Teams new to defense contracting often treat ‘NIST 800-171’ and ‘CMMC’ as competing standards to choose between. They are not. One is the control set; the other is the verification mechanism that makes you prove you actually implemented it.

NIST SP 800-171 is the control set

NIST Special Publication 800-171 defines 110 security requirements, organized into 14 families — access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, and so on. If you handle CUI, DFARS clause 252.204-7012 has required you to implement these for years. That obligation predates CMMC.

CMMC is the verification mechanism

The problem the Department of Defense set out to fix was simple: contractors were self-attesting to 800-171 without always having done the work. CMMC Level 2 takes the same 110 requirements and adds assessment — for many contracts, a third-party assessment by a C3PAO on a recurring cycle, with an annual affirmation of continued adherence in between. The requirements did not change; the accountability did.

What this means for your program

  • Your System Security Plan (SSP) is the spine. It describes how each of the 110 requirements is met in your environment. An assessor reads it first.
  • Evidence is the proof. A policy that says you review audit logs is worth little without records showing the reviews happened.
  • Scope decides the size. Where CUI lives determines which systems are in scope. Shrinking that boundary is the most underused way to cut the cost of the whole program.

Think of 800-171 as the exam and CMMC as the proctor. You still study the same material — you just cannot grade your own paper anymore. Here is how we build the SSP, POA&M, and evidence a C3PAO expects.