Where the frameworks genuinely overlap
- Access control: ISO 27001 A.5.15-A.5.18 ↔ NIST 800-171 3.1.* — high overlap, evidence reusable.
- Cryptography: ISO A.8.24 ↔ NIST 3.13.11 — partial overlap, but CMMC requires FIPS-validated implementations specifically. ISO doesn't.
- Logging and monitoring: ISO A.8.15-A.8.17 ↔ NIST 3.3.* — high overlap; ISMS audit logs usually suffice.
- Configuration management: ISO A.8.9 ↔ NIST 3.4.* — strong overlap.
- Vulnerability management: ISO A.8.8 ↔ NIST 3.11.* — strong overlap.
- Personnel security: ISO A.6.1-A.6.6 ↔ NIST 3.9.* — overlaps, but NIST requires explicit screening of anyone with CUI access.
Where CMMC asks for things ISO doesn't
- 72-hour incident reporting to DC3 (DFARS 7012). ISO 27001 requires you to have an incident response process — it doesn't require a specific external reporting timeline or destination.
- FIPS 140-2 / 140-3 validated cryptography. ISO requires "appropriate" crypto. CMMC requires specifically FIPS-validated modules, with a published CMVP certificate number.
- U.S. personnel access controls for CUI handling. ISO doesn't care about citizenship. CMMC + the underlying CUI handling rules effectively do.
- CUI flow-down to subcontractors. Specific to the DFARS clause — no ISO equivalent.
- SSP in the NIST format with explicit objective-by-objective implementation statements (~320 objectives in 800-171A). ISO's Statement of Applicability is conceptually similar but structurally different — assessors won't accept it verbatim.
Where ISO asks for things CMMC doesn't
- Formal risk-treatment plans with documented residual risk acceptance.
- Management review at planned intervals (typically annual minimum).
- Continual improvement program with metrics.
- Internal audit program with a documented schedule.
- None of this is wasted under CMMC — it just isn't directly assessed.
The pragmatic dual-program pattern
Don't run ISO and CMMC as separate programs. Run one ISMS with two output views:
- One control catalog. Map each implemented control to both the ISO A.* clause and the 800-171 control ID(s) it satisfies. Athena's SSP generator emits the NIST view from a unified control inventory.
- One evidence repository. Audit logs, configuration baselines, scan reports — captured once, referenced from both the ISO SoA and the CMMC SSP.
- One incident response process with a CMMC-specific branch that triggers the DC3 72-hour reporting workflow when CUI is involved.
- One risk register that tracks both ISO risk treatments and CMMC POA&M entries — the data model overlaps about 80%.
The result: your annual ISO surveillance audit and your triennial C3PAO assessment pull from the same evidence pipeline, with framework-specific reports generated on demand.