Key takeaways

  • NIST withdrew Revision 2 on May 14, 2024, and a DoD class deviation keeps your contract on it. Revision 3 is not a contract requirement.
  • The July 13, 2026 suspension stopped third-party certification. DFARS 252.204-7012 and Phase 1 self-assessments remain in place.
  • A machine holding no CUI is in scope if it is not isolated from one that does.
  • A score of 88 permits Conditional status and starts a 180-day closeout clock. Clearing without a plan of action means implementing all 110.
  • MORSECORP posted 104 when its real score was negative 142. It paid $4.6 million, and no breach was involved.

NIST withdrew Revision 2 of SP 800-171 on May 14, 2024, and it is still the version your contract requires. The Department of War suspended CMMC Phase 2 on July 13, 2026, and nothing you owe under DFARS 252.204-7012 changed.

Some teams build toward Revision 3 because it is the current publication. Others stopped spending in July and treated the suspension as a reprieve.

This guide covers the version that binds you and the score your assessment has to clear. It assumes you handle CUI and want to keep the contract.

The version that NIST withdrew

Revision 2 of NIST SP 800-171 was published in February 2020 with updates as of January 28, 2021. NIST withdrew it on May 14, 2024, and marked it as superseded by Revision 3.

The standard clause at DFARS 252.204-7012 points to the version of SP 800-171 in effect when the solicitation was issued, or a version the contracting officer authorizes. DoD issued Class Deviation 2024-O0013 on May 2, 2024, twelve days before Revision 3 was published. The deviation substitutes an alternate clause requiring Revision 2.

Under 32 CFR 170.14, the CMMC Level 2 security requirements are identical to those in NIST SP 800-171 R2.

Comparison Revision 2 Revision 3
Families 14 17
Level 2 requirements 110 Not applicable
Required by contract and CMCC Yes No

Family counts per NIST SP 800-171 Revision 2 Chapter Three and Revision 3 Section 2.2. Requirement count per 32 CFR 170.4.

Revision 3 adds Planning and System and Services Acquisition. Revision 2 excluded both families while keeping one requirement from each. Revision 3 also introduces organization-defined parameters, which are values the agency sets and NIST leaves open. DoD published its values on April 10, 2025, as preparation for making Revision 3 the minimum requirement for contractors.

What the Phase 2 suspension changed

Third-party certification from a C3PAO would have become a condition of award on November 10, 2026. The July 13 memoranda stopped that and froze pending and future implementation milestones across DoW solicitations and contracts.

Program managers may now designate only Level 1 self-assessment or Level 2 self-assessment. They may not designate Level 2 with a C3PAO or Level 3 with DIBCAC while the suspension holds. No waivers will be granted during that period.

Two things follow if your solicitation or contract already names one of the suspended assessments. Requiring activities must initiate amendments to active solicitations. For contracts already awarded, contracting officers were directed to remove the requirement before the next option exercise or during the next scheduled administrative modification.

Phase 1 self-assessments remain in place, and the Department said it will enforce Revision 2 through Level 1 and Level 2 self-assessment plus select government-led assessments. DFARS 252.204-7012 still applies.

The CMMC program rule at 32 CFR Part 170 is unchanged, and a memorandum does not amend a rule. Further guidance follows the 60-day review that began on July 13.

What NIST SP 800-171 requires and how it is organized

Confidentiality is the only security objective this standard measures. It applies to CUI on nonfederal systems. Availability falls outside its scope.

Each family splits into basic requirements drawn from FIPS 200 and derived requirements drawn from SP 800-53. That distinction carries into how an assessment scores you.

Numbering runs from the family, so 3.8.3 is the third requirement in Media Protection.

Identifier Family
3.1Access Control
3.2Awareness and Training
3.3Audit and Accountability
3.4Configuration Management
3.5Identification and Authentication
3.6Incident Response
3.7Maintenance
3.8Media Protection
3.9Personnel Security
3.10Physical Protection
3.11Risk Assessment
3.12Security Assessment
3.13System and Communications Protection
3.14System and Information Integrity

Family names and identifiers per NIST SP 800-171 Revision 2, Table 1 and Chapter Three.

Your scope decision sets your entire budget

Where you draw your boundary decides how many systems you have to bring up to standard, and the answer is rarely your whole company.

Federal contract information carries 15 basic safeguarding requirements under FAR 52.204-21. CUI carries the 110 in Revision 2.

Under 32 CFR 170.1, the program reaches systems that process, store, or transmit CUI, systems that provide security protections for those systems, and systems not logically or physically isolated from them. 

CMMC scoping allows a middle tier. Contractor Risk Managed Assets can handle CUI but are not intended to, because policy and practice prevent it. Those get documented in the system security plan and reviewed. A sufficiently documented asset is not assessed against every requirement.

An enclave saves money only when the separation holds, and you can show it.

  1. Confirm the requirement’s ownership

Primes sometimes ask suppliers to be NIST 800-171 certified. Under CMMC, you either self-assess and post the result to SPRS, or you undergo a certification assessment. A certificate comes only from the second route.

Ask which clause creates the obligation. FAR 52.204-21 flows down to subcontractors who may have federal contract information in their systems. DFARS 252.204-7012 flows down where subcontract performance involves covered defense information, and the prime contractor decides whether the information keeps that identity. Under 32 CFR 170.23, a subcontractor handling only FCI needs Level 1, and one handling CUI needs Level 2 at minimum.

  1. When your cloud and your MSP land inside the boundary

Under DFARS 252.204-7012, you must ensure that any cloud provider holding your CUI meets the FedRAMP requirements. That clause asks for security requirements equivalent to the FedRAMP Moderate baseline, which is not the same as holding a FedRAMP authorization.

A provider that is not a cloud provider is treated differently. Under 32 CFR 170.19, the services an external service provider delivers fall inside your assessment scope and are assessed alongside your own systems. The customer responsibility matrix must appear in your system security plan.

How your score is built and where DoD sees it

Teams sometimes read an assessment as a checklist where each requirement is met, planned, or not applicable. You start at 110 and subtract for every requirement not met.

Deductions run 1, 3, or 5 points according to how much the gap exposes the network and the CUI on it. Enough gaps push the total below zero. The lowest possible score is negative 203.

Two requirements allow partial credit, and both are ones teams commonly get half right. Multi-factor authentication costs 3 points if you have it for remote and privileged users but not general users. It costs 5 points if you have it for nobody, and also 5 if you covered general users but left admins out. Encryption costs 3 points if it is deployed but not FIPS-validated, and 5 points if none is employed.

Your score goes into SPRS with the assessment date and the date you expect to reach 110. The assessment cannot be more than three years old.

The 88-point floor

Under 32 CFR 170.21, a score of 88 is the minimum that makes a Conditional status possible, which starts a clock.

Two rules govern what you can put on a plan of action. Nothing worth more than one point qualifies, with one exception. CUI encryption at SC.L2-3.13.11 can be deferred when it draws the three-point deduction. The rule then names six requirements outright, including your system security plan.

That rules out every requirement the point tables value at three or five points. A score of 88 leaves 22 of the 110 points unearned, so the arithmetic only works if your gaps are the cheap ones.

A closeout assessment must confirm the plan is closed within 180 days of your Conditional status date, and the status expires if you miss it. If that happens while a contract is running, standard contractual remedies apply, and you become ineligible for further awards at that level or above.

The system security plan must be in place before the assessment. Without a current one, the finding is that the assessment could not be completed.

Two situations do not count against you when documented properly. An enduring exception described with its mitigations in the system security plan is assessed as met. A temporary deficiency addressed in an operational plan of action is assessed as met. Neither is a plan of action item, because a plan of action only attaches to a requirement scored not met.

The cost of a score you cannot defend

The score you post to SPRS is a representation to the government, and a false one is actionable under the False Claims Act.

MORSECORP, a contractor working for the Army and Air Force, posted a score of 104 in January 2021. In July 2022, a third-party consultant told the company its actual score was negative 142. The 104 stayed in place until June 2023, three months after the government served the company with a subpoena. MORSECORP paid $4.6 million in 2025.

The case came from a whistleblower inside the company, who filed a qui tam suit and took $851,000 of the settlement.

The affirmation is signed by a senior representative of your own company, and the score sits in a system contracting officers use.

If your posted score is older than your environment, reassess and repost before someone else finds the gap.

What you owe after the assessment ends

An affirmation is due after every assessment and annually after that, and your affirming official attests that the company has implemented and will maintain implementation of every applicable requirement. That is a forward commitment, not a snapshot of assessment week.

Evidence has to last as well, given that under 32 CFR 170.16, artifacts used in a Level 2 assessment must be retained for six years from your CMMC status date.

How Koop keeps the record current

Koop is an AI-native GRC platform built for companies selling into regulated and government markets, and two of its capabilities line up with what this guide covers.

Continuous control monitoring and automated evidence updates keep your record current between assessments, which is what the annual affirmation and the six-year retention window both require. Requirements management handles flow-down, running contract-level compliance assessments, and counterparty compliance status tracking so an obligation and your supplier's response to it sit in one place.

Koop reports that its Housekeeper agent automates up to 95% of compliance tasks, which is the work that otherwise accumulates between one assessment and the next.

Koop publishes clause-level detail on NIST SP 800-171 and DFARS 252.204-7012, and its platform covers CMMC alongside 50 more frameworks.

Book a demo and bring your asset inventory.

Book a demo

Frequently asked questions

  1. What if a requirement does not fit my environment?

DFARS 252.204-7012 lets you submit requests to vary in writing through your contracting officer for DoD CIO adjudication. If the CIO rules a requirement non-applicable or accepts an alternative as equally effective, that adjudication must be included in the system security plan to count during an assessment.

  1. Can the government overrule my self-assessment?

Yes. DoD reserves the right to run a DIBCAC assessment, and those results take precedence over any status you already hold.

  1. What is the difference between FIPS validated and FIPS compliant?

Validation means a module was tested by an accredited laboratory and issued a certificate under the Cryptographic Module Validation Program. NIST states that a product does not meet the requirement by implementing an approved algorithm alone.

‍

‍

article highlights: