NIST 800-171 vs CMMC: What Small Contractors Actually Need to Know

They're not competing standards — they're two halves of the same requirement. Here's how they fit together.

The whole relationship in one line: NIST SP 800-171 is the security requirements; CMMC is the program that makes you prove you meet them. Same 110 controls underneath — CMMC just adds verification on top.

If the alphabet soup of NIST 800-171, CMMC, DFARS, and SPRS has you confused, you're not alone — and the good news is the relationship is simpler than it sounds. This guide untangles it in plain English so you know exactly what your small business has to do.

The one-sentence answer

NIST SP 800-171 is the set of security requirements. CMMC is the program that makes you prove you meet them. Same controls underneath — CMMC just adds verification on top.

The "what"

NIST SP 800-171

  • A catalog of 110 requirements to protect CUI on non-federal systems
  • Required since DFARS 252.204-7012 took effect in 2017
  • The substance — the actual locks on the doors
The "prove it"

CMMC

  • The DoW program that verifies you implement those protections
  • Points back to the same 110 for Level 2 — no new controls for most
  • Adds accountability: a score, documentation, and (per contract) a C3PAO assessment

NIST SP 800-171: the "what"

NIST Special Publication 800-171 is a catalog of 110 security requirements for protecting Controlled Unclassified Information (CUI) on non-federal systems. If you handle CUI, you've technically been required to meet these since DFARS 252.204-7012 took effect back in 2017. It's the substance — the actual locks on the doors.

CMMC: the "prove it"

The Cybersecurity Maturity Model Certification (CMMC) is the Department of War program that verifies contractors actually implement the required protections — instead of just claiming they do. CMMC didn't invent new controls for most contractors; for Level 2 it points right back at the same 110 NIST 800-171 requirements. What it adds is accountability: a score, documentation, and — depending on the contract — a third-party assessment.

The CMMC levels

LevelForRequirementsHow it's assessed
Level 1Federal Contract Information (FCI)15 basic safeguarding requirements (FAR 52.204-21)Annual self-assessment
Level 2Controlled Unclassified Information (CUI)All 110 NIST SP 800-171 requirementsSelf-assessment or third-party (C3PAO) assessment, depending on the contract
Level 3The most sensitive programs110 + enhanced controls (NIST SP 800-172)Government-led assessment

Most small defense contractors handling CUI are aiming at Level 2 — which is exactly the 110 requirements your SPRS score measures.

Quick gut-check: if your contracts involve CUI, you're in Level 2 territory (all 110 requirements). If you only touch FCI (federal contract info that isn't CUI), you may only need Level 1. Your contract language and your prime can tell you which.

Where SPRS and your SSP fit

Two deliverables tie it all together, and they're the same ones whether you're prepping for self-assessment or a C3PAO:

Find out where you stand — free

Whichever level you're targeting, it starts with knowing your number. Run the SPRS calculator, then document it with the SSP generator.

Calculate your SPRS score →

What a small contractor actually needs to do

Step 1 · Level

FCI or CUI?

FCI-only points to Level 1; CUI means Level 2 — all 110 requirements.

Step 2 · Assess & document

Score, SSP, POA&M

Self-assess for your SPRS score, then document it in an SSP with a POA&M for gaps.

Step 3 · Verify & close

Know your path, fix heavy first

Confirm self-assess vs C3PAO from your contract, and close the 5-point gaps first.

  1. Figure out your level. FCI only → likely Level 1. CUI → Level 2.
  2. Self-assess against the applicable requirements and get your SPRS score.
  3. Document it in an SSP, with a POA&M for any gaps.
  4. Know your assessment type. Some Level 2 contracts allow self-assessment; others require a third-party C3PAO. Check your contract and ask your prime.
  5. Close gaps, highest-impact first — the 5-point requirements move your score (and your risk) the most.

2026 status

CMMC enforcement is live (Phase rollout began late 2025). SPRS scoring still runs on NIST SP 800-171 Revision 2 (not Rev 3 — here's why), and following the February 2026 FAR Overhaul, self-assessment score submission flows through CMMC under DFARS 252.204-7021. The Department of War estimates roughly 80,000 companies need Level 2 — so you're far from alone in working through this.

Start here

Don't overthink the acronyms. Score yourself, document it, and you've done the foundational work both NIST 800-171 and CMMC are asking for. Both tools are free.

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.