What Is the Relationship Between NIST SP 800-172 and CMMC?
Source: DoD CIO CMMC FAQs v5 (B-Q5)
NIST SP 800-172 provides security requirements designed to address advanced persistent threats and forms the basis for CMMC Level 3 security requirements. Contractors must implement 24 selected enhanced security requirements from NIST SP 800-172 in addition to the 110 security requirements found in NIST SP 800-171 when the Department identifies CMMC Level 3 as a contract requirement.
Have More Questions?
ChatCMMC can answer detailed questions about CMMC compliance, NIST 800-171, assessment preparation, and more β with source citations when available from selected official DoD and NIST sources.
Ask ChatCMMC βCMMC Readiness Assessment
Find out where your organization stands and what steps you need to take. Jun Cyber's CMMC experts can help you interpret the requirements.
You Might Also Want to Know
Ready to Start Your CMMC Journey?
Jun Cyber helps defense contractors prepare for applicable CMMC requirements. From scoping and gap assessments to documentation, remediation, and C3PAO assessment readiness β Jun Cyber provides hands-on compliance support.