APTSecurity Management

NIST 800-171 and CMMC Level 2: How Controls Map

Cody D. Martin//Updated August 9, 2026

CMMC Level 2 requires the same 110 security requirements as NIST SP 800-171 Rev. 2, across 14 families. The mapping is one to one. What CMMC adds is an assessment and affirmation process, not additional controls, which is why 800-171 work is never wasted.

The shortest accurate answer: CMMC Level 2 is NIST SP 800-171 with an assessment process attached. The 110 practices map one to one with the 110 security requirements in Rev. 2.

That matters practically, because it means 800-171 work is never wasted no matter what happens to the CMMC program itself.

The 14 families

Family Requirements
Access Control 22
Awareness and Training 3
Audit and Accountability 9
Configuration Management 9
Identification and Authentication 11
Incident Response 3
Maintenance 6
Media Protection 9
Personnel Security 2
Physical Protection 6
Risk Assessment 3
Security Assessment 4
System and Communications Protection 16
System and Information Integrity 7

Access Control and System and Communications Protection are over a third of the total between them, and they are where most remediation effort goes.

SPRS scoring, and why it goes negative

The scoring model starts at 110 and subtracts for each requirement not met. Weightings are 5, 3 or 1 depending on impact.

Because there are more than 110 points of possible deductions, your score can be negative, and a large number of companies self assess into the negative on their first honest pass. A score of minus 40 is common and is not a disaster. It is a starting position.

The five point items are worth attacking first, and they cluster around multifactor authentication, boundary protection, flaw remediation, and audit logging.

What CMMC adds

Not controls. Process.

  • Assessment. Self assessment at Level 2 (Self), or third party assessment at Level 2 (C3PAO) when that is required
  • Affirmation. An annual signed statement from a senior official
  • A contractual hook. DFARS 252.204-7021, which makes the level a condition of award

What the July 2026 suspension changed

Only the assessment layer, and only part of it.

Level 2 (C3PAO) and Level 3 assessments are paused. During the suspension a contract may specify Level 1 (Self) or Level 2 (Self) only.

The 110 requirements are untouched. DFARS 252.204-7012 has required NIST SP 800-171 compliance since 2017, independently of CMMC, and that clause was not suspended. So the technical work, the SSP, the POA&M, the SPRS score and the annual affirmation all continue.

Which is the argument for treating this as 800-171 work that CMMC happens to assess, rather than as CMMC work. The framing survives whatever the reform review concludes.

Where people go wrong on the mapping

Assuming a control is met because a tool is deployed. Requirement 3.5.3 wants multifactor for network access to privileged accounts and for remote access. Having MFA on email does not satisfy it.

Reading the requirement without the discussion. NIST SP 800-171A contains the assessment objectives, and they are what an assessor actually evaluates. A requirement often decomposes into four or five objectives, all of which need to be met.

Treating the boundary as an afterthought. Every requirement applies to the systems in scope. Get the boundary wrong and the mapping exercise is built on sand.

There is a free practice lookup covering all 110 with the evidence that satisfies each, if you would rather work through it yourself.

  • NIST 800-171
  • CMMC
  • SPRS
  • Level 2

More on compliance