Skip to content
FioSec Consulting

Frameworks · Government & supply chain

NIST SP 800-171 & CMMC

The bar for handling sensitive government information, and for doing business in its supply chain.

Maintained by
NIST (SP 800-171) and the U.S. Department of Defense (CMMC)
Origin
United States · 800-171 (current Rev 3, 2024); CMMC 2.0
Certifiable?
800-171 itself is self-assessed; CMMC adds tiered, sometimes third-party, certification.

What it is

NIST Special Publication 800-171 is a U.S. standard for protecting Controlled Unclassified Information, the sensitive but unclassified government information that lives on the systems of non-government organizations. If a contractor, supplier, or research partner handles this kind of information, 800-171 defines the security requirements they must meet.

CMMC, the Cybersecurity Maturity Model Certification, is the U.S. Department of Defense’s program for verifying that its contractors actually meet those requirements. Where 800-171 has historically relied on self-attestation, CMMC adds tiered certification, including independent third-party assessment at higher levels, so the DoD can trust that its supply chain is protected before awarding work.

For Canadian organizations, this matters whenever they sit in a U.S. federal or defense supply chain, as a subcontractor, supplier, or research collaborator, where these requirements flow down through contracts.

How it's structured

NIST 800-171 organizes its requirements into control families covering the familiar pillars of security: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. Compliance is measured against these requirements and documented in a System Security Plan with a Plan of Action and Milestones for any gaps.

CMMC 2.0 wraps this in a tiered model. Level 1 (Foundational) covers basic safeguarding of less-sensitive information. Level 2 (Advanced) aligns with the full set of 800-171 requirements and, for many contracts, requires assessment by an accredited third party. Level 3 (Expert) adds further requirements for the most sensitive programs. The control families below summarize the 800-171 backbone shared across these levels.

Access control & authentication

Limit system access to authorized users and devices, and verify identities with strong, multi-factor authentication.

Awareness & training

Ensure personnel are aware of security risks and trained in their responsibilities.

Configuration & integrity

Establish secure baselines, manage changes, and protect systems against malware and flaws through timely updates.

Audit & accountability

Create, protect, and review logs so actions can be traced to individuals and incidents investigated.

Incident response & recovery

Detect, report, and respond to incidents, and maintain the ability to recover affected systems and data.

Media & physical protection

Protect information on media and limit physical access to systems that store or process sensitive information.

Who it's for

These requirements apply to organizations that handle Controlled Unclassified Information for the U.S. government: defense contractors and their subcontractors, suppliers, manufacturers, and research institutions anywhere in the supply chain, including Canadian firms that participate in it.

The driver is contractual. The requirement to meet 800-171, and increasingly to hold the appropriate CMMC level, flows down from the prime contract to every supplier that touches the protected information. If you want to win or keep that work, compliance is a prerequisite, not an option.

For organizations with no U.S. government or defense business, 800-171 is not a requirement, though its control families are a rigorous reference. Outside this supply chain, a foundational framework like NIST CSF or the CIS Controls is the more proportionate choice.

How it compares

800-171 is derived from the broader NIST control catalogue (SP 800-53) and shares its DNA with NIST CSF and the CIS Controls: the same access control, configuration, logging, and incident-response ideas, specified more precisely and made mandatory for this context. A mature CIS- or NIST-based program covers much of the ground 800-171 demands.

CMMC is the assurance layer on top. Where ISO 27001 and SOC 2 provide independent assurance for commercial markets, CMMC provides it for the U.S. defense supply chain. The difference is who requires it and how it is verified, not a wholly different idea of security.

How it maps to a Layered Defence

NIST SP 800-171 / CMMC is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.

Free readiness checklist

How ready are you for NIST SP 800-171 / CMMC?

Answer honestly across the 5 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.

Know your obligation

Scope first.

Do you know whether you handle Controlled Unclassified Information and which CMMC level your contracts require?
Do you have a System Security Plan and a Plan of Action & Milestones for any gaps?

These documents are expected for 800-171 / CMMC.

Access & authentication

The largest control family.

Is access limited to authorized users and enforced with multi-factor authentication?
Is privileged access tightly controlled and separated from everyday accounts?

Configuration & integrity

Hardened, patched, protected.

Are systems built to secure baselines, patched promptly, and protected against malware?

Audit & monitoring

Traceability.

Are logs created, protected, and reviewed so actions can be traced and incidents investigated?

Incident response & media

Reacting and protecting data.

Do you have an incident response capability and the ability to recover affected systems?
Is sensitive information protected on media and disposed of securely?

No email required; scored in your browser, never sent anywhere.

Authoritative source: NIST SP 800-171 (csrc.nist.gov) & CMMC

Explore other frameworks

Need help putting NIST SP 800-171 / CMMC into practice?

FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.