
Key takeaways
- NIST SP 800-171 defines the security controls, DFARS 252.204-7012 makes them a contract obligation, and CMMC checks that you meet them.
- Revision 2 of NIST 800-171 governs Department of Defense work. Revision 3 applies to many civilian agency contracts.
- DFARS 252.204-7012 has applied since December 2017 and carries a 72-hour cyber incident reporting duty that starts the moment you discover an incident.
- The July 2026 suspension of CMMC Phase 2 paused third-party certification for Controlled Unclassified Information. Phase 1 self-assessments, SPRS scores, and the annual affirmation still apply.
- An accurate SPRS score protects your award eligibility and reduces False Claims Act exposure.
NIST SP 800-171, DFARS 252.204-7012, and CMMC appear together on defense contracts, and their names, clause numbers, and assessment steps can be read as three separate programs. One set of security controls satisfies all three. Knowing where each fits keeps a compliance program focused and an SPRS score accurate as the CMMC timeline shifts.
How NIST 800-171, DFARS 7012, and CMMC Relate
NIST SP 800-171 is the catalog of security controls. DFARS 252.204-7012 is the contract clause that requires those controls and adds cyber incident reporting. CMMC is the program that verifies the controls before an award. Each one builds on the one before it.

The three frameworks: Side-by-side comparison
Each one differs in how you prove it and where it stands after the 2026 pause.
NIST 800-171: The security control baseline
NIST SP 800-171 protects Controlled Unclassified Information (CUI) on the systems of contractors and other nonfederal organizations. The National Institute of Standards and Technology drew it from the broader NIST SP 800-53 catalog and grouped it into control families such as access control, incident response, and configuration management.
What NIST 800-171 requires
You document how each control operates in a System Security Plan (SSP) and record any gaps in a Plan of Action and Milestones (POA&M). The standard reaches every system that stores, processes, or transmits CUI, which usually includes email, file storage, endpoints, and cloud tools. Controls include technical measures like multifactor authentication and encryption, and written procedures like a documented incident response plan.
Rev 2 vs Rev 3: Which version applies
Two versions of the standard are active. Revision 2 holds 110 requirements across 14 families. Revision 3, published in May 2024, holds 97 requirements across 17 families and introduces organization-defined parameters. Department of Defense contracts and CMMC Level 2 assessments run against Revision 2, held there by a 2024 class deviation. Many civilian agencies reference Revision 3 for new work.
DFARS 7012: The clause that mandates 800-171
DFARS 252.204-7012 appears in defense contracts that involve Covered Defense Information (CDI), a category that overlaps closely with CUI. Once the clause is in a contract, you implement NIST SP 800-171 on every covered system and take on three further duties: reporting cyber incidents, using cloud services that meet a federal security baseline, and passing the same terms to your subcontractor.
The 72-Hour incident reporting rule
The clause defines a rapid report as one filed within 72 hours of discovering a cyber incident. The clock starts at discovery. You file through the Defense Industrial Base Cybersecurity portal, which requires a medium assurance certificate to submit, and preserve affected media for at least 90 days. The portal registration and the certificate both take time to obtain, which makes them worth arranging early.
How your SPRS score works
You score your NIST 800-171 implementation with the DoD Assessment Methodology and post the result to the Supplier Performance Risk System (SPRS) . The score starts at 110 for full implementation and drops by a weighted value for each control not yet met. A current score sits in SPRS at the time of award and stays valid for three years, and a senior official affirms it each year.
The DFARS 70-Series clauses you may see
The DFARS 70-series carries four clauses that build on each other:
- 252.204-7012 safeguards covered defense information and requires cyber incident reporting
- 252.204-7019 posts your NIST 800-171 self-assessment score to SPRS
- 252.204-7020 gives the government the right to review that assessment
- 252.204-7021 ties CMMC certification to an award
A February 2026 class deviation reorganized the assessment clauses, including 7019 and 7020, and both the original and new numbers now appear across active solicitations.
CMMC: The verification layer on top
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense (DoD) program for assessing NIST 800-171 implementation across the defense supply chain. The DoD established the program under 32 CFR Part 170, which took effect in December 2024, and set three levels tied to the sensitivity of the information you handle.
CMMC Level 1 vs Level 2 requirements
Level 1 covers Federal Contract Information (FCI) and maps to the basic safeguards in FAR 52.204-21. Level 2 covers Controlled Unclassified Information and maps to the 110 controls in NIST 800-171 Revision 2. Level 3 adds enhanced controls from NIST SP 800-172 for programs facing advanced threats. You establish your level by identifying the data your contract involves, and scoping the environment sets the assessment boundary.
When a C3PAO assessment applies
Level 1 and part of Level 2 rely on self-assessment, and the CMMC Level 1 self-assessment follows a defined set of steps. Higher-assurance Level 2 calls for a CMMC Third-Party Assessment Organization (C3PAO) to conduct the assessment, and the certificate carries a three-year term. Koop refers you to an independent C3PAO for Level 2 certification.
Where CMMC stands after the 2026 pause
On July 13, 2026, the Department suspended CMMC Phase 2, the point at which Level 2 C3PAO certification was set to become a condition of award for CUI contracts on November 10, 2026. The suspension came as a policy memo and opened a program review. Your obligations change only through a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170, and a memo is none of these.

Phase 1 self-assessments have been applied since November 2025 and continue. DFARS 252.204-7012, NIST 800-171 Revision 2, the SPRS score, and the annual affirmation remain in force because only a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170 changes the law. Keeping your evidence current and your score accurate keeps you ready whichever way the review lands. Koop's regulatory intelligence database tracks these clauses and program changes.
Which requirements apply to your contracts
Search your contract for the clause numbers and identify whether you handle FCI, CUI, or both. FCI alone points toward FAR 52.204-21 and CMMC Level 1. CUI brings in DFARS 252.204-7012, NIST 800-171, and CMMC Level 2.
A prime can also require CMMC Level 2 through its own contractual requirements ahead of the Department's timeline. Suppliers selling to the government through a prime follow the flowdown written into the subcontract.

Requirements by data type and CMMC level
More sensitive data brings a stricter clause, more controls, and a higher CMMC level.
What enforcement means for self-attestation
An SPRS score and an affirmation are representations to the government. The Department of Justice pursues inaccurate representations under the False Claims Act through its Civil Cyber-Fraud Initiative:
- A defense contractor in Alabama resolved claims for $507,144 in 2026 after gaps in its NIST 800-171 controls
- MORSECORP settled for $4.6 million in 2025 over an SPRS score higher than its controls supported
- Georgia Tech Research Corporation settled for $875,000 in 2025
- Raytheon and its successor settled for $8.4 million in 2025
How Koop simplifies DoD compliance
Koop supports all three requirements from one platform:
- Housekeeper AI Agent takes on routine compliance tasks for your team
- SSP, POA&M, and SPRS scoring automated through GovCloud integrations, pulling evidence from your live environment
- Requirements management, third-party risk, and security questionnaires run in the same place as your controls
- Vetted compliance experts guide the program, with a C3PAO assessor available for Level 2 certification
Simplify defense compliance with Koop
NIST SP 800-171, DFARS 252.204-7012, and CMMC connect into one security effort. Implement the controls once, keep an accurate SPRS score, and maintain a current System Security Plan, and you stay ready through revision updates and program changes.



