ZF/blog/cmmc-vs-nist-800-171
CMMC6 min readMay 8, 2025

CMMC vs NIST 800-171: What Changed

CMMC Level 2 reuses the 110 NIST 800-171 practices but adds a formal third-party assessment requirement. Here is what is the same, what is new, and what it means for your program.


What Stayed the Same: 110 Practices

The 110 security practices are identical between NIST SP 800-171 Rev 2 and CMMC Level 2. There are no new controls in CMMC. There is no expanded control set. The 14 families are the same, the practice IDs are the same, and the assessment objectives in NIST 800-171A are the canonical interpretation for both.

This means the technical work to comply does not change. If you were running NIST 800-171 fully implemented, you are also running CMMC Level 2 fully implemented from a controls perspective. What changes is how you prove it.

Read the CMMC framework details and the NIST 800-171 Rev 2 specification side by side. The mappings line up one-to-one.

What Changed: Mandatory Third-Party Assessment

The headline change is the assessment model. Under DFARS 252.204-7012, NIST 800-171 was a self-attestation regime. You wrote your SSP, calculated your SPRS score, submitted it, and the DoD relied on your representation. Audits happened, but they were rare.

Under CMMC Level 2, most contracts require a Certified Third Party Assessor Organization (C3PAO) to perform the assessment. The C3PAO is independent. They follow a defined assessment process, document findings, and submit a formal report through the Cyber AB to the DoD. The certificate is valid for three years.

The implications:

  • Cost: $40K-$120K per assessment vs. internal self-assessment cost
  • Time: 4-8 weeks of assessment activity vs. internal self-paced
  • Rigor: External examination of every practice with evidence
  • Visibility: A formal certificate the contracting officer verifies

Scoring, POA&M, and Conditional Certification

Both regimes use the SPRS scoring methodology. The 110 practices, weighted at 1, 3, or 5 points, deduct from a starting score of 110. SPRS submission is required under both regimes through DFARS 7019 and CMMC.

The difference is what counts as compliant. Under self-attested NIST 800-171, you could submit a low SPRS score with a long POA&M and still bid on contracts. The contracting officer made a risk decision based on the score plus the POA&M trajectory.

Under CMMC Level 2, you need to either fully meet all 110 practices (full certification) or qualify for conditional certification with a limited POA&M closed within 180 days. There is no "submit a low score and bid anyway" path. The certificate either issues or it does not.

Run the SPRS calculator to see if your current state qualifies for full or conditional certification, or if you need more remediation before booking.

Documentation Rigor

NIST 800-171 always required an SSP. CMMC Level 2 requires the same SSP, but the rigor expectation is higher because an external assessor reads it cover-to-cover.

Differences in practice:

  • SSP detail: Each practice gets a narrative describing the implementation, not a one-line "we comply"
  • Evidence linkage: Every practice references the specific evidence artifacts (config files, policy sections, log samples)
  • POA&M discipline: Milestones with dates, owners, and verification methods, not aspirational statements
  • Diagram quality: Network diagrams that match the actual environment, updated within the past 6 months

Companies that ran self-attested NIST 800-171 for years often need a documentation refresh before booking the C3PAO. The technical controls are usually fine. The narrative gaps are where assessments stall.

Transition Strategy from NIST 800-171 to CMMC

If you are already running NIST 800-171 in good faith, the transition to CMMC Level 2 takes 3-6 months of focused work. The sequence:

  1. Documentation refresh: Rewrite the SSP with assessor-quality narratives. This is usually 4-8 weeks.
  2. Evidence consolidation: Build a single repository with every artifact linked to a practice.
  3. POA&M cleanup: Close stale items, add real ones, verify dates and owners.
  4. Pre-assessment: Hire an RPO for a mock assessment. Fix what they find.
  5. C3PAO booking: Schedule 4-6 months in advance.
  6. On-site assessment: 5-10 days of assessor activity.

For companies that were not actually running NIST 800-171 (despite self-attesting), the transition is the full 12-18 month CMMC implementation project. The self-attestation regime was forgiving of paper compliance. CMMC Level 2 is not.

Frequently Asked Questions

CMMCNIST 800-171ComparisonAssessment

Related Articles