CMMC & 800-171: Readiness for the Defense Supply Chain
CMMC formalizes what NIST 800-171 already required — the difference now is that compliance has to be demonstrated and verified, not just claimed.
The business problem
Companies in the defense industrial base — prime contractors and their subcontractors — have long been contractually required to implement NIST 800-171 controls to protect Controlled Unclassified Information (CUI), but historically that requirement was largely self-attested. The Cybersecurity Maturity Model Certification (CMMC) program changes that: it requires independent (or, for lower levels, self-assessed but formally certified) verification, and companies that assumed self-attestation was sufficient are now facing a real assessment gap.
How CMMC relates to 800-171
CMMC doesn’t introduce a new control set from scratch — its middle tier (Level 2) is built directly on NIST 800-171’s 110 security requirements. What CMMC adds is a formal certification process and, depending on level and contract, a requirement for a third-party assessment rather than self-attestation alone. A company already genuinely 800-171 compliant has done most of the substantive work; what’s new is proving it to an independent assessor.
What readiness actually requires
Real readiness means every one of the 110 controls is implemented and evidenced — not just described in a policy — with a System Security Plan (SSP) documenting how each requirement is met and a Plan of Action & Milestones (POA&M) for anything not yet fully implemented. Companies that only have policy documents, without operational evidence the controls are actually functioning, tend to fail assessment even when their paperwork looks complete.
“Self-attestation asked what you were doing. CMMC asks you to prove it. That gap — between the policy and the evidence — is where most readiness efforts stall.”
Signs readiness is thinner than it looks
- The System Security Plan describes controls in general terms without specific, verifiable evidence for each requirement
- A significant share of the 110 controls are only "partially implemented," with an aging or incomplete POA&M
- Nobody has mapped which specific systems and data flows actually handle CUI, versus which don’t
- Subcontractor flow-down requirements haven’t been addressed — CMMC obligations extend down the supply chain
- The readiness effort started only after a specific contract deadline made it urgent, leaving little runway
Practical guidance
Start by scoping exactly where CUI lives in your environment — you can’t evidence controls for data flows you haven’t identified. Build a real SSP with specific, verifiable evidence for each of the 110 controls, and maintain an honest, actively-managed POA&M for anything not yet complete rather than letting it go stale. Address subcontractor flow-down requirements early, since your own certification can depend on theirs.
See how NIST and CMMC readiness is structured for prime contractors and subcontractors.
Explore NIST & CMMC ReadinessQuestions, answered directly.
800-171 is the underlying set of 110 security requirements for protecting Controlled Unclassified Information; CMMC is the certification program that verifies — via self-assessment or third-party assessment depending on level — that those requirements are actually in place, rather than relying on self-attestation alone.
Subcontractors are very much in scope if they handle CUI — CMMC requirements flow down the supply chain, and a prime contractor’s own certification can depend on its subcontractors meeting the appropriate level too.
A Plan of Action & Milestones documents any 800-171 requirement not yet fully implemented, along with the plan and timeline to close it — an honest, actively-managed POA&M is a normal part of the process, but a stale or vague one is a common reason readiness efforts stall at assessment.
It varies widely based on starting maturity and how much CUI-handling infrastructure exists, but companies starting from a thin 800-171 baseline should expect this to take significantly longer than a typical SOC 2 or ISO 27001 effort, given the number and specificity of the 110 requirements.
Want a CMMC / 800-171 readiness plan built around your actual contract requirements?
30 minutes. No obligation. No sales pitch.