Steady light for regulated work

Find your bearing on NIST SP 800-171 & CMMC

Beacon is Canopy Harbor’s plain-language guide for modern cloud and hybrid shops that handle Federal contract information (FCI) or Controlled Unclassified Information (CUI). We translate the official framework into readable orientation—without replacing the primary sources or a formal assessment.

What this is about

NIST SP 800-171 is NIST’s catalog of security requirements for protecting CUI in nonfederal systems. CMMC (Cybersecurity Maturity Model Certification) is the DoD program that assesses whether contractors meet those (and related) requirements at defined levels, with results used in contracting.

For cloud / hybrid teams

Identities in Entra ID, devices in Intune, workloads in Azure or SaaS, and logs that someone actually reviews—scope and evidence live across those boundaries.

Level 2 focus

Most CUI conversations center on CMMC Level 2, which aligns to the NIST SP 800-171 Rev. 2 security requirements as incorporated in 32 CFR Part 170.

Orientation, not counsel

Beacon helps you ask better questions and organize work. It is not legal advice, not a certification, and not a substitute for official guides or qualified assessors.

Requirements — ins & outs

CMMC has three levels. Assessment type (self vs third-party / government) matters as much as the level number. Always read your solicitation and the current Code of Federal Regulations—not a blog summary.

Level 1

FCI basics

Aligned to the 15 basic safeguarding requirements in FAR 52.204-21. Typically a self-assessment path for Federal contract information (not CUI).

Level 2

CUI — 800-171 Rev. 2

110 security requirements from NIST SP 800-171 Revision 2. May be self or C3PAO certification assessment, depending on what the contract requires.

Level 3

Enhanced / DIBCAC

Selected enhanced requirements from NIST SP 800-172 for higher-sensitivity programs. Government (DIBCAC) assessment path as defined in the rule.

Assessment objectives & scoring

  • NIST SP 800-171A defines assessment objectives used to decide Met / Not Met.
  • CMMC scoring methodology (32 CFR) measures implementation status; partial credit is limited.
  • Conditional status with a valid POA&M may be allowed under rule constraints—closeout windows apply.

SSP, POA&M, SPRS, monitoring

  • SSP — how your scoped environment implements the requirements.
  • POA&M — tracked gaps with owners and closure criteria (rule-limited for assessments).
  • SPRS — Supplier Performance Risk System entries / affirmations as required by DFARS and the CMMC program.
  • Continuous monitoring — living evidence, not a one-time binder.

Modern environment notes

Expect gap work (and assessors) to look at Entra ID (MFA, Conditional Access, privileged roles), Intune / endpoint compliance and encryption, Azure / M365 configuration and logging, SIEM or Defender review practices, and how SaaS boundaries are drawn (shared responsibility, CRM excerpts, encryption, process controls). “It’s in the cloud” is not a control—evidence is.

Program status changes. Confirm current expectations on dodcio.defense.gov/CMMC before planning contractual milestones (including any published phase / implementation notices).

Company journey guide

A practical outline many teams follow. Durations vary widely with scope size, legacy debt, and staffing— treat timelines as planning ranges, not promises.

  1. Discover scope Inventory contracts, FCI/CUI touchpoints, identities, endpoints, cloud tenants, and external providers. Decide enclave vs broader enterprise assessment scope.
  2. Gap assessment Map NIST SP 800-171 Rev. 2 requirements and 800-171A objectives to reality. Score honestly. Seed the POA&M.
  3. Remediate Close high-impact gaps first: phishing-resistant MFA where needed, admin boundaries, logging/review, encryption, endpoint hygiene, backup/IR readiness.
  4. Document Build a usable SSP, diagrams, policies that match practice, and an evidence index tied to objectives—not orphan screenshots.
  5. Mock assess Internal or advisor dry-run. Fix narrative and artifact gaps before money and calendar are on the line.
  6. Official path Complete self-assessment / SPRS steps when required; engage an authorized C3PAO when your contracts require Level 2 certification assessment.
  7. Maintain Continuous monitoring, change control for scope creep, and annual affirmations as applicable. Certification is not a finish line.

Rough planning ranges heard from industry (illustrative only): focused enclave remediation can be months; enterprise-wide lifts often run longer. C3PAO scheduling itself can add wait time. Build contingency—do not bid the best case.

Certifications — company vs individual

Do not confuse your company’s CMMC status with individual ecosystem credentials. Official role definitions live in 32 CFR Part 170 and with the Cyber AB / CAICO.

Who What it is Notes
Organization (OSA / OSC) CMMC Status at Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC), as applicable Driven by contract requirements and assessment results entered for DoD use (e.g., SPRS / program systems). Not the same as an individual’s CCP/CCA.
CCP — CMMC Certified Professional Foundational individual credential in the assessment ecosystem Training via an Approved Training Provider, exam, application requirements, and DoD Tier 3 determination as required by the program / Cyber AB pathway.
CCA — CMMC Certified Assessor Assessor who conducts Level 2 certification assessments with a C3PAO Requires active CCP path plus additional experience, 8140-aligned baseline qualification, training/exam, and other 32 CFR § 170.11 requirements.
C3PAO Organization authorized/accredited to perform Level 2 certification assessments Companies seeking certification hire a C3PAO; they do not “become” a C3PAO by passing CCP.

Start here: Cyber AB — Assessing and Certification · 32 CFR § 170.11 (CCA) · ISACA CCP overview (exam delivery partner materials; confirm against Cyber AB for current requirements).

References — official sources

Prefer .gov and primary publishers. Re-check URLs before citing in contracts.

Downloadable readiness checklist

Multi-page PDF covering company readiness, NIST SP 800-171 family evidence reminders for cloud/hybrid shops, journey milestones, and a documentation pack checklist. Free to use internally; still not an assessment.

Download PDF

© Canopy Harbor LLC. Beacon content is for general informational purposes only and does not create an attorney–client, assessor–client, or consulting relationship. Official requirements control in the event of any conflict. Not legal advice.