The short version
NIST SP 800-171 is the security-controls standard — 110 requirements that protect CUI on non-federal systems. CMMC (Cybersecurity Maturity Model Certification) is the DoD's assessment and certification program that verifies you actually meet those requirements.
In other words: 800-171 is what you must do; CMMC is how the DoD confirms you did it.
Not sure where you stand?
Get your CMMC/SPRS readiness score free in 60 seconds — no signup, no credit card.
Start the free Quick ScoreWhat each one is
- NIST SP 800-171 Rev. 2 — a controls catalog (110 security requirements across 14 families) that non-federal organizations must meet when storing, processing, or transmitting CUI. Introduced into DoD contracts by DFARS 252.204-7012.
- CMMC 2.0 — the DoD program that assesses whether contractors meet 800-171. Three levels: L1(Federal Contract Information, self-assessment), L2 (CUI — self-assessment for some, third-party assessment by a C3PAO for most CUI programs), and L3 (highest sensitivity, government-led assessment). Contract-flowdown clause: DFARS 252.204-7021.
How CMMC Level 2 builds on 800-171
CMMC Level 2 is aligned with the 110 requirements of NIST 800-171 Rev. 2. There are no extra controls at L2 — but the assessment bar is much higher:
- Every objective in each requirement (per NIST 800-171A) must be met with evidence — not just the requirement summary.
- Scoring is all-or-nothing per control. Miss one objective and you lose the whole point value.
- Weighted deductions of 1, 3, or 5 points per unmet control, per the DoD Assessment Methodology.
- Results are posted to SPRS (Supplier Performance Risk System) as a number from 110 down to -203.
- A POA&M is allowed only if your score is ≥ 88, and only certain controls are POA&M-eligible.
Self-assessment vs. third-party assessment
| Program | Data type | Who assesses | Cadence |
|---|---|---|---|
| DFARS 7012 (pre-CMMC) | CUI | Contractor (self-attestation, SPRS score) | Ongoing |
| CMMC Level 1 | FCI only | Contractor (annual self-assessment + affirmation) | Annual |
| CMMC Level 2 (self) | CUI (limited scope programs) | Contractor + affirming official | Every 3 years + annual affirmation |
| CMMC Level 2 (C3PAO) | CUI (most CUI programs) | Certified Third-Party Assessment Organization | Every 3 years + annual affirmation |
| CMMC Level 3 | Highest-sensitivity CUI | DIBCAC (government-led) | Every 3 years |
Which one applies to you
- You handle only FCI (no CUI): CMMC Level 1, self-assessed.
- You handle CUI: CMMC Level 2. Check the specific contract or solicitation — most CUI-carrying awards require a C3PAO third-party assessment; a subset are self-assessment.
- You subcontract to a prime that flows CUI down: the same L2 requirement flows to you under DFARS 7021.
- You're not sure whether you handle CUI at all: start by scoping — the wrong scope is the #1 reason SPRS scores end up wrong.
The DFARS clauses to know
- DFARS 252.204-7012 — Safeguarding CUI (requires 800-171 implementation + 72-hour incident reporting).
- DFARS 252.204-7019 / 7020 — Requires a current SPRS self-assessment score, and lets the government verify it (DIBCAC).
- DFARS 252.204-7021 — CMMC contract clause. Requires the specified CMMC level at award and flows to subs handling covered data.
What to do next
If you already have an SSP and a SPRS score, the most useful next step is a defensibility check: does your score survive an assessor looking at each of the 110 controls objective-by-objective? Athena's free Quick Score runs that check in about a minute and shows exactly where the weighted deductions land.
Not sure where you stand?
Get your CMMC/SPRS score free in 60 seconds — all 110 controls, weighted deductions, and a projected SPRS number.
- All 110 controls
- SPRS score projection
- No signup required