Skip to main content

Elevate

Questions to Ask Before Selecting a C3PAO

The right C3PAO for a CMMC Level 2 assessment is rarely the one with the most polished proposal. It is the one that answers specific, direct questions clearly, without retreating into generic language the moment a question gets uncomfortable. Most guidance on choosing a C3PAO lists criteria to consider, scope, cost, experience, but a criteria list does not tell you what to actually say on the call. This article is the script: the specific questions worth asking during initial selection, the different questions worth asking again before signing a contract, and what a strong versus a weak answer to each one actually sounds like. Before this call happens, confirming your organization meets the certification requirements a C3PAO expects saves time on both sides, since a scoping conversation goes very differently when the organization already knows its own boundary. Questions to Ask During Initial Selection The first round of conversations with prospective C3PAOs is where an organization narrows a list of candidates to a shortlist. These questions are designed to surface real differences between firms that otherwise sound similar on paper. Scope and Capacity Questions “How many CMMC Level 2 assessments has your team completed in the past twelve months, specifically at our approximate system size and complexity?” A strong answer names a specific number and describes at least one comparable engagement in enough detail to demonstrate it was real. A weak answer cites total firm experience across all assessment types without isolating CMMC Level 2 specifically, or describes engagements in terms too vague to verify. “What is your current assessment capacity, and when would our engagement realistically start?” A strong answer gives an honest, specific timeline, even if that timeline is further out than the organization would prefer. A weak answer promises an immediate start regardless of what was previously said about current workload, which usually means either the firm is overcommitting or the previous capacity answer was not accurate. “Will the same assessors who scope our engagement also conduct the actual assessment?” A strong answer confirms continuity or explains clearly how a handoff between scoping and assessment staff is managed without loss of context. A weak answer is unclear about who actually does the work, which becomes a real problem later if the team conducting the assessment does not understand decisions made during scoping. Assessor Experience and Team Composition Questions “Who specifically will be assigned to our assessment, and what is their individual CMMC assessment experience?” A strong answer names actual people and their track record, not just the firm’s aggregate credentials. A weak answer describes only the firm’s overall accreditation status without committing to specific personnel, which leaves the organization unable to evaluate who will actually be in the room. “Has any assessor on our proposed team had a finding overturned or successfully appealed in a past engagement, and if so, what happened?” A strong answer engages with this question directly, since every experienced assessor has encountered disputed findings at some point, and a thoughtful account of how one was resolved is a positive signal, not a red flag. A weak answer either deflects entirely or claims a flawless record with no disputed findings ever, which is a less credible claim than an honest account of a resolved disagreement. Timeline and Process Questions “Walk us through your assessment methodology step by step, from kickoff to final report.” A strong answer describes a specific, repeatable process with clear phases and realistic durations for each. A weak answer stays high-level and generic, unable to describe what actually happens in a given week of the engagement. “What is your typical timeline from assessment completion to final certification submission, and what has caused delays in past engagements?” A strong answer gives a realistic range and is candid about what has caused past delays, since delays happen in real engagements and a firm that claims otherwise is not being fully honest. A weak answer promises an unrealistically fast timeline with no acknowledgment that anything has ever gone differently than planned. Cost Structure Questions “What is included in your quoted price, and what would trigger an additional charge?” A strong answer itemizes clearly and names specific scenarios that would increase cost, such as scope changes discovered mid-assessment. A weak answer gives a single number with no breakdown, leaving the organization unable to budget for likely scenarios that would change the final cost. “How do you price a re-assessment if we do not pass on the first attempt?” A strong answer has a clear, pre-existing policy for this scenario. A weak answer has never considered this question, which suggests either overconfidence about first-attempt outcomes or a lack of experience with engagements that did not go smoothly. Independence and Methodology Questions “Does your firm, or any assessor on our proposed team, have any prior consulting or remediation relationship with our organization or with any affiliated entity?” A strong answer is direct and specific, disclosing any prior relationship and explaining how independence is preserved despite it, or confirming clearly that no such relationship exists. A weak answer is evasive about this question or treats it as unimportant, which is a serious concern given how much a CMMC assessment’s credibility depends on genuine assessor independence. “How do you handle a situation where our documentation is technically sufficient but your team believes the underlying control is not actually operating effectively?” A strong answer describes a real methodology for evaluating operational effectiveness beyond paper compliance, since a competent assessor is trained to distinguish a control that exists on paper from one that genuinely functions. A weak answer suggests the firm evaluates documentation alone without probing whether controls actually operate as described, which is a much lower bar than what a rigorous CMMC Level 2 assessment should apply. Logistics and On-Site Questions “Will the assessment be conducted on-site, remotely, or in a hybrid format, and how is that decision made?” A strong answer explains the firm’s actual methodology for this decision, tied to system complexity and physical security scope, rather

FAR Part 40: The Class Deviation Making CMMC Suspension Official

FAR Part 40 is where the CMMC Phase 2 suspension stopped being a policy statement and became a binding term in actual defense contracts. On September 3, 2026, the Office of the Assistant Secretary of War issued DARS Tracking Number 2026-O0025, Revision 3, a class deviation implementing the Revolutionary FAR Overhaul’s Part 40, Information Security and Supply Chain Security, along with the corresponding DFARS Part 240. Buried inside this deviation, alongside several unrelated supply chain security provisions, is the specific instruction that turns the Department of War CIO’s July suspension memo into something contracting officers are now required to act on in your actual solicitations and contracts. This article explains what this class deviation actually requires contracting officers to do, what it confirms remains unchanged, and what a defense contractor should expect to see happen to its own contracts as a direct result. What DARS 2026-O0025, Revision 3 Actually Is A class deviation is not a policy announcement. It is a formal instruction that authorizes and directs contracting officers to depart from the codified FAR or DFARS text and use different, specified language instead, effective immediately upon issuance. This particular deviation revises and supersedes its own prior version, Revision 2, which had been issued on July 16, 2026, meaning this is already the third iteration of this specific instrument in under two months. The Regulatory Chain From CIO Memo to Binding Deviation The Department of War Chief Information Officer’s memorandum suspending the advancement to CMMC Phase 2, dated July 13, 2026, announced the policy: program managers could require only CMMC Level 1 (Self) or Level 2 (Self) assessments, the Phase 2 third-party assessment transition was suspended, and baseline compliance with NIST SP 800-171 Revision 2 remained required. That memo, on its own, directed program managers and requiring activities. This class deviation is the document that formally authorizes contracting officers to depart from the codified regulatory text to actually implement that direction inside solicitations and contracts. The original suspension explained covers what the policy itself changed; this deviation is the mechanism that makes it enforceable contract language rather than internal guidance. Why This Is Already on Its Third Revision A class deviation reaching its third revision in under two months signals that the underlying policy area is still actively being refined, not that anything about the suspension itself is in doubt. This revision specifically implements several statutory requirements and corrects definitions, including fixes to the definitions of covered lobbyist and Chinese military company used elsewhere in the same Part 40 text. Contractors should treat a class deviation with an active revision history as a live document to monitor, not a one-time notice to file away, since a fourth revision addressing further corrections or statutory updates is a reasonable expectation given this pace. Reading a Class Deviation Correctly A class deviation is directive to contracting officers, not directly to contractors, which is a distinction worth understanding before drawing conclusions from one. It tells a contracting officer to use specific revised text in place of the codified FAR or DFARS provisions; it does not itself amend a contractor’s existing contract. The actual change to a contractor’s situation happens when a contracting officer acts on the deviation, through a solicitation amendment or a contract modification, which is why the timing questions addressed below matter as much as the deviation’s existence itself. Reading a class deviation and assuming it immediately and automatically changes every affected contract’s terms is a common and understandable misreading of how this instrument actually works. What Contracting Officers Are Now Required to Do The operational core of this deviation, for CMMC purposes, is a specific set of instructions directing contracting officers to take concrete action on solicitations and contracts already in progress. Amending Active Solicitations Contracting officers must collaborate with requiring activities to remove or revise CMMC requirements in new and existing solicitations in accordance with the CIO’s suspension memo. Program managers and requiring activities are required to initiate the amendments, provide them to the cognizant contracting officer, and contracting officers must then issue the corresponding solicitation amendments as soon as practicable. A contractor with a proposal currently in evaluation against a solicitation that still references Phase 2 CMMC requirements should expect an amendment removing or revising that language, rather than assuming the original solicitation text controls simply because it predates this deviation. Modifying Existing Contracts For contracts already awarded that contain Phase 2 CMMC requirements, this deviation requires contracting officers to remove them through a modification, either prior to the exercise of the next option period or through the next scheduled administrative modification, whichever comes first in the contract’s normal cycle. This means a contractor should not expect an immediate, out-of-cycle modification to every affected contract. The removal is tied to the contract’s existing administrative rhythm, which means the timing varies considerably depending on where a given contract sits in its option period or modification schedule. Contract situation What triggers the modification Realistic timing Contract nearing an option period exercise The option period exercise itself Weeks to a few months Contract with a scheduled administrative modification already planned That scheduled modification Depends on the existing schedule Contract with neither event imminent Whichever event happens first Potentially well over a year New solicitation not yet awarded Direct amendment, not a modification As soon as practicable per the deviation The pattern in this table matters for planning: a contractor should not expect uniform timing across a portfolio of contracts, and a contract with no option period or administrative modification on the near-term horizon may carry Phase 2 language in its official file for a considerable period even though the requirement is not being enforced. This administrative lag is normal under the deviation’s own terms and is not evidence that the suspension is not actually in effect. The Baseline That Does Not Move Consistent with the underlying CIO memo, this deviation reaffirms that baseline compliance with NIST SP 800-171 Revision 2 remains required through the clause at DFARS 252.204-7012, and that CMMC

CUI Compliance: The 2026 Rules Every Federal Contractor Faces

CUI compliance used to be a defense-contractor problem. In 2026 it stopped being one. A federal contract cybersecurity case closed in June 2026 with a $507,144 False Claims Act settlement tied to unmet safeguarding requirements, and two parallel regulatory moves now push controlled unclassified information obligations toward nearly every federal contractor and subcontractor. If your organization touches federal data of any kind, the question is no longer whether CUI compliance applies to you, but how soon you have to prove it. This article explains what changed in 2026, what agencies are now required to pass down to you in contracts, and the concrete steps that separate a defensible CUI program from a paper one. Why CUI Compliance Changed in 2026 For most of the last decade, controlled unclassified information lived in a strange gap. The government created the category in 2010, wrote the rules for agencies, and told defense contractors to protect it through a single Defense Federal Acquisition Regulation Supplement clause. Civilian-agency contractors had no equivalent obligation. That gap is closing on two fronts at once. The Agency Side: ISOO Notice 2026-07 On September 2, 2026, the Information Security Oversight Office issued ISOO Notice 2026-07, refreshing how every federal agency must run its CUI program. The notice consolidates and updates the required elements agencies must implement, from designation and marking through decontrol, misuse reporting, and annual self-inspection. It rescinds older guidance, including the 2020 notice that governed program implementation deadlines. The part that matters to you sits in the notice’s contract requirements. Agencies entering any contract that requires access to controlled unclassified information must, at a minimum, give the prime contractor specific guidance on a defined list of items. That list is effectively a preview of what will land in your contracts, and it is worth reading as a checklist rather than as background. The Contractor Side: The FAR CUI Rule The second front is the Federal Acquisition Regulation itself. The FAR CUI rule, formally FAR Case 2017-016, was first proposed in January 2025 and re-proposed on June 23, 2026 as part of the Revolutionary FAR Overhaul. The comment period closed on July 23, 2026 with 96 comments, and the rule now awaits finalization. Industry observers expect it to begin appearing in contracts before the end of 2026, though as a proposed rule its terms can still change. The rule would extend CUI safeguarding and incident reporting to nearly every federal contractor and subcontractor, not just defense suppliers. It relocates these obligations into the expanded FAR Part 40 and introduces a standard form the agency completes to identify the CUI in a given contract. The Cost of Getting It Wrong Enforcement is not theoretical. In June 2026, a contractor resolved False Claims Act allegations involving Navy contract cybersecurity requirements for $507,144, in a matter that reportedly involved a Defense Contract Management Agency assessment score of negative 170 after alleged noncompliance with required controls. The False Claims Act exposure attaches to the representations a contractor makes about its security posture, which means a weak or inaccurate CUI program is not only an operational risk but a financial and legal one. What the FAR CUI Rule Requires The proposed rule builds a single, uniform mechanism for communicating and enforcing CUI obligations across federal contracts. The table below summarizes the core requirements as proposed in the June 2026 version. Requirement What it means for you Source mechanism NIST SP 800-171 Rev 3 Meet the current revision of the security requirements for CUI in nonfederal systems FAR 52.240-7 clause 72-hour incident reporting Report a suspected or confirmed CUI incident within 72 hours of discovery FAR 52.240-7 clause Subcontractor flowdown Pass safeguarding and reporting requirements to subs that will receive CUI FAR 52.240-7 clause CUI identification Receive an agency-completed Standard Form identifying the CUI in the contract SF XXX, CUI Requirements Records preservation Preserve information related to a CUI incident for a defined retention period FAR 52.240-7 clause The single most consequential line in that table is the move to NIST SP 800-171 Revision 3. Defense contractors have operated under Revision 2 through the existing DFARS clause, so the shift to Revision 3 is a real delta in control expectations, not a rename. For civilian-agency contractors who have never lived under a cybersecurity clause at all, the entire framework is new. Either way, the practical work is the same: your information systems that store, process, or transmit CUI have to meet a named control set, and you have to be able to show it. The 72-Hour Clock The June 2026 version proposes a 72-hour window to report a suspected or confirmed CUI incident, a change from the 8-hour requirement in the January 2025 version. Seventy-two hours sounds generous until you consider what has to happen inside it: detection, triage, a preliminary determination that CUI was involved, and a report that contains the required data elements. Organizations that have never run this drill discover during a real incident that the clock starts at discovery, not at the moment they finish investigating. Flowdown Is Now Your Responsibility The rule requires prime contractors to flow safeguarding and incident-notification requirements down to subcontractors that will receive CUI. This is where many programs break. A prime can hold an excellent internal posture and still carry unmanaged risk through a sub that never received, acknowledged, or implemented the requirements. The obligations that primes and subs must meet to secure CUI are not a clause you paste once; they are a supplier-management process you have to be able to evidence. What Agencies Must Pass Down in Contracts ISOO Notice 2026-07 lists the specific guidance an agency must provide to a prime contractor for any contract requiring CUI access. Read this as the map of what your next CUI-bearing contract will ask of you. Contract element What you will need to operate Identification and marking A way to recognize government-furnished CUI and mark contractor-developed CUI correctly Safeguarding and access Controls limiting CUI to authorized holders, at rest and in transit Training

SPRS Score Calculator: Score Yourself Against All 110 Controls

A SPRS score calculator lets a defense contractor estimate where it stands against all 110 security requirements before it submits an official self-assessment, which is the difference between walking into that submission informed and walking in blind. The score matters because it is not a private diagnostic: it is submitted to the Supplier Performance Risk System, or SPRS, and a current score is a condition of eligibility for defense contracts. This guide explains how the scoring works, what drags a score below zero, and the path from a raw starting score to a defensible 110. The reason to estimate your score before the formal submission is that the number carries real consequences, and understanding how it is built lets you improve it deliberately rather than hope. The scoring method is fixed and public, so a calculator simply applies it to your current state, turning a wall of 110 requirements into a single number you can act on and a prioritized list of what is costing you the most points. How SPRS Scoring Works SPRS scoring starts from a perfect score of 110 and subtracts points for each of the 110 NIST 800-171 requirements that is not fully implemented. What makes the method more than simple counting is that not every requirement is worth the same: each unmet requirement subtracts a weighted value based on how much risk its absence creates. The table sets out the three weights. Point value What its absence reflects Effect on the score 5 points A requirement whose absence creates significant risk of exploitation or exfiltration Largest deduction, so these are the highest priority to fix 3 points A requirement whose absence has a specific, confined effect Moderate deduction 1 point A requirement whose absence has a limited or indirect effect Smallest deduction The weighting is the single most important thing to understand about the score, because it means two organizations missing the same number of requirements can have very different scores depending on which ones they miss. A contractor missing a handful of five-point requirements is in a worse position than one missing many one-point requirements, even though the second has more gaps overall. This scoring is defined in the DoD Assessment Methodology, version 1.2.1, and is codified in the regulation at 32 CFR 170.24, and it is unaffected by the pause on third-party assessments. What Drags a Score Negative A SPRS score can fall below zero, which surprises contractors who assume a self-assessment cannot produce a negative number. It happens because the deductions are cumulative and unbounded on the downside: there is no floor that stops the subtraction, so an organization that has not yet implemented many of the higher-weighted requirements can easily score well into the negatives. A negative score is not a scoring error; it is an accurate signal that foundational requirements are not yet in place. What drives a score down fastest is unmet five-point requirements, since each removes five times what a one-point gap does, so the path out of the negatives runs through them first. Two requirements are treated differently from all the others: multifactor authentication and the use of FIPS-validated cryptography are the only two that allow partial credit, so partial progress on them reduces the deduction rather than counting as a total miss. Every other requirement is scored as either fully met or not met, with no middle ground, which is why honest self-scoring matters: claiming partial credit where the method does not allow it produces a number that will not survive scrutiny. The Path From a Raw Score to 110 The path from a raw score to 110 is a prioritization exercise, and the weighting hands you the priority order. Remediating the unmet five-point requirements first recovers the most points for the effort, then the three-point requirements, then the one-point ones, so a rational plan works down the weights rather than through the requirements in numerical order. This is the logic behind a structured CMMC readiness roadmap that prioritizes gaps rather than treating every gap as equal. Reaching a true 110 means fully implementing all 110 requirements, which is the goal, but the score also has an interim role: requirements that are not yet met can be captured in a plan of action and milestones while remediation proceeds, so the score reflects genuine progress over time. The deeper mechanics of reaching and defending the perfect score are covered in the SPRS score and perfect 110 guide, and the sequencing over a realistic period is laid out in a 12-month CMMC remediation and audit-prep timeline. How to Use a SPRS Score Calculator A SPRS score calculator applies the scoring method to your current state, so using one means honestly marking each of the 110 requirements as met or not met, and for the two partial-credit requirements, marking the degree of implementation. The calculator then applies the weights and returns an estimated score along with the gaps that are costing the most points. Its value is speed and clarity: it converts a self-assessment that would otherwise take spreadsheets and cross-referencing into a number and a prioritized list in one pass. The important caveat is that a calculator produces an estimate, not an official SPRS score or any form of certification. The official score is the one an organization determines through a complete self-assessment and submits to SPRS, and only the organization can stand behind that determination. A calculator is a planning and prioritization aid that tells you where you stand and what to fix first, which is exactly what you need before committing to the formal submission. Used that way, it removes the guesswork from a process that has real contractual stakes. The handoff from an estimate to an official score is straightforward once the estimate has done its job. The estimate identifies the gaps and the priority order; remediation closes the gaps, with documentation captured as each control is implemented; the organization then performs a complete self-assessment against the fully implemented state and submits that score

DFARS 7012 Compliance: What the Clause Requires of Contractors

DFARS 7012 compliance has been the baseline expectation for defense contractors handling sensitive information for years, and yet the clause is regularly misread as a single requirement when it is really several distinct obligations bundled together. DFARS clause 252.204-7012 requires a contractor to safeguard covered defense information, to report cyber incidents quickly, to ensure any cloud it uses meets a specific standard, and to pass the same obligations down to its subcontractors. Missing any one of these is a compliance gap. This guide walks through what the clause actually requires, how each obligation works, and how it all connects to CMMC. The reason the clause matters so much is that it is the contractual hook for defense cybersecurity. It is where the requirement to implement a security standard becomes a binding term of your contract rather than a recommendation, and it is the mechanism that has obliged contractors to protect controlled unclassified information since well before CMMC arrived. Understanding it is the foundation for understanding everything that has been built on top of it. What DFARS 7012 Requires The clause sets out several related obligations, and treating them as a checklist rather than a single duty is the key to genuine compliance. Each one stands on its own, and an assessor or a contracting officer can hold you to any of them independently. The Adequate Security Requirement The core obligation is to provide adequate security for covered defense information on covered contractor information systems, and the clause defines adequate security as implementing the requirements of NIST SP 800-171. This is the safeguarding half of the clause: the 110 requirements of the standard are not optional good practice under DFARS 7012, they are the contractual definition of adequate security. A contractor that has not implemented 800-171 has not met the clause, which is why the standard and the clause are so tightly bound together. Working through the standard is the subject of the NIST 800-171 compliance checklist. Cyber Incident Reporting Within 72 Hours The clause also imposes a strict reporting duty. When a contractor discovers a cyber incident affecting a covered system or the covered defense information on it, it must report the incident to the Department of War within 72 hours of discovery, through the DIBNet portal. The obligation does not end with the report: the clause requires preserving and protecting images of the affected systems so evidence is available, commonly for a defined retention period, submitting any malicious software discovered, and providing the access needed for a forensic review. Because the clock runs from discovery rather than resolution, this is one of the obligations most likely to catch an unprepared contractor, and it is covered in depth in the guide to CMMC incident response. Cloud Service Provider Equivalency If a contractor uses an external cloud service to store, process, or transmit covered defense information, DFARS 7012 requires that cloud to meet security requirements equivalent to the FedRAMP Moderate baseline. The operative standard for the cloud is that FedRAMP Moderate equivalency, measured against the FedRAMP Moderate control set rather than against 800-171 directly, and it is demonstrated through a third-party assessment by a 3PAO that produces a body of evidence covering that control set. This is a distinct obligation that stacks with your own implementation of 800-171 rather than replacing it: the cloud must reach its equivalency, and you must still meet your contractor requirements. The detail of how that equivalency is established is covered in the guide to FedRAMP equivalency. Flowdown to Subcontractors Finally, the clause must flow down. A contractor is required to include the substance of DFARS 7012 in subcontracts where subcontractors will handle covered defense information, which means your compliance depends partly on theirs. This flowdown is easy to overlook and consequential when it is, because an incident or a gap in a subcontractor’s environment can become your problem when the covered defense information is yours. Managing the clause therefore means managing your supply chain, not just your own systems. How DFARS 7012 Connects to CMMC DFARS 7012 and CMMC are closely related but do different jobs, and understanding the relationship prevents a common confusion. DFARS 7012 requires you to implement 800-171 and to attest to that implementation yourself, historically on trust. CMMC, applied through a separate clause, adds the verification layer that confirms the self-attestation is real, assigning a certification level based on an assessment rather than relying on the contractor’s word alone. In other words, DFARS 7012 established the obligation and the self-attestation, and CMMC adds the assessment teeth. The security work is the same under both, because both rest on 800-171, but the accountability differs. For a fuller treatment of how the standard and the verification framework relate, the guide to NIST 800-171 versus CMMC draws the distinction in detail. The practical point for a contractor is that DFARS 7012 compliance is the durable foundation, and CMMC is the verification that increasingly sits on top of it. DFARS 7012 Compliance Under the Current Suspension The 2026 suspension of third-party CMMC assessment has led some contractors to relax, and where DFARS 7012 is concerned that is a mistake. DFARS 7012 is a contractual clause in your existing contracts, not a step in the CMMC certification process, so it is entirely unaffected by the suspension. The duty to safeguard covered defense information, the 72-hour reporting obligation, the cloud equivalency requirement, and the flowdown to subcontractors all remain fully in force today. The suspension paused the third-party verification layer, but it did nothing to the clause that underlies it. A contractor can be correct that its CMMC certification assessment is on hold and still owe every obligation in DFARS 7012, including a 72-hour incident report the moment an incident is discovered. If anything, the suspension makes DFARS 7012 compliance more prominent, because it is the live, enforceable cybersecurity obligation in your contracts while the certification layer waits. What DFARS 7012 Compliance Requires of You in Practice In practical terms, DFARS 7012 compliance comes down to

NIST 800-171 vs CMMC: Where the Frameworks Split and Overlap

The NIST 800-171 vs CMMC question usually starts from a misunderstanding, because the two are not competing frameworks you choose between; one is the security standard and the other is the mechanism that verifies you meet it. NIST SP 800-171 is the set of requirements for protecting controlled unclassified information, and CMMC is the framework that confirms a contractor has actually implemented them. Treating them as rivals, or as interchangeable, leads to the wrong preparation. This guide compares the two directly: where they overlap in controls, where CMMC adds assessment teeth, and which obligations actually apply to your contracts. The relationship is easiest to hold onto with a simple distinction. NIST 800-171 is the ruler, the standard that defines what good looks like, and CMMC is the act of measuring against it and certifying the result. For years, contractors measured themselves against 800-171 and attested to their own compliance; CMMC changes who does the measuring and how much it can be trusted. Understanding that shift is the whole point of comparing them. NIST 800-171 vs CMMC: The Core Relationship NIST SP 800-171 is a security standard published by NIST, containing the 110 requirements a nonfederal organization must implement to protect controlled unclassified information. It has been contractually required for defense contractors through DFARS clause 252.204-7012, which obliges a contractor to implement the standard and to attest to that implementation itself. For years, that self-attestation was the entire compliance story: you assessed yourself against 800-171 and reported the result. CMMC, the Cybersecurity Maturity Model Certification, is the framework that sits on top of 800-171 to verify that self-attestation is real. It does not replace the standard; it assesses compliance with it and assigns a level of certification based on the result. The two therefore operate at different layers: 800-171 defines the controls, and CMMC defines how compliance with those controls is assessed and confirmed. NIST 800-171 CMMC What it is The security standard, with 110 requirements for protecting CUI The framework that verifies compliance with that standard What it establishes The controls you must implement The assessment level and how compliance is confirmed How compliance is shown Self-attestation Assessment by level, self or third-party, with third-party currently paused Contract clause DFARS 252.204-7012 DFARS 252.204-7021, when included The table shows why the comparison so often confuses people: the two are not alternatives on the same axis but two layers of the same obligation. You do not choose 800-171 or CMMC; you implement 800-171 and CMMC is how your implementation is verified. That is why the technical work of the two is identical at Level 2 while the accountability is very different. Where They Overlap: The Shared Control Set The overlap is almost total at the level that matters most. CMMC Level 2 is built on exactly the 110 requirements of NIST SP 800-171 Revision 2, so meeting CMMC Level 2 controls and implementing 800-171 are the same technical exercise. There is no separate CMMC control set to learn at Level 2; the model adopts the standard wholesale. A contractor that has genuinely implemented 800-171 has, by definition, implemented the CMMC Level 2 controls. This is the single most important thing to understand about the relationship, because it means the security work does not double when CMMC applies. The controls you build for 800-171 are the controls CMMC assesses. What CMMC adds is not more controls but more accountability, which is where the two frameworks diverge. Working through the shared control set is the subject of the NIST 800-171 compliance checklist, which applies equally to CMMC Level 2 preparation. Where They Split: Assessment and Verification The split is entirely about verification. Under 800-171 and DFARS 252.204-7012, compliance was self-attested: you assessed yourself and reported a score, and that representation was largely taken on trust unless the government chose to review it. CMMC adds the teeth that self-attestation lacked by defining assessment levels and, for higher assurance, requiring independent verification rather than self-report. This is the “assessment teeth” the comparison is really about: the same controls, but a stronger mechanism for confirming they are in place. The CMMC Levels CMMC expresses its verification in levels of increasing rigor. Level 1 addresses Federal Contract Information and maps to the basic safeguarding requirements of FAR 52.204-21, verified by self-assessment. Level 2 addresses controlled unclassified information and adopts the 110 requirements of NIST SP 800-171 Revision 2. Level 3 adds enhanced requirements drawn from NIST SP 800-172 for the most sensitive programs. The level that applies to you depends on the type of information your contract involves, a distinction explored in the guide to FCI versus CUI and when Level 2 is mandatory. The Suspension and Its Effect The teeth are, at this moment, partly retracted. Under the 2026 suspension of third-party certification assessment, the independent verification that most distinguishes CMMC from plain 800-171 self-attestation is paused, and self-assessment is the live requirement. This does not collapse the two frameworks back into one, because the CMMC structure and its obligations remain, but it does mean that in practice the current difference between meeting 800-171 and meeting CMMC Level 2 is narrower than it will be when third-party assessment resumes. The standard and the self-attestation duty are fully in force throughout; it is the third-party layer that is on hold. Which Obligations Apply to Your Contracts The practical question is not which framework is better but which obligations your specific contracts impose, and that is answered by your contract clauses rather than by the frameworks in the abstract. DFARS 252.204-7012 applies when you handle controlled unclassified information and obliges you to implement 800-171 and report cyber incidents. CMMC applies through DFARS clause 252.204-7021 when that clause is included in your contract, at the level the contract specifies. The presence and level of that clause, not a general sense of the frameworks, determine what you actually owe. For most contractors handling CUI today, the live obligation is to implement 800-171 and to self-assess against it, with CMMC certification

NIST 800-171 Compliance Checklist: All 14 Control Families

A NIST 800-171 compliance checklist is most useful when it follows the standard’s own structure, because NIST SP 800-171 organizes its 110 requirements into 14 control families, and an assessment works through them family by family. Treating compliance as one undifferentiated list of 110 items is how contractors lose track of where they stand; treating it as 14 families, each with a purpose and a set of evidence, is how they stay oriented. This checklist walks all 14 families, what each one covers, and the evidence each needs before an assessment. The value of the family view is that it turns an overwhelming standard into a manageable map. Each family groups related requirements around a single security objective, so you can assess your posture one objective at a time and know exactly what evidence an assessor will expect for each. Used before an assessment, the checklist tells you not just whether a control exists but whether you can prove it, which is the distinction that decides your score. The 14 NIST 800-171 Control Families The table below lists all 14 families in the order the standard presents them, with the objective each addresses and the kind of evidence that demonstrates it. It is the fastest way to see the whole standard at a glance and to identify which families are strongest and weakest in your environment. Control family What it covers Key evidence to keep 3.1 Access Control Who and what can access systems and controlled unclassified information Access control policy, account and privilege lists, least-privilege configuration 3.2 Awareness and Training Security awareness and role-based training for users Training completion records, awareness materials 3.3 Audit and Accountability Logging activity and reviewing it Audit logs, log-review records, retention settings 3.4 Configuration Management Secure, controlled baselines and change control Baseline configurations, change records, approved-software lists 3.5 Identification and Authentication Verifying the identity of users and devices Multifactor authentication configuration, authentication policy 3.6 Incident Response Detecting, handling, and reporting incidents Incident response plan, incident logs, test records 3.7 Maintenance Performing and controlling system maintenance Maintenance logs, maintenance-tool control records 3.8 Media Protection Protecting and sanitizing media that holds CUI Media handling policy, sanitization and disposal records 3.9 Personnel Security Screening personnel and managing access on changes Screening records, access-removal-on-termination records 3.10 Physical Protection Controlling physical access to systems and facilities Physical access logs, visitor records, facility controls 3.11 Risk Assessment Identifying and assessing risk, including vulnerabilities Risk assessments, vulnerability scan records 3.12 Security Assessment Assessing controls and planning remediation System Security Plan, Plan of Action and Milestones 3.13 System and Communications Protection Protecting data in transit and system boundaries FIPS-validated encryption configuration, boundary protection records 3.14 System and Information Integrity Finding and fixing flaws and malicious code Patch and update records, malware protection, monitoring records The table is the map, but the work is in the evidence column, because that is what an assessment actually examines. A family where the controls are implemented but the evidence is thin will not score as well as its reality deserves, so the checklist is best used to test each family twice: once for whether the control is in place, and once for whether you can prove it. Evidence Each Family Needs Walking the families in related groups makes the evidence expectations clearer than reading them in isolation. The access and identity families, Access Control and Identification and Authentication, together govern who reaches your systems, and their evidence is largely configuration and policy: account and privilege records, least-privilege settings, and the multifactor authentication configuration that a heavily weighted requirement depends on. Awareness and Training sits alongside them, evidenced by the records showing your people were actually trained. The configuration and maintenance families, Configuration Management and Maintenance, govern how your systems are built and kept, and their evidence is baselines, change records, and maintenance logs that show control rather than ad hoc administration. The media, physical, and personnel families, Media Protection, Physical Protection, and Personnel Security, protect controlled unclassified information from physical and human exposure, evidenced by handling and sanitization records, physical access and visitor logs, and personnel screening and access-removal records. The monitoring and integrity families, Audit and Accountability and System and Information Integrity, are where many assessments find gaps, because collecting logs and deploying protection is only half the requirement; the evidence has to show the logs are reviewed and the flaws are remediated. Incident Response and Risk Assessment cover detecting and anticipating problems, evidenced by an incident response plan with test records and by risk assessments and vulnerability scans. Finally, System and Communications Protection and Security Assessment protect your data and document your posture, evidenced by FIPS-validated encryption configuration and boundary controls on one side and your System Security Plan and Plan of Action and Milestones on the other. For the incident response family specifically, the requirements and their evidence are covered in depth in the guide to CMMC incident response. How to Use This NIST 800-171 Compliance Checklist Before an Assessment The checklist earns its keep when you run it as a two-pass exercise rather than a single tick-through. On the first pass, go family by family and mark honestly whether each requirement is implemented, resisting the urge to round up a partial control to a complete one. On the second pass, go back through and ask, for each requirement you marked as implemented, whether you have the evidence to prove it, because the assessment scores demonstrable implementation and treats an unprovable control as absent. What emerges from those two passes is a prioritized list of gaps, and that list is the input to the rest of your preparation. Turning it into a scored picture and a remediation plan is the work of a CMMC gap assessment, and understanding how the families are scored, including the weighting that makes some gaps costlier than others, is covered in the guide to the NIST 800-171 assessment. Placing the whole effort in context, from checklist to assessment, is what a CMMC readiness assessment does. This 800-171

DFARS Compliance Checklist: Clauses, Evidence, and Deadlines

DFARS compliance is not a single requirement but a set of specific contract clauses, and for a defense supplier the difference between meeting them and missing one can be the difference between winning an award and being ruled ineligible for it. The clauses that matter most for cybersecurity are a small, related group, each with its own obligations, evidence, and deadlines, and some of them gate your eligibility to compete at all. This checklist walks the clauses that matter, the evidence each requires, and the traps that quietly stall contract awards. The value of a DFARS compliance checklist is that it turns a vague sense of obligation into a concrete list you can verify against your contracts and your records. Each clause either applies to a given contract or it does not, and where it applies, it demands specific, evidenceable things. Working through them one by one is how a supplier moves from hoping it is compliant to knowing it is. The DFARS Clauses That Matter Four DFARS clauses carry the cybersecurity obligations that most affect defense suppliers, and they work together: one sets the security standard and reporting duty, two govern the assessment and its posting to a government system, and one adds the certification requirement. The table below is the fastest way to see the whole cluster at once. DFARS clause What it requires What you must have 252.204-7012 Safeguard covered defense information and report cyber incidents NIST 800-171 implemented, a working incident reporting process 252.204-7019 A current NIST 800-171 assessment score in SPRS to be eligible for award A posted Basic assessment score, kept current 252.204-7020 Maintain the assessment, allow government assessment, and flow the requirement down A current SPRS score and the clause in relevant subcontracts 252.204-7021 Meet the CMMC level specified in the contract The required CMMC status, with third-party verification currently paused The table shows why these clauses cannot be treated in isolation: the security work under 252.204-7012 produces the score that 252.204-7019 requires you to post before award, which 252.204-7020 requires you to keep current, and which 252.204-7021 will eventually require to be independently verified. They are four views of one obligation, and a gap in any of them is a gap in your DFARS compliance. What Each Clause Requires Understanding the evidence behind each clause is what turns the table into an actionable checklist, because each clause asks for something specific and provable. DFARS 252.204-7012 This is the foundational clause, requiring adequate security for covered defense information by implementing NIST SP 800-171, and rapid reporting of cyber incidents to the Department of War within 72 hours of discovery. Its evidence is your implemented controls, your documentation, and a reporting process you can execute on short notice. Because it is the most substantial of the four, it is covered in depth in the guide to DFARS 7012 compliance. DFARS 252.204-7019 This clause is the one that most directly affects your ability to win work, because it requires that an offeror have a current NIST 800-171 assessment score posted in the Supplier Performance Risk System before a contract can be awarded. A score that is missing or out of date can make you ineligible, regardless of how good your actual security is, so the evidence here is simply a current, posted assessment score. The score itself comes from the assessment covered in the guide to the NIST 800-171 assessment. DFARS 252.204-7020 Where 7019 requires a score to exist, 7020 governs keeping it valid and honest over time. It requires a contractor to maintain a current assessment in SPRS, to provide the government access needed to conduct higher-level assessments if it chooses, and to flow the requirement down to subcontractors who will handle covered defense information. The evidence is a maintained SPRS entry and the presence of the requirement in your relevant subcontracts, which is an easy obligation to overlook and a consequential one to miss. DFARS 252.204-7021 This is the CMMC clause, requiring a contractor to hold the CMMC level specified in a given contract. Under the current suspension, the third-party verification that this clause ultimately depends on is paused, so in practice the live obligation is the self-assessment posture rather than a third-party certification. The clause still matters for planning, because CMMC verification will resume, and contracts increasingly reference it. Understanding how it relates to the underlying standard is covered in the comparison of NIST 800-171 versus CMMC. Traps That Stall Contract Awards The clauses above create several specific traps that can delay or block an award, and they catch suppliers who assumed their security was the only thing being judged. The most common is the absence of a current SPRS score: because 252.204-7019 makes that score a precondition of award, a missing or expired assessment can rule you out before your proposal is even evaluated. An assessment older than the permitted window has the same effect as no assessment at all, so a lapsed score is its own trap. A second trap is a posted score that reflects unaddressed gaps with no plan attached, which can raise questions about your readiness even when a score exists. A third is a broken flowdown: if the required clauses are not in your subcontracts, your compliance is incomplete in a way that surfaces at exactly the wrong moment. A fourth is a cloud environment that handles covered defense information without meeting the required equivalency, which is a 252.204-7012 gap that can undermine the whole package. None of these is about the quality of your security directly; each is about the administrative and contractual completeness that DFARS compliance demands alongside it. DFARS Compliance Under the Current Suspension The 2026 suspension of third-party CMMC assessment has changed one of these clauses and left the others untouched, and knowing which is which prevents a costly misread. The suspension paused the third-party verification tied to 252.204-7021, so CMMC certification assessment is not currently a gating step. It did nothing to 252.204-7012, 252.204-7019, or 252.204-7020, which remain fully in

CMMC Incident Response: The IR Practices Level 2 Demands

CMMC incident response is one of the requirement families a defense contractor has to satisfy for Level 2, and it carries an obligation many organizations underestimate until an assessor asks to see the evidence. The requirements are not simply about having a plan on a shelf; they are about demonstrating a working capability to detect, handle, and report security incidents, and proving that capability with records. This guide explains what CMMC incident response requires, what Level 2 assessors test, what evidence to keep, and how it connects to the separate reporting duty you owe the Department of War under your contract. There are really two obligations in play, and contractors frequently conflate them. The first is the set of incident response practices built into the security standard behind CMMC Level 2, which an assessor evaluates. The second is the contractual duty under a specific DFARS clause to report cyber incidents rapidly to the government. They overlap in spirit but are distinct in practice, and getting both right is what incident response readiness actually means for a defense contractor. What CMMC Incident Response Requires CMMC Level 2 is built on the 110 requirements of NIST SP 800-171 Revision 2, and incident response is one of the families within it. The family sets out three connected requirements that together define an operational capability rather than a paper exercise, and an assessor examines all three. An Operational Incident-Handling Capability The core requirement is an operational incident-handling capability for your systems that spans the full lifecycle of an incident: preparation before anything happens, detection and analysis when it does, containment to limit the damage, recovery to restore normal operations, and the user response activities that tie people into the process. The word that matters is operational. The requirement is not satisfied by a document describing what you would do; it is satisfied by a capability you can show actually exists and functions, with the roles, tools, and procedures to work an incident from detection through recovery. Incident Tracking, Documentation, and Reporting The second requirement is to track, document, and report incidents to the designated officials and authorities, both inside and outside your organization. This is the recordkeeping and communication half of incident response: every incident is logged, documented as it is worked, and reported to the people who need to know, which includes internal leadership and, where required, external authorities. The documentation this generates is also the evidence an assessor will later ask to see, so disciplined incident records serve both the operational and the assessment purpose. Capability Testing The third requirement is to test the incident response capability, because a capability that has never been exercised is an assumption rather than a fact. Testing, through tabletop exercises or more involved simulations, is how you confirm the capability works before a real incident proves it does not, and it is also how you generate the evidence that the capability is real. An assessor who asks whether you have tested your incident response is asking for proof, so the test itself has to be documented. The DFARS Reporting Duty: 72 Hours Alongside the CMMC practices sits a separate and specific contractual obligation. Under DFARS clause 252.204-7012, a contractor that discovers a cyber incident affecting a covered system or the controlled unclassified information on it must report it to the Department of War within 72 hours of discovery, through the DIBNet portal. This is a hard deadline measured from discovery, not from resolution, and it is one of the obligations most likely to catch an unprepared contractor because the clock is short and the reporting channel is specific. The duty does not end at the report. The clause also requires preserving and protecting images of the affected systems so that evidence is available for analysis, commonly for a defined retention period, submitting any malicious software discovered, and providing the government access needed for a forensic review. This reporting duty is distinct from the CMMC incident response practices and is in force regardless of the current suspension of third-party assessment, because it is a contractual clause rather than a certification step. A contractor can be fully occupied with its Level 2 self-assessment and still owe this 72-hour report the moment an incident is discovered. What Level 2 Assessors Test An assessor evaluating your incident response is looking for proof that the capability exists, is used, and has been tested, and that proof lives in your records. Expect an assessor to ask for your incident response plan or policy, for documentation of incidents you have handled, for evidence that you have tested the capability, and for the records that show incidents were tracked and reported appropriately. The recurring theme across all of it is that a capability you cannot evidence is treated, in an assessment, as a capability you do not have. This also matters to your score. Because incident response is part of the 110 requirements, gaps in it reduce your assessment score under the weighting codified in the CMMC rule, so an incomplete or unevidenced incident response capability costs you points as well as risking a failed assessment. Understanding how the requirements are scored, covered in the guide to the NIST 800-171 assessment, helps you see why the evidence behind incident response is worth building properly rather than assembling in a rush before an assessment. Evidence to Keep The practical takeaway is to treat evidence as a byproduct of running incident response well, rather than something to reconstruct later. The records worth maintaining include a documented incident response plan or policy that describes your capability, logs and documentation of the incidents you have actually handled, records of the exercises or tests you have run to validate the capability, and the reporting records that show incidents reached the right internal and external parties within the required timeframes. After-action reviews that capture what an incident taught you are valuable both operationally and as proof of a maturing capability. Kept consistently, these records do double duty: they make

NIST 800-171 Assessment: Methodology, Scoring, and Evidence

A NIST 800-171 assessment is the evaluation of your environment against the 110 security requirements in NIST SP 800-171, and it is the assessment that produces the score the government sees and that underpins CMMC Level 2. For any defense contractor handling controlled unclassified information, it is the measurement that matters, because the standard behind it sits in your contract through DFARS clause 252.204-7012 and the same requirements form the control set for CMMC. This guide explains the methodology behind the assessment, how it is scored, what evidence it expects, and how the result flows into the Supplier Performance Risk System and CMMC. The assessment is also the live obligation right now. Under the 2026 suspension of third-party certification assessment, the NIST 800-171 self-assessment is what most contractors are required to perform, and the score it produces is one you attest to with real consequences. Understanding the methodology is therefore not preparation for some future event; it is preparation for the assessment you are expected to run today. What a NIST 800-171 Assessment Is A NIST 800-171 assessment measures how completely your environment implements the 110 requirements of NIST SP 800-171, the standard for protecting controlled unclassified information in nonfederal systems. It is the assessment named in DFARS 252.204-7012, and because CMMC Level 2 is built on the same 110 requirements, the 800-171 assessment and the CMMC Level 2 assessment examine the same control set. The output is a score that represents how much of the standard you meet, and that score is submitted to the Supplier Performance Risk System where the government can see it. The assessment can be performed at different levels of rigor and by different parties, which matters for how much weight the result carries. A contractor can perform the assessment itself, and the government can perform a more thorough review, and under the current suspension the self-assessment is the live requirement for most contractors while government-led assessments continue. What does not change with the level is the standard being measured: every version of the assessment evaluates the same 110 requirements, so the difference is who checks the work and how deeply, not what is being checked. 800-171 Rev 2 Today, Rev 3 Later Assessments today are conducted against Revision 2 of NIST SP 800-171, which defines the 110 requirements currently in force. A move to Revision 3 is expected through future rulemaking, and it will change some of the requirements when it arrives, but there is no finalized deadline for that transition. The practical implication is to build your program against Revision 2 as it stands while staying aware that a revision is coming, rather than trying to assess against a standard that is not yet in effect. The DoD Assessment Methodology The scoring behind a NIST 800-171 assessment follows the DoD Assessment Methodology, which defines how the assessment is conducted and how the resulting score is calculated. The methodology sets out three assessment levels that differ in who performs the assessment and how much confidence the result carries, and understanding them clarifies what your self-assessed score means relative to a government review. Assessment level Who performs it Confidence in the result Basic The contractor, as a self-assessment Lower, because it is self-reported Medium The government, reviewing the assessment Higher High The government, through a thorough on-site review Highest The table shows why a self-assessment, while it is the live requirement during the suspension, is also the level the government trusts least on its own. A Basic self-assessment is your own honest measurement, and the government retains the ability to perform Medium and High assessments to verify it. This is one reason accuracy in a self-assessment matters so much: the score is self-reported, but it is not beyond scrutiny, and a self-assessment that a government review later contradicts is a serious problem. Self-Assessment and Government Assessment: What Each Involves The three levels are not just labels for confidence; they describe genuinely different exercises, and knowing what each involves clarifies what your own self-assessment does and does not settle. A Basic assessment is the one you perform yourself: you evaluate your environment against the 110 requirements, calculate your score, and submit it to the Supplier Performance Risk System. It is the live requirement for most contractors under the current suspension, and it is entirely self-reported, which is exactly why the methodology assigns it the lowest confidence. A Basic self-assessment is your honest measurement of your own posture, and it is an attestation you are held to, but it is not verification. A Medium or High assessment is where the government does the checking. In a Medium assessment, the government reviews and validates the Basic self-assessment you submitted, which raises the confidence in the result. In a High assessment, the government conducts a thorough on-site evaluation, examining evidence, interviewing the people who operate the controls, and observing implementation directly, which is why it carries the highest confidence of the three. These government-led assessments continue during the suspension, because it is the third-party certification route that is paused, not the government’s own ability to assess. The practical implication for a contractor is that a self-assessment is not the end of the story, and it should not be treated as one. Because the government can review or independently conduct an assessment, the gap between the score you self-report and the score a government assessor would reach is a real and exposed risk rather than a private matter. An inflated self-assessment is not hidden; it is simply waiting to be contradicted, with the attestation attached to it. This is what makes accuracy in the Basic assessment protective rather than optional, and it is why the evidence behind your score matters as much as the score itself. How Scoring Works The DoD Assessment Methodology produces a numeric score that reflects how much of the standard you meet. It begins from a maximum of 110, one point for each of the 110 requirements, and subtracts the weighted value of every requirement