The following images represent a hypothetical view of NIST 171 Assessment elements. The images are a snapshot of Basic L1, Focused L2, and Comprehensive or Expert or L3. Note that the 35 Enhanced Security Controls are from NIST SP 800-172. 

NIST 171 Basic Security Requirements Level 1 Basic

NIST 171 Level 2 Derived RequirementsDerived, Advanced, Medium

NIST 172 CMMC L3 Expert RequirementsExpert, L3, High

171 and 172 Requirements with Levels Scores and CMMC TagsScoring, Protection Criteria, CMMC Practice ID

Figure (s)14 Attributes for 171 and 172 requirements include Protection Criteria, Scoring Penalty, associated CMMC practice, Control Families, Testing Procedure, and Mapped ISO/IEC and SP 800-53 security requirements.

Start Today

The NIST 171 DoD Assessment and Cybersecurity Maturity Model Certificate (CMMC) Framework Levels 1 & 2 requirements are mandatory under the FAR, Federal Acquisition Regulation, and Defense Federal Acquisition Regulation Supplement (DFARS). All Vendors should prepare or actively be in the process of their DoD Assessment and in the performance of reporting a Basic self-assessment to the Supplier Performance Risk System (SPRS). Notification of a Level 3 requirement is in short order, so it is prudent to begin working with the NIST SP 800-172 and fully understand practice requirements for maintaining a POA&M, SSP, and all necessary Plans, Policies, and Procedures to be DoD Assessment ready.

Main Menu