Resources Explainer

NIST SP 800-171 vs. CMMC Level 2

One is a set of security requirements; the other is the program that verifies you actually meet them. Here's how they fit together — and what that means in practice for handling CUI.

Contractors meet these two names in the same breath so often that they blur together. The short version: NIST SP 800-171 defines what good protection of Controlled Unclassified Information (CUI) looks like; CMMC is the Department of Defense's program for checking that contractors actually do it. Level 2 of CMMC is, in substance, NIST SP 800-171 plus an assessment regime.

What NIST SP 800-171 is

NIST Special Publication 800-171 is the U.S. government's standard for protecting CUI when it lives in nonfederal systems — your network, your file sharing, your laptops. Its widely-implemented Revision 2 defines 110 security requirements across 14 families, including access control, audit and accountability, identification and authentication, media protection, and system and communications protection.

For defense contractors, it isn't optional reading: the DFARS 252.204-7012 clause contractually requires implementing 800-171 for covered defense information, and the associated assessment methodology produces the score contractors report to the government.

What CMMC is

The Cybersecurity Maturity Model Certification (CMMC) is DoD's answer to a chronic problem: self-attestation didn't reliably produce implementation. CMMC 2.0 defines three levels:

  • Level 1 — basic safeguarding for Federal Contract Information (FCI); self-assessed.
  • Level 2 — aligned to NIST SP 800-171 for contractors handling CUI; depending on the contract, verified by self-assessment or by a certified third-party assessor organization (C3PAO).
  • Level 3 — for the most sensitive programs; adds requirements drawn from NIST SP 800-172 with government-led assessment.

CMMC requirements are being phased into DoD contracts, which means the practical question for most contractors isn't whether Level 2 applies but when it shows up in their contract flow-downs — and whether their subcontractors are ready too, since the requirements flow down the supply chain.

The relationship, in one table

NIST SP 800-171CMMC Level 2
What it isA set of security requirements for protecting CUIA certification level in DoD's assessment program
Substance110 requirements across 14 families (Rev. 2)Adopts the 800-171 requirements
VerificationContractual obligation; self-scored under DFARSSelf-assessment or C3PAO assessment, per contract
Who it reachesAnyone holding CUI in nonfederal systemsDoD contractors and their subcontractors

What it means in practice

Most of the work is the same regardless of which label your contract uses:

  1. Find your CUI. You can't scope what you haven't inventoried — identify what CUI you hold, where it lives, and how it moves.
  2. Scope an enclave. Most contractors don't bring their whole network into scope; they concentrate CUI into a bounded environment that can actually meet the requirements.
  3. Write the SSP, track the POA&M. The System Security Plan describes how each requirement is met; the Plan of Action & Milestones tracks what isn't yet.
  4. Fix the sharing problem. External file sharing is where CUI most often escapes scope — email attachments and consumer file links undo an otherwise solid enclave. Purpose-built tools like SecureExport keep marking, access expiry, screening, and audit logging attached to the file as it crosses your boundary.
  5. Rehearse the assessment. Whether self-assessed or C3PAO-assessed, evidence beats assertion: access records, audit trails, and configuration proof, organized per requirement.
This article is educational, not legal or compliance advice. Requirements evolve and contracts differ — confirm specifics against your contract clauses and current DoD guidance.

Frequently asked questions

Is CMMC Level 2 the same as NIST SP 800-171?

Nearly. CMMC Level 2 adopts the security requirements of NIST SP 800-171 as its substance; what CMMC adds is the assessment and certification regime — the mechanism by which DoD verifies a contractor actually implements the requirements rather than just attesting to them.

Who needs CMMC Level 2?

Defense contractors and subcontractors that handle CUI. Contracts specify the required level and whether a self-assessment or a third-party (C3PAO) assessment applies. Contractors handling only Federal Contract Information typically need Level 1.

Does NIST SP 800-171 apply outside defense contracting?

Yes. It's the general standard for protecting CUI in nonfederal systems, referenced by agencies beyond DoD, and many commercial organizations adopt it voluntarily as a recognized baseline.

Contact One business day

Working toward Level 2?

Our export-controls & CMMC readiness practice helps teams scope enclaves, fix the file-sharing gap, and build audit evidence into daily work.