NIST 800-171 vs NIST 800-53: Which Applies to Your System?
By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026
NIST 800-171 vs NIST 800-53 comes down to the system's role and governing requirement. 800-171 protects Controlled Unclassified Information (CUI) in nonfederal systems; Cybersecurity Maturity Model Certification (CMMC) Level 2 uses its Rev. 2, with 110 requirements. 800-53 is a broader security and privacy control catalog. Your contract and system role determine which applies—not who owns the hardware. (NIST scope, CMMC Level 2, 800-53)
Both are Special Publications (SP) from the National Institute of Standards and Technology (NIST). One company can owe both, on different systems. The map below shows which is which, and the worked example shows how to document the decision.
Status, checked September 23, 2026: The Department of Defense (DoD), which now also uses the name Department of War, suspended CMMC's Phase II transition on July 13, 2026. Its CMMC program page says all Phase I self-assessment requirements remain in place. Class Deviation 2026-O0025, Revision 3, September 3, 2026 retains NIST SP 800-171 Rev. 2 in Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 and limits current CMMC procurement designations to Level 1 (Self) or Level 2 (Self). The official implementation sources checked for this page do not supply a replacement Phase II date. What the suspension changed
Three quick checks before you read further:
- Does your contract include DFARS 252.204-7012? If yes, its safeguarding requirement applies to covered contractor systems handling covered defense information—the clause-defined information to protect. For those systems not operated on behalf of an agency, the current deviation specifies 800-171 Rev. 2. (Clause (a), (b)(2))
- Does any external cloud service store, process, or send that information? If yes, you must require and ensure the specific service meets the clause’s FedRAMP Moderate-equivalent security and incident-response obligations. FedRAMP—the Federal Risk and Authorization Management Program—uses 800-53-based controls. You still own your side. (Clause (b)(2)(ii)(D))
- Do you run a system that does the government's own information processing for it? If yes, that system follows the agency's specified requirements, including its applicable 800-53-based controls. Analyze your other systems separately, including any shared services. (32 CFR 2002.14(h); clause (b)(1))
If you only handle Federal Contract Information (FCI), have no CUI in that environment, and have no other requirement for either publication, neither standard automatically applies in full. The basic safeguarding set is the 15 requirements in Federal Acquisition Regulation (FAR) clause 52.204-21; CMMC Level 1 applies when required by the governing instrument. An unknown answer above is not a “no.” See FCI vs. CUI. (FAR 52.204-21; 32 CFR 170.14(c)(2))
NIST 800-171 vs 800-53 at a glance
800-53 is a catalog that federal agencies choose from. 800-171 is a fixed requirement set that contractors holding CUI are measured against when their governing agreement requires it. An agency picks a baseline—a starting set of controls—from 800-53B and tailors it to the system; a contractor implements the applicable 800-171 requirements across its defined assessment boundary. That does not mean installing every safeguard on every device. (800-53B; 800-171 Rev. 2, §1.1)
| Question | NIST SP 800-53 | NIST SP 800-171 |
|---|---|---|
| What it is | A customizable catalog of security and privacy controls (NIST) | Requirements for protecting CUI confidentiality in nonfederal systems within the publication’s stated scope (NIST, §1.1) |
| Written for | Organizations selecting security and privacy controls, including federal agencies and systems a contractor operates on an agency’s behalf (NIST; 800-171 Rev. 2, §1.1, note 7) | Contractors, universities, and others handling CUI in their own nonfederal systems, when required by the governing agreement (NIST, §1.1) |
| What makes it mandatory | Applicable federal-system requirements under the Federal Information Security Modernization Act (FISMA), agency requirements, or your contract; the whole catalog is not automatically mandatory (NIST) | The applicable contract, agreement, or other governing requirement. For covered DoD work: DFARS 252.204-7012 under the current deviation and, for CMMC Level 2, 32 CFR 170.14 |
| Size | Release 5.2.0: 20 families; 1,014 active controls and enhancements. Untailored 800-53B baselines: Low 149, Moderate 287, High 370 | Rev. 2 (the CMMC version): 110 requirements in 14 families. Rev. 3 (NIST’s newest): 97 active requirements in 17 families. Counts and sources are explained below. |
| Security goal | Confidentiality, integrity, availability, and privacy (NIST) | Protecting CUI confidentiality; requirements also help protect against unauthorized modification (NIST Rev. 2, §1.1 and note 19) |
| Which version matters | NIST’s current catalog is Rev. 5, Release 5.2.0 (August 27, 2025); verify the edition and selected baseline your instrument requires (NIST) | CMMC Level 2: Rev. 2 (February 2020), even though NIST withdrew it on May 14, 2024 (CMMC rule; NIST record) |
| How it’s assessed or authorized | Under the applicable agency process, a senior official authorizes a federal system to operate; FedRAMP separately authorizes specific cloud offerings. A voluntary 800-53 program is not automatically an agency authorization. (Risk Management Framework) | The governing assessment process. For CMMC Level 2 (Self), assessment results and an official’s affirmation go into the Supplier Performance Risk System (SPRS). A self-assessment produces a CMMC status, not third-party certification. (32 CFR 170.16) |
| Does meeting one prove the other? | No automatic 800-171 or CMMC result follows from an 800-53 claim or mapping (NIST’s mapping caveat) | No—NIST says meeting 800-171 does not automatically satisfy 800-53 (Rev. 2 cautionary note and Appendix D) |
The catalog and baseline counts come from NIST's own machine-readable files; how we counted is explained in the family-by-family section below. These are editorial counts from the NIST catalogs and baseline profiles, checked September 23, 2026—not workload or cost estimates.
Knowing which standard governs each system is half the decision. If that requirement points to CMMC, the next step depends on your situation. The other half is what kind of help closes the gap, and that isn't the same for every contractor. It depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, where your CUI lives (your own network, an appropriately authorized or equivalent cloud service, or a CUI enclave—a separated environment for the CUI work in scope), and your contract timeline. The contract clause sets your level, not a checklist. Because a general comparison can't settle those for you, use The Defense Compliance Report's Find My CMMC Path tool to explore which path and kind of help fit your situation — a Registered Practitioner Organization (RPO) for readiness work, a Managed Security Service Provider (MSSP), a governance, risk, and compliance (GRC) platform, or a CUI enclave — before you request quotes. Do not submit CUI, drawings, or sensitive contract details.
Which one applies to your system?
It depends on who the system serves and what your contract says, one system at a time. A defense contractor can owe 800-171 in its own nonfederal CUI environment and have separate cloud-provider obligations. 800-53-based requirements can apply directly when you operate a system on the government's behalf—or when another written requirement calls for them. (32 CFR 2002.14(h); DFARS 7012(b))
No web page, including this one, can tell you which standard your contract requires. Your contract does. Here is where to look: search your contract and any subcontract flow-down for 252.204-7012, for 52.204-21, and for any line that names 800-53 or says a system is "operated on behalf of the Government." If you can't find 252.204-7012, search for its title, "Safeguarding Covered Defense Information and Cyber Incident Reporting" — some newer DoD contracts use updated clause text, which our clause-search guide walks through. Read incorporated attachments and written amendments or modifications too. The September 3 deviation retains clause 252.204-7012 with revised text and includes the separate government-assessment clause 252.240-7997. A number alone does not identify the version in your contract. (Revision 3, memorandum and Attachment 1)
| Your situation | Standard for that system | What puts it there | What proof looks like |
|---|---|---|---|
| Your own nonfederal system holds covered defense information under a DoD safeguarding clause | NIST SP 800-171 Rev. 2—the 110-requirement set; implementation and evidence must match the boundary | Current DFARS 252.204-7012(b)(2)(i); 32 CFR 170.14(c)(3) for CMMC Level 2 | A system security plan and evidence under the applicable process. When Level 2 (Self) is required: self-assessment every three years, results in SPRS, and affirmation at assessment and annually. Clause 7012 alone does not create a CMMC status. (§170.16(a)) |
| An external cloud service stores, processes, or sends that information | The specific offering meets the applicable FedRAMP Moderate-equivalent security requirement; the contractor still meets its own requirements | DFARS 252.204-7012(b)(2)(ii)(D); 32 CFR 170.16(c)(2) | For CMMC Level 2: a FedRAMP Authorized Moderate-or-higher offering, or equivalency evidence meeting DoD policy—not merely any Marketplace listing. Document or reference customer responsibilities in the system security plan, and ensure the provider meets clause 7012(c)–(g). |
| You operate a system for the government: it does the agency’s own information processing | The agency’s specified requirements, including its applicable 800-53 baseline or selected controls | 32 CFR 2002.14(h)(1); DFARS 252.204-7012(b)(1) | The agency’s required assessment and authorization evidence, as the contract describes |
| You handle only FCI, no CUI, with no other requirement for these publications | Neither automatically in full: the 15 safeguards in FAR 52.204-21; CMMC Level 1 when required | FAR 52.204-21; 32 CFR 170.14(c)(2) | When Level 1 is required: annual self-assessment and annual affirmation in SPRS. (§170.15) |
| Your paperwork calls for CMMC Level 3 | The codified model uses 800-171 Rev. 2 plus 24 selected requirements from NIST SP 800-172 (February 2021)—not an 800-53 High baseline | 32 CFR 170.14(c)(4) and §170.18 | The model requires Final Level 2 (C3PAO) first, then government assessment by DCMA DIBCAC. Current direction suspends Level 3 procurement designations and directs removal of existing requirements by written action; obtain the amendment or modification, rather than ignoring your paperwork. (Current deviation) |
| Your nonfederal CUI environment serves a civilian agency | Whatever that contract requires today. The June 23, 2026 FAR proposal specifies 800-171 Rev. 3 for covered nonfederal CUI systems | FAR Case 2026-001, 91 FR 37550—a proposal is not itself an amendment to your contract | Depends on the agency—see CUI rules for civilian-agency contractors |
| Not sure yet whether you hold CUI or run a system for the government | The new applicability decision is unresolved; continue safeguards already required | Identify the governing instrument, system role, and information designation | Ask in writing, using the request below. Unknown does not mean “no CUI,” “no requirement,” or compliant. |
C3PAO means CMMC Third-Party Assessment Organization; DCMA DIBCAC is the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center. For Level 2, Final status requires all 110 requirements to be MET under the rule’s assessment method; a documented NOT APPLICABLE determination is assessed as MET, not an unexamined blank. Conditional status is limited by the plan of action and milestones (POA&M) rules and a 180-day closeout window—it is not permission to omit requirements from the comparison. (§170.16, §170.21, §170.24)
Your own system vs. a system you run for the government
The line is set in the federal CUI rule, not by who owns the hardware. A system is a federal information system when a contractor operates it on an agency's behalf — meaning it processes, stores, or sends federal information as the service itself, not incidentally to delivering a product or service (32 CFR 2002.4(hh)).
Think of it this way. A machine shop that receives CUI drawings so it can make parts is using its own system; the drawings are incidental to the parts. For nonfederal systems within its scope, the CUI rule directs agencies to use 800-171 rather than treating the system as agency-operated (32 CFR 2002.14(h)(2)). A company hired to host and run a records system that agency staff log into is doing the agency's processing for it. That system is treated as agency-operated and follows the agency’s applicable security and authorization requirements, including its selected 800-53-based controls.
Say your company does both. Your contract has you host a scheduling portal that Army staff use, and your engineers also keep CUI drawings on the company network. That's two answers, not one: the portal's requirements come from the contract (NIST says 800-53 applies to systems run on an agency's behalf), and your company network still follows 800-171 under DFARS 7012(b)(2). A shared security tool can support both. It doesn't make the two records interchangeable. The shared services and connections still need to be evaluated in the relevant boundaries. (NIST Rev. 2, §1.1; CMMC scoping)
Your cloud provider: where 800-53 reaches your supply chain
If an external cloud service stores, processes, or sends covered defense information, DFARS 252.204-7012 says you must require and ensure the provider meets security equivalent to the FedRAMP Moderate baseline. FedRAMP's baselines are built from NIST SP 800-53; FedRAMP updated them to 800-53 Rev. 5 in May 2023 (FedRAMP). This is one way 800-53 reaches a subcontractor: through the provider’s applicable cloud baseline, not a requirement to implement the entire catalog. Clause 7012 also requires and obliges you to ensure the provider complies with paragraphs (c)–(g), covering incident reporting, malicious-software submission, preservation, forensic access, and damage-assessment cooperation. (Current clause (b)(2)(ii)(D))
The provider’s authorization covers the specific offering and its authorized boundary, not your whole company. Your tenant settings, user accounts, laptops, and the network that connects to the cloud remain in your assessment scope when they support the CUI environment, and the provider's customer responsibility matrix must be documented or referenced in your system security plan (32 CFR 170.16(c)(2)(iii)). A provider that locks its data center doesn't prove you turned on multifactor login. For the authorization-vs.-equivalency details, see CMMC vs. FedRAMP.
When the request just says "NIST compliant"
"NIST compliant" isn't enough to scope a project or answer a customer. Before you answer a questionnaire or sign a proposal, ask for the publication, the revision, the system, and the evidence they expect. Copy this, send it through your normal contracting channel, and leave CUI out of it:
Please identify the system and the written security requirement you are asking us to meet. If it is based on NIST SP 800-53, please specify the revision, the baseline or selected control set, any required parameters, and the assessment or authorization evidence you expect. If it is NIST SP 800-171 or CMMC, please identify the required revision and any CMMC level and assessment type. Please also confirm whether this system is operated on behalf of the agency or is our own system.
Write the answer down: the baseline decision record
Once you have answers, record them. One record per system boundary. This is our own worksheet, not an official NIST or CMMC form, and it isn't an assessment result — it's the paper trail that lets an owner, a prime, or an assessor see why you built to what you built to. Fill it in your own approved workspace, not on a website.
Do not enter CUI, drawings, or sensitive contract details on this website.
Baseline decision record controls
| # | Field | What to write |
|---|---|---|
| 1 | System | A plain, non-sensitive name (“engineering file server and computer-aided design workstations”) |
| 2 | Role | Our own nonfederal system / operated on behalf of an agency / not yet known; identify the basis for that answer |
| 3 | Information | CUI / FCI only / other / not yet known—and who confirmed it |
| 4 | Governing clause | Clause number and title; incorporated requirement, amendment or modification; applicable deviation; date read. Keep sensitive documents in your approved workspace. |
| 5 | Standard and revision | The edition required by the instrument and its incorporated authorities (for example, “NIST SP 800-171 Rev. 2”), or “not yet known” |
| 6 | CMMC level and type | As written in the contract (for example, “Level 2 (Self)”), “none required” if established, or “not yet known” |
| 7 | If 800-53 applies | Revision, baseline or selected controls, tailoring, required parameters, and agency contact; identify anything still unknown |
| 8 | Cloud and service providers | Relevant provider responsibilities and where each responsibility record is filed; for cloud offerings, the applicable FedRAMP Authorized status or equivalency evidence. Do not apply the cloud rule automatically to non-cloud providers. |
| 9 | Existing evidence to evaluate | Requirement ID; old control ID and edition; evidence owner and internal reference; same boundary and implementation? applicable assessment objectives covered? yes / no / unknown; remaining gap |
| 10 | Open question | What’s still unknown, who must answer, date asked |
| 11 | Decision | “The supported requirement for this system is…” or “Applicability unresolved pending #10.” An unresolved decision does not suspend existing safeguards or contract duties. This is not an assessment result. |
| 12 | Review | Owner, date checked, next review date; revisit when the governing requirement or system boundary changes |
A filled-in example (hypothetical). Say you run a 30-person machine shop. Your prime's subcontract includes DFARS 252.204-7012, requires 800-171 Rev. 2, and calls for CMMC Level 2 (Self). You keep CUI drawings on your own file server and in a cloud offering that, for this fictional example, has a current FedRAMP Moderate authorization. A consultant has pitched a full 800-53 program. Your record reads: System—engineering file server, computer-aided design (CAD) workstations, cloud tenant. Role—our own nonfederal system. Information—CUI, confirmed by the prime's contracts manager. Standard—800-171 Rev. 2. Level—2 (Self). If 800-53 applies—nothing in this fictional contract requires our own system to meet a separate 800-53 baseline. Cloud—specific authorized offering checked; customer responsibility matrix and clause 7012(c)–(g) obligations documented. Existing evidence—a multifactor login configuration, not yet accepted as evidence for requirement 3.5.3. Open question—does it also cover local privileged access? Decision—build to 800-171 Rev. 2, evaluate the evidence, and keep the unresolved check visible; the 800-53 pitch is optional extra work, not a requirement of this fictional contract. You haven't ruled out doing more than the minimum. You've just stopped paying for it by mistake.
The headcount and circumstances are illustrative. The cloud conditions come from clause 7012(b)(2)(ii)(D) and §170.16(c)(2); the authentication check comes from 800-171A, 3.5.3. The worksheet does not establish the shop’s assessment result.
Once each system has a standard next to it, the question left is what kind of help gets you there — scoping, a managed service provider (MSP) or MSSP to run the controls, a CUI enclave, or cloud work — and that depends on where your CUI lives and what your contract calls for.
If your only obligation turns out to be a system you run for an agency, your next step is that agency's security office and your contracting officer, not a CMMC tool.
Is NIST 800-171 a subset of 800-53?
Yes, in origin. NIST built Rev. 2 from FIPS 200’s basic requirements and the 800-53 Rev. 4 Moderate baseline, tailoring the derived requirements for CUI in nonfederal systems. FIPS means Federal Information Processing Standards. It's smaller because it's narrower, not because it's weaker: NIST says the tailoring isn't meant to reduce the protection CUI gets (SP 800-171 Rev. 2, §1.1).
Here's the size comparison, counted from NIST's own files and publications. The editions are labeled because these rows are not successive cuts from one current baseline:
| Set or edition | Count | What it is |
|---|---|---|
| Full 800-53 catalog | 1,196 entries | Every control and enhancement in Release 5.2.0, including 182 NIST marks as withdrawn |
| Active catalog | 1,014 | 300 controls and 714 enhancements, across 20 families |
| Moderate baseline | 287 | The untailored Release 5.2.0 starting set for a Moderate-impact system: 177 base controls and 110 enhancements—not a headcount-based “typical company” baseline |
| 800-171 Rev. 3 | 97 active requirements | NIST’s newest version; its published Appendix C designates 156 Moderate-baseline controls and enhancements as CUI-related. That is a lineage count, not 156 extra requirements. (Appendix C) |
| 800-171 Rev. 2 | 110 requirements | The version CMMC uses, built from FIPS 200 and the 800-53 Rev. 4 Moderate baseline—not the Rev. 5 baseline above (§2.2 and Appendix D, note 31) |
The 1,196-entry catalog count includes the withdrawn entries; 1,014 excludes them. Neither catalog total is an automatic implementation checklist. The selected baseline, tailoring, and other applicable requirements define the actual set. (NIST catalog and profiles; 800-53B)
NIST gives three reasons for cutting controls (SP 800-171 Rev. 2, §2.2):
- It's uniquely federal. The Moderate baseline expects federal systems to accept government Personal Identity Verification (PIV) smart cards (800-53 IA-2(12)). 800-171 says its multifactor login requirement does not mean you need PIV or Common Access Card (CAC)-style cards. These are the standard’s tailoring decisions, not permission to disregard a separate contractual smart-card requirement. (Rev. 2, note 24; Rev. 3 Appendix C, IA-02(12))
- It is not directly about CUI confidentiality. This is an 800-171 tailoring criterion, not a statement that the entire federal CUI rule ignores integrity and availability. Rev. 2 omits a standalone Contingency Planning family while retaining backup confidentiality under Media Protection. (Rev. 2, §2.2, note 18; 32 CFR 2002.14)
- Organizations were expected to do it anyway. Rev. 2 treated some controls, including policy-and-procedure controls, as expected organizational practices. Rev. 3 eliminated that “NFO” tailoring category and explicitly added some requirements previously covered by the assumption; other controls were reassigned to other tailoring categories. NFO meant “expected to be routinely satisfied by nonfederal organizations without specification.” (NIST Rev. 3 FAQ)
An everyday way to picture it: 800-53 is a building-code library. A baseline is the starting selection for a defined impact level, not the whole library or a measure of building size. 800-171 selects and adapts requirements for protecting the government's CUI in a nonfederal environment. Leaving a general contingency-planning requirement out of that selection does not mean the backup generator is useless—and it does not erase the incident-recovery and backup-confidentiality requirements that are included.
The family-by-family map
800-53 has 20 control families; 800-171 Rev. 2 has 14 requirement families and Rev. 3 has 17. Neither 800-171 edition has a standalone Contingency Planning, Program Management, or Personally Identifiable Information (PII) Processing and Transparency family. That does not mean every related safeguard is absent: backup confidentiality appears under Media Protection. The table separates catalog size, the untailored Moderate baseline, and requirement counts. (Rev. 2, §2.2; Rev. 3, §3 and Appendix C)
| 800-53 family | Active in 800-53 (Rel. 5.2.0) | In untailored Moderate baseline | 800-171 Rev. 2 requirements (CMMC Level 2) | 800-171 Rev. 3 active requirements | Moderate entries designated CUI in Rev. 3 Appendix C |
|---|---|---|---|---|---|
| Access Control (AC) | 131 | 39 | 22 | 16 | 33 |
| Awareness and Training (AT) | 15 | 6 | 3 | 2 | 5 |
| Audit and Accountability (AU) | 56 | 16 | 9 | 8 | 13 |
| Assessment, Authorization, and Monitoring (CA) | 25 | 10 | 4 | 4 | 5 |
| Configuration Management (CM) | 56 | 24 | 9 | 10 | 14 |
| Contingency Planning (CP) | 49 | 23 | — | — | 2 |
| Identification and Authentication (IA) | 59 | 24 | 11 | 8 | 12 |
| Incident Response (IR) | 40 | 13 | 3 | 5 | 8 |
| Maintenance (MA) | 28 | 9 | 6 | 3 | 7 |
| Media Protection (MP) | 20 | 7 | 9 | 7 | 7 |
| Physical and Environmental Protection (PE) | 51 | 18 | 6 | 5 | 7 |
| Planning (PL) | 11 | 7 | — | 3 | 3 |
| Program Management (PM) | 37 | — | — | — | — |
| Personnel Security (PS) | 17 | 9 | 2 | 2 | 4 |
| PII Processing and Transparency (PT) | 21 | — | — | — | — |
| Risk Assessment (RA) | 22 | 10 | 3 | 3 | 6 |
| System and Services Acquisition (SA) | 108 | 17 | — | 3 | 4 |
| System and Communications Protection (SC) | 139 | 25 | 16 | 10 | 14 |
| System and Information Integrity (SI) | 102 | 18 | 7 | 5 | 7 |
| Supply Chain Risk Management (SR) | 27 | 12 | — | 3 | 5 |
| Total | 1,014 | 287 | 110 | 97 | 156 |
How to read it. Read across a row. The first number counts active controls and enhancements in that family. The second is the untailored Moderate baseline. The next two count 800-171 requirements: Rev. 2 for CMMC today, Rev. 3 for NIST's newest version. The last column counts entries that NIST’s published Rev. 3 Appendix C marks “CUI,” meaning directly related to protecting CUI confidentiality. A dash means no standalone family or selected entries in that column—not an unknown input or permission to skip related requirements.
Requirements and controls aren't one-for-one. Media Protection has 9 Rev. 2 requirements but 7 controls in the Rev. 5 Moderate baseline; those are different units and editions, not a compliance percentage. A requirement can relate to several source controls, and one control can support more than one requirement. A control not retained separately is not necessarily unaddressed: another control may cover its outcome. NIST’s Rev. 3 Appendix C records the tailoring reasons.
Rev. 2's families have slightly different names (“Physical Protection,” “Security Assessment”). Its development discussion identifies Contingency Planning, System and Services Acquisition, and Planning as omitted standalone families, while retaining three requirements: backup confidentiality (from CP-9), the system security plan (from PL-2), and security engineering principles (from SA-8), placed in Media Protection, Security Assessment, and System and Communications Protection. Rev. 3 adds Planning, System and Services Acquisition, and Supply Chain Risk Management as standalone families. (Rev. 2, §2.2, note 18; Rev. 3 FAQ)
What 800-171 leaves out, and why you might still want it
800-171 Rev. 2 does not prescribe the full contingency-planning program represented by 800-53’s disaster-recovery plans, restoration tests, and alternate sites. It does retain backup confidentiality in requirement 3.8.9, and requirement 3.6.1 includes recovery in incident handling. Meeting 800-171 alone doesn't mean you can recover from ransomware. (Rev. 2, 3.6.1, 3.8.9 and Appendix E)
NIST says this plainly. It calls 800-171 a subset of what a full security program needs and strongly advises organizations to review the whole Moderate baseline so their plans provide necessary and sufficient protection (SP 800-171 Rev. 2, cautionary note and note 17). That's worth reading as permission, not pressure: you can borrow the parts of 800-53 that protect your business without claiming compliance with an entire 800-53 baseline. Whether a system or security service belongs in CMMC scope still follows its actual role, not whether you call its controls voluntary. (32 CFR 170.19)
What we counted and how. On September 23, 2026, we recalculated the catalog, baseline, and Rev. 3 requirement counts using NIST’s official machine-readable files (usnistgov/oscal-content): the SP 800-53 Release 5.2.0 catalog, the SP 800-53B Release 5.2.0 profiles, and the SP 800-171 Rev. 3 catalog. “Active” excludes entries NIST marks withdrawn; a base control and each enhancement count separately. For the last column, we counted the distinct entries marked CUI in the published Rev. 3 Appendix C, grouped by their 800-53 family—not a count of source links in the machine-readable requirement records. That yields 33 for Access Control and 156 overall. Rev. 2 family counts were checked against its Chapter 3 requirement set and the CMMC model. The figures describe structure and lineage, not implementation effort or automatic equivalence. (Rev. 3 Appendix C; Rev. 2; CMMC model)
Can you reuse 800-53 work for 800-171 or CMMC?
Often, yes, as a starting point. 800-171 came from 800-53's Moderate baseline, and NIST built its mapping tables for organizations whose programs are organized around 800-53 or ISO/IEC 27001, an information-security management standard. But a mapping isn't proof: NIST calls those mappings informal, and a CMMC assessment tests the 800-171 Rev. 2 requirements using the incorporated assessment procedures, within your CUI boundary. (Rev. 2, Appendix D; §170.14(d))
The reverse is not automatic either. You can evaluate 800-171 evidence for an 800-53-based program, but it does not prove that the broader selected set is satisfied. NIST warns that meeting 800-171 shouldn't be assumed to satisfy 800-53 (SP 800-171 Rev. 2, cautionary note).
Here is where existing 800-53 work can help, and what still needs checking:
| 800-171 Rev. 2 requirement | Where it comes from in 800-53 Rev. 4 | What your 800-53 evidence may already show | What you still have to show for 800-171 |
|---|---|---|---|
| 3.5.3 Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts | IA-2(1), IA-2(2), and IA-2(3), per Rev. 2 Appendix D, Table D-5—not Rev. 3’s source list (NIST) | A multifactor authentication (MFA) policy and login settings | All three access paths named in the requirement. Assessors start by checking that your privileged accounts are identified, then check local admin logons, network admin access, and network user access separately. MFA on email alone does not establish coverage of a local admin logon at a shop-floor workstation. ([800-171A, 3.5.3[a]–[d]](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171a.pdf#page=43)) |
| 3.8.9 Protect the confidentiality of backup CUI at storage locations | CP-9, System Backup, identified in Rev. 2 §2.2 note 18 and Appendix D note 34 (NIST) | A backup schedule and restore tests | That backed-up CUI stays confidential where it is stored. Assess the access and protection measures actually used; a restore test alone does not prove confidentiality. (800-171A, 3.8.9) |
| 3.12.4 Develop, document, and update system security plans | PL-2, expressly identified in Rev. 2 §2.2 note 18. Appendix D displays the broader 3.12.1–3.12.4 mapping as a group, not four separate one-to-one rows. (NIST) | An existing system security plan | That the plan describes the boundary, environment, how the requirements are implemented, and connections to other systems—including any documented implementation gaps rather than falsely stating every requirement is met. For cloud CUI services, document or reference the customer responsibility matrix. (Rev. 2, 3.12.4; 32 CFR 170.16(c)(2)(iii)) |
Requirement text is from NIST SP 800-171 Rev. 2. CMMC Level 2 is assessed using NIST SP 800-171A (June 2018), per 32 CFR 170.14(d). Suggested evidence is our judgment, not a promise any assessor will accept a particular document.
One version trap: Rev. 2 Appendix D footnote 31 explicitly says its mappings use 800-53 Revision 4. This is not an inference from publication dates. Control IDs and their content can change between editions; match the requirement, edition, scope, implementation, and assessment objectives—not the ID alone. (Appendix D, printed page 61)
Say you already sell a FedRAMP Moderate-authorized software product, and you just won a DoD subcontract that expressly requires 800-171 Rev. 2 and puts CUI in your corporate email. The product's authorization covers that offering, not automatically your corporate email, laptops, or file shares. Evaluate your policies, tools, and evidence through a mapping—then write the system security plan against the 110 requirements and demonstrate implementation inside the applicable boundary. This is a hypothetical example, not a provider authorization check. (§170.16(c)(2); Rev. 2 Appendix D)
Should a small contractor build to 800-53 anyway? Our judgment: do not commission a complete 800-53 baseline project merely because your contract requires 800-171. A separate agency or customer requirement—or a documented business-risk decision—can justify broader work. Meet the required edition of 800-171 and borrow from 800-53 where it protects the business, like backup and restore testing. Before you pay for another project, ask the provider to separate what your contract requires from optional improvements, and to say which existing evidence it will check against which requirement.
If you're starting from an existing 800-53 or FedRAMP program, the right help depends on your CUI boundary and your contract, not on how many controls you already have.
Which revisions are you actually comparing?
For CMMC Level 2 today, 800-171 Rev. 2 — even though NIST withdrew it on May 14, 2024. CMMC's rule names Rev. 2 as the Level 2 requirement set, and a new NIST edition doesn't change a regulation or a contract by itself. (32 CFR 170.14(c)(3); current clause 7012)
| Publication | NIST status | What uses it today |
|---|---|---|
| 800-171 Rev. 2 | Withdrawn May 14, 2024 (NIST record) | CMMC Level 2 (32 CFR 170.14(c)(3)); the current September 3 deviation specifies it in clause 7012 |
| 800-171 Rev. 3 | Current publication, May 14, 2024 (NIST record) | Not the current CMMC baseline. An agreement can independently require it; the June 23 FAR proposal would use it for covered nonfederal CUI systems. |
| 800-53 Rev. 5, Release 5.2.0 | NIST release dated August 27, 2025 (NIST record) | The current catalog for control selection. Agency and cloud-program requirements determine the adopted edition, release, baseline, and tailoring; a NIST release does not by itself amend them. |
| 800-53 Rev. 4 | Withdrawn September 23, 2021 (NIST record) | The edition explicitly used in 800-171 Rev. 2 Appendix D’s informational mappings (footnote 31) |
A page that says 800-171 has "110 controls in 17 families" is mixing Rev. 2's count with Rev. 3's families. For which document binds you, see which revision your contract requires. For what changed between the two editions, see 800-171 Rev. 2 vs. Rev. 3.
Questions that can change the answer
Is there a "NIST 800-53 certification" or a "NIST 800-171 certification"?
NIST does not issue contractor certification against either publication. A federal-system authorization, a specific cloud offering’s FedRAMP authorization, and a CMMC status are different results; evidence has to match the applicable scope and process. A CMMC self-assessment is not a third-party certification, and “we’re NIST certified” does not identify an official result a prime can rely on. (NIST Risk Management Framework; 32 CFR 170.16)
Does 800-171 ignore integrity and availability?
Not entirely. It focuses on keeping CUI confidential, and NIST notes its requirements also protect against unauthorized changes. Rev. 2 includes recovery in incident handling and backup confidentiality, but it is not a complete disaster-recovery or availability program; your business may need more. (Rev. 2, note 19, 3.6.1, and 3.8.9)
Is 800-53 High the same thing as CMMC Level 3?
No. The untailored 800-53B High baseline has 370 controls and enhancements under the Release 5.2.0 count above. CMMC Level 3 instead adds 24 selected requirements from SP 800-172, February 2021, requires Final Level 2 (C3PAO) as a prerequisite, and is assessed by DCMA DIBCAC; current procurement direction suspends new Level 3 designations. (§170.14, §170.18, current deviation) See CMMC levels.
Can we use 800-53 voluntarily even if our contract requires 800-171?
Yes. NIST says nongovernmental organizations may use its publications voluntarily. Just keep voluntary work and required work labeled separately in your plan, so your SPRS results and affirmation describe what the contract actually requires. (NIST Rev. 2, Authority and cautionary note; §170.16)
Does 800-53 cover classified systems?
800-53 controls can be used for national security systems under the responsible authorities; ordinary NIST federal-system applicability does not automatically extend to those systems. Classified information is not CUI, and its governing security requirements are outside this contractor-CUI comparison. Confirm them through the relevant agency security process, not the worksheet above. (NIST Rev. 5, Authority and §1.1, note 11; CUI definition, 32 CFR 2002.4)
What we verified
On September 23, 2026, we read the relevant primary-source provisions below, recalculated the catalog and baseline figures from NIST's official data, and counted the CUI-designated entries in Rev. 3 Appendix C. We did not see your contract, inspect your systems, or test any provider, and the decision record above organizes your decision—it isn't an assessment result.
- Rules and clauses: the relevant CMMC model, self-assessment, affirmation, scoping, and Level 3 provisions in 32 CFR Part 170; 32 CFR Part 2002, including §2002.4 and §2002.14(h); and clause 252.204-7012 in the September 3, 2026 deviation and its attachment. The retrieved eCFR display was current through September 21, 2026. We distinguish the codified Acquisition.gov clause from the revised deviation text rather than treating them as interchangeable.
- NIST publications and data: SP 800-171 Rev. 2 scope, development discussion, requirements, and Appendix D—including footnote 31 and the original mapping tables; the June 2018 SP 800-171A assessment objectives; SP 800-171 Rev. 3 and its Appendix C and FAQ; SP 800-53/800-53B publication records; and NIST’s machine-readable catalogs and baseline profiles. The catalog and baseline profiles checked identify Release 5.2.0; the Rev. 3 requirement catalog identifies version 1.1.0.
- Program status: the Department’s CMMC program page, July 13 implementation memo, and Class Deviation 2026-O0025 Revision 3, dated September 3, 2026. The deviation retains Phase I self-assessment requirements and Rev. 2; it directs written changes to existing C3PAO/Level 3 procurement requirements rather than telling contractors to ignore their contracts.
- Proposed civilian rule: FAR Case 2026-001 at 91 FR 37550, published June 23, 2026. Its proposed Rev. 3 text is identified as a proposal, not applied to a reader’s contract by this article.
- What we could not establish: a published Reform Task Force outcome or replacement Phase II date from the official implementation sources reviewed. A review deadline is not a restart instruction. We also did not verify a specific provider’s authorization or equivalency, or complete the Find My CMMC Path interactive flow; its description here is limited to its live landing page.
Before you commission the work
Leave with a standard written next to each system, not a framework name. Your record should show the clause, the revision, the boundary, the evidence you'll evaluate, and any question still open. For a covered nonfederal system under the current DoD clause, that's 800-171 Rev. 2. If an external cloud holds the covered defense information, check the specific offering’s authorization or equivalency, its clause 7012(c)–(g) obligations, and the responsibility matrix. If you run a system for the government, get that system's requirements in writing from the agency. An unknown fact stays open until the right person answers it. (Current clause 7012(b); §170.16(c)(2))
Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.
Sources
Relevant provisions and records checked September 23, 2026; the verification limits above apply. Catalog totals are editorial calculations, not quoted regulatory totals.
- NIST SP 800-171 Rev. 2 (February 2020, updated January 28, 2021; withdrawn May 14, 2024): publication record · PDF
- NIST SP 800-171 Rev. 3 (May 14, 2024): publication record · FAQ · full publication and Appendix C
- NIST SP 800-171A (June 2018): PDF
- NIST SP 800-53 Rev. 5: publication PDF, including Authority and §1.1. Release 5.2.0 (August 27, 2025): NIST announcement · Risk Management Framework page
- NIST SP 800-53 Rev. 4 (withdrawn September 23, 2021): publication record
- NIST machine-readable catalogs and baselines (SP 800-53 Rel. 5.2.0, SP 800-53B Rel. 5.2.0, SP 800-171 Rev. 3): usnistgov/oscal-content · SP 800-53B publication · SP 800-53 Rev. 5 publication and mapping caveat
- 32 CFR 170.14, CMMC Model: eCFR
- 32 CFR 170.16, Level 2 self-assessment and affirmation: eCFR
- 32 CFR Part 2002, Controlled Unclassified Information: eCFR
- CMMC Level 1, Level 3, scope, POA&M, and assessment method: §170.15, §170.18, §170.19, §170.21, §170.24
- FAR 52.204-21, basic safeguarding: Acquisition.gov
- DFARS 252.204-7012: codified Acquisition.gov text · Class Deviation 2026-O0025 Revision 3, September 3, 2026, including revised clause and assessment provisions. Use the text applicable to the actual instrument, not the number alone.
- Department of War CIO, CMMC program page: dowcio.war.gov/CMMC
- Implementing Suspension of CMMC Phase II (July 13, 2026): memo
- DoD CMMC Model Overview, Version 2.13: PDF
- FedRAMP Rev. 5 baselines release (May 2023): FedRAMP
- FAR Case 2026-001, proposed rule, 91 FR 37550 (June 23, 2026): Federal Register
About The Defense Compliance Report
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
We are not affiliated with the Cyber AB, DoD, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney. See our Editorial & Advertising Policy.