Thousands of contractors search every month for a NIST-800-171-to-CMMC crosswalk — a spreadsheet that translates one framework into the other. Here's the answer nobody selling crosswalks wants to lead with: for CMMC Level 2, the mapping is identity. CMMC Level 2 is NIST SP 800-171's 110 controls, adopted verbatim. Nothing added, nothing removed, nothing renamed except a prefix. If you understand one, you understand the other.
Why Everyone Thinks a Crosswalk Exists
Because one used to. CMMC 1.0 (2020) had 130 practices at its old Level 3 — the 110 NIST requirements plus 20 "delta" practices unique to CMMC. Mapping spreadsheets from that era are still floating around, and they're what old blog posts and consultants' slide decks reference. CMMC 2.0 (2021) deleted the deltas specifically to align with NIST exactly — the crosswalk industry just never got the memo.
The Actual Mapping, All of It
| CMMC element | Maps to | Notes |
|---|---|---|
| Level 1 (FCI only) | FAR 52.204-21 — 15 basic safeguards | Not from 800-171 at all; the 15 overlap with 800-171 concepts but the source is the FAR clause. Level 1 vs 2 here. |
| Level 2 (CUI) | NIST SP 800-171 Rev 2 — all 110 requirements, verbatim | The identity mapping. All 110 in plain English. |
| Level 3 (critical programs) | Level 2 + 24 requirements from NIST SP 800-172 | DIBCAC-assessed; out of scope for most small subs. |
| SPRS scoring | DoD Assessment Methodology over the same 110 | 110 down to −203; the arithmetic. |
| Assessment objectives | NIST SP 800-171A | What an assessor (or you, honestly) verifies per control. |
How to Read a CMMC Control ID
The "mapping" people actually need is usually just ID decoding. Take AC.L2-3.1.1:
- AC — the family (Access Control, one of 14)
- L2 — the CMMC level where it applies
- 3.1.1 — the NIST SP 800-171 requirement number, unchanged
Strip the prefix and you're holding the NIST requirement. Every CMMC Level 2 practice ID decodes this way, which is why no lookup table needs to exist — the ID is the crosswalk.
What Actually Differs — the Wrapper, Not the Controls
- NIST SP 800-171 is the standard: what to implement. It's invoked contractually by DFARS 252.204-7012.
- SPRS is the reporting layer: your self-assessed score against those 110, posted under DFARS 7019. Submission guide.
- CMMC is the verification layer: the program that has a third party check the same 110 at Level 2 — currently suspended pending reform, which changed who verifies, not what you owe.
One control set; three layers. Implement once, report honestly, and be ready to be verified whenever that layer switches back on.
Assess the 110 once — cover all three layers
CMMC Map walks the same 110 controls that NIST wrote, SPRS scores, and CMMC verifies — in plain English, free, with your live score as you go. The SSP and POA&M generate from your answers when you need them.
Start free →One Wrinkle to Watch: Revision 3
NIST published 800-171 Revision 3 in 2024 with a restructured requirement set — but DoD formally kept Rev 2 as the basis for DFARS compliance, SPRS scoring, and CMMC. If you've seen "97 requirements" and "17 families" and wondered whether your mapping broke: it didn't, because Rev 3 isn't operative for defense contracts yet. The full Rev 2 vs Rev 3 picture.