CMMC vs NIST 800-171: What Changed
CMMC Level 2 reuses the 110 NIST 800-171 practices but adds a formal third-party assessment requirement. Here is what is the same, what is new, and what it means for your program.
What Changed: Mandatory Third-Party Assessment
The headline change is the assessment model. Under DFARS 252.204-7012, NIST 800-171 was a self-attestation regime. You wrote your SSP, calculated your SPRS score, submitted it, and the DoD relied on your representation. Audits happened, but they were rare.
Under CMMC Level 2, most contracts require a Certified Third Party Assessor Organization (C3PAO) to perform the assessment. The C3PAO is independent. They follow a defined assessment process, document findings, and submit a formal report through the Cyber AB to the DoD. The certificate is valid for three years.
The implications:
- Cost: $40K-$120K per assessment vs. internal self-assessment cost
- Time: 4-8 weeks of assessment activity vs. internal self-paced
- Rigor: External examination of every practice with evidence
- Visibility: A formal certificate the contracting officer verifies
Scoring, POA&M, and Conditional Certification
Both regimes use the SPRS scoring methodology. The 110 practices, weighted at 1, 3, or 5 points, deduct from a starting score of 110. SPRS submission is required under both regimes through DFARS 7019 and CMMC.
The difference is what counts as compliant. Under self-attested NIST 800-171, you could submit a low SPRS score with a long POA&M and still bid on contracts. The contracting officer made a risk decision based on the score plus the POA&M trajectory.
Under CMMC Level 2, you need to either fully meet all 110 practices (full certification) or qualify for conditional certification with a limited POA&M closed within 180 days. There is no "submit a low score and bid anyway" path. The certificate either issues or it does not.
Run the SPRS calculator to see if your current state qualifies for full or conditional certification, or if you need more remediation before booking.
Documentation Rigor
NIST 800-171 always required an SSP. CMMC Level 2 requires the same SSP, but the rigor expectation is higher because an external assessor reads it cover-to-cover.
Differences in practice:
- SSP detail: Each practice gets a narrative describing the implementation, not a one-line "we comply"
- Evidence linkage: Every practice references the specific evidence artifacts (config files, policy sections, log samples)
- POA&M discipline: Milestones with dates, owners, and verification methods, not aspirational statements
- Diagram quality: Network diagrams that match the actual environment, updated within the past 6 months
Companies that ran self-attested NIST 800-171 for years often need a documentation refresh before booking the C3PAO. The technical controls are usually fine. The narrative gaps are where assessments stall.
Transition Strategy from NIST 800-171 to CMMC
If you are already running NIST 800-171 in good faith, the transition to CMMC Level 2 takes 3-6 months of focused work. The sequence:
- Documentation refresh: Rewrite the SSP with assessor-quality narratives. This is usually 4-8 weeks.
- Evidence consolidation: Build a single repository with every artifact linked to a practice.
- POA&M cleanup: Close stale items, add real ones, verify dates and owners.
- Pre-assessment: Hire an RPO for a mock assessment. Fix what they find.
- C3PAO booking: Schedule 4-6 months in advance.
- On-site assessment: 5-10 days of assessor activity.
For companies that were not actually running NIST 800-171 (despite self-attesting), the transition is the full 12-18 month CMMC implementation project. The self-attestation regime was forgiving of paper compliance. CMMC Level 2 is not.
Frequently Asked Questions
Related Articles
NIST 800-171 Controls Explained
NIST 800-171 has 110 practices across 14 families. This walks through each family, what the practices require, and what implementation looks like in real environments.
CMMC Level 2 Requirements
CMMC Level 2 covers 110 practices across 14 families, all aligned to NIST 800-171. Here is what your environment needs to satisfy and what assessors actually verify.
How to Calculate Your SPRS Score
The SPRS score starts at 110 and deducts weighted points for every practice you have not implemented. Here is how to calculate it correctly and what counts as fully implemented.