govcon.forum

What is NIST 800-171, and how is it different from CMMC Level 2?

Ask a question
Asked Active Viewed 0 timesAnswered
Short answer · from the accepted reply
  • CMMC Level 2 incorporates the 110 security requirements of NIST SP 800-171 Revision 2.
  • CMMC Level 2 builds on NIST 800-171 by adding assessment and certification requirements.
  • NIST SP 800-171 outlines safeguards for Controlled Unclassified Information (CUI) in non-federal systems.
Read the accepted answer
2answers

We are an IT subcontractor on a defense prime's contract, NAICS 541519. The prime asked for our SPRS score and a system security plan by the end of the month. I've been looking into NIST 800-171 and CMMC Level 2, and honestly, I'm confused. It seems like they're related, but I can't tell if they're two separate requirements or if CMMC Level 2 just *is* NIST 800-171 with some extra steps. I tried reading through some DoD guidance, but it uses a lot of jargon. Can someone explain the relationship between NIST 800-171 and CMMC Level 2? What does a gap assessment for these look like?

asked Luis A. Verified vendorSDVOSB founder, court reporting and legal support · San Antonio, TX · 262 rep

2 answers

2
Accepted answer

CMMC Level 2 incorporates the 110 security requirements of NIST SP 800-171 Revision 2. CMMC Level 2 builds on NIST 800-171 by adding assessment and certification requirements. NIST SP 800-171 outlines safeguards for Controlled Unclassified Information (CUI) in non-federal systems. CMMC Level 2 requires either a self-assessment or a certification assessment by a C3PAO, depending on the contract. A CMMC Level 2 self-assessment is conducted every 3 years. The resulting CMMC Status is valid for three years from the CMMC Status Date. A gap assessment involves comparing your current cybersecurity posture against the 110 controls in NIST SP 800-171. This identifies controls that are not yet implemented or are only partially implemented. You then develop a System Security Plan (SSP) detailing how each control is met and a Plan of Action and Milestones (POAM) for any gaps.

answered Dave H. Verified vendorParts distributor, DLA and DIBBS · Dayton, OH · 233 rep
Thanks, Dave. This clarifies the relationship well. I will start by mapping our current security practices against the 110 NIST SP 800-171 controls to identify our gaps. · Luis A. ·
2

NIST SP 800-171 is the baseline for CMMC Level 2, but the CMMC program rule was published in October 2024 and took effect in December 2024, with the DFARS acquisition rule taking effect in November 2025. This means that while the technical requirements are the same, the CMMC framework adds the requirement for a formal assessment and reporting of that assessment, which was not explicitly part of NIST SP 800-171 compliance prior to CMMC. Your prime is asking for your SPRS score because that score is what gets reported to the DoD as part of your compliance with NIST SP 800-171 and CMMC Level 2.

answered Helen M. Former county procurement analyst · Raleigh, NC · 252 rep

Your answer

Sign up to answerCite the FAR clause or procurement code where you can.