NIST SP 800-171 is the set of security requirements for protecting controlled unclassified information on contractor systems. DFARS clauses make those requirements part of defense contracts. CMMC is the program that checks whether a contractor meets them, through self-assessments or independent assessments depending on the level a contract specifies.

Status note, reviewed 2026-09-29. On July 13, 2026 the Department of War suspended Phase 2 of CMMC implementation, which had been scheduled for November 2026. During the suspension, contracts may require only CMMC Level 1 (Self) or Level 2 (Self), and the underlying safeguarding and reporting obligations remain in effect. A review of the program was under way and its results had not been published as of the review date above. Details are in what the CMMC Phase 2 suspension changes.

This guide maps how the pieces fit together. It is written for owners, contracts managers and IT leads at small and mid-sized defense suppliers, and it is deliberately conservative about dates: the program has changed several times, so every date below carries its source.

What information does this apply to: FCI or CUI?

Everything in CMMC starts with the kind of information your organization handles for the government.

Federal Contract Information (FCI) is defined in FAR 52.204-21 as "information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments" (FAR 52.204-21, retrieved 2026-09-29). Nearly every federal contractor handles some FCI.

Controlled Unclassified Information (CUI) is a narrower category: information that a law, regulation or government-wide policy requires or permits to be protected with safeguarding or dissemination controls. In defense work, the DFARS term is covered defense information, which includes controlled technical information such as drawings and specifications. CUI is where the heavier requirements apply. See what is CUI? for how to recognize it.

The distinction matters because it decides which requirements apply: FCI alone points to CMMC Level 1; CUI points to Level 2 or above.

What is NIST SP 800-171?

NIST Special Publication 800-171 sets out security requirements for protecting CUI on systems that are not operated by the federal government. It covers areas such as access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.

Which revision applies matters. NIST published Revision 3 in May 2024, organized into 17 families, and marked it as superseding Revision 2 (NIST CSRC, retrieved 2026-09-29). The Department of Defense, however, issued class deviation 2024-O0013 on May 2, 2024, requiring contractors under DFARS 252.204-7012 to comply with Revision 2, which contains 110 requirements, until the deviation is rescinded. The July 2026 suspension memorandum likewise states that the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 (DoW CIO implementation memorandum, 26-P-1023, retrieved 2026-09-29). Check which revision your contract references; for DoD work today, that is almost always Revision 2.

Our NIST SP 800-171 services page describes how implementation work is organized.

Which DFARS clauses put these requirements into contracts?

Several clauses work together. The ones a small supplier most often meets are:

DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. Requires implementing NIST SP 800-171 on systems that handle covered defense information; reporting cyber incidents to DoD at dibnet.dod.mil "within 72 hours of discovery"; preserving images of affected systems "for at least 90 days from the submission of the cyber incident report"; using cloud services that meet security requirements equivalent to the FedRAMP Moderate baseline; and flowing the clause down to subcontractors that handle covered defense information (DFARS 252.204-7012, retrieved 2026-09-29).

DFARS 252.204-7019 and 252.204-7020, NIST SP 800-171 DoD Assessment Requirements. Require a current assessment, not more than three years old, with a summary score posted in the Supplier Performance Risk System (SPRS). A Basic Assessment is a self-assessment scored against the 110 requirements, and the posting includes the date by which any open requirements will be met (DFARS 252.204-7019, retrieved 2026-09-29).

DFARS 252.204-7021 and 252.204-7025, the CMMC clauses. Added by the DFARS CMMC rule published September 10, 2025 and effective November 10, 2025 (Federal Register 2025-17359, retrieved 2026-09-29). 252.204-7025 is the solicitation notice that states the required CMMC level; 252.204-7021 requires the contractor to hold and maintain that status, including annual affirmations by a designated official.

What is CMMC and how do the levels work?

The Cybersecurity Maturity Model Certification program is established in 32 CFR Part 170, published October 15, 2024 and effective December 16, 2024 (Federal Register 2024-22905, retrieved 2026-09-29). CMMC does not create new security requirements so much as verify existing ones.

Level Protects Requirements Assessment type
Level 1 (Self) FCI The 15 basic safeguarding requirements in FAR 52.204-21 Annual self-assessment and affirmation
Level 2 (Self) CUI NIST SP 800-171 Rev 2 (110 requirements) Self-assessment, with affirmation
Level 2 (C3PAO) CUI NIST SP 800-171 Rev 2 (110 requirements) Independent assessment by an authorized third-party assessment organization
Level 3 (DIBCAC) CUI in higher-priority programs Level 2 plus selected enhanced requirements from NIST SP 800-172 Government assessment

For Levels 2 and 3, a contractor that meets the minimum score but has open items may receive a conditional status, which the DFARS rule limits to "a period not to exceed 180 days" to close them.

Current status. The rule planned a four-phase rollout beginning November 10, 2025. Phase 1 is in effect. Phase 2, which would have expanded Level 2 (C3PAO) requirements from November 2026, is suspended; while the suspension lasts, program offices may designate only Level 1 (Self) or Level 2 (Self), and existing requirements for C3PAO or DIBCAC assessments are being removed from solicitations and contracts (DoW CIO implementation memorandum, retrieved 2026-09-29).

What still applies during the Phase 2 suspension?

In short, almost everything that costs effort:

  • NIST SP 800-171 Rev 2 on systems that handle covered defense information.
  • 72-hour incident reporting, image preservation and flowdown under DFARS 252.204-7012.
  • A current SPRS score under DFARS 252.204-7019 and 7020.
  • CMMC Level 1 and Level 2 self-assessments and affirmations where a contract requires them.
  • The possibility of a government-led assessment: the implementation memorandum refers to "select Government-led assessments" during the suspension.

What the suspension paused is the requirement to obtain an independent third-party assessment before award. It did not reduce what must be implemented. An affirmation signed by a company official is a representation to the government about the state of your systems, so the accuracy of a self-assessment matters as much as ever.

Who in the supply chain is affected?

Requirements flow down. A prime contractor that shares FCI or CUI with a subcontractor must flow down the relevant clauses, and the subcontractor then carries the same obligations for that information. Machine shops, engineering firms, IT providers and logistics companies several tiers from the prime can hold covered defense information without ever contracting with DoD directly.

A managed service provider that can access systems containing CUI is also in scope for those systems, which is one reason to ask any IT provider how it secures its own access. In the Aiken and Augusta area, suppliers around the Savannah River Site and Fort Gordon frequently meet these clauses through subcontracts rather than prime awards. Our government contractors page describes the environments we build for.

Where should a contractor start?

A practical order of work, regardless of what happens to the program timeline:

  1. Read your contracts and subcontracts. Find which clauses apply: 52.204-21, 252.204-7012, 7019, 7020, 7021, 7025.
  2. Identify the information. Determine whether you handle FCI only, or CUI as well, and where it arrives from.
  3. Map where it lives. Email, file shares, engineering workstations, cloud storage, backups, personal devices, paper. This defines the systems in scope.
  4. Decide on scope. Protecting a smaller, well-defined environment for CUI is often more practical than bringing an entire company network up to the requirement.
  5. Assess honestly against Rev 2. Score each requirement as met or not met, with evidence.
  6. Write the System Security Plan and a plan of action. The SSP describes how each requirement is met; the plan of action records what is not yet met and when it will be.
  7. Post an accurate SPRS score and keep it current.
  8. Implement, then operate. The requirements describe ongoing practices (log review, patching, access reviews, training, incident response), not a one-time project.

What we do and do not do

Jowers Technology Solutions helps contractors assess their environment against NIST SP 800-171, implement and operate the technical controls, and maintain the documentation that supports a self-assessment. We are not a certified third-party assessment organization and do not issue CMMC certifications or assessment results. No provider can guarantee an assessment outcome; what we can do is help make sure your controls are real and your documentation describes them accurately. See CMMC services.

If a clause has landed in a contract and you are not sure where you stand, request an assessment.