NIST 800-171 vs. DFARS 7012 vs. CMMC compliance guide cover by Koop

Key takeaways

  • NIST SP 800-171 defines the security controls, DFARS 252.204-7012 makes them a contract obligation, and CMMC checks that you meet them.
  • Revision 2 of NIST 800-171 governs Department of Defense work. Revision 3 applies to many civilian agency contracts.
  • DFARS 252.204-7012 has applied since December 2017 and carries a 72-hour cyber incident reporting duty that starts the moment you discover an incident.
  • The July 2026 suspension of CMMC Phase 2 paused third-party certification for Controlled Unclassified Information. Phase 1 self-assessments, SPRS scores, and the annual affirmation still apply.
  • An accurate SPRS score protects your award eligibility and reduces False Claims Act exposure.

NIST SP 800-171, DFARS 252.204-7012, and CMMC appear together on defense contracts, and their names, clause numbers, and assessment steps can be read as three separate programs. One set of security controls satisfies all three. Knowing where each fits keeps a compliance program focused and an SPRS score accurate as the CMMC timeline shifts.

How NIST 800-171, DFARS 7012, and CMMC Relate

NIST SP 800-171 is the catalog of security controls. DFARS 252.204-7012 is the contract clause that requires those controls and adds cyber incident reporting. CMMC is the program that verifies the controls before an award. Each one builds on the one before it.

NIST SP 800-171, DFARS 252.204-7012, and CMMC shown as three stacked layers of one defense compliance requirement: NIST as the security controls, DFARS as the contract obligation, and CMMC as the verification.

The three frameworks: Side-by-side comparison

Each one differs in how you prove it and where it stands after the 2026 pause.

What It Is What It Governs How You Show It Current Status
Security control catalog Protecting CUI on nonfederal systems System Security Plan and POA&M Revision 2 (110 controls) for DoD work, Revision 3 (97 controls) for many civilian contracts
Contract clause Safeguarding covered defense information and reporting cyber incidents Self-assessment score in SPRS plus an annual affirmation Applies to DoD contracts since December 2017, unchanged by the 2026 pause
Assessment program Confirming NIST 800-171 implementation for DoD Self-assessment or a Level 2 C3PAO assessment Phase 1 self-assessments in effect since November 2025; Phase 2 C3PAO certification suspended in July 2026

NIST 800-171: The security control baseline

NIST SP 800-171 protects Controlled Unclassified Information (CUI) on the systems of contractors and other nonfederal organizations. The National Institute of Standards and Technology drew it from the broader NIST SP 800-53 catalog and grouped it into control families such as access control, incident response, and configuration management.

What NIST 800-171 requires

You document how each control operates in a System Security Plan (SSP) and record any gaps in a Plan of Action and Milestones (POA&M). The standard reaches every system that stores, processes, or transmits CUI, which usually includes email, file storage, endpoints, and cloud tools. Controls include technical measures like multifactor authentication and encryption, and written procedures like a documented incident response plan.

Rev 2 vs Rev 3: Which version applies

Two versions of the standard are active. Revision 2 holds 110 requirements across 14 families. Revision 3, published in May 2024, holds 97 requirements across 17 families and introduces organization-defined parameters. Department of Defense contracts and CMMC Level 2 assessments run against Revision 2, held there by a 2024 class deviation. Many civilian agencies reference Revision 3 for new work.

DFARS 7012: The clause that mandates 800-171

DFARS 252.204-7012 appears in defense contracts that involve Covered Defense Information (CDI), a category that overlaps closely with CUI. Once the clause is in a contract, you implement NIST SP 800-171 on every covered system and take on three further duties: reporting cyber incidents, using cloud services that meet a federal security baseline, and passing the same terms to your subcontractor.

The 72-Hour incident reporting rule

The clause defines a rapid report as one filed within 72 hours of discovering a cyber incident. The clock starts at discovery. You file through the Defense Industrial Base Cybersecurity portal, which requires a medium assurance certificate to submit, and preserve affected media for at least 90 days. The portal registration and the certificate both take time to obtain, which makes them worth arranging early.

How your SPRS score works

You score your NIST 800-171 implementation with the DoD Assessment Methodology and post the result to the Supplier Performance Risk System (SPRS) . The score starts at 110 for full implementation and drops by a weighted value for each control not yet met. A current score sits in SPRS at the time of award and stays valid for three years, and a senior official affirms it each year.

The DFARS 70-Series clauses you may see

The DFARS 70-series carries four clauses that build on each other:

  • 252.204-7012 safeguards covered defense information and requires cyber incident reporting
  • 252.204-7019 posts your NIST 800-171 self-assessment score to SPRS
  • 252.204-7020 gives the government the right to review that assessment
  • 252.204-7021 ties CMMC certification to an award

A February 2026 class deviation reorganized the assessment clauses, including 7019 and 7020, and both the original and new numbers now appear across active solicitations.

CMMC: The verification layer on top

CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense (DoD) program for assessing NIST 800-171 implementation across the defense supply chain. The DoD established the program under 32 CFR Part 170, which took effect in December 2024, and set three levels tied to the sensitivity of the information you handle.

CMMC Level 1 vs Level 2 requirements

Level 1 covers Federal Contract Information (FCI) and maps to the basic safeguards in FAR 52.204-21. Level 2 covers Controlled Unclassified Information and maps to the 110 controls in NIST 800-171 Revision 2. Level 3 adds enhanced controls from NIST SP 800-172 for programs facing advanced threats. You establish your level by identifying the data your contract involves, and scoping the environment sets the assessment boundary.

When a C3PAO assessment applies

Level 1 and part of Level 2 rely on self-assessment, and the CMMC Level 1 self-assessment follows a defined set of steps. Higher-assurance Level 2 calls for a CMMC Third-Party Assessment Organization (C3PAO) to conduct the assessment, and the certificate carries a three-year term. Koop refers you to an independent C3PAO for Level 2 certification.

Where CMMC stands after the 2026 pause

On July 13, 2026, the Department suspended CMMC Phase 2, the point at which Level 2 C3PAO certification was set to become a condition of award for CUI contracts on November 10, 2026. The suspension came as a policy memo and opened a program review. Your obligations change only through a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170, and a memo is none of these.

CMMC timeline: 32 CFR Part 170 takes effect December 2024, Phase 1 self-assessments begin November 2025, Phase 2 pauses July 2026, and the CMMC Reform Task Force reports September to October 2026.

Phase 1 self-assessments have been applied since November 2025 and continue. DFARS 252.204-7012, NIST 800-171 Revision 2, the SPRS score, and the annual affirmation remain in force because only a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170 changes the law. Keeping your evidence current and your score accurate keeps you ready whichever way the review lands. Koop's regulatory intelligence database tracks these clauses and program changes.

Which requirements apply to your contracts

Search your contract for the clause numbers and identify whether you handle FCI, CUI, or both. FCI alone points toward FAR 52.204-21 and CMMC Level 1. CUI brings in DFARS 252.204-7012, NIST 800-171, and CMMC Level 2.

A prime can also require CMMC Level 2 through its own contractual requirements ahead of the Department's timeline. Suppliers selling to the government through a prime follow the flowdown written into the subcontract.

Decision flow from data type to requirements: Federal Contract Information leads to FAR 52.204-21 and CMMC Level 1; Controlled Unclassified Information leads to DFARS 252.204-7012 with NIST 800-171 Revision 2 and CMMC Level 2.

Requirements by data type and CMMC level

More sensitive data brings a stricter clause, more controls, and a higher CMMC level.

Data You Handle Clause You Will See NIST Scope CMMC Level Assessment Today
Federal Contract Information (FCI) FAR 52.204-21 15 basic safeguarding requirements Level 1 Self-assessment
Controlled Unclassified Information (CUI) DFARS 252.204-7012 NIST 800-171 Revision 2 (110 controls) Level 2 Self-assessment now. C3PAO certification paused
High-sensitivity CUI programs DFARS 252.204-7012 NIST 800-171 plus NIST 800-172 Level 3 Government-led assessment (future)

What enforcement means for self-attestation

An SPRS score and an affirmation are representations to the government. The Department of Justice pursues inaccurate representations under the False Claims Act through its Civil Cyber-Fraud Initiative:

How Koop simplifies DoD compliance

Koop supports all three requirements from one platform:

  • Housekeeper AI Agent takes on routine compliance tasks for your team
  • SSP, POA&M, and SPRS scoring automated through GovCloud integrations, pulling evidence from your live environment
  • Requirements management, third-party risk, and security questionnaires run in the same place as your controls
  • Vetted compliance experts guide the program, with a C3PAO assessor available for Level 2 certification

Simplify defense compliance with Koop

NIST SP 800-171, DFARS 252.204-7012, and CMMC connect into one security effort. Implement the controls once, keep an accurate SPRS score, and maintain a current System Security Plan, and you stay ready through revision updates and program changes. 

Map your CMMC requirements to a plan that fits your business.

Book a demo
article highlights: