Three SaaS products live · OpsTicket · Winrove · OnboardIQ·SAM.gov UEI PR9KWJPM4JU9 · CAGE 91CE1
IT Custom SolutionFour Practices, One Firm · Est. MMXXI
§ SAM.gov UEI · PR9KWJPM4JU9§ CAGE · 91CE1§ NYC MBE · MWCERT2022-353

CMMC 2.0 vs NIST 800-171: What a Contractor Must Actually Implement

CMMC 2.0 and NIST 800-171 overlap but are not identical. Here is what defense contractors must actually build, document, and prove.

The Gap That Gets Contractors Dinged

A mid-size defense subcontractor completes a NIST SP 800-171 self-assessment, scores it at 95 out of 110, and submits the number to the Supplier Performance Risk System (SPRS). Six months later, a contracting officer asks for a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M). The contractor has neither in a form that survives scrutiny. The award slips. This scenario repeats across the Defense Industrial Base (DIB) because contractors conflate two related but distinct frameworks: NIST SP 800-171 and CMMC 2.0.

This post breaks down what each framework requires, where they overlap, and what you must actually build, document, and prove before a contract award or a third-party assessment.

What NIST SP 800-171 Actually Requires

NIST SP 800-171 Revision 2 contains 110 security requirements organized across 14 control families, covering areas from Access Control (AC) to System and Information Integrity (SI). The framework was designed to protect Controlled Unclassified Information (CUI) in nonfederal systems. It is not a certification program. There is no third-party auditor who stamps your compliance. You self-attest, produce a score, and upload it to SPRS.

The practical deliverables NIST 800-171 demands include:

  • System Security Plan (SSP): A document describing your system boundary, the CUI it processes, and how each of the 110 requirements is met or planned. This is not optional. DFARS 252.204-7012 makes it a contract requirement.
  • Plan of Action and Milestones (POA&M): A living document listing every requirement you have not fully implemented, with a remediation timeline and responsible owner.
  • SPRS Score: A numerical score derived from the DoD Assessment Methodology. Each unimplemented requirement carries a point deduction. The maximum score is 110; the minimum is negative 203.

The self-assessment model means the score is only as reliable as the organization's honesty and methodology. DoD has made clear it will pursue False Claims Act liability against contractors who knowingly inflate scores.

What CMMC 2.0 Actually Requires

CMMC 2.0 is a verification program layered on top of NIST 800-171, not a replacement for it. It has three levels:

  • Level 1 (Foundational): 17 practices drawn from FAR 52.204-21. Self-assessment with annual affirmation. Applies to contractors handling Federal Contract Information (FCI) but not CUI.
  • Level 2 (Advanced): All 110 practices from NIST SP 800-171 Rev 2. Most contracts involving CUI will require Level 2. Prioritized acquisitions require a triennial assessment by a CMMC Third-Party Assessment Organization (C3PAO). Non-prioritized acquisitions may allow annual self-assessment with senior official affirmation.
  • Level 3 (Expert): 110 NIST 800-171 practices plus a subset of NIST SP 800-172 requirements. Government-led assessment. Reserved for contractors on the highest-priority programs.

The critical operational difference: at Level 2 with a C3PAO requirement, a third-party assessor reviews your evidence, interviews your staff, and tests your controls. A score in SPRS is not enough. You must demonstrate implementation, not just assert it.

Where the Frameworks Overlap and Where They Diverge

The 110 requirements in NIST 800-171 are the technical foundation for CMMC Level 2. If you have fully implemented 800-171 with a defensible SSP and POA&M, you are close to Level 2 readiness, but not there yet. The gaps are procedural and evidentiary:

  • Evidence packages: CMMC assessors use the CMMC Assessment Process (CAP) guide. They expect artifacts: screenshots, configuration exports, policy documents, access logs, and interview responses. A self-assessment does not require you to organize these. A C3PAO assessment does.
  • Scoping: CMMC scoping guidance (published by the DoD in the CMMC rule and associated guidance) requires you to define CUI Asset categories, Security Protection Assets, and Contractor Risk Managed Assets. NIST 800-171 scoping is less prescriptive. Contractors who scoped narrowly for 800-171 often find their CMMC boundary is larger than expected.
  • Affirmation requirement: Under the final CMMC rule (32 CFR Part 170), a senior company official must annually affirm compliance. This is a legal attestation, not an administrative checkbox.
  • POA&M limits: CMMC 2.0 allows conditional certification with a POA&M, but only for practices below a certain risk threshold. High-weighted practices (those worth five points in the DoD scoring model) cannot be on a POA&M at time of assessment under the CMMC final rule. NIST 800-171 imposes no such restriction on self-assessment.

The Practical Implementation Checklist

Whether you are preparing for a SPRS submission or a C3PAO assessment, the operational work is the same. The difference is the rigor of evidence required.

  1. Define your CUI boundary. Identify every system, application, and location where CUI is created, processed, stored, or transmitted. Include cloud services, mobile devices, and remote access paths. Use the CMMC scoping guide categories, even if you are only doing a NIST 800-171 self-assessment. It will save rework later.
  2. Build or update your SSP. The SSP must describe each of the 110 requirements and state whether it is fully implemented, partially implemented, or planned. Vague language like "we use firewalls" does not satisfy the requirement. Describe the specific control, the tool or process that implements it, and where the evidence lives.
  3. Score honestly using the DoD methodology. The DoD Assessment Methodology assigns point values to each practice. Apply the deductions accurately. A score of 88 that reflects reality is legally safer than a score of 110 that does not.
  4. Maintain a live POA&M. Every gap gets a row: the practice number, the current state, the planned remediation, the target date, and the owner. Review it quarterly. Assessors and contracting officers will ask for it.
  5. Collect and organize evidence artifacts. For each implemented practice, store the supporting evidence in a retrievable location. Policy documents, configuration screenshots, training completion records, and audit logs are the most commonly requested artifacts.
  6. Conduct an internal gap assessment before a C3PAO engagement. A pre-assessment gap review against the CMMC Assessment Process guide will surface scoping errors, missing artifacts, and POA&M items that would block certification. Fixing them before the formal assessment avoids costly remediation cycles mid-assessment.

Common Mistakes That Delay Awards

Three patterns appear repeatedly in contractor compliance failures. First, treating the SSP as a one-time document rather than a living record. Systems change; the SSP must reflect current state. Second, scoping the CUI boundary too narrowly to reduce the compliance burden, then having a C3PAO expand it during assessment. Third, submitting a SPRS score without an SSP or POA&M on file, then being unable to produce them when a contracting officer requests them under DFARS 252.204-7012.

Takeaway

NIST 800-171 and CMMC 2.0 are not interchangeable. NIST 800-171 defines what to implement. CMMC 2.0 defines how implementation will be verified and by whom. A contractor who has done the 800-171 work rigorously, with a complete SSP, an honest SPRS score, and organized evidence artifacts, is well-positioned for a Level 2 assessment. A contractor who has only submitted a number to SPRS is not. Start with the boundary, build the SSP, score honestly, and collect evidence as you go.

If you are working through a CMMC readiness gap assessment or need to pressure-test your SSP before a C3PAO engagement, the Consulting and AI Advisory practice at IT Custom Solution works with defense contractors on compliance architecture and documentation strategy. Reach out through the contact page if a brief scoping conversation would be useful.

#cmmc-2.0#nist-800-171#cui#defense-contracting#dib-compliance#c3pao
§ ShareX / TwitterLinkedIn
§ Need a quote?

Tell us about the work.

IT Custom Solution delivers cybersecurity, cloud, managed IT, and custom software for federal, state, and local agencies.

Analytics cookies? Details: cookies policy or privacy policy.