skip to content

Under NIST SP 800-171 Rev. 3 and the CMMC rule (32 CFR part 170), what must a defence subcontractor handling Controlled Unclassified Information demonstrate?

level: seniorimportance: should knowfreq 34%

answer

  1. CUI in nonfederal systems
  2. Moderate baseline, tailored for confidentiality
  3. CMMC Level 2 cites Revision 2
  4. flow-down by prime's level
  5. 0.8 score, 180 days

basics

~20 s

SP 800-171 sets confidentiality requirements for CUI in nonfederal systems. CMMC is DoD's verification: a subcontractor handling CUI needs at least Level 2, whose 110 requirements are those of SP 800-171 Revision 2, not Revision 3.

solid answer

~50 s

**NIST SP 800-171 Rev. 3** (May 2024) gives agencies recommended requirements to protect the **confidentiality** of CUI in **nonfederal systems**; it is built by tailoring the SP 800-53B **Moderate** baseline into **17 families** with organization-defined parameters. The **CMMC** rule, **32 CFR part 170**, is how DoD verifies contractors. **Level 1** covers FCI with the 15 FAR 52.204-21 requirements; **Level 2** is identical to **SP 800-171 Revision 2** (110 requirements), by self-assessment or a C3PAO certification assessment every three years with annual affirmation; **Level 3** adds 24 requirements selected from SP 800-172. Under **170.23**, a subcontractor handling CUI needs at least Level 2 (Self), or Level 2 (C3PAO) if the prime's contract requires C3PAO or Level 3. A POA&M is allowed only within 170.21's limits - among them a score of at least 0.8 of the requirements, none of the excluded requirements on it, and closeout within 180 days.

go deeper

for a junior

Recall that SP 800-171 protects CUI confidentiality in nonfederal systems and that CMMC has three levels, with Level 2 for CUI.

for a middle

Explain how SP 800-171 is derived from the Moderate baseline, what ODPs are, and how CMMC Level 2 self and C3PAO assessments differ.

for a senior

Demonstrate running the programme: scope a CUI enclave, handle the Revision 2 versus 3 mismatch, apply the 0.8 and excluded-item POA&M rules, and meet the 180-day closeout.

for a principal

Weigh enclave versus enterprise-wide scope, and when a CMMC-driven investment should also target Revision 3 for future contracts.

## Two documents, two jobs A defence subcontractor meets two separate texts, and the most common interview error is to merge them. - **NIST SP 800-171** says *what* protection CUI needs when it sits in a **nonfederal system**. It is a NIST guideline that agencies place in contracts or agreements. - The **Cybersecurity Maturity Model Certification (CMMC) Program**, codified at **32 CFR part 170**, is the Department of Defense's way to **verify** that contractors and subcontractors actually implement the required safeguards for **Federal Contract Information (FCI)** and **CUI**. ## SP 800-171 Rev. 3 **Controlled Unclassified Information** is information that a law, regulation or government-wide policy requires to have safeguarding or dissemination controls, excluding classified information. SP 800-171 Rev. 3 (May 2024) provides recommended requirements for protecting its **confidentiality** in nonfederal systems. Its construction is worth knowing: 1. Start from the SP 800-53 controls in the SP 800-53B **Moderate** baseline (CUI's confidentiality impact is no less than moderate). 2. Tailor out controls that are primarily the Federal Government's responsibility, not directly related to CUI confidentiality, adequately addressed by other controls, or not applicable. 3. Organize what remains into **17 families**. The PT (PII processing), PM (program management) and CP (contingency planning, which addresses availability) families are not included. Rev. 3 carries **organization-defined parameters (ODPs)**: assignment and selection values that agencies may specify, and that the nonfederal organization must assign itself if the agency does not. By count of its non-withdrawn requirement numbers, Rev. 3 holds 97 requirements; assessment procedures are in the companion SP 800-171A. ## CMMC levels under 32 CFR 170 | Level | Information | Requirements | Assessment | |---|---|---|---| | Level 1 (Self) | FCI | 15 requirements of 48 CFR 52.204-21(b)(1) | Annual self-assessment, no POA&M permitted | | Level 2 (Self) or Level 2 (C3PAO) | CUI | 110 requirements, identical to **SP 800-171 R2** | Self-assessment or C3PAO certification assessment every three years; affirmation at each assessment and annually | | Level 3 (DIBCAC) | CUI, generally for the most critical programmes | 24 requirements selected from SP 800-172, with DoD-set ODPs | DCMA DIBCAC assessment every three years; Final Level 2 (C3PAO) is a prerequisite | The version trap: **32 CFR 170 incorporates SP 800-171 Revision 2 (February 2020) by reference**, and states that Level 2 requirements are identical to it. A contractor preparing for a CMMC Level 2 assessment is assessed against Revision 2's 110 requirements using SP 800-171A (June 2018), even though NIST has since published Revision 3. ## What a subcontractor is held to Section **170.23** makes primes flow CMMC down through all tiers of the supply chain: - FCI only: **Level 1 (Self)**. - CUI: **Level 2 (Self)** at minimum. - CUI where the prime contract requires Level 2 (C3PAO): **Level 2 (C3PAO)** at minimum. - CUI where the prime contract requires Level 3 (DIBCAC): **Level 2 (C3PAO)** at minimum. If the subcontractor stores CUI in a cloud service, the Level 2 sections require that offering to be **FedRAMP Authorized at Moderate or higher**, or to meet equivalent requirements under DoD policy. ## POA&Ms and running the programme Section **170.21** limits when an assessment may end in a *Conditional* status with a **Plan of Action and Milestones (POA&M)**: - No POA&M at Level 1. - At Level 2, the assessment score divided by the total number of Level 2 requirements must be **at least 0.8**. - No POA&M item may carry a point value above 1, except `SC.L2-3.13.11` CUI encryption where encryption is used but not FIPS-validated. - Some requirements may never be on a POA&M, including `CA.L2-3.12.4` System Security Plan and the physical-access requirements `PE.L2-3.10.3` to `PE.L2-3.10.5`. - The POA&M must be closed out within **180 days** of the Conditional status date, or the Conditional status expires. Senior judgement lives in **scoping**: the requirements apply to systems that process, store or transmit CUI, that protect such systems, or that are not isolated from them. Shrinking that boundary (a dedicated enclave) usually saves more than any single control. Keep a clean system security plan: it is the document the assessor starts from, and its requirement can never be deferred to a POA&M. Track Revision 3 for future contracts while assessing to what the rule actually cites.

  • Why does SP 800-171 omit the Contingency Planning family?
    SP 800-171 protects the confidentiality of CUI. Rev. 3 says CP is excluded because it addresses availability; PT is excluded because PII is a CUI category needing no additional confidentiality requirements, and PM because it is tied to no baseline.
  • What happens if a Conditional Level 2 POA&M is not closed within 180 days?
    Under 32 CFR 170.16 and 170.17 the Conditional status expires. Standard contractual remedies apply during an active contract, and the organization cannot win new awards needing that level for the in-scope system until it achieves a new status.
  • May a subcontractor use a cloud service for CUI?
    Yes, under the Level 2 sections of 32 CFR 170, if the offering is FedRAMP Authorized at Moderate or higher, or meets equivalent requirements under DoD policy.

saying these in an interview costs you the question

  • Says CMMC Level 2 assesses against SP 800-171 Revision 3
  • Believes a subcontractor inherits the prime's CMMC certification
  • Thinks any failed requirement can sit on a POA&M indefinitely
  • Treats SP 800-171 as covering availability of CUI
  • Assumes Level 1 allows a POA&M for unmet items