Is CMMC Level 2 the Same as NIST 800-171?
Yes, at the level of the requirements themselves, and the regulation says so in exactly those words: 32 CFR 170.14(c)(3) states that "the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2." Our own crosswalk agrees exactly. In the framework mapping dataset, the CMMC Level 2 lens and the NIST SP 800-171 Rev 2 lens each reach the same 218 distinct NIST SP 800-53 controls, the only identity among the pairings on this site. Read that as consistency rather than proof: both lenses are derived from the same Secure Controls Framework release, whose CMMC Level 2 column cites each practice by its 800-171 Rev 2 requirement number, so the dataset agrees with the regulation because its source does. The contrarian part, and the reason the question keeps getting asked: the standard is identical and the programme is not, and every dollar CMMC adds is spent outside the standard.
This article separates the two things the question is really asking about, shows what the crosswalk says and what it cannot say, lists what CMMC adds on top of the requirements, and gives the practical consequences for a contractor deciding where to spend.
Key takeaways
- 32 CFR 170.14(c)(3) says CMMC Level 2's security requirements are "identical to" those in NIST SP 800-171 R2. This is regulatory text, not a characterisation.
- The CMMC Program final rule states that an organisation seeking assessment at Level 2 "must comply with the 110 Level 2 security requirements derived from NIST SP 800-171 R2."
- Our control crosswalk agrees exactly: 218 shared NIST 800-53 controls out of a 218-control combined footprint, against 63 out of 121 for the next-closest pairing on the site. That agreement is inherited from a shared source, not independent confirmation.
- CMMC adds assessment, affirmation, scoring, POA&M rules and flow-down. None of that is in NIST SP 800-171, and all of it costs money.
- NIST withdrew SP 800-171 Rev 2 in May 2024, and CMMC still points at Rev 2. That is deliberate, and it is the source of most of the confusion in this area.
The question is really two questions
"Is CMMC Level 2 the same as 800-171" is asked by two different people with two different problems.
An engineer asks it about the control set: if I have implemented 800-171, have I implemented CMMC Level 2? The answer there is yes by regulation, and the crosswalk section below shows our dataset agreeing with it, and says why that agreement is not independent evidence.
A contracts or finance lead asks it about obligation: if I already comply with 800-171 under DFARS, why is CMMC a project? The answer there is no, and the gap is not in the requirements at all. It is in what has to be proved, by whom, to what standard, and with what consequences for getting it wrong.
Both answers are correct. Conflating them is what produces the two wrong postures we see most often: a contractor who assumes CMMC needs a new control programme and rebuilds one they already had, and a contractor who assumes 800-171 compliance means CMMC readiness and discovers at assessment that nothing was evidenced.
What the regulation says, verbatim
Three quotations, because the precise wording is doing the work here.
On Level 1, 32 CFR 170.14(c)(2): "The security requirements in CMMC Level 1 are those set forth in 48 CFR 52.204-21(b)(1)(i) through (xv)."
On Level 2, 170.14(c)(3): "The security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2."
On Level 3, 170.14(c)(4): "The security requirements in CMMC Level 3 are selected from NIST SP 800-172 Feb2021, and where applicable, Organization-Defined Parameters (ODPs) are assigned."
The CMMC Program final rule, published 15 October 2024 and effective 16 December 2024, puts the same point in operational terms: at Level 2 by self-assessment, "The OSA must comply with the 110 Level 2 security requirements derived from NIST SP 800-171 R2." The same rule describes Level 1 as "the 15 security requirements set by FAR clause 52.204-21" and Level 3 as "24 additional requirements derived from NIST SP 800-172."
Note what none of those sentences says. None of them says anything about assessment, scoring, affirmation, or the consequences of a shortfall. That material is elsewhere in Part 170, and it is the part that is genuinely new.
What our crosswalk says, and what it cannot say
Our dataset was not built to answer this question, and it cannot answer it independently either; what it can do is show the identity in full and be clear about where it comes from.
Every framework in it is mapped to NIST SP 800-53 Rev 5, and the CMMC to NIST 800-171 pair page lists the intersection in full. The CMMC Level 2 lens reaches 218 distinct NIST 800-53 controls. The NIST SP 800-171 Rev 2 lens reaches 218. The shared set is 218, so the union is 218 and the two lenses agree on every control.
For scale, the next-closest pairing on the site is ISO/IEC 42001 to the NIST AI Risk Management Framework, at 63 shared out of a 121-control union. Third is SOC 2 to NIST CSF 2.0, at 175 out of 359. Nothing else is remotely near an identity, and we explain the general shape of these numbers in how much do compliance frameworks actually overlap.
Why the agreement is exact is the less flattering and more useful fact. Both lenses are generated from the Secure Controls Framework 2026.2 workbook, and its CMMC Level 2 column cites each practice by its NIST SP 800-171 Rev 2 requirement number, so every CMMC practice inherits the 800-53 controls of the 800-171 requirement it names. A perfect score here is one source being consistent with itself, not two tables built separately arriving at the same answer. We say so rather than presenting the identity as evidence, because a crosswalk that reports perfect agreement without saying where both sides came from invites exactly that misreading. The regulation remains the authority; the dataset merely does not contradict it.
The wider spread is worth a look for scoping. The 218 shared controls touch all 20 NIST 800-53 families, led by Access Control (37), System and Communications Protection (37), Physical and Environmental Protection (17), Audit and Accountability (16) and Configuration Management (14). If you are budgeting an 800-171 or CMMC remediation, that ranking is a reasonable first cut at where the work concentrates.
What CMMC adds that 800-171 never asked for
This is the answer to the contracts lead's version of the question. NIST SP 800-171 is a set of security requirements. CMMC is a programme wrapped around them, and the wrapper is where the project lives.
Assessment. 800-171 obliged implementation. CMMC defines who assesses it, at what level, and with what independence. Choosing a third-party assessor and preparing for the visit is its own workstream, and implementing the control set does not prepare you for it.
Affirmation. A senior company official affirms continuing compliance, which converts an internal status into a representation to the government. That changes the risk profile of an optimistic self-assessment considerably.
Scoring. The Supplier Performance Risk System score is not a percentage and not a pass mark; it is a weighted deduction methodology keyed to Rev 2 requirement identifiers. How to calculate your SPRS score works through the mechanics.
POA&M rules. 800-171 is silent on what may be deferred. CMMC is not, and the rules on which requirements can sit on a plan of action are narrow. See CMMC POA&M rules.
Scope and flow-down. Which systems are in the assessment boundary, and what your subcontractors owe, are CMMC constructs. Flow-down requirements for subcontractors covers the second, and the assessment boundary is the first thing a readiness engagement has to settle.
None of those five appears anywhere in NIST SP 800-171. All five appear in every CMMC programme plan we have seen. That is the entire answer to why a contractor already implementing 800-171 still has a project.
The revision trap
There is one more reason this question produces bad answers, and it is a genuine landmine rather than a quibble.
NIST's own publication page records that SP 800-171 Rev 2 was "Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3." So the standard CMMC Level 2 is defined against is, from NIST's point of view, no longer current. CMMC still points at Rev 2 regardless: 32 CFR 170.14(c)(3) names "NIST SP 800-171 R2" by number, and the final rule repeats the same revision throughout.
The practical consequence is that a source describing "the current NIST 800-171" and a source describing "what CMMC requires" can both be accurate and be describing different documents. We do not publish a view here on which revision any particular contract clause pins, because that turns on the clause and the contract date and it is exactly the kind of statement that is wrong six months after it is written. If you take one operational point from this article, take this one: check which revision a vendor's gap assessment was written against, and against which instrument, before you accept its findings.
The honest caveat
Three things this article is not claiming.
A mapping table is not a legal opinion. Our crosswalk agrees with the regulation, which is reassuring, but if it disagreed the regulation would still be the answer. Use the dataset to plan work, not to interpret an obligation.
Requirement identity does not mean assessment equivalence. Meeting a requirement and evidencing it to an assessor's satisfaction are different tasks, and the second one is where first-time assessments go wrong. An assessor works to assessment objectives in a companion publication, not to the requirement sentence.
The programme is in motion. The phased introduction of CMMC assessment requirements beyond the first phase is currently suspended, which changes when an outside assessor arrives and nothing about what you owe in the meantime. What still applies during the suspension is the current status; treat any article on this subject, including this one, as needing a date check.
Against our own interest: if you have a current, honest SPRS score built on real implementation, and your scope is a single enclave, the gap between where you are and CMMC Level 2 readiness may be small enough that an outside readiness engagement is not the best use of the budget. Evidence organisation and a mock assessment usually beat a second gap assessment of a control set you already know.
Where Top Floor fits
Our CMMC readiness work is scoped around the wrapper rather than the control list, because the control list is the part the regulation already settled. That means scope definition, evidence structure, System Security Plan quality, POA&M discipline, and a mock assessment against the objectives an assessor will actually use. We are a readiness partner and not an authorised assessor, and those roles cannot be held by the same firm for the same client.
Where the work spans more than defense, compliance as a service is the multi-framework version, and audit and assurance readiness is the independent look at whether your evidence survives a different reader.
How to decide this week
Pull your most recent 800-171 self-assessment and check three things before you buy anything.
First, which revision it was written against. If the answer is Rev 3, or the document does not say, the findings need re-basing before they mean anything for CMMC.
Second, whether each implemented requirement has evidence attached that a stranger could follow, or only a status field. Requirement identity means your control work transfers to CMMC completely. It says nothing about whether your evidence does, and that is the gap most first assessments actually fail on.
Third, whether the boundary in your System Security Plan matches the systems that actually handle Controlled Unclassified Information today. Scope drift between the plan and reality is the most expensive finding to fix late, and it is a CMMC construct that 800-171 compliance alone never forced you to settle.
Frequently asked questions
Does implementing NIST 800-171 mean we are CMMC Level 2 compliant?
At the level of the security requirements, yes: 32 CFR 170.14(c)(3) says the CMMC Level 2 requirements are identical to those in NIST SP 800-171 R2, and our own control crosswalk agrees control for control, 218 of 218, because both lenses derive from the same source. At the level of the CMMC programme, no. CMMC adds assessment, senior official affirmation, SPRS scoring, POA&M limits, and defined assessment scope, none of which appears in NIST SP 800-171. Implementation transfers completely; readiness does not.
How many security requirements are in CMMC Level 2?
The CMMC Program final rule states that an organisation seeking assessment at Level 2 must comply with the 110 Level 2 security requirements derived from NIST SP 800-171 R2. Level 1 is the 15 requirements in FAR clause 52.204-21, and Level 3 adds 24 requirements derived from NIST SP 800-172 on top of Level 2.
Which revision of NIST 800-171 does CMMC use?
Revision 2. NIST withdrew Rev 2 on 14 May 2024 and superseded it with Rev 3, but 32 CFR 170.14(c)(3) names Rev 2 by number and the CMMC Program final rule repeats it. That means the current NIST publication and the revision CMMC is defined against are different documents, which is a genuine trap when reading vendor material. Check which revision any gap assessment or vendor claim was written against before you rely on it.
Why does the crosswalk agree exactly, and does that prove the requirements are identical?
It agrees because both lenses are derived from the same Secure Controls Framework release, whose CMMC Level 2 column cites each practice by its NIST SP 800-171 Rev 2 requirement number, so the two sides inherit the same NIST SP 800-53 controls by construction. That is consistency with the regulation, not proof of it; the proof is 32 CFR 170.14(c)(3), which is the authority on the underlying question. We say where both sides come from rather than presenting a perfect score as independent evidence, because a mapping that reports perfect agreement usually means one side was built from the other, and here that is exactly what happened.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.