A gap analysis compares your existing safeguards with the updated requirements. It helps you identify the changes, evidence, and responsibilities to plan for before a CMMC transition takes effect.
Published by NIST
The technical comparison can begin now.
Revision 3 and its assessment procedures were published in May 2024. Changes include more specific requirements, reorganized controls, new requirements, and organization-defined parameters (ODPs).
The planned CMMC amendment addresses the transition period and Level 2 and Level 3 assessment objectives. The agenda does not establish an effective date.
When the amendment and accompanying guidance are issued, confirm their applicability, parameter values, and assessment instructions. The current Level 2 baseline remains Revision 2.
What a gap analysis should cover
01
Compare the requirements
Start with your current Revision 2 implementation and NIST’s change analysis. Record new, changed, reorganized, and withdrawn requirements, then read the full Revision 3 text. A matching control name or number does not establish equivalent coverage.
02
Check controls and configurations
Review the systems that handle or protect CUI, the safeguards actually deployed, and their settings. Identify where a technical change, a process update, or additional coverage may be needed.
03
Resolve organization-defined parameters
ODPs specify values such as time periods or review frequencies. Record the applicable government-assigned value or permitted organizational choice, who approves it, and how it is implemented and demonstrated.
04
Review evidence and responsibilities
Compare NIST’s published assessment procedures with your System Security Plan, policies, configurations, logs, reports, and test results. Identify what your organization, IT provider, and Network Box must each implement and document within the agreed scope.
05
Prioritize the work
For each gap, record the affected requirement, current implementation, evidence needed, action owner, priority, and planned completion date. Track dependencies on the CMMC amendment separately so provisional assumptions can be revisited.
Turn findings into an actionable plan.
The useful outcome is a requirement-by-requirement record of existing coverage, gaps, evidence, and assigned actions. Network Box’s service mappings can help frame the managed-security contribution; your organization’s assessment must consider the complete environment and its responsibilities.
A managed security layer within a broader compliance program.
CMMC verifies cybersecurity practices within a defined contractor assessment scope; it is not a product certification. Network Box managed network security, vulnerability management, SIEM, MDR/XDR, email and web protection, awareness training, and 24/7 SOC services can implement and document important technical outcomes, but they do not independently make an organization CMMC compliant or certified.
Current implementation status
Reviewed September 7, 2026
Phase I is active. Phase II is suspended.
On July 13, 2026, the Department suspended the planned Phase II certification requirements while it conducts a broader program review. The suspension does not remove existing contractual duties to protect covered information.
Phase I Level 1 and Level 2 self-assessment requirements remain in effect.
The broader rollout of Level 2 C3PAO certification requirements is suspended.
Level 1 uses 15 FAR 52.204-21 safeguards with annual self-assessment and affirmation.
Level 2 self-assessment uses 110 NIST SP 800-171 Revision 2 requirements every three years, with annual affirmation.
Contractors must still follow applicable solicitation, contract, DFARS, safeguarding, reporting, and SPRS obligations.
Standing CMMC model
Understand the levels and the Phase II suspension.
The regulatory model still defines three levels, but current Phase 1 implementation may require only Level 1 and Level 2 self-assessments. Always confirm the controlling solicitation and contract.
Level 1 · Self
Basic safeguarding of FCI
Annual self-assessment and affirmation against the 15 requirements in FAR 52.204-21. POA&Ms are not permitted.
Level 2 · Self
Broad protection of CUI
Self-assessment every three years against 110 NIST SP 800-171 Revision 2 requirements, plus annual affirmation and limited POA&M use.
Level 2 · C3PAO
Third-party assurance for CUI
Uses the same 110 requirements under the standing model, but the broader Phase II certification rollout is currently suspended.
Level 3 · DIBCAC
Enhanced protection
Standing model adds 24 selected NIST SP 800-172 requirements after Final Level 2 status; rollout is not active while implementation remains in Phase I.
Level 1 · FCI
Basic safeguarding across six domains.
The 15 Level 1 requirements come from FAR 52.204-21. These domain mappings show where managed security can contribute without replacing the contractor's annual self-assessment.
Select a framework area to explore its detailed control mapping.
Framework area
Network Box contribution
Relevant services
Coverage
Managed network controls and secure connectivity help restrict system and external access.
Level 1 access controls limit system access to authorized users, devices, and functions and control information posted to publicly accessible systems.
Network Box contribution
Partial
Managed firewalls, segmentation, VPN access, traffic policies, and supported authentication integrations help restrict system and external access within the managed environment.
Contractor responsibility
Client responsibility
Authorize users and devices, limit permitted functions, control public posting of FCI, and manage account and access lifecycles across the complete FCI environment.
Authentication integrations and logs support access to managed services and remote connectivity.
Level 1 requires the organization to identify and authenticate users, processes, and devices before allowing access to covered systems.
Network Box contribution
Partial
VPN authentication, supported directory integration, MFA capabilities, administrative controls, and authentication logs help identify and authenticate access to Network Box-managed services.
Contractor responsibility
Client responsibility
Identify and authenticate every user, process, and device throughout the full FCI environment, including systems and applications outside Network Box management.
Managed access and handling controls protect security data inside the Network Box service scope.
Level 1 requires media containing FCI to be sanitized or destroyed before disposal or reuse.
Network Box contribution
Supporting
Network Box restricts access to and protects security data handled within the agreed managed-service scope.
Contractor responsibility
Client responsibility
Inventory, handle, sanitize, and destroy all physical and digital media containing FCI before disposal or reuse.
Available service and assurance records can support due diligence for Network Box facilities and operations.
Service documentationAssurance documentationSOC operational controls
Supporting
Detailed mapping2 mapping notes
Level 1 physical safeguards restrict access to systems, equipment, and operating environments and require visitor and access-device controls.
Network Box contribution
Supporting
Service descriptions and available assurance documentation may support evaluation of the facilities and operational environments used to deliver Network Box services.
Contractor responsibility
Client responsibility
Restrict physical access, escort and monitor visitors, maintain physical-access logs, and manage physical-access devices at contractor facilities.
Managed boundaries, segmentation, and secure connectivity protect communications within the deployed architecture.
Level 1 requires monitoring and control at external boundaries and key internal boundaries, plus separation of public-facing components.
Network Box contribution
Strong
Firewalls, segmentation, protected remote connectivity, monitored boundaries, and separation of public-facing services help secure communications and system boundaries within the managed scope.
Contractor responsibility
Client responsibility
Define the complete FCI boundary and ensure every required external and internal boundary, public-facing service, and system connection is appropriately protected.
Layered threat prevention and monitoring identify malicious code, attacks, and system flaws within scope.
Level 1 integrity safeguards address flaws, malicious code, security alerts, and monitoring of covered systems.
Network Box contribution
Strong
Intrusion prevention, anti-malware, email and web protection, MDR/XDR, vulnerability findings, security updates, and continuous SOC monitoring help detect and address attacks and flaws.
Contractor responsibility
Client responsibility
Patch and remediate affected systems, maintain endpoint protection outside the service scope, monitor relevant advisories, and correct identified flaws promptly.
These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.
Control mapping
Level 2 domains and Network Box support.
Level 2 self-assessment currently evaluates 110 NIST SP 800-171 Revision 2 requirements across 14 domains. Each requirement and assessment objective must be evaluated individually within the contractor's documented scope.
Select a framework area to explore its detailed control mapping.
Framework area
Network Box contribution
Relevant services
Coverage
Managed enforcement, segmentation, secure remote access, and telemetry support least privilege and controlled connections.
UTM+VPNSecure SD-WANNetwork segmentationSecure Web GatewayWAFDirectory integrationSIEM
Partial
Detailed mapping2 mapping notes
Protect CUI by limiting system access, functions, connections, information flows, remote sessions, and public exposure according to authorized need.
Network Box contribution
Partial
Managed firewalls, segmentation, VPN, secure remote-access gateways, traffic policy, and supported identity integrations help limit access, control external connections, and route traffic through managed enforcement points.
Contractor responsibility
Client responsibility
Own user authorization, least privilege, separation of duties, session policy, wireless and mobile controls, public posting, application access, and information-flow decisions across the full CUI environment.
Awareness education, phishing simulations, and reporting support workforce security responsibilities when subscribed.
Security Awareness TrainingPhishing simulationsTraining and campaign reports
Strong
Detailed mapping2 mapping notes
Ensure personnel understand security risks, responsibilities, insider-threat indicators, and the skills needed for their assigned duties.
Network Box contribution
Strong
Security-awareness education and phishing simulations help users recognize threats, protect credentials, respond to suspicious activity, and document participation and results.
Contractor responsibility
Client responsibility
Assign training, ensure completion, cover insider-threat awareness, and provide specialized role-based instruction appropriate to each person's responsibilities.
Centralized logs, correlation, alerting, retention, investigations, and reporting support auditability within scope.
Create, protect, review, and retain audit records that support individual accountability, detection, investigation, and reporting.
Network Box contribution
Strong
SIEM and managed platforms collect and centralize logs, correlate events, alert analysts, support investigations, protect managed logging functions, and produce reports within the contracted scope.
Contractor responsibility
Client responsibility
Define required events, connect all in-scope sources, ensure individual accountability and time synchronization, protect logs, and retain assessment evidence for required periods.
Controlled configurations, updates, administrative restrictions, and change records protect managed security systems.
UTM+Secure SD-WANSecure Web GatewayWAFManaged Cloud Email SecurityNBX: MDR, EDR, XDRVulnerability ManagementChange records
Partial
Detailed mapping2 mapping notes
Establish baselines, control changes, enforce secure settings, and restrict unnecessary software, ports, services, and functions across the CUI environment.
Network Box contribution
Partial
Network Box maintains controlled configurations for managed appliances, virtual systems, policies, and services; records applicable changes; limits administration; and can identify exposed services or misconfigurations.
Contractor responsibility
Client responsibility
Own baselines, inventories, approvals, secure configuration, application control, and change management for every other asset in the CUI assessment scope.
Uniquely identify and authenticate users, devices, and processes and manage credentials throughout their lifecycle.
Network Box contribution
Partial
Supported directory integration, VPN authentication, MFA/TOTP capabilities, administrative controls, and authentication logging help protect remote connectivity and Network Box-managed services.
Contractor responsibility
Client responsibility
Own identity proofing, identifier lifecycle, password and authenticator controls, enterprise MFA coverage, service accounts, device authentication, and application authentication.
The 24/7 SOC detects, validates, investigates, documents, escalates, and assists with incidents within scope.
Establish, test, and operate an incident-handling capability spanning preparation, detection, analysis, containment, recovery, and reporting.
Network Box contribution
Strong
The SOC categorizes and prioritizes alerts, investigates available evidence, documents activity, escalates to authorized contacts, and assists with containment and remediation using available controls.
Contractor responsibility
Client responsibility
Own the formal response plan and testing program, executive decisions, CMMC and DFARS reporting, evidence preservation, recovery, legal coordination, and government communication.
Secure administration and documented maintenance protect the managed security systems Network Box supplies.
Managed security maintenanceSecure remote administrationMFA supportChange recordsService records
Partial
Detailed mapping2 mapping notes
Control system maintenance, tools, diagnostic media, personnel, and remote maintenance sessions throughout the assessment scope.
Network Box contribution
Partial
Network Box controls and performs maintenance on its managed security systems, restricts administrative access, uses secure remote-management methods, and documents applicable maintenance activity.
Contractor responsibility
Client responsibility
Govern maintenance tools and personnel for other systems, sanitize equipment, inspect diagnostic media, supervise unauthorized personnel, and terminate maintenance sessions.
Secure transport, access controls, and monitored handling protect in-scope security data used by managed services.
Protect, control, transport, mark, sanitize, and dispose of media containing CUI, including removable media and backups.
Network Box contribution
Supporting
Access control, encrypted transport, monitoring, and protected handling support security logs and configuration data managed within the service scope.
Contractor responsibility
Client responsibility
Own CUI media inventories, markings, physical storage, access, transport, removable-media controls, sanitization, disposal, and protection of backup CUI.
Defined service roles and assurance information can support due diligence for Network Box as an external provider.
Service rolesAuthorized support accessContractual documentationAssurance documentation
Supporting
Detailed mapping2 mapping notes
Screen individuals before granting access and protect systems and information during personnel transfers and terminations.
Network Box contribution
Supporting
Defined service roles, authorized support access, contractual commitments, and available assurance documentation help the contractor evaluate Network Box personnel-related controls as an external provider.
Contractor responsibility
Client responsibility
Perform personnel screening, manage transfers and terminations, revoke access promptly, and protect CUI during personnel actions throughout the contractor organization.
Service and assurance documentation can support evaluation of facilities used to deliver managed services.
Service documentationAssurance documentationSOC operational controls
Supporting
Detailed mapping2 mapping notes
Restrict and monitor physical access to systems, equipment, facilities, visitors, and physical-access devices in the CUI environment.
Network Box contribution
Supporting
Available service and assurance documentation may support evaluation of the facilities and operating environments used to deliver Network Box services.
Contractor responsibility
Client responsibility
Limit physical access to systems and CUI environments, control and escort visitors, maintain access records, and manage physical-access devices at contractor facilities.
Recurring vulnerability assessment, threat intelligence, event analysis, and guidance identify technical risk when subscribed.
Assess organizational and system risk, scan for vulnerabilities, and remediate weaknesses according to risk.
Network Box contribution
Strong
Within scope, Network Box performs recurring vulnerability assessment, validates and prioritizes findings, analyzes threat and event information, and supplies remediation guidance and reporting.
Contractor responsibility
Client responsibility
Own organizational risk assessment, business-impact and likelihood analysis, risk acceptance, remediation decisions, and completion and documentation of corrective actions.
Monitoring records, findings, configuration evidence, incidents, reports, and reviews support assessment preparation.
Assess security requirements, develop and maintain the SSP and POA&M, monitor controls, and ensure external providers protect CUI appropriately.
Network Box contribution
Partial
Continuous monitoring, vulnerability findings, configuration records, incident histories, reports, and service reviews provide evidence that in-scope technical safeguards are operating.
Contractor responsibility
Client responsibility
Own the formal assessment, SSP, POA&M, assessment scope, remediation program, external-provider oversight, SPRS submission, affirmation, and final control determinations.
UTM+VPNSecure SD-WANNetwork segmentationIDS/IPSSecure Web GatewayWAFManaged Cloud Email Security24/7 monitoring
Strong
Detailed mapping2 mapping notes
Protect system boundaries and communications, control connections and information flows, and apply suitable cryptography and architectural separation.
Network Box contribution
Strong
Managed firewalls, segmentation, VPN, secure gateways, intrusion prevention, SWG, WAF, email protection, and monitoring can enforce deny-by-default policy, separate public services, control external connectivity, and protect data in transit.
Contractor responsibility
Client responsibility
Verify cryptographic implementations, CUI-at-rest protection, key management, collaborative devices, voice services, and every other scoped communications-protection requirement.
Managed prevention, monitoring, vulnerability findings, and SOC response identify and address attacks and flaws.
Identify, report, and correct system flaws; protect against malicious code; monitor advisories and communications; and respond to attacks.
Network Box contribution
Strong
Network Box monitors communications, detects attacks and unauthorized activity, blocks malicious code, applies threat intelligence, maintains managed protections, and identifies vulnerabilities and security events.
Contractor responsibility
Client responsibility
Patch and remediate affected systems, deploy endpoint protection everywhere required, monitor advisories for all technologies, and correct flaws within applicable timelines.
These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.
CMMC assessment scope
Design managed services into the boundary.
External Service Providers may enter the assessment scope when they process, store, or transmit CUI or Security Protection Data such as logs and configuration information. Before deployment, the contractor, MSP, and Network Box should document data flows, implicated assets and facilities, service responsibilities, required evidence, and the Customer Responsibility Matrix in the System Security Plan.
Architecture-specific verification
Product capability is not assessment evidence by itself.
These requirements depend on the actual architecture, validated technologies, operating procedures, and assessment scope, rather than a general product claim.
01
FIPS-validated cryptography
Encryption, TLS, or VPN capability alone does not prove compliance. Verify the exact module, version, operating mode, and CUI use case.
02
CUI at rest
Boundary protection does not establish protection for CUI on endpoints, servers, databases, cloud services, backups, or removable media.
03
Enterprise MFA
MFA for VPN or Network Box administration does not demonstrate coverage for every required privileged and non-privileged access scenario.
04
Incident reporting
Network Box can investigate and escalate, while the contractor retains government reporting, preservation, and legal coordination duties.
05
System Security Plan
Reports and service documentation support the SSP but do not replace the contractor's complete boundary and requirement implementation narrative.
06
Penetration testing
Vulnerability scanning, IDS/IPS, SIEM, and MDR do not substitute for penetration testing wherever the applicable requirement calls for it.
Assessment evidence
Show that safeguards are operating.
Available evidence depends on deployed services, configured log sources, agreed scope, format, and retention period.
01Service descriptions and a documented Customer Responsibility Matrix
02Managed security asset and service inventories
03Network architecture and security-boundary information
04Firewall, segmentation, VPN, and access-policy configurations
05Administrative access and authentication records
06Security configuration and change records
07Centralized security logs and log-source status
08SIEM alerts, correlations, searches, dashboards, and reports
09Vulnerability findings, priorities, and remediation recommendations
10IDS/IPS, malware, email, web, and application-security events
11Security-awareness participation and phishing-simulation results
12SOC procedures, investigations, escalation histories, and incident reports
13Records of containment or other response actions performed within scope
14Periodic service reviews and security recommendations
Coverage key
What each label means.
Strong
Network Box can directly deliver and operate a substantial part of this technical outcome when the relevant services are in scope.
Partial
Network Box contributes meaningful controls, but the requirement also depends on the client's systems, configuration, people, or processes.
Supporting
Network Box provides useful security operations or evidence, but does not satisfy the requirement by itself.
Client responsibility
This area primarily remains with the MSP and client, their assessors, or other qualified parties.
Shared responsibility
Network Box helps operate the controls. The organization owns the compliance program.
The contractor identifies FCI and CUI, defines the assessment boundary, maintains its System Security Plan and evidence, implements every applicable requirement, scopes external providers, remediates findings, completes assessments and SPRS submissions, and makes required affirmations.
CMMC / NIST 800-171 FAQ
Questions about scope, evidence, and responsibility.
What is CMMC / NIST 800-171?+
Build an operational security foundation for protecting Federal Contract Information and Controlled Unclassified Information.
How can Network Box USA support CMMC / NIST 800-171?+
Network Box USA can operate managed technical safeguards, monitor the subscribed environment, investigate and escalate security activity, maintain managed configurations, and produce service evidence that may support applicable CMMC / NIST 800-171 requirements.
Does using Network Box USA make an organization CMMC / NIST 800-171 compliant?+
No. A managed security service can contribute controls, operations, and evidence, but it cannot guarantee compliance or replace the organization's governance, complete scope, legal interpretation, assessment, or formal certification and attestation work.
How should the CMMC / NIST 800-171 control mapping be used?+
Use the mapping as a scoping and evidence-planning aid. Each row explains the requirement, the potential Network Box contribution, available evidence, the coverage level, and the work that remains with the organization.
What evidence may be available for a CMMC / NIST 800-171 assessment?+
Depending on the deployed services and agreed retention, evidence may include managed configurations, logs, alerts, incident records, vulnerability findings, change records, service reports, and recurring operational reviews. The assessor determines whether evidence is sufficient.
What remains the organization's responsibility under CMMC / NIST 800-171?+
The contractor identifies FCI and CUI, defines the assessment boundary, maintains its System Security Plan and evidence, implements every applicable requirement, scopes external providers, remediates findings, completes assessments and SPRS submissions, and makes required affirmations.
Important information
Compliance and legal disclaimer
The information in this Compliance Center is provided for general informational purposes and does not constitute legal, regulatory, audit, or certification advice. Requirements vary by organization, jurisdiction, contract, data, and system scope. Network Box services can support selected technical and operational safeguards but do not by themselves establish compliance, certification, or attestation. Each organization remains responsible for determining its obligations, defining scope, implementing governance and non-technical controls, and obtaining advice or assessment from qualified legal, compliance, audit, or certification professionals.