ISO 27001 → CMMC

    ISO 27001 to CMMC: How Much Credit Do You Actually Get?

    ISO 27001 certified shops often assume they're 80% of the way to CMMC Level 2. The honest number is closer to 50-60% in coverage and 30-40% in evidence reuse — because CMMC asks for things ISO 27001 doesn't (incident reporting to DC3 within 72 hours, FIPS-validated crypto, U.S. personnel control) and ISO asks for things CMMC doesn't (formal risk treatment, management review cadence). This page maps the genuine overlap, the real gaps, and how to reuse your ISMS evidence pipeline without rebuilding it.

    Where the frameworks genuinely overlap

    • Access control: ISO 27001 A.5.15-A.5.18 ↔ NIST 800-171 3.1.* — high overlap, evidence reusable.
    • Cryptography: ISO A.8.24 ↔ NIST 3.13.11 — partial overlap, but CMMC requires FIPS-validated implementations specifically. ISO doesn't.
    • Logging and monitoring: ISO A.8.15-A.8.17 ↔ NIST 3.3.* — high overlap; ISMS audit logs usually suffice.
    • Configuration management: ISO A.8.9 ↔ NIST 3.4.* — strong overlap.
    • Vulnerability management: ISO A.8.8 ↔ NIST 3.11.* — strong overlap.
    • Personnel security: ISO A.6.1-A.6.6 ↔ NIST 3.9.* — overlaps, but NIST requires explicit screening of anyone with CUI access.

    Where CMMC asks for things ISO doesn't

    • 72-hour incident reporting to DC3 (DFARS 7012). ISO 27001 requires you to have an incident response process — it doesn't require a specific external reporting timeline or destination.
    • FIPS 140-2 / 140-3 validated cryptography. ISO requires "appropriate" crypto. CMMC requires specifically FIPS-validated modules, with a published CMVP certificate number.
    • U.S. personnel access controls for CUI handling. ISO doesn't care about citizenship. CMMC + the underlying CUI handling rules effectively do.
    • CUI flow-down to subcontractors. Specific to the DFARS clause — no ISO equivalent.
    • SSP in the NIST format with explicit objective-by-objective implementation statements (~320 objectives in 800-171A). ISO's Statement of Applicability is conceptually similar but structurally different — assessors won't accept it verbatim.

    Where ISO asks for things CMMC doesn't

    • Formal risk-treatment plans with documented residual risk acceptance.
    • Management review at planned intervals (typically annual minimum).
    • Continual improvement program with metrics.
    • Internal audit program with a documented schedule.
    • None of this is wasted under CMMC — it just isn't directly assessed.

    The pragmatic dual-program pattern

    Don't run ISO and CMMC as separate programs. Run one ISMS with two output views:

    • One control catalog. Map each implemented control to both the ISO A.* clause and the 800-171 control ID(s) it satisfies. Athena's SSP generator emits the NIST view from a unified control inventory.
    • One evidence repository. Audit logs, configuration baselines, scan reports — captured once, referenced from both the ISO SoA and the CMMC SSP.
    • One incident response process with a CMMC-specific branch that triggers the DC3 72-hour reporting workflow when CUI is involved.
    • One risk register that tracks both ISO risk treatments and CMMC POA&M entries — the data model overlaps about 80%.

    The result: your annual ISO surveillance audit and your triennial C3PAO assessment pull from the same evidence pipeline, with framework-specific reports generated on demand.

    Frequently asked questions

    If I'm ISO 27001 certified, can I shortcut my CMMC assessment?

    Partially. A C3PAO can accept ISO 27001 audit evidence as supporting documentation for overlapping controls — but they must still independently verify each NIST 800-171 control objective. Expect ~50% of your evidence to be directly reusable, with the rest requiring CMMC-specific artifacts (DC3 reporting procedure, FIPS module inventory, U.S. personnel attestations).

    Is the ISO Statement of Applicability the same as a CMMC SSP?

    Conceptually similar, structurally different. The SoA lists ISO Annex A controls with applicability and justification. The CMMC SSP requires per-control implementation narratives mapped to ~320 assessment objectives in 800-171A. Plan to author a fresh SSP using your SoA + control implementations as the source material.

    Which is harder to maintain — ISO 27001 or CMMC Level 2?

    ISO 27001 is heavier in process (management review, internal audit, continual improvement). CMMC Level 2 is heavier in technical evidence (audit logs, scan results, FIPS module verification). Mature shops find ISO's annual rhythm easier to sustain; CMMC's evidence freshness requirements punish neglect.

    Does ISO 27001:2022 change the mapping?

    It improves it. The 2022 revision consolidated and modernized Annex A and added explicit controls around threat intelligence and cloud security that align more closely with NIST 800-171. If you're freshly certifying, certify to 2022 — the mapping work is easier.

    Further reading

    Related Athena pages and authoritative external references.

    Ready to act on this?

    Run the free Quick Score, then walk through the Assessment Pack.