If you support a company in the Defense Industrial Base, you have almost certainly run into both NIST SP 800-171 and CMMC in the same conversation, often used as if they were interchangeable. They are not the same thing, but they are tightly connected, and understanding how they relate is essential if your organization handles Controlled Unclassified Information (CUI) for the Department of Defense.
This guide explains what each framework does, how they fit together, and where compliance requirements actually stand as of late 2026.
What Is NIST SP 800-171?
NIST Special Publication 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” is a catalog of security requirements published by NIST. It tells contractors what safeguards they must have in place to protect CUI when that information lives on their own systems rather than a federal network.
Revision 2 of NIST SP 800-171 organizes 110 security requirements across 14 families, covering areas like access control, incident response, configuration management, and system integrity. For years, Revision 2 has been the baseline that defense contractors are contractually required to meet under DFARS 252.204-7012.
Revision 3, published in May 2024, reorganizes the catalog into 97 requirements across 17 families, drops the old basic/derived split, and adds new control families focused on supply chain risk and incident response maturity. It is a more current standard, but it is not yet the operative requirement for most DoD contracts. CMMC assessments and DFARS 7012 still reference Revision 2, and the DoD has not announced a firm transition date, even though a proposed FAR rule from mid-2026 would eventually require Revision 3 government-wide. Contractors should keep preparing against Revision 2 until the department formally says otherwise.
What Is CMMC?
The Cybersecurity Maturity Model Certification, or CMMC, is the Department of Defense’s verification program built on top of NIST SP 800-171. Where NIST SP 800-171 defines what security controls a contractor needs, CMMC defines how the DoD confirms that a contractor actually has those controls in place.
CMMC 2.0 organizes compliance into three levels. Level 1 covers basic safeguarding of Federal Contract Information and allows for annual self-assessment. Level 2 aligns directly with the 110 requirements in NIST SP 800-171 Revision 2 and is the level most contractors handling CUI will need to meet. Level 3 adds a smaller set of additional requirements drawn from NIST SP 800-172 for the highest-priority programs and requires government-led assessment.
The critical design decision in CMMC 2.0 is that it does not invent new security requirements. Level 2, the level that matters to most of the Defense Industrial Base, is simply NIST SP 800-171 with a formal verification process layered on top.
How CMMC and NIST SP 800-171 Actually Relate
Think of it this way: NIST SP 800-171 is the standard, and CMMC is the enforcement mechanism. A contractor cannot achieve CMMC Level 2 without already meeting the 110 requirements in NIST SP 800-171 Revision 2. The two are not competing frameworks or alternative paths to the same goal. They are two layers of the same requirement.
This matters practically because preparing for CMMC and implementing NIST SP 800-171 are the same work. A contractor that has fully implemented and documented its controls, including a System Security Plan (SSP) and Plan of Action and Milestones (POA&M) for any gaps, has already done nearly everything needed to pursue CMMC certification. The certification itself just adds a formal assessment, whether that is a self-assessment for some Level 2 contracts or a third-party assessment conducted by a Certified Third-Party Assessment Organization (C3PAO) for others.
Where Things Stand in 2026
The compliance landscape shifted significantly this year. The phased CMMC rollout began in November 2025 following publication of the 48 CFR acquisition rule, and Phase 1 self-assessment requirements for Level 1 and Level 2 contracts took effect as a condition of contract award, with affirmations submitted through the Supplier Performance Risk System (SPRS).
Phase 2, which would have expanded mandatory third-party C3PAO assessments and was originally scheduled for November 2026, was suspended on July 13, 2026. The Department of Defense launched a 60-day CMMC Reform Task Force review to evaluate a more scalable approach to the program, with public comments collected through mid-August and a report expected between mid-September and early October 2026.
What has not changed is DFARS 252.204-7012 itself, along with the underlying requirement to protect CUI according to NIST SP 800-171. Contractors handling CUI still need to have their security controls in place regardless of exactly when or how third-party assessment requirements are finalized. Treating the Phase 2 suspension as a reason to pause compliance work is a mistake. The reform review is about how certification gets verified, not about whether the underlying security requirements apply.
What This Means for Your Compliance Timeline
For contractors still building out their program, the practical guidance has not changed much despite the news cycle. Continue implementing the 110 Revision 2 requirements, maintain a current System Security Plan, and keep your POA&M realistic and actively worked. Do not wait for a final CMMC rule to start closing security gaps, because the obligation to protect CUI exists independently of the certification program’s assessment mechanics. Keep an eye on the Revision 3 transition too; organizations that understand the differences now will have an easier time when the requirement eventually shifts.
Building the Skills to Get There
Meeting NIST SP 800-171 and preparing for CMMC requires people who understand both the technical controls and the governance process behind them. This overlaps heavily with the discipline of the Risk Management Framework (RMF), which uses the same NIST control catalog structure and documentation approach: system security plans, control assessments, and continuous monitoring.
Certifications also play a direct role in staffing a compliance program. A CISSP brings the broad security management background needed to oversee an organization’s overall control implementation. CompTIA Security+ establishes the technical foundation for the staff actually configuring and maintaining the required safeguards. For organizations building out a dedicated compliance function, CISM helps develop the governance and risk management skills needed to keep a security program aligned with both NIST SP 800-171 and evolving CMMC guidance.
How IT Dojo Can Help
If you need training in NIST SP 800-171, CMMC readiness, or the broader Risk Management Framework that underpins DoD compliance, IT Dojo can help. Our Risk Management Framework (RMF) for DoD IT course gives your team the practical, hands-on understanding of the control assessment and documentation process that NIST SP 800-171 and CMMC both depend on. We also offer CISSP, CISM, and CompTIA Security+ training for the certifications that support a well-staffed compliance program. All courses are live instructor-led and available live remote online. Contact IT Dojo to discuss your organization’s compliance training needs.
Bottom Line
NIST SP 800-171 sets the security requirements, and CMMC verifies that contractors actually meet them. They are not competing standards, they are two parts of a single compliance obligation. The Phase 2 suspension and ongoing reform review affect how assessment happens, not whether the underlying security requirements apply. Contractors that keep building toward full NIST SP 800-171 compliance now will be ready regardless of how the CMMC assessment mechanics ultimately shake out.