NIST 800-171 vs. CMMC Crosswalk: Control Mapping for Defense Contractors
NIST SP 800-171 and CMMC 2.0 are not parallel paths to the same destination — one is a control framework, the other is an assessment and certification requirement that sits on top of it. Defense industrial base contractors who treat them as interchangeable build compliance programs that pass self-assessment but fail third-party evaluation. Understanding the precise relationship between 800-171’s 110 controls and CMMC’s practice and assessment requirements is the foundational step in building a compliant, defensible CUI protection program. Armorstack’s VERITY team works this crosswalk for regulated defense contractors across the supply chain.
What NIST SP 800-171 Requires
NIST SP 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” establishes the security requirements for any organization that handles Controlled Unclassified Information (CUI) on behalf of the federal government. The current revision is Revision 3, published May 2024, which reorganized and updated the framework. However, CMMC 2.0 currently maps to Revision 2 (110 controls across 14 control families) — the alignment between CMMC and SP 800-171 Rev. 3 is a subject of ongoing regulatory development.
SP 800-171 Rev. 2 is derived from NIST SP 800-53 Rev. 4 (with updates to align with Rev. 5 through NIST SP 800-171A). It identifies 110 security requirements organized into 14 control families that collectively define the minimum security posture for protecting CUI in nonfederal environments. Compliance with SP 800-171 is required under DFARS clause 252.204-7012 for any defense contractor processing, storing, or transmitting CUI. It is not optional and does not require CMMC certification to be mandatory — the DFARS clause alone creates the obligation.
CMMC 2.0 Sits On Top of 800-171 — It Doesn’t Replace It
CMMC 2.0 does not replace SP 800-171 — it adds an assessment and certification structure that verifies whether contractors actually meet the 800-171 requirements. Prior to CMMC, contractors self-attested compliance with 800-171 through the DFARS 7012 clause. CMMC changes the verification mechanism for a subset of contractors: self-assessment remains for some; third-party assessment by a C3PAO (Certified Third-Party Assessment Organization) is required for others; government-led assessment applies to the most sensitive programs. CMMC 2.0 has three levels, reflecting both the sensitivity of the CUI involved and the sophistication of the cyber threats relevant to the program.
17 Practices, FCI Only
Foundational cybersecurity practices — 17 practices drawn from FAR clause 52.204-21. Applies to contractors handling Federal Contract Information (FCI) but not CUI. Requires annual self-assessment and senior official affirmation. Does not map to SP 800-171.
110 Practices, Maps 1:1 to 800-171
Advanced cybersecurity practices. Maps directly to all 110 security requirements of NIST SP 800-171 Rev. 2 — no more, no less. Applies to contractors handling CUI on programs not prioritized for Level 3. Assessed either by self-assessment with senior official affirmation (lower-priority programs) or by a DoD-authorized C3PAO (higher-priority programs) — the C3PAO assessment is what most contractors mean by “CMMC certification.”
Level 2 Plus 800-172 Enhanced Controls
Expert cybersecurity practices. Encompasses all 110 Level 2 requirements plus an additional set of practices drawn from NIST SP 800-172 (Enhanced Security Requirements for CUI). Applies to contractors on the most sensitive DoD programs and requires government-led assessment by DCMA’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
The 800-171 to CMMC Level 2 Control Mapping
Because CMMC Level 2 maps directly to SP 800-171 Rev. 2, each of the 110 security requirements in 800-171 corresponds to a CMMC practice at the same level. The 14 SP 800-171 control families and their CMMC Level 2 practice counts are as follows.
The one-to-one mapping between 800-171 Rev. 2 requirements and CMMC Level 2 practices means that an organization’s System Security Plan (SSP) — the primary documentation artifact for 800-171 compliance — is also the primary evidence artifact for CMMC Level 2 assessment. A C3PAO will assess the organization’s practices against all 110 requirements, using the SSP as the baseline and supplementing it with technical testing, interviews, and evidence review.
Where Contractors Fail: The Assessment vs. Self-Assessment Gap
The most significant operational shift CMMC introduces for most Level 2 contractors is the difference between self-assessment and C3PAO assessment. In the self-assessment model, contractors scored their own compliance using the NIST SP 800-171 DoD Assessment Methodology and submitted scores to the Supplier Performance Risk System (SPRS). Industry-wide, self-assessed scores were substantially higher than scores produced by independent assessors evaluating the same environments.
A C3PAO assessment is objective. Assessors do not accept policy documents as evidence of operational controls. A written MFA policy is not evidence that MFA is enforced — the technical configuration is. A documented incident response plan is not evidence of a tested response capability — testing records are. A vendor list is not evidence of a supply chain risk management process — documented due diligence and contractual security requirements are. Organizations that have self-assessed favorably and then undergone C3PAO evaluation routinely discover gaps in the AC, IA, AU, and CM families where operational implementation lags policy documentation.
The CMMC scoring methodology assigns point values to each of the 110 practices. Not all practices carry equal weight — some are foundational to the scoring model and failures reduce the score more significantly. A score of 110 represents full compliance; the DoD’s current threshold for CMMC Level 2 self-assessment affirmation is a plan of action for any practices not yet fully implemented, with timelines for closure.
The System Security Plan
Both 800-171 and CMMC Level 2 require a System Security Plan that documents how the organization implements each of the 110 security requirements — or, for requirements not yet fully implemented, the plan and timeline for achieving implementation (the Plan of Action and Milestones, or POA&M). The SSP must describe the system boundary (the boundary of the environment in which CUI is processed, stored, or transmitted), the security requirements applicable to the system, and how each requirement is implemented through specific controls, policies, and procedures.
A common and consequential error is defining the system boundary too broadly. Including systems that do not touch CUI in the assessment boundary increases the scope of assessment without adding compliance value and drives up both remediation cost and assessment cost. Conversely, defining the boundary too narrowly and excluding systems that do handle CUI creates false compliance — a C3PAO will identify boundary errors as a finding.
Armorstack’s VERITY team assists defense contractors in scoping the system boundary accurately, building the SSP to the documentation standards C3PAOs expect, identifying and closing control gaps before assessment, and managing the POA&M process for requirements that are on a remediation timeline. The full CMMC compliance program — including C3PAO selection, assessment scheduling, and continuous compliance maintenance — is detailed at the Armorstack CMMC page.
NIST CSF and 800-171: The Connection
Defense contractors frequently operate under both NIST CSF (as the organizing framework for their overall cybersecurity program) and SP 800-171 (as the specific control requirement for CUI environments). The two are compatible — CSF subcategories map to 800-171 requirements through the NIST reference tool, meaning a CSF-structured program can be crosswalked to identify 800-171 gaps without building a parallel compliance structure.
Armorstack uses CSF as the program structure and 800-171 as the CUI-environment control specification. A NIST CSF maturity assessment conducted for a defense contractor includes a crosswalk to 800-171 requirements, identifying where CSF gaps map to CMMC Level 2 practices. The relationship between CSF and the broader SP 800-53 control catalog that underlies 800-171 is covered at NIST CSF vs. NIST 800-53. For how the GOVERN function applies to supply chain risk management requirements in both CSF and CMMC, see the NIST CSF GOVERN function page. The full NIST CSF pillar overview is at the NIST CSF compliance page. To discuss your organization’s 800-171 compliance posture and CMMC readiness timeline, contact the Armorstack VERITY team or start the 90-Day Proof.
Frequently Asked Questions
What is the relationship between NIST SP 800-171 and CMMC?
NIST SP 800-171 defines the 110 security requirements for protecting Controlled Unclassified Information in nonfederal environments. CMMC 2.0 adds an assessment and certification structure on top of those requirements. CMMC Level 2 maps directly to all 110 SP 800-171 Rev. 2 security requirements — one CMMC practice for each 800-171 requirement. CMMC does not replace 800-171; it changes how compliance is verified, from self-attestation to third-party assessment for higher-priority programs.
How many controls are in NIST SP 800-171 and CMMC Level 2?
NIST SP 800-171 Rev. 2 contains 110 security requirements across 14 control families. CMMC Level 2 contains exactly 110 practices, mapped one-to-one to the 800-171 Rev. 2 requirements. The 14 control families cover Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.
What is a System Security Plan and why is it required for CMMC?
A System Security Plan (SSP) is the primary documentation artifact for both NIST SP 800-171 and CMMC Level 2 compliance. It documents the system boundary (where CUI is processed, stored, or transmitted), the security requirements applicable to the system, and how each of the 110 requirements is implemented. For requirements not yet fully implemented, a Plan of Action and Milestones (POA&M) documents the remediation timeline. A C3PAO assessment uses the SSP as the baseline for evaluating compliance.
What is the difference between CMMC Level 2 and Level 3?
CMMC Level 2 encompasses all 110 security requirements of NIST SP 800-171 Rev. 2 and applies to contractors handling CUI on programs not prioritized for Level 3. Assessment at Level 2 is either self-assessment with senior official affirmation or third-party assessment by a C3PAO, depending on the program. CMMC Level 3 encompasses all Level 2 requirements plus additional practices from NIST SP 800-172, applies to the most sensitive DoD programs, and requires government-led assessment by DCMA DIBCAC.