Graphic comparing DFARS, CMMC, and NIST SP 800-171 to help defense contractors understand the differences between contractual cybersecurity obligations, security requirements, and CMMC assessment requirements.

DFARS vs. CMMC vs. NIST 800-171: What’s the Difference?

If your company works with the Department of Defense, you have probably encountered three acronyms that seem to appear in nearly every cybersecurity compliance conversation: DFARS, CMMC, and NIST SP 800-171.

At first glance, they can sound like three versions of the same requirement.

They are not.

DFARS establishes contractual cybersecurity obligations for applicable defense contractors. NIST SP 800-171 provides security requirements for protecting Controlled Unclassified Information, commonly called CUI, in nonfederal systems. CMMC provides the Department of Defense with a framework for assessing whether contractors have implemented applicable cybersecurity requirements.

The easiest way to think about the relationship is this:

DFARS = Contractual obligations

NIST SP 800-171 = Security requirements

CMMC = Assessment and verification

Understanding that distinction can make the entire compliance conversation much easier.

It is especially important now. CMMC implementation has entered a changing period, but that does not mean defense contractors can ignore cybersecurity requirements while waiting to see what happens next.

Let’s break down what each acronym actually means, how they work together, and what defense contractors should be doing today.

DFARS vs. CMMC vs. NIST 800-171 at a Glance

Here is a quick comparison before we dig into each one.

Requirement DFARS NIST SP 800-171 CMMC
What is it? Defense acquisition regulations Cybersecurity security requirements DoD cybersecurity assessment program
Primary purpose Establish contractual obligations Protect CUI in nonfederal systems Assess implementation of applicable cybersecurity requirements
Who may be affected? Applicable DoD contractors and subcontractors Organizations required to protect CUI under applicable contracts or agreements Defense contractors and subcontractors when an applicable CMMC level is required
Is it a certification? No No Some requirements involve third-party certification, while others use self-assessment
How does it connect? Can require implementation of NIST SP 800-171 Provides the 110 requirements currently used for CMMC Level 2 Provides a mechanism for assessing cybersecurity implementation

There is considerable overlap between the three, but they serve different purposes.

That distinction matters because becoming “CMMC ready” does not automatically mean every DFARS obligation has been addressed, and following NIST SP 800-171 does not by itself mean an organization has completed every applicable CMMC requirement.

What Is DFARS?

DFARS stands for the Defense Federal Acquisition Regulation Supplement.

Think of DFARS as the contractual layer of the cybersecurity compliance puzzle.

DFARS supplements federal acquisition regulations with requirements specifically applicable to Department of Defense procurement.

One of the most important clauses for cybersecurity is DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.

For covered contractor information systems subject to the clause, DFARS 252.204-7012 requires applicable security based on NIST SP 800-171. The clause also addresses other responsibilities, including cyber incident reporting and requirements involving certain cloud services.

This is where the relationship between DFARS and NIST SP 800-171 becomes clearer.

DFARS can create the contractual obligation. NIST SP 800-171 provides the cybersecurity requirements that the contractor must implement when applicable.

Why Does DFARS Matter to Defense Contractors?

If a DFARS cybersecurity clause is included in your contract, it is not simply a cybersecurity recommendation.

It is part of your contractual obligations.

This distinction is particularly important during periods when CMMC rules, timelines, or implementation plans are changing.

A change to CMMC implementation does not automatically remove existing DFARS requirements from contracts.

Defense contractors should therefore review the actual clauses in their contracts and subcontracts rather than assuming that a CMMC announcement determines all of their cybersecurity responsibilities.

What Is NIST SP 800-171?

NIST SP 800-171 is a cybersecurity publication developed by the National Institute of Standards and Technology.

Its purpose is to provide security requirements for protecting the confidentiality of Controlled Unclassified Information in nonfederal systems and organizations.

CUI is information that is not classified but still requires safeguarding or dissemination controls under applicable laws, regulations, or government-wide policies.

For many organizations within the Defense Industrial Base, NIST SP 800-171 is the technical foundation behind their cybersecurity compliance efforts.

What Does NIST SP 800-171 Actually Cover?

NIST SP 800-171 addresses cybersecurity areas such as:

  • Access control
  • Identification and authentication
  • Audit and accountability
  • Configuration management
  • Incident response
  • Media protection
  • Personnel security
  • Physical protection
  • Risk assessment
  • Security assessment
  • System and communications protection
  • System and information integrity

The objective is not simply to create documentation.

The goal is to establish security requirements that help protect sensitive government information when that information resides outside federal systems.

NIST SP 800-171 Revision 2 vs. Revision 3

This is an important distinction for defense contractors.

NIST published NIST SP 800-171 Revision 3 in May 2024, superseding Revision 2 as the latest NIST publication.

However, CMMC Level 2 currently uses the 110 security requirements from NIST SP 800-171 Revision 2.

That means contractors should not automatically assume that the newest NIST publication is the version currently used for their CMMC Level 2 assessment.

Your applicable contract requirements and current DoD CMMC requirements should guide your compliance efforts.

What Is CMMC?

CMMC stands for the Cybersecurity Maturity Model Certification program.

If DFARS represents the contractual layer and NIST SP 800-171 represents the security requirements, CMMC represents the assessment and verification layer.

CMMC was created by the Department of Defense to provide a structured approach for assessing whether companies in the Defense Industrial Base have implemented applicable cybersecurity protections.

Rather than relying solely on a company saying its cybersecurity controls are in place, CMMC establishes assessment requirements tied to different levels.

What Are the Three CMMC Levels?

CMMC has three levels, with requirements increasing based on the sensitivity of the information involved and the cybersecurity needs associated with the contract.

CMMC Level 1

CMMC Level 1 focuses on safeguarding Federal Contract Information, or FCI.

It includes 15 safeguarding requirements based on FAR 52.204-21.

Level 1 requires an annual self-assessment, and Plans of Action and Milestones, commonly called POA&Ms, are not permitted for Level 1.

CMMC Level 2

CMMC Level 2 is focused on protecting CUI.

It currently incorporates the 110 security requirements from NIST SP 800-171 Revision 2.

Depending on the applicable DoD requirement, Level 2 may involve either a self-assessment or an assessment conducted by an authorized CMMC Third-Party Assessment Organization, or C3PAO.

This is where CMMC and NIST SP 800-171 are most directly connected.

NIST SP 800-171 provides the security requirements.

CMMC provides the framework for assessing implementation of those requirements.

CMMC Level 3

CMMC Level 3 is designed for organizations requiring a higher level of protection against advanced cybersecurity threats.

It builds on Level 2 and includes additional security requirements.

Level 3 assessments are conducted by the Defense Industrial Base Cybersecurity Assessment Center, commonly called DIBCAC.

How Do DFARS, NIST 800-171, and CMMC Work Together?

Here is where the alphabet soup starts making sense.

Imagine a Colorado engineering company pursuing Department of Defense work that will require it to process, store, or transmit CUI.

The company could encounter all three requirements, but each plays a different role.

Step 1: DFARS Establishes Contractual Requirements

The company’s DoD contract or subcontract contains applicable DFARS clauses.

Those clauses establish cybersecurity responsibilities the contractor is expected to meet.

Step 2: NIST SP 800-171 Defines Security Requirements

If the company’s covered systems process, store, or transmit CUI and its contract requires NIST SP 800-171, the organization needs to implement the applicable security requirements.

Those requirements address how the organization protects that information across its systems and operations.

Step 3: CMMC Assesses Implementation

When an applicable CMMC requirement is included in a solicitation or contract, CMMC establishes the assessment requirements the contractor must satisfy.

That could involve a self-assessment or, depending on the required CMMC level and contract, an independent assessment.

Put simply:

DFARS tells you what you are contractually responsible for.

NIST SP 800-171 provides cybersecurity requirements for protecting CUI.

CMMC provides a framework for assessing whether applicable requirements have been implemented.

They are not competing compliance programs.

They are connected parts of the Department of Defense cybersecurity ecosystem.

Does CMMC Replace NIST 800-171?

No. CMMC does not simply replace NIST SP 800-171.

For CMMC Level 2, NIST SP 800-171 Revision 2 currently provides the 110 security requirements against which implementation is assessed.

A useful way to think about it is that NIST SP 800-171 provides the requirements, while CMMC establishes an assessment structure around those requirements.

This is why organizations preparing for CMMC Level 2 need to understand NIST SP 800-171 rather than treating CMMC as an entirely separate cybersecurity checklist.

Does CMMC Replace DFARS?

No. CMMC does not simply replace DFARS.

DFARS clauses can establish contractual cybersecurity obligations, including requirements related to safeguarding covered defense information and cyber incident reporting.

CMMC adds an assessment component to the broader cybersecurity compliance landscape.

A contractor may therefore need to consider its DFARS clauses, applicable NIST SP 800-171 requirements, and CMMC requirements together.

What Does the Current CMMC Pause Mean?

This question is particularly important for defense contractors right now.

CMMC Phase 1 implementation began on November 10, 2025. The Department of Defense has since paused implementation in Phase 1 while reviewing the program.

That has understandably created uncertainty throughout the Defense Industrial Base.

But there is an important distinction:

A pause in CMMC implementation does not eliminate existing requirements to protect information under applicable DFARS clauses.

The DoD has indicated that the current CMMC implementation pause does not eliminate requirements for companies to protect information in accordance with DFARS 252.204-7012.

For contractors, this means “CMMC is paused” should not be interpreted as “cybersecurity compliance is paused.”

Do You Still Need NIST 800-171 During the CMMC Pause?

If your organization is contractually required to implement NIST SP 800-171, a pause in CMMC implementation does not automatically remove that contractual requirement.

That is why defense contractors should separate two questions:

What is happening with CMMC implementation?

and

What does my contract currently require?

Those are not necessarily the same question.

Companies should review their contracts, applicable DFARS clauses, CUI environment, subcontractor responsibilities, and prime contractor expectations before deciding to slow or stop compliance efforts.

What About Prime Contractors and Subcontractors?

Cybersecurity compliance does not stop with the prime contractor.

DFARS and CMMC requirements can involve flow-down obligations to subcontractors when applicable.

This is one reason suppliers should not assume that a government implementation delay means their prime contractor will stop asking cybersecurity questions.

A prime contractor may still need confidence that organizations within its supply chain can appropriately protect FCI and CUI and meet applicable contractual requirements.

For small and midsized defense suppliers, this can make cybersecurity readiness a competitive issue as well as a compliance issue.

The Biggest Mistake Is Treating DFARS, CMMC, and NIST 800-171 as Three Separate Projects

One of the easiest ways to make compliance more complicated than necessary is to treat each acronym as an entirely separate initiative.

They overlap.

A better approach is to build a coordinated cybersecurity compliance program around the information your organization handles and the contractual requirements that apply to it.

That means understanding:

  • Where FCI and CUI enter your organization
  • Where that information is stored
  • Who has access to it
  • Which systems process or transmit it
  • Which contractual clauses apply
  • Which NIST SP 800-171 requirements must be implemented
  • What documentation supports those controls
  • What evidence demonstrates implementation
  • What CMMC assessment level may be required
  • Which requirements must flow down to subcontractors

The goal should not be to collect three separate piles of compliance paperwork.

The goal should be to create a cybersecurity environment where your technical controls, policies, documentation, contracts, and assessment readiness support one another.

How Do I Know Which Requirements Apply to My Company?

There is no single answer that applies to every defense contractor.

Start by asking these questions:

Do we have DoD contracts or subcontracts?

Review the cybersecurity clauses included in them.

Do we handle Federal Contract Information?

If yes, CMMC Level 1 requirements may become relevant when required by the applicable solicitation or contract.

Do we process, store, or transmit CUI?

If yes, additional cybersecurity requirements may apply, including requirements connected to NIST SP 800-171 and potentially CMMC Level 2.

What does our contract actually say?

Never rely solely on a general article, webinar, vendor statement, or CMMC headline to determine your contractual responsibilities.

Are requirements being flowed down from a prime contractor?

Subcontractors should carefully review the cybersecurity obligations included in their agreements.

Can we prove our cybersecurity requirements are actually implemented?

Policies alone are not enough. Organizations should be prepared to demonstrate how applicable security requirements operate within their environment.

What Should Defense Contractors Do Now?

With CMMC implementation evolving, waiting for the next announcement may seem tempting.

For organizations with existing contractual cybersecurity responsibilities, that approach can create unnecessary risk.

Instead, consider these practical steps.

1. Review Your Contracts

Identify applicable DFARS clauses and other cybersecurity requirements in your current contracts and subcontracts.

2. Identify FCI and CUI

Determine whether your organization receives, processes, stores, or transmits FCI or CUI.

Then identify the people, systems, applications, devices, and service providers that interact with that information.

3. Evaluate Your Current NIST SP 800-171 Implementation

If NIST SP 800-171 applies to your organization, determine where your current security program meets the applicable requirements and where gaps remain.

4. Review Your Documentation and Evidence

Compliance is not only about having security tools.

Your organization may need policies, procedures, system documentation, assessment records, and evidence demonstrating that cybersecurity requirements are implemented.

5. Understand Your Potential CMMC Level

Determine which CMMC requirements could apply to the work your company performs or plans to pursue.

6. Keep Moving Forward

Changing timelines can provide additional preparation time.

They should not automatically be interpreted as permission to ignore existing contractual cybersecurity responsibilities.

Still Trying to Make Sense of CMMC? Join Us in Denver

Reading about DFARS, CMMC, and NIST SP 800-171 can help clarify the terminology.

Applying those requirements to your actual contracts, systems, CUI, and business is where the questions usually get more complicated.

That is exactly why eCreek IT Solutions is hosting CMMC Chaos, a complimentary CMMC event for Colorado defense contractors, manufacturers, engineering firms, aerospace suppliers, construction contractors, and other organizations working within or looking to enter the Defense Industrial Base.

The event takes place Thursday, August 27, 2026, from 6:00 PM to 9:00 PM at Carboy Winery in Denver.

The discussion will focus on practical questions businesses are asking right now, including:

  • What do the latest CMMC developments mean for defense contractors?
  • Which DFARS and NIST SP 800-171 requirements still matter today?
  • What could prime contractors continue to expect from suppliers?
  • Should organizations continue preparing for CMMC?
  • What should defense contractors focus on while the DoD reviews the program?

This is designed to be a practical conversation, not another technical seminar filled with compliance terminology.

Attendees will have an opportunity to hear multiple perspectives, ask questions, connect with other members of Colorado’s defense contracting community, and walk away with a clearer understanding of what their organization should be doing now.

Save Your Spot at CMMC Chaos

DFARS vs. CMMC vs. NIST 800-171: The Bottom Line

You do not need to memorize every acronym to understand how these requirements fit together.

Remember these three concepts:

DFARS = Contractual obligations

NIST SP 800-171 = Security requirements for protecting CUI

CMMC = Assessment and verification

The details become more complicated depending on your contracts, the information you handle, and your place in the defense supply chain, but that basic framework makes the relationship much easier to understand.

Most importantly, changing CMMC implementation timelines do not automatically erase existing cybersecurity responsibilities.

Defense contractors should understand what their contracts require today, determine what sensitive information they handle, identify cybersecurity gaps, and continue building a security program that can support both current contractual obligations and future opportunities.

If you are a Colorado defense contractor and still have questions about what the latest CMMC developments mean for your organization, join the conversation at our CMMC Chaos event in Denver.

Frequently Asked Questions About DFARS, CMMC, and NIST 800-171

What is the main difference between DFARS, CMMC, and NIST 800-171?

DFARS establishes contractual requirements for applicable Department of Defense contractors. NIST SP 800-171 provides security requirements for protecting CUI in nonfederal systems. CMMC establishes an assessment framework for verifying implementation of applicable cybersecurity requirements.

Is NIST 800-171 the same as CMMC?

No. NIST SP 800-171 and CMMC are connected but are not the same. CMMC Level 2 currently uses the 110 security requirements from NIST SP 800-171 Revision 2 as the basis for its security requirements.

Does CMMC replace DFARS?

No. CMMC does not simply replace existing DFARS contractual obligations. Contractors need to understand both the CMMC requirements applicable to a contract and the DFARS clauses included in that contract.

Do I still need NIST 800-171 if CMMC is paused?

If your contract requires implementation of NIST SP 800-171, a CMMC implementation pause does not automatically remove that contractual requirement. Defense contractors should continue to follow the requirements contained in their applicable contracts.

Which version of NIST 800-171 does CMMC Level 2 use?

CMMC Level 2 currently uses the 110 security requirements from NIST SP 800-171 Revision 2. NIST has published Revision 3, but contractors should distinguish the latest NIST publication from the requirements currently incorporated into CMMC Level 2.

Does CMMC apply to subcontractors?

CMMC requirements can apply to subcontractors when applicable requirements are flowed down through contracts and other contractual instruments. Subcontractors should review their agreements carefully rather than assuming CMMC applies only to prime contractors.

What is the difference between FCI and CUI?

Federal Contract Information, or FCI, is information provided by or generated for the government under a contract that is not intended for public release, subject to certain exclusions. Controlled Unclassified Information, or CUI, is information that requires safeguarding or dissemination controls under applicable laws, regulations, and government-wide policies.

Where can Colorado defense contractors learn more about CMMC?

Colorado defense contractors can attend eCreek IT Solutions’ CMMC Chaos event in Denver to hear practical perspectives on CMMC, DFARS, NIST SP 800-171, prime contractor expectations, and what businesses should consider doing in the current compliance environment.