We are an IT subcontractor on a defense prime's contract, NAICS 541519. The prime asked for our SPRS score and a system security plan by the end of the month. I've been looking into NIST 800-171 and CMMC Level 2, and honestly, I'm confused. It seems like they're related, but I can't tell if they're two separate requirements or if CMMC Level 2 just *is* NIST 800-171 with some extra steps. I tried reading through some DoD guidance, but it uses a lot of jargon. Can someone explain the relationship between NIST 800-171 and CMMC Level 2? What does a gap assessment for these look like?
What is NIST 800-171, and how is it different from CMMC Level 2?
Ask a question- CMMC Level 2 incorporates the 110 security requirements of NIST SP 800-171 Revision 2.
- CMMC Level 2 builds on NIST 800-171 by adding assessment and certification requirements.
- NIST SP 800-171 outlines safeguards for Controlled Unclassified Information (CUI) in non-federal systems.
2 answers
CMMC Level 2 incorporates the 110 security requirements of NIST SP 800-171 Revision 2. CMMC Level 2 builds on NIST 800-171 by adding assessment and certification requirements. NIST SP 800-171 outlines safeguards for Controlled Unclassified Information (CUI) in non-federal systems. CMMC Level 2 requires either a self-assessment or a certification assessment by a C3PAO, depending on the contract. A CMMC Level 2 self-assessment is conducted every 3 years. The resulting CMMC Status is valid for three years from the CMMC Status Date. A gap assessment involves comparing your current cybersecurity posture against the 110 controls in NIST SP 800-171. This identifies controls that are not yet implemented or are only partially implemented. You then develop a System Security Plan (SSP) detailing how each control is met and a Plan of Action and Milestones (POAM) for any gaps.
NIST SP 800-171 is the baseline for CMMC Level 2, but the CMMC program rule was published in October 2024 and took effect in December 2024, with the DFARS acquisition rule taking effect in November 2025. This means that while the technical requirements are the same, the CMMC framework adds the requirement for a formal assessment and reporting of that assessment, which was not explicitly part of NIST SP 800-171 compliance prior to CMMC. Your prime is asking for your SPRS score because that score is what gets reported to the DoD as part of your compliance with NIST SP 800-171 and CMMC Level 2.