Compliance field guide · Keepgrade

Do I need CMMC, NIST SP 800-171 — or both?

NIST SP 800-171 describes the safeguards. CMMC Level 2 adds the Department of Defense program path around those safeguards: scope, assessment, evidence, certification or affirmation, and the contract consequences that can shape source selection.

01 · Start with the distinction

NIST tells you what to safeguard. CMMC Level 2 tells you how the DoD path gets evaluated.

NIST SP 800-171 is the requirements baseline many teams use to design and assess protections for CUI. CMMC Level 2 is the DoD program path around contract applicability, scope, assessment method, evidence, and affirmation or certification.

That makes a NIST implementation or gap assessment valuable preparation, but not a substitute for the CMMC path your solicitation requires. Read both through the lens of the actual information flow, the contract, and the version of the requirements it names.

Overlap without interchangeability
CMMC Level 2 is commonly prepared against the 110 requirements associated with NIST SP 800-171 Rev. 2. Rev. 3 is important planning context, but it should not be presented as a one-to-one replacement for the CMMC Level 2 catalog or outcome.

02 · Side-by-side

Same control conversation. Different decision boundary.

The useful question is not which logo sounds stronger. It is which requirements and program path your contract makes relevant.

Comparison of NIST SP 800-171 and CMMC
DimensionNIST SP 800-171CMMC
The starting pointA NIST requirements publication used to protect CUI in nonfederal systems.A DoD program that turns contract language into a level, scope, assessment, and outcome path.
Level 2 overlapRev. 2 provides the 110-requirement baseline historically associated with CMMC Level 2.Level 2 uses that baseline with CMMC-specific scoping, assessment procedures, evidence, and affirmation or certification rules.
Rev. 3 contextRev. 3 reorganizes the NIST publication and is useful for modernization planning.Rev. 3 is not a drop-in replacement or automatic Level 2 certification crosswalk; keep the contract-required CMMC mapping explicit.
What the buyer seesAn internal implementation record, gap analysis, SSP, or other evidence package — not a CMMC status by itself.A contract-relevant assessment, affirmation or certification artifact, and source-selection condition when the solicitation requires it.

03 · Assessment path

Self-attestation is not a smaller C3PAO assessment.

A self-assessment and self-attestation are an organization’s own annual review and affirmation when the solicitation permits that route. A C3PAO assessment is an independent third-party assessment for the contract-defined CMMC path, with assessor obligations and evidence expectations that do not exist merely because a team used the NIST catalog.

For CMMC Level 2, the solicitation or contract determines whether an annual self-assessment or a triennial C3PAO assessment applies. Do not infer the path from company size alone.

What readiness can do
Organize the boundary, surface gaps, assemble evidence, and clarify the next review. It cannot issue the attestation, replace the C3PAO, or decide contract eligibility.

04 · What CMMC adds

CMMC adds the proof and procurement layer.

The difference matters when a prime is deciding what it can claim, what evidence it must preserve, and what a contracting officer may evaluate. A NIST implementation is part of the work; CMMC defines the program outcome around it.

Independent review
When the contract calls for it, a C3PAO examines the scoped environment against the CMMC assessment requirements. That is a different event from an internal NIST gap review.
Certification artifact
The formal affirmation or certification record is the evidence of the CMMC path’s outcome. A private score, draft SSP, or gap report cannot stand in for it.
Source selection
If the solicitation names CMMC, the required level and status can become part of the government’s eligibility and award evaluation. The solicitation controls the exact consequence.
Read the band as a signal

Foundational, Transitional, and Ready describe preparation posture.

They are not official CMMC levels, a NIST score, or a conversion between frameworks.

05 · Readiness-score mapping

One rubric can orient both frameworks without pretending to certify either.

The public questionnaire provides a readiness signal before formal work begins. Use it to orient a CMMC Level 2 conversation or a NIST SP 800-171 conversation, but keep the selected framework, version, information scope, evidence, and contract path explicit.

06 · Keepgrade’s parallel lanes

Share the work. Keep the claims separate.

Most teams do not have the luxury of finishing one framework before planning the next. Keepgrade keeps common owners, evidence, findings, and remediation visible while preserving the framework and version attached to each workstream.

Lane A

CMMC Level 2 · Rev. 2-aligned preparation
Track the contract scope, 110-requirement baseline, assessment procedures, evidence owners, and the readiness needed for self-attestation or C3PAO review.

Lane B

NIST SP 800-171 Rev. 3 · modernization planning
Map the reorganized NIST structure, identify future-state gaps, and plan changes without labeling Rev. 3 planning as a current CMMC Level 2 certification.

07 · Which one applies?

Let the contract drive the framework decision.

A practical sequence for a small defense prime evaluating a compliance claim:

01
Read the contract first
Identify FCI or CUI, then find the exact CMMC level, NIST language, or flow-down requirement in the solicitation and contract.
02
Draw the real boundary
List the systems, people, facilities, devices, and providers that store, process, or transmit the information in scope.
03
Use a readiness signal
Run the CMMC or NIST readiness questionnaire that matches your lane. Treat the result as preparation, not an official outcome or crosswalk.
04
Preserve both workstreams
Keep shared remediation moving, but route the final evidence and review through the self-attestation or assessment path your contract requires.

The answer is usually in the solicitation.

Confirm current CMMC rule text, NIST publications, and contract language with the authoritative DoD and NIST sources before relying on any compliance claim. This page is educational guidance, not legal advice or a guarantee of security or award eligibility.

The assessment picker is a protected workspace for signed-in teams. The public score is a readiness aid, not a formal CMMC or NIST determination.

08 · Questions teams ask

CMMC vs NIST, without the marketing fog.

Short answers for defense primes sorting out the requirements baseline, the CMMC program path, and what a readiness tool can — and cannot — prove.

Keep researching

Take the next step that matches your buying question.

Go deeper on levels, the NIST guide, partner delivery, or commercial fit — then return to the readiness score when you are ready to quantify the starting point.

Keep the claim precise

Prepare for the path your contract actually names.

Start with a readiness-only signal, then move into the framework-specific workspace when your team is ready to document the boundary and evidence.

Get your readiness score