The Road to CMMC 2.0 & 32 CFR Part 170
How U.S. federal law, the CUI program, and DoD contract rules converge
into the Cybersecurity Maturity Model Certification
FISMA → NIST SP 800-53 → NIST SP 800-171 (Rev 2) → DFARS 7012 → CMMC 1.0 → CMMC 2.0 → 32 CFR Part 170 (effective 11/10/2025) → 48 CFR/DFARS puts it in contracts
FISMA
Federal Information Security Management Act. Requires agencies to protect federal information and directs NIST to write the standards.
FIPS 199 / FIPS 200 + NIST SP 800-53
Security categorization plus the master controls catalog. Everything downstream draws its controls from 800-53.
NIST SP 800-171
"Protecting CUI in Nonfederal Systems." Distills 800-53 into 110 controls written for contractors.
NIST SP 800-171 Revision 2
110 controls across 14 families. This is the technical baseline for CMMC Level 2. Not Rev 3.
CMMC Level 2 = this baselineExecutive Order 13556
Creates the government-wide Controlled Unclassified Information program and names NARA as Executive Agent.
32 CFR Part 2002: the CUI Rule
Defines CUI categories, marking, and handling, and points to 800-171 as the safeguarding standard for nonfederal systems. (Different part of the CFR from Part 170.)
DFARS 252.204-7012
Safeguarding Covered Defense Information. Contract clause requiring 800-171 plus 72-hour incident reporting.
CMMC 1.0
Original five-level model with third-party audits. Criticized as too costly and complex.
DFARS Interim Rule: 7019 / 7020 / 7021
Adds the assessment requirement, the DoD Assessment Methodology, and the CMMC clause. Introduces SPRS self-assessment scoring.
CMMC 2.0 Announced
Restructures five levels into three: Level 1 (FCI, self-assess), Level 2 (CUI = 800-171 Rev 2), Level 3 (DIBCAC-led, adds 800-172).
Proposed Rule: 32 CFR Part 170
The CMMC Program rule enters public rulemaking.
Final Rule: 32 CFR Part 170
The CMMC Program itself: levels, C3PAOs, assessment process, POA&M rules, and affirmations.
32 CFR Part 170 Effective
The CMMC program is live.
Program in force48 CFR / DFARS Rule
Revises DFARS 252.204-7021 to put CMMC requirements into actual contracts, phased over roughly three years.
Three distinctions people get wrong
- 32 CFR Part 170 is the CMMC program rule (how assessments work). 48 CFR / DFARS is the contractual rule (how it lands in your contract). Both are needed for CMMC to bite.
- 32 CFR Part 2002 (the CUI rule) is a different animal from 32 CFR Part 170 (the CMMC rule): same CFR title, different parts.
- CMMC Level 2 is frozen at 800-171 Rev 2, even though NIST published Rev 3 in 2024.