The Short Answer
NIST SP 800-171 is the standard containing the 110 security controls. CMMC is the Department of Defense programme that verifies you have actually implemented them. The controls are identical. CMMC adds the assessment, the certification, and the consequence for not having done the work. One is the rulebook; the other is the referee.
Which means the question most contractors ask — "should we do CMMC or 800-171?" — does not have an answer, because it is not a choice. If CMMC Level 2 applies to you, you are implementing 800-171 either way.
How They Relate
DFARS 252.204-7012 has required defense contractors handling CUI to implement NIST SP 800-171 and report an SPRS score for years. What it relied on was self-attestation.
CMMC exists because self-attestation turned out to be unreliable. It keeps the same control set and adds verification: at Level 2 on prioritized contracts, an authorized C3PAO assesses you rather than taking your word.
The practical consequence is good news. Every hour spent on 800-171 is an hour spent toward CMMC Level 2. Contractors who did the work properly under 7012 are not starting again — they are getting assessed on work they already did.
Side by Side
| NIST SP 800-171 | CMMC | |
|---|---|---|
| What it is | A standard — 110 controls in 14 families | A DoD verification programme |
| Published by | NIST | U.S. Department of Defense |
| Verification | Self-attestation via SPRS | C3PAO assessment at Level 2 (prioritized), government-led at Level 3 |
| Produces | An SPRS score, −203 to 110 | A certification, valid 3 years |
| Levels | None — one control set | Three |
| Contract clause | DFARS 252.204-7012 | DFARS 252.204-7021 |
| Flows to subcontractors | Yes | Yes, at the level their data requires |
Which Applies to You
Read the contract, not the internet. The clauses tell you directly.
DFARS 252.204-7012 present, no CMMC clause: implement 800-171 and keep a current SPRS score. Self-attestation, for now — and "for now" is doing real work in that sentence, because contracts get renewed.
DFARS 252.204-7021 present: CMMC applies, and the clause states the level. Level 2 on a prioritized contract means a C3PAO assessment.
FCI only, no CUI: CMMC Level 1, which maps to 17 basic safeguarding requirements from FAR 52.204-21, not to 800-171. Annual self-assessment.
You are a subcontractor: the requirement flows down at the level set by the data the prime shares with you, not by the prime's own level. A Level 2 prime can legitimately have Level 1 subcontractors who never touch CUI.
Not sure which category you are in? That is a scoping question and it is the first thing we answer — usually inside thirty minutes. See CMMC consulting.
Self-Assessment vs C3PAO Assessment
| Scenario | Who assesses | What you produce |
|---|---|---|
| 800-171 under 7012 | You | SPRS score, SSP, POA&M |
| CMMC Level 1 | You, annually | Self-assessment and affirmation |
| CMMC Level 2, non-prioritized | You, annually | Self-assessment and affirmation |
| CMMC Level 2, prioritized | Authorized C3PAO | Certification, valid 3 years |
| CMMC Level 3 | Government (DIBCAC) | Certification |
The gap between "we self-attested a score" and "an assessor verified it" is where most contractors discover their evidence does not hold up. A gap assessment is how you find that out on your own schedule rather than the assessor's.
What Each Costs
| Programme | Startup 5–50 | Mid-Market 51–200 | Large Enterprise 201–500 |
|---|---|---|---|
| NIST SP 800-171 / CSF | $7,000 | $18,000 | $30,000 |
| CMMC (readiness) | $20,000 | $55,000 | $90,000 |
CMMC costs more than 800-171 alone because it adds assessment preparation, evidence rigor a self-attestation never faced, and the C3PAO engagement itself — whose fee is separate and paid directly to the assessor. Full detail in CMMC certification cost.
CMMC vs NIST 800-171 FAQs
What is the difference between CMMC and NIST 800-171?
NIST SP 800-171 is the standard containing the 110 security controls. CMMC is the Department of Defense programme that verifies you have implemented them. The controls are the same; CMMC adds the assessment, the certification and the enforcement. One is the rulebook, the other is the referee.
Does CMMC replace NIST 800-171?
No. CMMC Level 2 is built directly on the 110 controls of NIST SP 800-171 — it does not replace them, it verifies them. Work you do to meet 800-171 is work toward CMMC Level 2, not work you repeat.
Do I need CMMC if I already comply with NIST 800-171?
Probably yes. Complying with 800-171 under DFARS 252.204-7012 has been required for years, but CMMC adds verification. If your contract carries the CMMC clause, self-attestation is no longer sufficient at Level 2 on prioritized contracts — an authorized C3PAO has to assess you.
Is NIST 800-171 mandatory for defense contractors?
If your contract includes DFARS 252.204-7012 and you handle Controlled Unclassified Information, yes. That clause has required 800-171 implementation and an SPRS score for some time, independently of the CMMC rollout.
What is the difference between CMMC Level 1 and NIST 800-171?
CMMC Level 1 covers Federal Contract Information and maps to 17 basic safeguarding requirements from FAR 52.204-21, not to NIST SP 800-171. The 110 controls of 800-171 arrive at Level 2, which covers Controlled Unclassified Information.
Where to Start
A NIST 800-171 gap assessment answers both questions at once: your real position against the 110 controls, and what CMMC certification would take from here. See also CMMC consulting, how the SPRS score works, and CMMI if you have been sent here by the other acronym confusion.
Official references: NIST SP 800-171, U.S. DoD, CMMC.
Find out which one applies to you
Thirty minutes with your contract clauses and we can tell you.