
NIST 800-171 and CMMC Level 2 Compliance
A practical guide for DIB contractors navigating the 14 control families, SPRS scoring and the road to third-party certification
Quick Answer:
CMMC Level 2 compliance requires implementing all 110 NIST 800-171 controls and passing a C3PAO audit. Contractors must align systems, documentation, and SPRS scoring while closing gaps in access control, logging, and incident response to remain eligible for DoD contracts.
Somewhere in your organization, a contract officer is reviewing a solicitation that includes DFARS 252.204-7021. If any of the following describes your organization, that contract may not be yours to win:
- Your Supplier Performance Risk System (SPRS) score isn’t current
- Your cybersecurity documentation is incomplete
- Your System Security Plan is still a work in progress
- Your POA&Ms aren’t resourced or tracked
This compliance gap isn’t a distant regulatory threat. As of November 10, 2025, the 48 CFR Cybersecurity Maturity Model Certification Acquisition Rule became enforceable, meaning CMMC clauses now appear in DoD solicitations. Phase 2, which mandates Level 2 third-party certification from a C3PAO for contracts involving Controlled Unclassified Information (CUI), goes into effect in November 2026. The window to get ready is narrower than most contractors realize, and the groundwork for certification typically takes 12 to 18 months to establish.
NIST Special Publication 800-171 is the technical foundation underneath all of this. It defines the 110 security requirements that map directly to CMMC Level 2’s 110 practices. Understanding that relationship and, more importantly, understanding what it demands of your people, systems and documentation is where the real compliance work begins.
This article walks you through what NIST 800-171 compliance looks like on the ground for a DIB contractor: the 14 control families, how SPRS scoring works, where contractors most consistently fall short and how Red River’s managed services combined with Abacode’s assessment expertise close those gaps before a third-party auditor finds them first.
The NIST 800-171 / CMMC Level 2 Relationship, Plainly Explained
CMMC Level 2 does not introduce its own security requirements. It codifies NIST SP 800-171, the same control set that has governed how defense contractors handle CUI since DFARS 252.204-7012 went into effect in 2017. NIST published Revision 3 in May 2024, but the DoD locked CMMC assessments to Revision 2 through a class deviation. C3PAO assessors are still benchmarking against it, SPRS doesn’t accept Rev. 3-based scores, and no formal transition timeline has been set. Revision 2 is what your assessor will use.
What CMMC adds is verification. Under the old regime, contractors self-attested to compliance. Under CMMC Level 2, that self-attestation gets replaced by an assessment conducted by a Certified Third-Party Assessment Organization (C3PAO), an independent auditor who will scrutinize your evidence, interview staff and test the controls you’ve applied.
The 110 practices in CMMC Level 2 map one-for-one to the 110 requirements in NIST 800-171, organized across 14 control families. Those families are:
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
Each family carries a different weight in the scoring methodology, which matters a great deal once you understand how SPRS works.
SPRS Scoring: What It Measures and Why It’s Not Enough on Its Own
The Supplier Performance Risk System is where your CMMC assessment score lives, and contracting officers check it. Your SPRS score for NIST 800-171 starts at 110 points. Each of the 110 practices has an assigned value ranging from one to five points. Every unimplemented practice subtracts from that total. Scores can go deeply negative if enough high-value controls are missing.
Here’s where contractors frequently misjudge the situation: posting a score in SPRS, even a positive one, does not equal compliance. A score reflects a self-assessment. It can reflect an optimistic one, or an uninformed one. CMMC Level 2 requires a C3PAO to independently validate the accuracy of your score and that the underlying controls are genuinely operational, not just documented. If an assessor finds discrepancies between your SPRS score and your actual implementation, that gap becomes a serious problem, one with potential False Claims Act exposure, not just a failed audit.
Plans of Action and Milestones, known as POA&Ms, are the mechanism CMMC provides for addressing gaps that haven’t fully closed at assessment time. Under Level 2, POA&Ms are permitted for non-critical controls, but are subject to strict timelines and closure criteria. However, they are not a blank check. Critical controls, those the DoD has designated as foundational, must be fully implemented before the certification process proceeds. For non-critical controls, the DoD allows a maximum of 180 days from conditional certification to close out open POA&Ms. Miss that window and conditional status lapses, which means no final certification or contract eligibility.
Treating your POA&M as a compliance strategy rather than a temporary exception is one of the fastest ways to fail an assessment.
A well-structured POA&M:
- Specifically identifies each incomplete control
- Assigns an owner and a realistic completion date within DoD-prescribed limits
- Links to a funded, resourced remediation plan rather than wishful thinking
- Reflects evidence that the organization is actively closing the gap
The organizations that handle this well treat POA&Ms as a sign of a mature compliance program, not a workaround. The goal is to enter your C3PAO assessment with your POA&M list as short as possible.
Where DIB Contractors Commonly Fall Short
After years of helping defense contractors prepare for and navigate CMMC assessments, Red River’s cybersecurity partner Abacode has identified consistent patterns in where organizations fail to meet NIST 800-171 requirements. Perhaps surprisingly, the gaps aren’t usually in obscure corners of the control set. They cluster in three domains that most contractors believe they have covered.
Access Control
Access Control is the largest family in NIST 800-171, with 22 requirements. It also generates the most findings during assessments. The issues typically aren’t about whether multi-factor authentication is enabled or whether privileged accounts exist. Most contractors have done the basics. The problems emerge in the details:
- System access isn’t limited to the minimum necessary to perform authorized tasks
- Separation of duties isn’t enforced or documented
- Remote access sessions aren’t controlled and monitored the way the control requires
- CUI enclave boundaries aren’t clearly defined, so access controls apply inconsistently across systems that touch sensitive data
- Least-privilege isn’t enforced within the enclave, and access decisions aren’t documented or periodically reviewed
Access control findings are rarely a surprise to experienced assessors. They know exactly where to look, and years of assessment data have mapped precisely where contractors cut corners, make assumptions or simply run out of time before an audit. What catches organizations off guard is not the access control findings themselves but the downstream effect: a weak enclave boundary and inconsistent least-privilege enforcement create cascading evidence gaps in the audit logging and incident response domains that follow. Contractors who shore up access control thoroughly tend to find the next two areas more manageable. Those who don’t tend to find that one gap becomes three.
Audit Logging and Accountability

Audit logging sounds straightforward until an experienced assessor starts asking for proof. AU.L2-3.3.5 requires organizations to review and analyze audit logs for indications of inappropriate or unusual activity, and that requirement goes well beyond collecting logs. Most contractors collect logs. Far fewer have a defined process for reviewing them, documented review frequency and evidence that reviews are happening on schedule rather than sitting as an unchecked capability on a compliance checklist.
Assessors want to see operational proof: tickets, triage notes and SIEM dashboards showing active monitoring. Contractors lose points in the gap between having a SIEM deployed and demonstrating that it’s in use as required.
The reality of these new requirements becomes more manageable when you realize continuous monitoring isn’t a technology purchase. It’s an operational discipline, and without the human analyst time and documented workflows to back it up, the technology sitting in your environment is just evidence of a capability you haven’t built.
Incident Response Documentation
IR.L2-3.6.1 requires an operational incident-handling capability that your team can execute under pressure, not just a plan that satisfies a documentation requirement. What assessors find far too often is an incident response plan that exists in a binder or a shared drive but has never been tested, doesn’t have current contact information and couldn’t guide a team through a real event.
A mature incident response program runs tabletop exercises, documents what they reveal and updates procedures accordingly. A plan sitting untouched for two years is not a compliant incident response program, regardless of how professionally it reads.
The Timeline You Can’t Afford to Misread
Phase 1 of CMMC, active since November 10, 2025, allows DoD contracting officers to require Level 2 certification in select solicitations at their discretion. Phase 2 begins November 10, 2026. At that point, third-party C3PAO certification for contracts involving CUI becomes a mandatory condition of award, not an optional demonstration of cyber maturity.
Preparation typically takes 12 to 18 months. Assessor scheduling, with a still-limited pool of C3PAOs, adds additional lead time. Prime contractors are also increasingly flowing CMMC requirements down to their subcontractors ahead of contractual deadlines, which means the effective date for many organizations in the supply chain is earlier than the official Phase 2 date.
There is also a False Claims Act dimension that CIOs and legal teams should understand. Organizations that self-certify compliance in SPRS and then fail to meet the requirements they attested to face potential civil liability, not just contract consequences. The Department of Justice now treats cybersecurity-related FCA enforcement as a stated priority. That risk changes the calculus for how organizations should treat their SPRS scores and their POA&M management.
If your organization hasn’t started a formal NIST 800-171 gap assessment, the clock is running. If you have started but your SSP is incomplete, your POA&M isn’t resourced, or your monitoring program isn’t generating operational evidence, the clock is running faster than you may realize. That urgency is exactly why the Red River and Abacode partnership exists.
How Red River and Abacode Close Your CMMC Compliance Gaps
Achieving CMMC Level 2 certification is a two-phase challenge: you must implement the controls, and then prove to an independent assessor that you implemented them correctly.
Red River’s managed services infrastructure makes control implementation sustainable. These aren’t checkbox deployments. They’re operational programs that generate the evidence an assessor needs to see.
Red River delivers:
- 24/7 Security Operations Center monitoring that satisfies audit logging and continuous monitoring requirements
- Endpoint detection and response aligned to NIST 800-171’s SI family
- Identity and access management that maps directly to the AC and IA control families
- Vulnerability management and patch workflows that produce documented, time-stamped evidence
That evidence matters when a C3PAO assessor asks for proof. Red River can supply:
- Time-stamped logs showing active monitoring
- Incident tickets demonstrating response workflows
- Monitoring dashboards with operational activity
- Policy-to-procedure traceability across control families
We design our cybersecurity managed services for organizations that need a defensible security program, not just a compliance document.
Abacode brings the assessment expertise. As a Cyber AB Registered Practitioner Organization, Abacode has successfully guided clients through C3PAO and DIBCAC assessments. Their approach starts with a thorough gap assessment against the 110 NIST 800-171 practices, the same methodology an assessor will use, and produces a prioritized remediation roadmap. From there, Abacode takes ownership of the compliance program end to end:
- Manages and maintains the System Security Plan
- Coordinates control ownership across the organization
- Curates the evidence repository so assessors find what they need
- Serves as the primary liaison through the formal C3PAO engagement
- Monitors ongoing control health through a continuous compliance portal so organizations don’t slip between annual affirmations
Most single-vendor CMMC programs deliver either the security technology or the compliance expertise, rarely both. What that means in practice is that a contractor can have a fully deployed security stack and still walk into a C3PAO assessment without the documented evidence, tested procedures and traceable control ownership an assessor expects to see. Red River and Abacode close that gap by design, combining operational security infrastructure with compliance program management to turn implementation into certification.
Ready to Assess Where You Stand?
Red River and Abacode offer a structured NIST 800-171 gap assessment that maps your current controls against all 110 practices, produces a prioritized remediation roadmap and positions you for a successful C3PAO engagement. Contact Red River to start the conversation before your next solicitation starts it for you.
Q&A
written by
Corrin Jones
Corrin Jones is the Director of Digital Demand Generation. With over ten years of experience, she specializes in creating content and executing campaigns to drive growth and revenue. Connect with Corrin on LinkedIn.
