CMMC and NIST 800-171

CMMC compliance consultant for defense contractors

We help defense suppliers implement NIST SP 800-171, document it in a system security plan, calculate an accurate SPRS score and prepare for CMMC assessment. You get a realistic plan that holds up whichever way the program moves next.

  • NIST SP 800-171 gap assessment and remediation
  • SPRS score, SSP and POA&M preparation
  • Readiness for Level 1 and Level 2 assessments
Two engineers reviewing data on a manufacturing floor

For the defense supply chain

Scoped for manufacturers and suppliers handling FCI and CUI

Remediation in house

Engineers for identity, network, endpoint and logging controls

Top virtual CISO services company

Recognized by Cyber Security Review

CMMC 2.0 compliance

What CMMC and NIST 800-171 require

The Cybersecurity Maturity Model Certification (CMMC) program verifies that Department of Defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC 2.0 has three levels, and the level in your contract depends on the information you handle.

For most suppliers that handle CUI, the standard behind CMMC is NIST SP 800-171. DFARS 252.204-7012 already requires you to implement it, and the DoD assessment methodology turns your implementation into an SPRS score that you post in the Supplier Performance Risk System.

The three levels

CMMC levels at a glance

Your contracting officer sets the level and assessment type in the solicitation.

  • Level 1: basic safeguarding of FCI, annual self-assessment
  • Level 2: the 110 NIST SP 800-171 requirements for CUI, by self-assessment or C3PAO assessment
  • Level 3: added NIST SP 800-172 requirements, assessed by the government

Program status

Where CMMC stands as of 2026

CMMC is being phased into DoD contracts. The program rule (32 CFR Part 170) took effect in December 2024, and the acquisition rule (48 CFR) took effect on November 10, 2025. That started Phase 1, in which contracts can require Level 1 and Level 2 self-assessments.

Phase 2 was scheduled to begin on November 10, 2026 and would have made third-party (C3PAO) Level 2 certification a condition of award for many contracts. On July 13, 2026, the Department suspended Phase 2 and the later phases and set up a CMMC Reform Task Force to review the program. During the review, new requirements are limited to Level 1 and Level 2 self-assessments. As of late September 2026, the task force’s recommendations have not been made public.

What has not changed

  • DFARS 252.204-7012 and NIST SP 800-171 still apply to contracts that involve CUI
  • Phase 1 self-assessment requirements remain in place
  • You still need a current SPRS score and a senior official’s affirmation
  • Contractors can still choose a voluntary C3PAO assessment

The work to implement 800-171 is the same whether your eventual assessment is a self-assessment or a C3PAO assessment. We recommend continuing it. Requirements change, so confirm the CMMC level and assessment type for each contract with your contracting officer.

What’s included

NIST 800-171 compliance and CMMC Level 2 assessment readiness

How it works

From scoping to assessment-ready

1

Scope

Confirm which contracts involve FCI or CUI, which level applies and which systems are in scope.

2

Assess

Test all applicable requirements, calculate your current SPRS score and document gaps.

3

Remediate and document

Close gaps, write the SSP and POA&M and gather the evidence an assessor will ask for.

4

Affirm and maintain

Support your self-assessment, SPRS update and affirmation, or a C3PAO assessment, then keep controls current.

Deliverables

What you receive

  • CUI and FCI data flow and scope diagram
  • Requirement-by-requirement gap report
  • Calculated SPRS score with supporting notes
  • System security plan (SSP)
  • Plan of action and milestones (POA&M)
  • Evidence package organized for assessment

FAQ

CMMC and NIST 800-171 questions

Partly. On July 13, 2026, the Department suspended Phase 2, which would have required C3PAO certification for many Level 2 contracts starting November 10, 2026. Phase 1 self-assessments, NIST SP 800-171 and DFARS 252.204-7012 still apply. Confirm current requirements with your contracting officer.

It’s the score from a NIST SP 800-171 assessment under the DoD assessment methodology, posted in the Supplier Performance Risk System. A perfect score is 110, and unimplemented requirements subtract points. Contracting officers can see your score.

Level 1 is always a self-assessment. Level 2 can be a self-assessment or a C3PAO assessment, depending on the contract, and during the current review new requirements call only for self-assessments. Level 3 is assessed by the government.

NIST SP 800-171 is the set of security requirements for protecting CUI. CMMC is the DoD program that verifies contractors have implemented them, through self-assessment or third-party assessment at Level 2.

Cost depends on how much of your environment handles CUI, your current SPRS score, how many gaps need remediation and whether you need a C3PAO assessment. Narrowing the CUI scope is often the biggest lever. We give you a fixed proposal after scoping.

No. Certification assessments are performed by authorized C3PAOs, and Level 3 by the government. We prepare you, document your controls and support you through the assessment.

Talk to a CMMC expert

Know your SPRS score and your path to CMMC

Tell us about your DoD contracts and an advisor will reply by email to scope your 800-171 and CMMC work.

  • A scoping call on CUI, level and timeline
  • A fixed proposal for assessment and remediation

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message