BisGentech logo
    AI & Technology Assessment
    AI & Technology Assessment
    Back to Insights

    Cybersecurity & Resilience

    CUI, NIST SP 800-171, and CMMC; How They Fit Together

    Confused by CUI, NIST SP 800-171, and CMMC? Learn how the information type, security requirements, and assessment framework connect in defense contracting.

    Benjamin IsidoreSeptember 29, 202612 min read

    Current as of September 30, 2026. CMMC implementation requirements continue to evolve; businesses should verify the requirements in the applicable solicitation, contract, subcontract, and current federal guidance.

    CUI, NIST SP 800-171, and CMMC are related, but they are not interchangeable.

    A simple way to think about them is:

    • CUI describes the information that requires protection.
    • NIST SP 800-171 describes security requirements for protecting CUI in applicable nonfederal systems.
    • CMMC provides an assessment framework used in applicable defense contracting situations to verify implementation of required cybersecurity practices.

    That distinction matters because businesses can waste time and money when they start with “Which certification do I need?” before understanding what information they actually handle and what their contract requires.

    Start With CUI

    Controlled Unclassified Information, or CUI, is information that requires safeguarding or dissemination controls under applicable law, regulation, or government-wide policy but is not classified information.

    For contractors, the practical question is not simply whether the company works with the federal government.

    It is:

    Does the organization receive, create, process, store, or transmit information that has been identified as CUI?

    NIST explains that SP 800-171 applies to components of nonfederal systems that process, store, or transmit CUI, or provide security protection for those components.

    That makes information identification and system scoping foundational.

    CUI Is Not the Same as Every Piece of Government Information

    Not all government-related information is CUI.

    Some information may be public.

    Some may be Federal Contract Information.

    Some may qualify as CUI because of the category involved and the applicable safeguarding requirements.

    For a defense contractor, relying on assumptions can create problems in both directions:

    • treating ordinary information as CUI can expand scope unnecessarily;
    • failing to recognize actual CUI can leave required protections out of scope.

    The applicable solicitation, contract, data markings, program guidance, and contracting direction should help determine what information must be protected.

    NIST SP 800-171 Defines the Security Requirements

    Once CUI is present in an applicable nonfederal environment, NIST SP 800-171 becomes important.

    NIST SP 800-171 Revision 3, published in May 2024, is the current NIST publication.

    It provides recommended security requirements for protecting the confidentiality of CUI in nonfederal systems and organizations.

    Its scope includes system components that:

    • process CUI;
    • store CUI;
    • transmit CUI;
    • or provide security protection for those components.

    That means the standard is not simply a policy checklist.

    It affects the actual systems, users, applications, networks, services, and security components involved with CUI.

    NIST SP 800-171A Explains How Requirements Can Be Assessed

    NIST SP 800-171 tells organizations what security requirements should be implemented.

    NIST SP 800-171A provides assessment procedures for evaluating those requirements.

    The current NIST SP 800-171A Revision 3 was published in May 2024.

    NIST describes it as a methodology and set of assessment procedures organizations and assessors can use to evaluate implementation of SP 800-171 requirements.

    This creates an important distinction:

    Implementing a requirement and demonstrating that it is implemented are different activities.

    A business may have a security tool in place but still need evidence that the associated requirement is operating as intended.

    Then Where Does CMMC Fit?

    CMMC sits on top of this broader protection and assessment structure for applicable defense contracting.

    It does not create CUI.

    It does not replace NIST SP 800-171.

    Instead, CMMC provides a structured way for the Department to evaluate whether required cybersecurity practices have been implemented when the CMMC requirement applies to a solicitation or contract.

    This is why the sequence matters:

    Information → Security Requirements → Assessment Requirement

    or, in practical terms:

    CUI → NIST SP 800-171 → CMMC

    That is a conceptual sequence, not a substitute for reading the actual contract.

    CMMC and NIST Revision Numbers Require Care

    This is one of the most important distinctions in the current environment.

    The current NIST publication is:

    NIST SP 800-171 Revision 3.

    However, current CMMC Level 2 guidance still references the 110 requirements in NIST SP 800-171 Revision 2 for CMMC purposes.

    That means a business should not automatically assume:

    “Revision 3 is newer, so Revision 3 must be the CMMC assessment baseline.”

    That conclusion may be wrong for the specific procurement.

    The correct baseline depends on the applicable:

    • rule;
    • solicitation;
    • contract;
    • subcontract;
    • assessment methodology;
    • and current Department guidance.

    This is particularly important during the current CMMC transition period.

    DFARS Adds Another Layer

    Defense contractors may also encounter DFARS cybersecurity clauses.

    DFARS 252.204-7012 addresses safeguarding covered defense information and cyber incident reporting.

    Where applicable, it establishes cybersecurity obligations involving covered contractor information systems, covered defense information, incident reporting, cloud services, and subcontractors.

    This is why a contractor cannot rely on a CMMC article alone to determine its obligations.

    The contract clauses matter.

    The DoD Assessment Process Is Also Related, but Distinct

    DFARS includes separate NIST SP 800-171 DoD assessment requirements.

    DFARS 252.204-7020 addresses NIST SP 800-171 DoD Assessment Requirements for applicable solicitations and contracts.

    The DoD assessment framework includes Basic, Medium, and High assessment approaches, with different levels of government review and validation.

    This assessment process and CMMC are related parts of the broader defense cybersecurity ecosystem, but they should not be casually treated as identical.

    A business should determine which assessment obligations actually appear in the applicable procurement.

    Think in Layers

    For a small business, it can help to think about the requirements in layers.

    Layer 1: What Information Do We Handle?

    Determine whether the organization receives or creates:

    • public information;
    • FCI;
    • CUI;
    • covered defense information;
    • or another category of protected information.

    Layer 2: What Contract Clauses Apply?

    Review the solicitation, contract, subcontract, and flow-down clauses.

    Layer 3: What Systems Are in Scope?

    Identify systems that:

    • process the information;
    • store it;
    • transmit it;
    • or provide security protection for those systems.

    Layer 4: What Security Requirements Apply?

    Determine which NIST, FAR, DFARS, or other requirements are incorporated into the procurement.

    Layer 5: What Assessment Is Required?

    Determine whether the procurement requires:

    • a self-assessment;
    • a DoD NIST SP 800-171 assessment;
    • a CMMC assessment;
    • a C3PAO assessment;
    • another government assessment;
    • or some combination.

    This layered approach helps prevent the business from beginning with the wrong question.

    A System Security Plan Connects the Requirements to the Environment

    One of the key artifacts in this process is often the System Security Plan, or SSP.

    The SSP should describe the system boundary and how applicable security requirements are implemented within the environment.

    That makes it more than a compliance document.

    A useful SSP helps answer:

    • what systems are covered;
    • where CUI exists;
    • which requirements protect it;
    • who is responsible;
    • what dependencies exist;
    • and where gaps remain.

    Current DFARS assessment requirements tie the NIST SP 800-171 assessment process to review of the contractor's system security plan or plans.

    An SSP, however, does not by itself prove that the organization complies with every requirement.

    Documentation, implementation, and supporting evidence all matter.

    Scope Can Have a Major Cost Impact

    A poorly defined CUI boundary can make compliance substantially harder.

    If CUI is allowed to spread across:

    • every employee device;
    • every file-sharing platform;
    • multiple cloud environments;
    • unrestricted email;
    • numerous SaaS tools;
    • and broad administrative access,

    the number of systems that may require protection increases.

    A carefully designed environment may reduce unnecessary exposure by limiting where CUI is processed, stored, and transmitted.

    That is not about avoiding requirements.

    It is about understanding the actual system boundary so the business protects the right environment.

    Cloud Services Do Not Automatically Solve the Requirement

    Using Microsoft, AWS, Google Cloud, or another major cloud provider does not automatically make the organization compliant with CUI requirements.

    The organization still needs to understand:

    • whether the service is appropriate for the intended use;
    • what configuration is required;
    • who controls access;
    • what contractual requirements apply;
    • what evidence exists;
    • and whether the service itself falls within the defined system boundary.

    This connects directly to the shared-responsibility principles discussed in Article 6.

    Do not assume that purchasing a particular cloud service, license, or security product automatically satisfies CMMC, DFARS, or NIST SP 800-171 requirements.

    Vendors Can Become Part of the CUI Environment

    Managed service providers, cloud providers, security providers, software vendors, and other third parties can become relevant if they:

    • access CUI;
    • store CUI;
    • transmit CUI;
    • administer systems containing CUI;
    • or provide security protection to systems in scope.

    DFARS 252.204-7012 also contains subcontract flow-down requirements where applicable.

    That means vendor-risk management and CUI protection often intersect.

    A business should understand what its providers do, what information they can access, and how their services relate to the defined environment and contractual requirements.

    Documentation Does Not Replace Implementation

    A company can have:

    • policies;
    • procedures;
    • diagrams;
    • an SSP;
    • a risk register;
    • and assessment spreadsheets

    and still have security gaps.

    Likewise, a company can have strong technical controls but weak documentation and evidence.

    A defensible environment needs both:

    implementation and evidence.

    That is why NIST distinguishes between the security requirements in SP 800-171 and the assessment procedures in SP 800-171A.

    Current CMMC Status Still Matters

    As of September 30, 2026, Phase I self-assessment requirements remain in effect.

    The Department suspended the planned Phase II requirements on July 13, 2026 and announced a broader review of the program.

    This means businesses should not rely on an old implementation chart or assume that every previously announced milestone remains unchanged.

    The safest approach is to verify the current requirements against the actual procurement and current official federal guidance.

    A Practical Decision Path

    When a small business encounters CUI or a CMMC requirement, the sequence should look something like this:

    1. Identify the Information

    Determine whether CUI is actually involved.

    2. Review the Procurement

    Identify applicable FAR, DFARS, CMMC, and other cybersecurity clauses.

    3. Define the System Boundary

    Determine where the information is processed, stored, transmitted, and protected.

    4. Identify the Required Security Baseline

    Confirm which version of NIST SP 800-171 or other standard applies.

    5. Assess the Current Environment

    Determine what is implemented and what is missing.

    6. Document the Environment

    Maintain the SSP, policies, procedures, diagrams, inventories, and supporting evidence appropriate to the requirement.

    7. Address Gaps

    Remediate missing or partially implemented requirements.

    8. Prepare for the Required Assessment

    Follow the assessment path specified by the procurement.

    9. Maintain the Environment

    Continue managing users, systems, vendors, evidence, changes, incidents, and reassessments.

    The Relationship in One Sentence

    For a small defense contractor, the simplest accurate summary is:

    CUI tells you what needs protection; NIST SP 800-171 tells you how the applicable nonfederal environment should protect it; CMMC helps determine how implementation is assessed when the CMMC requirement applies.

    The contract determines how those pieces apply to your specific situation.

    Not Sure How These Requirements Apply to Your Environment?

    CUI protection can involve IT infrastructure, cloud services, identity management, endpoints, policies, vendors, security controls, documentation, and assessment evidence.

    The BisGentech AI & Technology Assessment can help clarify your current technology environment, identify the areas that deserve attention first, and determine a practical next step.

    Key Takeaways

    • CUI, NIST SP 800-171, and CMMC are distinct but connected: CUI is the information that requires protection, NIST SP 800-171 defines the security requirements for protecting CUI in applicable nonfederal systems, and CMMC is the assessment framework used to verify implementation when the CMMC requirement applies. The conceptual sequence is CUI → NIST SP 800-171 → CMMC.
    • NIST SP 800-171 Revision 3 is the current NIST publication, but current CMMC Level 2 guidance still references NIST SP 800-171 Revision 2. The correct baseline depends on the applicable rule, solicitation, contract, subcontract, assessment methodology, and current Department guidance — not on which publication is newest.
    • As of September 30, 2026, Phase I self-assessment requirements remain in effect. The Department suspended the planned Phase II requirements on July 13, 2026 and announced a broader review. Verify current requirements against the actual procurement and current official federal guidance rather than relying on outdated implementation charts.
    • An SSP documents the system boundary and how requirements are implemented, but an SSP alone does not prove compliance. Documentation, implementation, and supporting evidence are separate concerns; a defensible environment needs both implementation and evidence.
    • DFARS clauses — including 252.204-7012 and the NIST SP 800-171 DoD assessment requirements in 252.204-7020 — can add obligations separate from CMMC. Cloud providers and vendors can also enter the CUI environment. The applicable solicitation and contract, not a general article, determine what applies.

    Sources and References

    1. NIST — NIST SP 800-171 Revision 3 (Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations) (source)
    2. NIST — NIST SP 800-171A Revision 3 (Assessing Security Requirements for Controlled Unclassified Information) (source)
    3. NIST — NIST Protecting Controlled Unclassified Information Project (source)
    4. Acquisition.gov / DFARS — DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (source)
    5. Acquisition.gov / DFARS — DFARS Part 204, Administrative and Information Matters (source)
    6. Acquisition.gov / DFARS — DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements (source)
    7. DoD Office of Small Business Programs — Official CMMC Program Information (source)
    8. DoD Office of Small Business Programs — Official CMMC Announcements (including the July 13, 2026 Phase II suspension notice) (source)

    About the Author

    Benjamin Isidore

    Founder & CEO, BisGentech

    Benjamin Isidore is the Founder and CEO of BisGentech. He helps growing small and medium-sized businesses clarify technology decisions, improve operations, and strengthen security with practical, business-first guidance built on more than 24 years of technology leadership.