A working walkthrough of the DoD Cybersecurity Maturity Model Certification (CMMC 2.0) — the three Maturity Levels (Level 1 FCI baseline + Level 2 CUI / NIST SP 800-171 Rev 2 + Level 3 DIB-priority / NIST SP 800-172), the 17-practice Level 1 baseline, the 110-control Level 2 control family set, the DFARS 252.204-7012 / SPRS self-assessment pathway, the C3PAO third-party assessment ladder, and the 2026 readiness roadmap for DoD primes and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
CMMC 2.0 is the Department of Defense's certification scheme for defense industrial base (DIB) contractors. Formalized as a final rule at 32 CFR Part 170 effective October 15, 2024, CMMC 2.0 supersedes the prior CMMC 1.0 model (2020) and aligns tightly with the NIST cybersecurity controls already in DFARS 252.204-7012 (DFARS 7012). CMMC 2.0 applies to any prime contractor or subcontractor that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) in performance of a DoD contract.
The CMMC 2.0 model organizes contractor cybersecurity obligations under three Maturity Levels, each tied to the sensitivity of the information handled. Level 1 — Foundational covers FCI (information provided by or generated for the Government under contract not intended for public release) and requires 17 safeguarding practices from FAR 52.204-21 with an annual self-assessment and affirmation in SPRS. Level 2 — Advanced covers CUI and requires the 110-control set in NIST SP 800-171 Rev 2, with either a triennial self-assessment (Level 2 self) or a C3PAO-led third-party assessment (Level 2 third-party), depending on the DoD program's contractual requirement. Level 3 — Expert covers CUI for DoD-priority programs and adds selected NIST SP 800-172 enhanced-security requirements; the assessment is government-led by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAO). ComplianceStack maps each DoD contract solicitation to the applicable CMMC Level via the contract CMMC requirement line, and pairs every Level 2 / Level 3 contractor with the appropriate SPRS scoring roadmap.
The rule-making lineage matters: CMMC 2.0 is the second iteration of a DoD program that began in 2019 with the interim DFARS rule, was finalized as CMMC 1.0 in 2020 (with five Maturity Levels and process maturity requirements), and was substantially restructured in 2021 around NIST SP 800-171 alignment. The October 2024 32 CFR Part 170 rule finalized the CMMC 2.0 framework. DoD contract solicitations began including CMMC requirements in Q4 2025; full phased rollout extends through Q4 2027 (Level 1 in Q4 2025, Level 2 third-party in Q2 2026, Level 3 DIBCAO in Q4 2026, all CMMC requirements self-asserted by prime contracts at Q4 2027). ComplianceStack tracks the rollout calendar with a CMMC contract-conditions checklist that flags any solicitation with a CMMC requirement line that exceeds the contractor's certified level.
CMMC 2.0 is not a "framework" in the closed-list sense — it is a conformance assessment scheme layered over NIST SP 800-171 Rev 2 (Level 2) and NIST SP 800-172 (Level 3). The controls live in the underlying NIST publications; CMMC adds the assessment mechanism, the SPRS scoring pipeline, the C3PAO accreditation structure, the Conditional / Final designation state for Level 2 third-party assessments, and the contractual-cyber-maturity linkage. The DIB contractor must implement NIST SP 800-171 controls across the CUI enclave boundary; the CMMC assessment confirms the implementation matches the published control implementation evidence.
CMMC 2.0 organizes contractor cybersecurity obligations under three Maturity Levels tied to the type of Federal information handled. ComplianceStack tracks the 32 CFR Part 170 model as the single effective baseline for DoD contract solicitations dated October 15, 2024 or later.
Level 1 covers FCI — information provided by or generated for the Government under contract not intended for public release. FCI is the lower-tier information class (per FAR 2.101 and DFARS 252.204-7012); CUI is the higher-tier class and is separately addressed at Level 2. Level 1 requires the 17 safeguarding practices enumerated in FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems. Level 1 also requires an annual self-assessment by the contractor against the 17 practices and an affirmation of compliance posted to SPRS via the Contracting Officer. Level 1 does not require a C3PAO third-party assessment; the entire Level 1 path is self-attested.
Level 2 covers CUI. CUI is unclassified information that requires safeguarding or dissemination controls pursuant to federal law, regulation, or government-wide policy (per 32 CFR Part 2002). CUI includes things like export-controlled technical drawings, controlled technical information, NIST 800-171-protectable defense articles, and a wide range of program-specific DoD information categories. Level 2 requires the 110 controls in NIST SP 800-171 Rev 2 (the DoD Assessment Methodology explicitly maps each CMMC Level 2 practice to its NIST 800-171 Rev 2 control identifier; CMMC practice AC.L2-3.1.1 maps to 3.1.1, AT.L2-3.2.1 maps to 3.2.1, etc.). Level 2 requires either a triennial self-assessment (Level 2 self) for select DoD programs, or a C3PAO third-party assessment (Level 2 third-party) that yields a Conditional or Final CMMC Level 2 designation. ComplianceStack notes that the C3PAO-led Level 2 third-party assessment is required for any prime contract handling CUI in non-priority program scope; the conditional / final POA&M closeout cycle is the canonical remediation pathway.
Level 3 covers a subset of CUI in DoD-priority programs. Level 3 adds selected NIST SP 800-172 enhanced-security requirements (typically 24-30 practices) covering advanced persistent threat (APT) protection, enhanced personnel security, and emerging-technology protection. Level 3 is functionally the CUI protection set applicable to DIB-priority programs (select missile programs, naval nuclear propulsion programs, space programs, and other DoD-priority acquisition pathways). Level 3 requires a government-led DIBCAO assessment; the DIBCAO assessment is scheduled only after a current CMMC Level 2 Final designation is in place. ComplianceStack notes that Level 3 requirement lines are sparse in the published contract vehicles but expanding per the 2024-2027 phased rollout. ComplianceStack provides a free CMMC Phase 2 Readiness Analyzer at /free-cmmc-readiness-analyzer — contractor-tier-aware scoring with applicable Phase 2 deadlines and shareable results for DoD contracting offices. Run it before scheduling a C3PAO assessment or refreshing your SPRS posting.
CMMC 2.0 scope is defined by the categorical boundary between FCI and CUI data flows, and the control set is fixed by the underlying NIST publications. Below the level-of-applicability decision, every CMMC contractor must implement a defined set of practices; CMMC assessments then verify conformance. ComplianceStack's CMMC readiness analyzer scores every Level 1 practice and every Level 2 control family.
FAR 52.204-21 enumerates 17 safeguarding practices that any contractor that receives, processes, stores, or transmits FCI must implement. The practices are: (1) limit system access to authorized users; (2) limit system access to the types of transactions and functions that authorized users are permitted to execute; (3) verify and control/limit connections to and use of external information systems; (4) control information posted or processed on publicly accessible information systems; (5) identify and authenticate the identities of those users, processes, or devices that access the contractor's information system; (6) limit physical access to the contractor's information system, equipment, and the respective operating environment to authorized individuals; (7) protect and monitor physical access points; (8) escort visitors and monitor visitor activity; (9) establish and maintain physical protection of the contractor's information system, equipment, and operating environment; (10) create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity; (11) ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions; (12) establish and maintain basic operational security (OPSEC) for the contractor's information system; (13) employ sufficient malware protection to detect, quarantine, and eradicate malicious software; (14) update malicious code protection mechanisms when new releases are available; (15) establish and enforce security configuration settings for information technology products employed in organizational information systems; (16) periodically assess and manage risk to information systems; (17) protect the confidentiality of FCI. ComplianceStack maps each of the 17 practices to its operational evidence category (system access control list, badge access log, audit log retention policy, malware scan results, etc.).
Level 2 is the 110-control set from NIST SP 800-171 Rev 2 (February 2020; revision 3 finalized May 2024). The controls are organized under 14 control families. AC — Access Control (22 controls, CUI asset access enforcement); AT — Awareness and Training (3 controls); AU — Audit and Accountability (9 controls); CM — Configuration Management (9 controls); IA — Identification and Authentication (11 controls); IR — Incident Response (3 controls); MA — Maintenance (6 controls); MP — Media Protection (9 controls); PE — Physical and Environmental Protection (6 controls); PL — Planning (2 controls); PS — Personnel Security (8 controls); RA — Risk Assessment (3 controls); SA — System and Services Acquisition (5 controls); SC — System and Communications Protection (16 controls); SI — System and Information Integrity (7 controls). Each control includes a basic security requirement and (where applicable) one or more derived security requirements. ComplianceStack notes that NIST 800-171 Rev 3 introduces a refactored organization with a planned-organizational structure; the DoD CMMC L2 mapping will be updated when the DoD Assessment Methodology is updated to track Rev 3.
CMMC 2.0 enforces a boundary-protection principle: the CUI enclave is the network boundary inside which all 110 NIST 800-171 controls must be enforced. Boundary devices — firewalls, intrusion detection systems, encryption gateways, identity-aware proxies — carry the SC family requirements (SC-7 boundary protection, SC-8 transmission confidentiality and integrity, SC-13 cryptographic protection). The CUI asset inventory (CM-8, IA-2, IA-3, IA-5) defines the population of devices that must be in scope for the audit trail, the vulnerability management cadence, the configuration management baseline, and the change-management ticketing flow. ComplianceStack pairs the CUI enclave inventory with the ComplianceStack CUI Asset Discovery tool that scans Windows / macOS / Linux endpoints, identifies FCI and CUI handling, and produces the Level 2 system security plan (SSP) inventory list.
CMMC 2.0 has four assessment paths. The path depends on the contractor's Maturity Level (1 / 2 / 3) and, for Level 2, the DoD program's contractual CMMC requirement line. ComplianceStack's assessment-type selector maps every contract solicitation to its applicable path and pairs each contractor with the documentation expectations of the selected path.
| Assessment path | Level | Who audits | Frequency | Output |
|---|---|---|---|---|
| Self-assessment | Level 1 (FCI) | Contractor | Annual | SPRS affirmation |
| Self-assessed | Level 2 (CUI) — select programs | Contractor (scored against NIST 800-171 via DoD Assessment Methodology) | Triennial | SPRS NIST 800-171 score (-203 to +110) |
| C3PAO third-party | Level 2 (CUI) — standard programs | Authorized C3PAO (Cyber AB accredited) | Triennial | Conditional or Final CMMC L2 designation |
| DIBCAO assessment | Level 3 (DIB priority) | DoD Defense Industrial Base Cybersecurity Assessment Center (DIBCAO) | Triennial | Final CMMC L3 designation (requires prior L2 Final) |
Level 1 is the lightest assessment path. The contractor self-assesses against the 17 FAR 52.204-21 practices annually, retains the self-assessment results, and provides an affirmation of compliance in SPRS. The affirmation is a Senior Official's affirmation — typically a C-suite officer (CISO, COO, GM) signature attesting that the contractor's assessment accurately reflects the state of the information system. ComplianceStack pairs the Level 1 self-assessment with the ComplianceStack Level 1 Self-Assessment Workflow, which scores the 17 practices, generates the affirmation template, and submits to SPRS.
For some DoD programs, the contractual CMMC requirement line is "CMMC L2 Self" rather than "CMMC L2 Third-Party." In that case, the contractor self-assesses against all 110 NIST SP 800-171 Rev 2 controls triennially, scoring each control on the -203 to +110 scale per the DoD Assessment Methodology, and submits the consolidated SPRS score to the DoD (sprs.csd.disa.mil). The SPRS score is the lowest single-control score assigned, not a sum — one control with a -50 assessment drags the overall SPRS score down to -50. ComplianceStack pairs the SPRS submission with an in-tool scoring engine that runs the DoD Assessment Methodology against every control and assigns the conservative (-203 floor) for any control with documented gaps. The ComplianceStack SPRS scoring engine generates the SPRS submission package and the supporting evidence catalog.
For most DoD programs, the contractual CMMC requirement line is "CMMC L2 Third-Party" with an active C3PAO assessment. The contractor hires an authorized C3PAO (Cyber AB accredited) to conduct the assessment. The C3PAO audits the contractor against all 110 NIST 800-171 Rev 2 controls using the DoD Assessment Methodology, drafts an assessment report, and submits to the Cyber AB. The Cyber AB reviews and either issues a Conditional CMMC Level 2 (90-day POA&M remediation window for specified gaps) or Final CMMC Level 2 (3-year triennial cycle). Conditional CMMC Level 2 designations carry 90 days to close specified POA&M items before Final designation; non-closure in 90 days invalidates the Conditional designation. ComplianceStack pairs the C3PAO assessment with a pre-audit readiness pass that shadows the C3PAO methodology, identifies controls at risk of POA&M designation, and produces a POA&M closeout plan. Typical C3PAO assessment cost for a mid-size contractor (200-1,000 employees): $30K-$100K+ for a CMMC Level 2 third-party assessment; the cost band widens for larger organizations or organizations with broad multi-enclave scope.
Level 3 is government-led DIBCAO assessment, applicable only to select DoD-priority programs. The DIBCAO assessment is scheduled only after a valid CMMC Level 2 Final designation. The Level 3 assessment adds the selected NIST SP 800-172 enhanced-security requirements (typically 24-30 practices). ComplianceStack notes that the Level 3 requirement set is small in 2024-2025 contract solicitations but is expected to expand through the 2026 phased rollout.
DFARS 252.204-7012 (DFARS 7012) is the flow-down clause that operationalizes CMMC requirements across the entire Defense Industrial Base supply chain. The clause requires every DoD contractor and subcontractor at every tier to — at minimum — safeguard Covered Defense Information (CDI) per NIST SP 800-171, report cyber incidents through DIBNet within 72 hours, and submit a NIST 800-171 self-assessment score to SPRS. The CMMC 2.0 certification scheme layers assessment on top of this baseline.
DFARS 7012 flow-down is required in every subcontract at every tier where CDI will be received or generated. Failing to flow DFARS 7012 down creates contractor liability under the False Claims Act (31 USC §3729) — the most-cited violation pattern in DCAA audits. ComplianceStack pairs the flow-down requirement with the ComplianceStack Subcontractor Flow-Down Inventory, which maps every tier-1 to tier-N subcontractor against its applicable CMMC Level. SPRS scoring is on a -203 to +110 scale; -203 is the floor (a control rated as "absent"), 0 is the median under the DoD Assessment Methodology, +110 is the ceiling (a control fully implemented). An SPRS score of +110 reflects a perfect implementation; 88 is the median for organizations under conditional CMMC L2 review; a score below 0 reflects material weakness across multiple control families.
SPRS is the contract-award eligibility gate. DoD acquisition officers rely on SPRS for source selection decisions. An SPRS score below 0 typically disqualifies a contractor from a CMMC-required solicitation. ComplianceStack pairs the SPRS scoring pathway with a contract-award eligibility estimator that scores every active DoD solicitation against the contractor's most recent SPRS score. The estimator outputs a per-solicitation eligibility flag, the required CMMC level (1 / 2 / 3), the assessment path (Self / Self-Assessed / C3PAO / DIBCAO), and the SPRS score gap if applicable.
ComplianceStack packages the CMMC 2.0 readiness program as a 14-family, 90-day gap checklist that maps every NIST SP 800-171 Rev 2 control into a sequenced remediation backlog, calibrated for the upcoming C3PAO Level 2 third-party assessment. The 90-day program is the baseline ramp before the SPRS final submission and the C3PAO's Conditional / Final designation issuance.
ComplianceStack tracks three sector-specific 2026 CMMC readiness roadmaps. The roadmaps share a NIST SP 800-171 / DFARS 7012 baseline but diverge on the assessment path, the CUI enclave structure, and the contract-award eligibility timing.
The recommended pathway is C3PAO third-party assessment for Level 2 Final followed by Level 3 government DIBCAO assessment for any DoD-priority program scope. The 90-day program covers all 110 NIST SP 800-171 Rev 2 controls plus the selected NIST SP 800-172 enhanced-security requirements (typically 24-30 Level 3 practices); the 90-day program also covers the Supply Chain Risk Management family (NIST SR-1 / SR-3) and the incident response family aligned to DIBNet reporting. SPRS final submission target: +110. Contract-award eligibility: full CMMC L2 Final + L3 Final designation. ComplianceStack pairs the prime contractor pattern with the CUI enclave boundary discovery + the supply-chain flow-down inventory mapping every tier-1 to tier-3 subcontractor back to its CMMC Level. Typical C3PAO cost: $50,000-$100,000+ for a mid-size prime contractor; 501+ employee prime contractors commonly exceed $150,000 for the C3PAO engagement.
The recommended pathway is the annual Level 1 self-assessment against the 17 FAR 52.204-21 practices with affirmation of compliance posted to SPRS. The 90-day program covers the 17 practice areas (basic safeguarding of FCI, MFA on FCI-bearing systems, physical access, malware protection, patch management, account management). ComplianceStack pairs the Level 1 subcontractor pattern with the DFARS 7012 flow-down inventory mapping every tier above + every tier below. Contract-award eligibility: FCI-bearing DoD subcontract work where the prime's CUI enclave is tightly scoped and the FCI operations remain separate.
The recommended pattern recognizes that a single contractor can run different enclaves at different CMMC Levels. The CUI enclave is hardened to Level 2 + select Level 3 controls; the FCI operations rest at Level 1; the network boundary between the CUI enclave and the FCI operations must enforce isolation (NIST SC-7 boundary protection + SC-8 transmission confidentiality + SC-32 system partitioning) so that the CUI enclave cannot leak FCI-bearing data into the FCI network boundary. The compliance-pulse assessment scores the systems in each enclave separately; the SSP and POA&M cover each enclave scope. ComplianceStack pairs the hybrid pattern with a dual-enclave inventory + enclave-isolated audit-trail scoping.
Four ComplianceStack tools pair directly with this pillar guide. The free CMMC compliance pulse is the lightweight Level / SPRS scoring diagnostic (under 60 seconds, no signup, no email required); the 90-day roadmap deliverable converts the 110-control gap backlog into a sequenced plan; the free-compliance-assessment covers CMMC 2.0 alongside HIPAA / SOX / GDPR / OSHA / PCI-DSS / NIST CSF 2.0 for multi-scope DIB contractors; and ComplianceStack pricing covers audit-ready deliverables from free gap-mapping to paid 90-day roadmap reports.
Run the ComplianceStack free CMMC 2.0 compliance pulse at /cmmc-compliance-pulse. Under 60 seconds, no email or signup required. Instant CMMC readiness score (Level-applicability-aware), SPRS scoring readiness, CUI enclave boundary integrity, DFARS 7012 flow-down completeness, plus the most-cited CMMC Level 2 deficiency categories surfaced (missing MFA enforcement under AC.L2-3.1.1, missing SPRS submission under DFARS 7012, missing documented SSP under PL.L2-3.2.1, missing POA&M under CA.L2-3.5.1, missing incident-response DIBNet reporting alignment to IR.L2-3.6.2), and the top three remediation actions ranked by likelihood times impact — with assessment-path recommendation (Self / Self-Assessed / C3PAO / DIBCAO) and a 90-day checklist timeline.
Run the Free CMMC 2.0 Assessment →The ComplianceStack free compliance assessment at /free-compliance-assessment scores CMMC 2.0 alongside NIST 800-171 + HIPAA / SOX / GDPR / OSHA / PCI-DSS / SEC / FINRA in a single multi-question instrument. Useful for any DIB contractor whose compliance scope spans defense contracts (CMMC 2.0 / NIST 800-171 / DFARS 7012) and adjacent regulated industry compliance (HIPAA for healthcare adjacency, SOX for SEC-reporting-company adjacency, GDPR for European-bound CUI scope). Output: every-framework risk score and a cross-framework remediation map keyed to the contract-award eligibility signal.
Open the Multi-Framework Assessment →The ComplianceStack 90-Day Roadmap at /90-day-roadmap converts the CMMC 2.0 110-control gap backlog into a sequenced implementation plan. Output: a 90-day delivery plan covering AC + IA + AU + SI + CM + SC + MP + PE + PL + PS + RA + AT + IR + MA, with named owners, evidence-package expectations, the SPRS scoring submission timeline, and the C3PAO assessment engagement window for the Level 2 third-party path. ComplianceStack delivers this in 3-5 business days.
Build the 90-Day Roadmap →Upgrade from the free assessment to a ComplianceStack audit-ready report ($49-$149), remediation action plan ($79), or 90-day roadmap ($299) for documented output that satisfies the CMMC / NIST 800-171 / DFARS 7012 cross-reference evidence-format expectation and is defensible at any C3PAO Level 2 third-party engagement. The ComplianceStack SSP and POA&M artifacts are the closing-package deliverable for the readiness program.
View Pricing →ComplianceStack pairs every CMMC 2.0 Level 2 practice with its NIST SP 800-171 Rev 2 control family and its NIST CSF 2.0 Function / Category / Subcategory counterpart — covering the new Govern (GV) Function plus Identify (ID), Protect (PR), Detect (DE), Respond (RS), and Recover (RC). Use this crosswalk to map a finished CMMC Level 2 evidence package to a NIST CSF 2.0 Current-vs-Target Profile without re-papering controls, and to demonstrate continued CSF 2.0 alignment to enterprise buyers who request both attestations.
| CMMC 2.0 Level 2 Family | NIST SP 800-171 Rev 2 Section | NIST CSF 2.0 Function / Category / Subcategory | HIPAA Security Rule safeguard (45 CFR §164) | SOC 2 Trust Services Criterion | Primary-source citation |
|---|---|---|---|---|---|
| AC — Access Control | §3.1.1–3.1.22 | PR.AA-01 through PR.AA-05 + PR.AC-01/04/06 | §164.312(a)(1) Access Control + §164.308(a)(3) Workforce Security | CC6.1 + CC6.3 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| AT — Awareness and Training | §3.2.1–3.2.3 | PR.AT-01 through PR.AT-05 | §164.308(a)(5) Security Awareness & Training | CC1.4 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| AU — Audit and Accountability | §3.3.1–3.3.9 | DE.AE-02/03 + DE.CM-01 | §164.312(b) Audit Controls + §164.308(a)(1)(ii)(D) Information System Activity Review | CC7.1 + CC7.2 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| CM — Configuration Management | §3.4.1–3.4.9 | PR.PS-01 + PR.DS-01 + ID.IM-01 | §164.308(a)(8) Evaluation + §164.310(a)(1) Facility Access Controls | CC8.1 + CC6.1 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| IA — Identification and Authentication | §3.5.1–3.5.11 | PR.AA-01/03 | §164.312(a)(2)(i) Unique User Identification + §164.312(d) Person/Entity Authentication | CC6.1 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| IR — Incident Response | §3.6.1–3.6.3 | RS.AN-01 + RS.RP-01 + RS.MI-01/02 | §164.308(a)(6) Security Incident Procedures | CC7.2 + CC7.3 + CC7.4 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| MA — Maintenance | §3.7.1–3.7.6 | PR.MA-01/02 | §164.310(a)(2)(iv) Facility Maintenance + §164.310(c) Device/Media Controls | CC6.7 + CC7.2 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| MP — Media Protection | §3.8.1–3.8.9 | PR.DS-01 + MP-6 sanitization | §164.310(d)(1) Device & Media Controls | CC6.7 + CC6.1 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| PE — Physical and Environmental Protection | §3.10.1–3.10.6 | PR.AA-04 | §164.310(a) Facility Access Controls | CC6.4 + CC6.5 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| PL — Planning | §3.9.1–3.9.2 | GV.PO-01 + ID.AM-01/-05 | §164.308(a)(7) Contingency Plan | CC1.1 + CC3.1 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| PS — Personnel Security | §3.9.1–3.9.2 | PR.AT-01/04 | §164.308(a)(3) Workforce Security + §164.308(a)(7)(ii)(D) Data Backup Plan (training-driven) | CC1.2 + CC6.3 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| RA — Risk Assessment | §3.11.1–3.11.3 | ID.RA-01 through ID.RA-05 + GV.RM-01 | §164.308(a)(1)(ii)(A) Risk Analysis + §164.308(a)(8) Evaluation | CC3.1 + CC3.2 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| SA — System and Services Acquisition | §3.13.1–3.13.5 | PR.PS-06 + ID.SC | §164.308(a)(4) Information Access Management + §164.314(b) Subcontractor BAA | CC9.2 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| SC — System and Communications Protection | §3.13.1–3.13.16 | PR.DS-01/02 + PR.PS-01 | §164.312(e)(1) Transmission Security + §164.312(e)(2)(ii) Encryption | CC6.6 + CC6.7 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
| SI — System and Information Integrity | §3.14.1–3.14.7 | DE.CM + RS.AN | §164.308(a)(1)(ii)(D) Information System Activity Review + §164.312(a)(2)(i) Audit Controls | CC7.1 + CC7.2 | 32 CFR Part 170 / NIST SP 800-171 Rev 2 |
Pair this crosswalk with the two other pillar references below. Each row can be lifted wholesale into a CMMC Level 2 evidence cell, an SPRS scoring cell, a NIST SP 800-171 Rev 2 control inventory row, a NIST CSF 2.0 Target Profile cell, or a HIPAA Security Rule §164 evidence map.
The ComplianceStack NIST CSF 2.0 pillar at /pillar/nist-csf walks the six Functions (Govern + Identify / Protect / Detect / Respond / Recover), the four Tiers (Partial → Adaptive), Current-vs-Target Profiles, Implementation Examples, and Informative References — the Function/Category side of every row above, plus the §8a crosswalk mapping NIST SP 800-53 Rev 5 ↔ §164.308-312 ↔ CMMC 2.0 AC/IA/SC family controls.
Open the NIST CSF 2.0 Pillar Guide →The ComplianceStack HIPAA pillar at /pillar/hipaa walks the Security Rule §164.308-312 safeguard table that anchors the HIPAA-adjacent healthcare DIB contractor program — Privacy Rule, Security Rule, Breach Notification, OCR §160.404 enforcement, the 90-day ComplianceStack roadmap, and the §6 crosswalk mapping §164 ↔ NIST SP 800-66 Rev 2 ↔ CMMC 2.0 AC / IA / AU family controls.
Open the HIPAA Practical Guide →