CMMC vs. NIST 800-171: What's the Difference?

By Amit Singla·June 29, 2025·Updated June 26, 2026·4 min read

A Common Point of Confusion

Quick answer

CMMC and NIST 800-171 are related but not the same: NIST SP 800-171 is the set of 110 security controls (the "what"), while CMMC 2.0 is the DoD's certification framework that verifies and audits whether you've actually implemented those controls (the "how").

If you're a DoD contractor, you're buried in acronyms. Two of the biggest are CMMC and NIST SP 800-171. They are often used interchangeably, but they are not the same thing. They have a very clear "parent-child" relationship.

Understanding this difference is the key to understanding your compliance journey. Here's the simple version:

  • NIST 800-171 is the "What." It's the list of security controls.
  • CMMC is the "How." It's the framework the DoD uses to verify that you've actually implemented the list.
Dimension NIST 800-171 CMMC 2.0
What it is A NIST publication (SP 800-171 Rev 2) listing 110 security controls in 14 families for protecting Controlled Unclassified Information (CUI). The DoD's certification framework that verifies a contractor has implemented the required controls.
Who requires it Mandated for DoD contractors via the DFARS 252.204-7012 clause. The U.S. Department of Defense, as a condition of holding certain contracts.
Self-assessment vs audit Historically satisfied by contractor self-attestation. Level 1 allows annual self-assessment; Level 2 generally requires a third-party (C3PAO) assessment; Level 3 requires a government-led assessment.
Levels/scope A single set of 110 controls. Three levels — Level 1 (Foundational, 17 controls), Level 2 (Advanced, all 110 NIST 800-171 controls), Level 3 (Expert, 110 plus added NIST 800-172 controls).
Goal Define what a secure environment looks like. Prove that you actually meet those requirements.

NIST SP 800-171: The "What" (The Security Controls)

NIST stands for the "National Institute of Standards and Technology." They are a non-regulatory government agency that creates standards for (among other things) cybersecurity.

NIST Special Publication (SP) 800-171 (currently Revision 2) is a specific document titled "Protecting Controlled Unclassified Information in Nonfederal Systems."

That's it. It's a "cookbook." It's a list of 110 security controls, broken into 14 "families" (like "Access Control," "Incident Response," and "Physical Security").

For years, the DoD has required contractors to self-attest that they are following this "cookbook" via the DFARS 7012 clause. The problem? Many contractors said they were, but weren't. This led to massive data breaches.

The DoD needed a way to verify compliance. That's CMMC.

CMMC: The "How" (The Verification Framework)

CMMC stands for "Cybersecurity Maturity Model Certification." It's the DoD's enforcement and verification program. It's the "audit."

CMMC 2.0 was created to solve the "self-attestation" problem. It takes the NIST "cookbook" and wraps it in an audit framework that says, "We're no longer taking your word for it. You have to prove it."

Here is the direct relationship:

  • CMMC Level 1 ("Foundational"): This requires you to implement 17 of the most basic controls from NIST 800-171.
  • CMMC Level 2 ("Advanced"): This requires you to implement all 110 controls from NIST 800-171.
  • CMMC Level 3 ("Expert"): This requires all 110 from NIST 800-171 plus extra controls from another cookbook (NIST 800-172).

CMMC also defines how you'll be audited:

  • Level 1 allows an annual "Self-Assessment."
  • Level 2 requires a "Third-Party Assessment" by a C3PAO for critical programs.
  • Level 3 requires a "Government-Led Assessment."

The Simple Summary

Think of it like this:

NIST 800-171 is the textbook of 110 things you must do to be secure.

CMMC is the final exam. It's the audit where a proctor (the C3PAO) comes in to prove you actually did the 110 things in the textbook.

You cannot be "CMMC Level 2 compliant" without first implementing all 110 controls of "NIST 800-171." Your entire compliance journey is about one thing: implementing, documenting, and proving that you are living by the 110 controls in the NIST "cookbook."

Ready to Put This Into Practice?

Book a free 30-minute AI Workflow Audit. We'll identify your highest-ROI automation opportunity and show you the exact build plan.

Book Free AI Audit →