HomeFrameworksInformation Security & PrivacyCMMC/NIST 800-171

Framework  Information Security & Privacy

CMMC/NIST 800-171

The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense (now styled the Department of War) program that verifies defense contractors protect Federal Contract Information and Controlled Unclassified Information.

The program rule at 32 CFR Part 170 took effect December 16, 2024 and the contracting rule in DFARS (48 CFR) took effect November 10, 2025, starting Phase 1. Level 1 is an annual self-assessment against 15 basic requirements.

Level 2 is the 110 requirements of NIST SP 800-171 Revision 2, verified by self-assessment or by a certified third-party assessment organization (C3PAO) depending on the solicitation. Level 3 adds 24 requirements from NIST SP 800-172 and is assessed by the government's DIBCAC. Level 2 certifications last three years with an annual affirmation by a senior official.

Phase 2, which would have made C3PAO Level 2 certification a condition of award for most applicable contracts from November 10, 2026, was suspended on July 13, 2026 pending a 60-day review by a CMMC Reform Task Force. Phase 1 self-assessment requirements, DFARS 252.204-7012, SPRS score submissions and annual affirmations remain in force.

In writing, a contractor needs a System Security Plan describing how each 800-171 requirement is met, policies and procedures for the 14 control families, a plan of action and milestones for gaps, incident response procedures, and records supporting the affirmation.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedSSP policy set v2by name, on record
110 Controls One Trailwith AllyMatter
Cleared, the Modern WayEvery 800-171 policy, acknowledged before the C3PAO arrives
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every cleared employee on record
Who read which version, and when
03
Export the trail for the assessor
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Defense contractors and subcontractors that process, store or transmit Federal Contract Information (Level 1) or Controlled Unclassified Information (Levels 2 and 3) under contracts containing DFARS 252.204-7021. The required level is set in each solicitation and flows down the supply chain.

What the assessor asks to see

System Security Plan with boundary and data flows; CUI inventory and data classification; policies and procedures for each NIST 800-171 family; SPRS score and prior self-assessment; access control, MFA and account management records; configuration baselines; audit log samples; vulnerability scans and patching records; incident response plan and records; awareness training completion; POA&M; external service provider and cloud FedRAMP evidence; the senior official affirmation.

Where the requirement sits: 800-171 3.2.1-3.2.3 awareness and training; 3.12.4 SSP; 800-171A assessment objectives '[a] ... is defined'; 3.3 audit and accountability, 3.14 system monitoring are technical

Levels

Level 1 (FCI): 15 requirements from FAR 52.204-21, annual self-assessment. Level 2 (CUI): 110 requirements from NIST SP 800-171 Rev 2, self-assessment or C3PAO certification as specified in the solicitation, valid three years. Level 3 (highest-risk CUI): Level 2 certification plus 24 NIST SP 800-172 requirements assessed by DIBCAC.

Phase-in and the 2026 suspension

Phase 1 began November 10, 2025 (self-assessments). Phase 2 was scheduled for November 10, 2026 and would have expanded C3PAO Level 2 certification as a condition of award; Phases 3 and 4 were scheduled a year apart after that. On July 13, 2026 the Department suspended Phase 2 and later phases pending a 60-day CMMC Reform Task Force review reporting around mid-September 2026.

Contracting officers were told to remove Phase 2 and 3 requirements from existing agreements by modification. Verify the outcome of the review before planning around a date.

What AllyMatter does here

The policy, procedure and training-record layer of CMMC Level 2 / NIST 800-171. Policies alone score nothing at assessment.

AllyMatter publishes this site.

Assessors

Who assesses CMMC/NIST 800-171

Level 1 and Level 2 (self): the organization's own assessment with senior official affirmation. Level 2 (certification): a C3PAO authorized by the Cyber AB, using certified CMMC assessors. Level 3: the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

Accredited by The Cyber AB (Cybersecurity Maturity Model Certification Accreditation Body), under contract with the Department, authorizes C3PAOs and accredits assessors; DCMA DIBCAC assesses the C3PAOs themselves.

Public register of assessors: https://cyberab.org/Catalog

No firm has claimed a CMMC/NIST 800-171 assessor listing yet. Claim yours →

Consultants

Who helps with CMMC/NIST 800-171

A large ecosystem: Registered Provider Organizations (RPOs) listed on the Cyber AB Marketplace, managed service providers offering enclave solutions, and GRC platforms. They write SSPs and policies, run gap assessments and mock assessments, and manage remediation. Engagements typically run six to eighteen months before a C3PAO assessment.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

TevoraIrvine, CA, USANot yet verified
What they do
Enterprise multi-framework
Who they help
Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. CMMC final rule: key takeaways for defense contractorsLaw firm read of the acquisition rule that puts the CMMC clause in contracts, including affirmations and flow-down to subcontractors.Arnold & Porter
  2. Defense contractors face a new reality: the final 48 CFR rule brings CMMC into federal acquisitionSets out the phase-in, what a self-assessment versus a C3PAO assessment involves, and the SPRS score a contract now requires.BDO

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for CMMC/NIST 800-171

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of CMMC/NIST 800-171 in AllyMatter

Approve the policies CMMC/NIST 800-171 asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.