← CMMC / NIST 800-171

The Road to CMMC 2.0 & 32 CFR Part 170

How U.S. federal law, the CUI program, and DoD contract rules converge

into the Cybersecurity Maturity Model Certification

The chain in one line:
FISMA → NIST SP 800-53 → NIST SP 800-171 (Rev 2) → DFARS 7012 → CMMC 1.0 → CMMC 2.0 → 32 CFR Part 170 (effective 11/10/2025) → 48 CFR/DFARS puts it in contracts
Statutory & standards foundation The CUI program DoD contractual mechanism
Stream 1  ·  Statutory & Standards Foundation
2002

FISMA

Federal Information Security Management Act. Requires agencies to protect federal information and directs NIST to write the standards.

2003 onward

FIPS 199 / FIPS 200 + NIST SP 800-53

Security categorization plus the master controls catalog. Everything downstream draws its controls from 800-53.

2015 (Rev 1, Dec 2016)

NIST SP 800-171

"Protecting CUI in Nonfederal Systems." Distills 800-53 into 110 controls written for contractors.

February 2020

NIST SP 800-171 Revision 2

110 controls across 14 families. This is the technical baseline for CMMC Level 2. Not Rev 3.

CMMC Level 2 = this baseline
Stream 2  ·  The CUI Program (what we protect)
November 2010

Executive Order 13556

Creates the government-wide Controlled Unclassified Information program and names NARA as Executive Agent.

September 2016

32 CFR Part 2002: the CUI Rule

Defines CUI categories, marking, and handling, and points to 800-171 as the safeguarding standard for nonfederal systems. (Different part of the CFR from Part 170.)

Stream 3  ·  DoD Contractual Mechanism (the teeth)
2016

DFARS 252.204-7012

Safeguarding Covered Defense Information. Contract clause requiring 800-171 plus 72-hour incident reporting.

January 2020

CMMC 1.0

Original five-level model with third-party audits. Criticized as too costly and complex.

November 2020

DFARS Interim Rule: 7019 / 7020 / 7021

Adds the assessment requirement, the DoD Assessment Methodology, and the CMMC clause. Introduces SPRS self-assessment scoring.

November 2021

CMMC 2.0 Announced

Restructures five levels into three: Level 1 (FCI, self-assess), Level 2 (CUI = 800-171 Rev 2), Level 3 (DIBCAC-led, adds 800-172).

↓   The three streams converge   ↓
December 26, 2023

Proposed Rule: 32 CFR Part 170

The CMMC Program rule enters public rulemaking.

October 15, 2024

Final Rule: 32 CFR Part 170

The CMMC Program itself: levels, C3PAOs, assessment process, POA&M rules, and affirmations.

November 10, 2025

32 CFR Part 170 Effective

The CMMC program is live.

Program in force
Phased rollout

48 CFR / DFARS Rule

Revises DFARS 252.204-7021 to put CMMC requirements into actual contracts, phased over roughly three years.

Three distinctions people get wrong

  • 32 CFR Part 170 is the CMMC program rule (how assessments work). 48 CFR / DFARS is the contractual rule (how it lands in your contract). Both are needed for CMMC to bite.
  • 32 CFR Part 2002 (the CUI rule) is a different animal from 32 CFR Part 170 (the CMMC rule): same CFR title, different parts.
  • CMMC Level 2 is frozen at 800-171 Rev 2, even though NIST published Rev 3 in 2024.