Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Comparison of CMMC and NIST 800-171 security standards for defense industrial base.

CMMC vs NIST 800-171: The Complete 2026 Guide for Defense Contractors

The CMMC vs NIST 800-171 question became harder to answer on July 13, 2026, not easier. That was the day the Department of War suspended CMMC Phase II — the milestone that would have forced third-party certification on contractors handling controlled unclassified information (CUI) from November 10, 2026. Plenty of contractors read the headline, concluded the program had been canceled, and quietly stood their remediation projects down. That was the wrong call. The verification layer paused. The underlying security requirements did not move an inch.

Here is the short version: NIST SP 800-171 tells you what to implement. CMMC tells you how you prove it. One is a control catalog, the other is an audit regime bolted on top. That single distinction resolves most of the CMMC vs NIST 800-171 confusion, and the suspension has made it commercially important rather than academic.

CMMC vs NIST 800-171 comparison infographic showing the 110 NIST SP 800-171 Rev 2 requirements and the three CMMC levels
CMMC vs NIST 800-171 at a glance: the control catalog, the assessment layer, and what the Phase II suspension changed.

CMMC vs NIST 800-171: what each one actually is

NIST Special Publication 800-171 is a catalog of security requirements for protecting CUI on non-federal systems. Revision 2 contains 110 security requirements grouped into 14 families — access control, audit and accountability, configuration management, incident response, and so on. It is published by the National Institute of Standards and Technology and it carries no enforcement mechanism of its own. It becomes binding when a contract clause points at it.

CMMC — the Cybersecurity Maturity Model Certification — is the Department’s assurance program, codified at 32 CFR Part 170 and made contractually operational through DFARS clause 252.204-7021. At Level 2 it invents no new controls. It assesses the same 110 requirements from Revision 2. What CMMC adds is evidence, scoring rules, and, at higher levels, an independent assessor.

The cleanest way to hold the CMMC vs NIST 800-171 relationship in your head is this: 800-171 is the syllabus, CMMC is the proctored exam. Suspending the exam does not delete the syllabus.

What the July 2026 suspension did and did not change

On July 13, 2026 the Department of War announced the immediate suspension of CMMC Phase II, along with all pending and future CMMC implementation milestones across departmental solicitations and contracts. Phases 3 and 4 are frozen with it.

The stated reasoning was blunt. DoW Chief Information Officer Kirsten A. Davies described the move as a response to compliance barriers facing small and medium businesses, and the release cited Small Business Administration reporting that CMMC costs were pushing innovative companies out of the Defense Industrial Base altogether. A CMMC Reform Task Force was established the same day to run a 60-day top-to-bottom review, with its report due to the CIO in mid-September 2026. An accompanying request for information closed to industry responses on August 14, 2026.

Now the part most summaries skip. Three things explicitly survived the suspension:

  • Phase I self-assessment requirements remain firmly in place. Solicitations that already carry Level 1 or Level 2 self-assessment obligations still carry them.
  • DFARS 252.204-7012 still applies. Every defense contractor and subcontractor remains contractually obliged to safeguard covered defense information, including the 72-hour cyber incident reporting duty.
  • NIST SP 800-171 Revision 2 remains the enforced standard. The Department said it will check compliance through self-assessments and select government-led assessments during the interim period.

That last point deserves emphasis, and it is where CMMC vs NIST 800-171 stops being a theory question. Government-led assessment did not go away. If anything, the removal of the C3PAO bottleneck makes a DIBCAC-style review the more likely form of scrutiny in the near term, and those are conducted against the same 110 requirements you were already supposed to have met.

CMMC vs NIST 800-171: side-by-side comparison

DimensionNIST SP 800-171 (Rev 2)CMMC
What it isSecurity requirements catalogAssessment and certification program
Issued byNISTDepartment of War, via 32 CFR Part 170
Contract hookDFARS 252.204-7012DFARS 252.204-7021
Content110 requirements across 14 familiesLevel 1: 15 requirements. Level 2: the same 110. Level 3: 110 plus 24 selected from NIST SP 800-172
How you demonstrate itSelf-assessment scored into SPRSLevel 1 self-assessment; Level 2 self or C3PAO; Level 3 government-led (DIBCAC)
Who it applies toAny non-federal organization holding CUI, including for civilian agenciesDoW contracts and their subcontract flow-down
Status, August 2026In force and actively enforcedPhase I in force; Phase II onward suspended
Main cost driverRemediation and documentationAssessment fees layered on top of remediation

Read down the “status” row and the practical answer to CMMC vs NIST 800-171 in late 2026 becomes obvious: the column that can cost you a contract today is the left one.

The revision trap that catches contractors out

Revision choice is the second place the CMMC vs NIST 800-171 distinction trips people up. NIST withdrew Revision 2 on May 14, 2024 and superseded it with Revision 3, which reorganizes the catalog into 97 requirements across 17 families, adding Planning, System and Services Acquisition, and Supply Chain Risk Management. Revision 3 also introduced organization-defined parameters, which give assessors far more to argue about.

Despite that, the Department of War’s July 2026 release named Revision 2 as the standard it will enforce. So the position today is genuinely odd, and worth stating plainly: the standard your DoW contract requires is a publication NIST has formally withdrawn. Building your system security plan against Revision 3 because it is the current document is a common and expensive mistake. Read the clause in your contract, not the NIST website. Our guide to which NIST SP 800-171 revision your contract actually names works through the traps in more detail.

What CMMC Level 1, 2 and 3 require

Even suspended, the level structure is the yardstick any reformed program will be measured against, so it is worth knowing where you sit.

Level 1

Fifteen basic safeguarding requirements drawn from FAR 52.204-21, covering federal contract information rather than CUI. Annual self-assessment with an affirmation. This tier was never in scope for the Phase II certification requirement.

Level 2

All 110 Revision 2 requirements. This is where the great majority of CUI-handling contractors land, and where the suspended Phase II milestone would have replaced self-assessment with a C3PAO assessment on a three-year cycle. A limited plan of action and milestones was permitted for certain requirements, with a closure window rather than an indefinite reprieve.

Level 3

The 110 requirements plus 24 selected from NIST SP 800-172, aimed at advanced persistent threats — 134 assessed requirements in total, assessed by the government’s DIBCAC rather than a commercial body. Reserved for the most sensitive programs.

Your SPRS score is still the number that gets you shortlisted

Under the DoD Assessment Methodology, a self-assessment produces a score that starts at 110 and subtracts weighted points for each unmet requirement, with a floor of −203. That score goes into the Supplier Performance Risk System, and primes look at it when they build their supply chains.

Nothing in the Phase II suspension makes a negative SPRS score attractive. With certification off the table for now, the score reverts to being the main discriminator a prime has available — which is why the CMMC vs NIST 800-171 answer matters most to subcontractors. This is also where third-party risk management bites: flow-down obligations do not evaporate because a departmental milestone slipped, and primes have every incentive to keep asking.

What to do between now and the task force report

The temptation to pause is understandable and, in most cases, wrong. Remediation and documentation work is the part that typically takes twelve to eighteen months for a mid-sized contractor; assessment scheduling is measured in weeks. Suspending the fast part is not a reason to stop the slow one.

  1. Read your actual contract clauses. Identify whether 252.204-7012 and 252.204-7021 are present and what level, if any, is specified. Your obligations come from the clause, not the news cycle.
  2. Refresh your SPRS score honestly. An inflated score submitted in 2025 is a False Claims Act exposure, and that risk was never suspended.
  3. Finish the system security plan and POA&M. Both are requirements in their own right under Revision 2, independent of CMMC.
  4. Keep evidence, not just policy. Government-led assessments continue during the interim period and they test implementation, not intent.
  5. Watch mid-September 2026. The task force report will shape whatever replaces Phase II. Reform is not the same as repeal.

For the full phase-by-phase background, our CMMC compliance guide sets out how the rollout was designed and which parts of it still bind you.

Frequently asked questions

Is NIST 800-171 still mandatory now that CMMC Phase II is suspended?

Yes. DFARS 252.204-7012 is untouched, and the Department confirmed it will enforce Revision 2 through self-assessments and government-led assessments during the interim period.

Does CMMC replace NIST 800-171?

No, and this is the central misunderstanding in the whole CMMC vs NIST 800-171 debate. CMMC Level 2 assesses the 110 Revision 2 requirements. Remove CMMC and the 110 requirements remain.

Should I build to Revision 2 or Revision 3?

Revision 2, unless your contract says otherwise. NIST withdrew it in May 2024, but the Department of War has continued to name it as the enforced standard.

Do I still need a C3PAO assessment?

Not as a precondition of new awards while Phase II is suspended. If your existing contract already carries a certification obligation, check the clause before assuming the relief applies to you.

Will CMMC come back?

The Department framed this as reform rather than cancellation, with a task force reporting in mid-September 2026 on scalable alternatives including expanded self-attestation. Treat a changed program as the likely outcome, not a vanished one.

Where to start with CMMC vs NIST 800-171

Most of the work sitting between a contractor and a defensible position is documentation: the system security plan, the POA&M, incident response and access control policies, and evidence registers mapped to each of the 110 requirements. That is exactly the work that does not benefit from waiting for a task force.

Our CMMC Documentation Toolkit gives you 107 editable templates mapped to the CMMC control set for $99, so you can spend your time on implementation and evidence instead of drafting from a blank page.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.