NIST 800-171 vs CMMC: What Subcontractors Must Show
Compliance reviewed by Onur Oncer, SDVOSB Materials compliance lead.
NIST Special Publication 800-171 is a set of security requirements. Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense program that verifies you met them. SDVOSB Materials Technology & Supply LLC works both sides of that line on federal infrastructure jobs: 800-171 tells you what to build, CMMC decides who has to prove it.
One Is a Standard. The Other Is a Verification Program.
People treat these as two names for one obligation. They aren't, and the confusion costs subcontractors real money, usually as a readiness engagement bought before anyone checked whether the contract required one.
NIST SP 800-171 Rev. 2 is a publication from the National Institute of Standards and Technology (NIST). It describes how to protect Controlled Unclassified Information (CUI) when that information sits on a system your company owns rather than one the government owns. It is a document. Nobody at NIST audits you, and there is no such thing as being "certified in 800-171." You implement it, you write down what you implemented, and you write down what you haven't gotten to yet.
CMMC exists because self-attestation and actual implementation drifted apart across the defense industrial base. It does not replace the security requirements. It adds a verification layer on top of them and ties the depth of that verification to how sensitive the information on the contract is. Lower levels rest on the contractor's own assessment. Higher levels bring in an outside assessor who wants evidence, not assertions.
800-171 is the building code. CMMC is the inspection. Our federal IT infrastructure procurement guide covers where both land inside a full technology scope of work.
Which One Applies, and When
The mechanism that pulls either one onto your contract is a clause. Not a policy, not a general rule about federal work. A clause, in the document you signed or the solicitation you're bidding.
On Department of Defense work, the usual route is DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. That clause does two things a subcontractor needs to understand. It applies the NIST SP 800-171 security requirements to covered contractor information systems, and at paragraph (m) it requires the prime to include the clause in subcontracts whose performance will involve covered defense information. If it's in your subcontract, it's yours. The prime does not absorb it for you.
Outside the Department of Defense, DFARS doesn't reach you at all. Civilian agency CUI obligations arrive through whatever clause that agency writes, and the wording varies. Read the clause.
CMMC applicability works the same way and gets assumed even more often. The requirement, and its level, comes from the solicitation. Guessing the level in advance and buying against the guess is how a small subcontractor spends money it will not recover.
Side by Side, Where the Two Actually Differ
The comparison below runs three columns in order: the question, how NIST SP 800-171 Rev. 2 answers it, then how CMMC answers it.
What is it. 800-171: security requirements for protecting CUI on nonfederal systems. CMMC: a DoD program verifying whether those requirements were implemented.
Who owns it. 800-171: NIST, a standards body. CMMC: the Department of Defense, a customer.
How it reaches you. 800-171: a contract clause, most commonly DFARS 252.204-7012 on DoD work. CMMC: a requirement written into the solicitation.
What you produce. 800-171: a system security plan, plus a plan of action for the gaps. CMMC: evidence an assessor can examine, at the level named.
Can you be certified in it. 800-171: no, it is a standard you implement and document. CMMC: yes, certification is the point of the program.
When it stops applying. 800-171: when no covered information touches systems you control. CMMC: when the contract carries no CMMC requirement.
What a Subcontractor Actually Has to Show
Primes ask for evidence in a fairly predictable order. Ranked by how often it is the thing that stalls an award, here is what to have ready before you're asked.
A written scope answer. Does covered information touch systems your company controls on this job? Most infrastructure subcontractors have never written this down, and it is the first question that matters. If the answer is no, say so in writing and explain why.
A system security plan. It describes your actual environment and how each requirement is met inside it. A generic template with your logo on it reads as a generic template with your logo on it.
A plan of action for the gaps. Nobody expects a small subcontractor to be complete. They expect you to know what is missing and to have dated, owned remediation against it. Honest gaps beat a clean sheet nobody believes.
The flow-down clause, read. Pull DFARS 252.204-7012 out of your subcontract and confirm whether paragraph (m) put it there. Primes have flowed it to vendors who never touch covered information.
An incident reporting path. Know who reports, to whom, and how fast, before the incident.
Here is the uncomfortable part. If your firm pulls cable, installs racks, and hands over a network you never administer, a full readiness program may be money spent against a requirement you do not carry. Establishing that in writing, early, beats any control you could implement this quarter.
Where Infrastructure Work Sits in All This
SDVOSB Materials Technology & Supply LLC is an infrastructure provider, not a managed security service provider. On the technology infrastructure side we plan, install and integrate voice, data, video, audiovisual, IT and physical security systems for federal facilities, built to the compliance baseline the customer sets. Where a customer wants AI-driven threat detection at the network edge, we work with GuardDog.ai. Formal assessment belongs to an accredited assessor, and we say so rather than blurring it.
Our contract paths are worth stating plainly, because subcontractors get burned by vague answers here. We do not hold a GSA Schedule; GSA orders run through GSA-registered partner vendors. We do hold the TIPS cooperative purchasing contract, number 230701, and we bid direct SDVOSB and HUBZone set-asides. Credentials include SBA SDVOSB certification, SBA HUBZone certification, and Small Disadvantaged Business status, verifiable on the company's SBA Small Business Search profile. UEI K39HBMPLN4B3, CAGE 7YX60, EIN 82-2895228, registered active on SAM.gov.
Compliance scope rarely arrives alone. A secure facility build carrying a CUI requirement usually carries power and continuity requirements in the same specification, which is why this work often runs alongside the division handling energy storage and microgrids for federal facilities.
Frequently Asked Questions
Is CMMC replacing NIST SP 800-171?
No. CMMC is built on the NIST SP 800-171 security requirements, not in place of them. The requirements still describe what to implement. CMMC governs how, and by whom, that implementation gets verified on Department of Defense contracts.
Do we need CMMC if we are a subcontractor and not the prime?
It depends on what your subcontract says and whether covered information reaches systems you control. Flow-down is real and primes do pass these obligations along. The subcontract document is the authority, not the prime's verbal summary of it.
Does NIST SP 800-171 apply to civilian agency work?
It can, but not through DFARS. Civilian agencies impose CUI protection through their own clauses, and the language differs between agencies. Read the clause in your contract rather than applying the DoD pattern by default.
What is the single most useful document to have ready?
A system security plan describing your actual environment, paired with a dated plan of action for what you have not met yet. Between those two, most prime and contracting officer questions get answered without a scramble.
What is SDVOSB Materials' own CMMC level?
We do not publish a level here. Publishing a status we cannot substantiate on the day you read it would be worse than saying nothing. Ask in writing and you will get a written answer on current status.
Can you take on the assessment itself?
No. We are an infrastructure and integration provider with cybersecurity compliance support built into how we scope work. Accredited assessors perform CMMC assessments, and we coordinate with partners rather than claiming that role.
Where does this fit in a federal IT scope of work?
Usually as a baseline stated before design starts. Our technology infrastructure services page shows how a compliance baseline drives cabling, network, physical security and audiovisual decisions instead of being bolted on afterward.
Talk to the Technology Infrastructure Division
Working a federal infrastructure requirement with a CUI or CMMC clause attached? Send the solicitation or the subcontract language through the technology division contact page or call (917) 216-9400. We will tell you what the clause obligates, what we can build against it, and where you need somebody who is not us.




Comments