CMMC guide

    NIST 800-171 vs CMMC: What Actually Changes for Your Contract

    If you handle Controlled Unclassified Information (CUI) for the DoD, you have to comply with NIST SP 800-171. CMMC is how the DoD verifies that you do. This guide walks through what changes when a contract moves from a DFARS 7012 self-attestation to a CMMC Level 2 third-party assessment — in plain English.

    The short version

    NIST SP 800-171 is the security-controls standard — 110 requirements that protect CUI on non-federal systems. CMMC (Cybersecurity Maturity Model Certification) is the DoD's assessment and certification program that verifies you actually meet those requirements.

    In other words: 800-171 is what you must do; CMMC is how the DoD confirms you did it.

    Not sure where you stand?

    Get your CMMC/SPRS readiness score free in 60 seconds — no signup, no credit card.

    Start the free Quick Score

    What each one is

    • NIST SP 800-171 Rev. 2 — a controls catalog (110 security requirements across 14 families) that non-federal organizations must meet when storing, processing, or transmitting CUI. Introduced into DoD contracts by DFARS 252.204-7012.
    • CMMC 2.0 — the DoD program that assesses whether contractors meet 800-171. Three levels: L1(Federal Contract Information, self-assessment), L2 (CUI — self-assessment for some, third-party assessment by a C3PAO for most CUI programs), and L3 (highest sensitivity, government-led assessment). Contract-flowdown clause: DFARS 252.204-7021.

    How CMMC Level 2 builds on 800-171

    CMMC Level 2 is aligned with the 110 requirements of NIST 800-171 Rev. 2. There are no extra controls at L2 — but the assessment bar is much higher:

    • Every objective in each requirement (per NIST 800-171A) must be met with evidence — not just the requirement summary.
    • Scoring is all-or-nothing per control. Miss one objective and you lose the whole point value.
    • Weighted deductions of 1, 3, or 5 points per unmet control, per the DoD Assessment Methodology.
    • Results are posted to SPRS (Supplier Performance Risk System) as a number from 110 down to -203.
    • A POA&M is allowed only if your score is ≥ 88, and only certain controls are POA&M-eligible.

    Self-assessment vs. third-party assessment

    ProgramData typeWho assessesCadence
    DFARS 7012 (pre-CMMC)CUIContractor (self-attestation, SPRS score)Ongoing
    CMMC Level 1FCI onlyContractor (annual self-assessment + affirmation)Annual
    CMMC Level 2 (self)CUI (limited scope programs)Contractor + affirming officialEvery 3 years + annual affirmation
    CMMC Level 2 (C3PAO)CUI (most CUI programs)Certified Third-Party Assessment OrganizationEvery 3 years + annual affirmation
    CMMC Level 3Highest-sensitivity CUIDIBCAC (government-led)Every 3 years

    Which one applies to you

    • You handle only FCI (no CUI): CMMC Level 1, self-assessed.
    • You handle CUI: CMMC Level 2. Check the specific contract or solicitation — most CUI-carrying awards require a C3PAO third-party assessment; a subset are self-assessment.
    • You subcontract to a prime that flows CUI down: the same L2 requirement flows to you under DFARS 7021.
    • You're not sure whether you handle CUI at all: start by scoping — the wrong scope is the #1 reason SPRS scores end up wrong.

    The DFARS clauses to know

    • DFARS 252.204-7012 — Safeguarding CUI (requires 800-171 implementation + 72-hour incident reporting).
    • DFARS 252.204-7019 / 7020 — Requires a current SPRS self-assessment score, and lets the government verify it (DIBCAC).
    • DFARS 252.204-7021 — CMMC contract clause. Requires the specified CMMC level at award and flows to subs handling covered data.

    What to do next

    If you already have an SSP and a SPRS score, the most useful next step is a defensibility check: does your score survive an assessor looking at each of the 110 controls objective-by-objective? Athena's free Quick Score runs that check in about a minute and shows exactly where the weighted deductions land.

    Not sure where you stand?

    Get your CMMC/SPRS score free in 60 seconds — all 110 controls, weighted deductions, and a projected SPRS number.

    • All 110 controls
    • SPRS score projection
    • No signup required
    Start the free Quick Score

    Frequently asked questions

    Is NIST 800-171 the same as CMMC?

    No. NIST 800-171 is the underlying set of 110 security requirements. CMMC is the DoD's assessment and certification program that verifies you meet 800-171. Level 2 of CMMC is aligned with all 110 requirements of 800-171 Rev. 2.

    Do I still need to comply with DFARS 7012 under CMMC?

    Yes. DFARS 7012 remains in force — CMMC 7021 sits alongside it and adds an assessment / certification requirement. 7012 also requires 72-hour incident reporting, which is not superseded by CMMC.

    How do I know if my contract requires L2 self-assessment or a C3PAO assessment?

    The contract or solicitation states the CMMC level and assessment type required. Most CUI-carrying contracts require a C3PAO third-party assessment; a limited subset allows self-assessment. Ask your contracting officer if it isn't spelled out.

    What is my SPRS score based on?

    SPRS scores start at 110 and subtract weighted deductions (1, 3, or 5 points) for each unmet 800-171 requirement. Scoring is all-or-nothing per control. A score below 88 means no CMMC status is available.

    Further reading

    Related Athena pages and authoritative external references.

    Ready to act on this?

    Run the free Quick Score, then walk through the Assessment Pack.