The following images represent a hypothetical view of NIST 171 Assessment elements. The images are a snapshot of Basic L1, Focused L2, and Comprehensive or Expert or L3. Note that the 35 Enhanced Security Controls are from NIST SP 800-172.
Scoring, Protection Criteria, CMMC Practice ID
Figure (s)14 Attributes for 171 and 172 requirements include Protection Criteria, Scoring Penalty, associated CMMC practice, Control Families, Testing Procedure, and Mapped ISO/IEC and SP 800-53 security requirements.
Start Today
The NIST 171 DoD Assessment and Cybersecurity Maturity Model Certificate (CMMC) Framework Levels 1 & 2 requirements are mandatory under the FAR, Federal Acquisition Regulation, and Defense Federal Acquisition Regulation Supplement (DFARS). All Vendors should prepare or actively be in the process of their DoD Assessment and in the performance of reporting a Basic self-assessment to the Supplier Performance Risk System (SPRS). Notification of a Level 3 requirement is in short order, so it is prudent to begin working with the NIST SP 800-172 and fully understand practice requirements for maintaining a POA&M, SSP, and all necessary Plans, Policies, and Procedures to be DoD Assessment ready.

Basic
Derived, Advanced, Medium
Expert, L3, High
Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics