NIST SP 800-171 vs. CMMC- What’s the Difference?

NOTE: The Alaska PTAC has been renamed as Alaska APEX Accelerator. This change occurred on September 15, 2023. Learn why.

What is the relationship between NIST SP 800-171 rev.1 and CMMC?

The intent of the CMMC is to combine various cybersecurity control standards such as NIST SP 800-171, NIST SP 800-53, ISO 27001, ISO 27032, AIA NAS9933 and others into one unified standard for cybersecurity. In addition to cybersecurity control standards, the CMMC will also measure the maturity of a company’s institutionalization of cybersecurity practices and processes.

How will CMMC be different from NIST SP 800-171?

Unlike NIST SP 800-171, CMMC will implement multiple levels of cybersecurity. In addition to assessing the maturity of a company’s implementation of cybersecurity controls, the CMMC will also assess the company’s maturity/institutionalization of cybersecurity practices and processes.