Short answer
CMMC vs NIST 800-171 is a question of standard versus program. NIST SP 800-171 Rev 2 sets the 110 security requirements for protecting CUI, required by DFARS 252.204-7012. CMMC is the Department of War program that assesses them: Level 2 is those same 110 requirements. Phase 2 certification was suspended in July 2026, but 800-171 still applies.
Key takeaways
- NIST SP 800-171 is the requirement set; CMMC is how compliance is assessed and certified.
- CMMC Level 2 equals the 110 requirements of NIST SP 800-171 Rev 2.
- DFARS 252.204-7012 still requires Rev 2 through a class deviation, even though Rev 3 exists.
- The July 2026 suspension paused third-party certification, not the underlying requirements.
How the two fit together
NIST SP 800-171 is a NIST publication listing the security requirements for Controlled Unclassified Information (CUI) in non-federal systems. Defense contractors have been required to meet it since DFARS 252.204-7012, and to post a self-assessment score in the Supplier Performance Risk System (SPRS) under DFARS 252.204-7019 and 7020.
CMMC, set out in 32 CFR Part 170, is the program that verifies it. Level 1 covers 15 basic safeguarding requirements for Federal Contract Information. Level 2 covers all 110 NIST SP 800-171 Rev 2 requirements, assessed by self-assessment or by a CMMC Third-Party Assessment Organization (C3PAO). Level 3 adds 24 requirements from NIST SP 800-172, assessed by DIBCAC.
| NIST SP 800-171 | CMMC 2.0 | |
|---|---|---|
| What it is | Security requirements for CUI | Assessment and certification program |
| Owner | NIST | Department of War (DoD CIO) |
| Required by | DFARS 252.204-7012, 7019, 7020 | 32 CFR Part 170 and the 48 CFR DFARS rule |
| Content | 110 requirements in 14 families (Rev 2) | Levels 1–3; Level 2 = the 110 requirements |
| Proof | SPRS self-assessment score | Self-assessment, C3PAO or DIBCAC assessment, plus annual affirmation |
| 2026 status | Rev 2 still required via class deviation | Phase 1 applies; Phase 2 suspended 13 July 2026 |
Rev 2 or Rev 3?
NIST published Revision 3 in May 2024 with 97 requirements in 17 families. The Department of War has kept DFARS 252.204-7012 tied to Revision 2 through a class deviation, and CMMC Level 2 still assesses Rev 2. Plan for Rev 3, but assess and score against Rev 2.
What the Phase 2 suspension changes
Phase 1, from 10 November 2025, lets contracting officers require Level 1 and Level 2 self-assessments. Phase 2 would have made C3PAO certification the default for most CUI contracts from 10 November 2026. A memo of 13 July 2026 suspended Phase 2 and put Phases 3 and 4 on hold while a reform task force reviewed the program. The 800-171 requirements, SPRS scores and 72-hour incident reporting under DFARS 7012 did not change.
Checklist
What to keep doing during the pause
0 of 5 done
Put this into practice on QULDEX
Frequently asked questions
Is CMMC the same as NIST 800-171?
No. NIST SP 800-171 is the set of requirements. CMMC is the program that assesses them; CMMC Level 2 is the 110 NIST SP 800-171 Rev 2 requirements.
Do I still need NIST 800-171 if CMMC is suspended?
Yes. DFARS 252.204-7012 still requires NIST SP 800-171 Rev 2, and DFARS 7019 and 7020 require a current SPRS score, whatever happens to CMMC Phase 2.
Which NIST 800-171 revision does CMMC use?
Revision 2, with 110 requirements. A DoD class deviation keeps DFARS 7012 tied to Rev 2 although Rev 3 was published in May 2024.