If your company handles information for the U.S. Department of Defense, two acronyms now shape almost every contract you touch: CMMC and NIST SP 800-171. They are closely related, frequently confused, and increasingly non-negotiable. Here is the plain-language version.
What is NIST SP 800-171?
NIST Special Publication 800-171 is the federal standard for protecting Controlled Unclassified Information (CUI) when it lives on non-government systems — in other words, on your network. It defines 110 security controls across 14 families, covering things like access control, configuration management, incident response, and system integrity.
Then what is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense program that verifies a contractor has actually implemented those controls. NIST 800-171 is the rulebook; CMMC is the referee. Most contractors handling CUI fall under CMMC Level 2, which maps directly to the 110 NIST 800-171 controls.
Who needs this?
- Prime contractors and subcontractors in the Defense Industrial Base (DIB).
- Any organization that stores, processes, or transmits CUI or Federal Contract Information (FCI).
- Anyone whose contracts include the DFARS 252.204-7012 clause.
The 2026 landscape
The program continues to evolve. As of mid-2026, the Department paused the third-party (C3PAO) assessment requirement while it reviews the program, so many Level 2 requirements in new solicitations are currently met through a triennial self-assessment plus an annual affirmation in SPRS. This can change, and it varies by contract — always confirm the exact requirement in your specific solicitation and DFARS clauses.
How to prepare
- Scope your CUI. Identify where it enters, lives, and leaves your environment.
- Run a gap assessment against all 110 controls.
- Document a System Security Plan (SSP) and a Plan of Action & Milestones (POA&M).
- Remediate the gaps, prioritizing the highest-risk items first.
- Affirm your compliance and keep the evidence current — this is continuous, not one-and-done.
Done well, the same work strengthens your overall security posture and positions you for adjacent frameworks like FedRAMP, GovRAMP, and the emerging IA9100 aerospace quality standard.