environment. Update the SSP when material systems, technologies, boundaries, security mechanisms, or processes change. Review POA&M items to confirm they remain accurate and determine whether any unresolved deficiencies require remediation. Evidence should also be refreshed so the organization can demonstrate current implementation.

Confirm SPRS and Affirmation Requirements

Contractors subject to applicable DoD assessment requirements should verify that the information associated with their organization and systems in SPRS is accurate and current. Under current CMMC requirements, annual affirmations are also an important part of maintaining applicable status. Current DFARS provisions require applicable affirmation information to remain current in SPRS.

Continue Preparing While CMMC Rules Evolve

The Phase II suspension changed the timeline for broader third-party assessment requirements. It did not make cybersecurity preparation unnecessary. Organizations should continue implementing safeguards, correcting deficiencies, documenting their environments, maintaining evidence, and tracking official program changes. Companies that continue preparing will generally be in a stronger position when new contract opportunities or future CMMC requirements arise.

How Nexeris Helps Contractors Prepare for CMMC and NIST 800-171

Preparing for CMMC involves more than completing a checklist. Nexeris helps defense contractors understand what requirements apply to their environments and turn those requirements into an assessment-ready cybersecurity program. Support can include:

  • Determining applicable CMMC and NIST requirements
  • Mapping and scoping CUI environments
  • NIST SP 800-171 gap assessments
  • SSP and POA&M development
  • Policy and procedure alignment
  • Security requirement implementation guidance
  • Evidence collection and organization
  • SPRS readiness
  • CMMC assessment preparation

Working with an experienced CMMC consultant can also help organizations identify gaps between what their documentation says and what their systems actually do before those gaps become assessment findings. The goal should not simply be to produce compliance paperwork. It should be to build a defensible, supportable security environment that protects sensitive information and can demonstrate that protection when required.

Frequently Asked Questions

1. What is the main difference between CMMC and NIST 800-171?

NIST SP 800-171 establishes cybersecurity requirements for protecting Controlled Unclassified Information in applicable nonfederal systems. CMMC provides a defense assessment and verification framework used to determine whether applicable contractors have implemented required safeguards. For CMMC Level 2, those safeguards currently include all 110 security requirements from NIST SP 800-171 Revision 2.

2. Does CMMC replace NIST SP 800-171?

No. CMMC does not replace NIST SP 800-171. Instead, it incorporates applicable existing security requirements and establishes mechanisms for assessing, reporting, affirming, and verifying their implementation. NIST provides the security baseline, while CMMC adds the assessment framework.

3. Is NIST 800-171 compliance enough for CMMC Level 2?

Implementing all 110 NIST SP 800-171 Rev. 2 requirements is the technical foundation of CMMC Level 2, but organizations must also satisfy applicable CMMC requirements involving assessment scope, evidence, documentation, reporting, affirmations, POA&Ms, and assessment status. An organization therefore needs to be able to demonstrate its implementation, not simply state that requirements have been addressed.

4. Does CMMC Level 2 use NIST 800-171 Rev. 2 or Rev. 3?

CMMC Level 2 currently uses NIST SP 800-171 Revision 2. NIST finalized Revision 3 in May 2024, but the current CMMC Level 2 framework remains aligned with the 110 requirements in Revision 2. Contractors should monitor Rev. 3 developments but should not replace their current CMMC Rev. 2 baseline unless applicable requirements formally change.

5. Do DoD contractors need both CMMC and NIST 800-171?

It depends on the information handled and the requirements contained in the organization’s contracts and solicitations. Contractors handling CUI may have NIST SP 800-171 obligations through clauses such as DFARS 252.204-7012 and may also face CMMC Level 2 assessment requirements. Contractors handling only FCI may instead fall under CMMC Level 1, which uses 15 safeguarding requirements from FAR 52.204-21.

6. How does the 2026 CMMC Phase II suspension affect NIST 800-171 compliance?

The July 13, 2026 suspension paused the planned transition to CMMC Phase II and the broader expansion of third-party Level 2 assessment requirements. It did not eliminate applicable NIST SP 800-171 obligations or Phase I self-assessment requirements. Organizations subject to DFARS 252.204-7012 must continue protecting applicable CUI and should maintain accurate cybersecurity controls, documentation, assessments, evidence, SPRS information, and required affirmations while the CMMC program review continues.

Zach Tracy, Nexeris founder and CEO

Zach Tracy, CISA, CISSP

Zach Tracy is the CEO and a cybersecurity executive with more than 10 years of experience in security program management and regulatory compliance. He has served as a fractional Chief Information Security Officer for over 40 organizations and has led more than 100 audits across frameworks including SOC 2, CMMC, NIST CSF, ISO 27001, HIPAA, and HITRUST.

Zach specializes in helping defense contractors and regulated organizations build practical, audit-ready security programs that protect contract eligibility and reduce operational risk. He holds CISA, CISSP, CMMC-RP, and ISO 27001 and 9001 Lead Implementer certifications, along with a B.S. in Cybersecurity from Thomas College.

A Marine Corps veteran and former law enforcement officer, Zach brings a mission-focused, disciplined approach to cybersecurity leadership.

Connect with Zach on LinkedIn

Scroll to Top