Federal contractingUnited States

CMMC 2.0 and NIST SP 800-171

Build an operational security foundation for protecting Federal Contract Information and Controlled Unclassified Information.

View the control mapping

Revision 2 to Revision 3 · Preparation guide

Preparing for Revision 3.

A gap analysis compares your existing safeguards with the updated requirements. It helps you identify the changes, evidence, and responsibilities to plan for before a CMMC transition takes effect.

CMMC transition

Confirm how and when the changes apply.

The planned CMMC amendment addresses the transition period and Level 2 and Level 3 assessment objectives. The agenda does not establish an effective date.

When the amendment and accompanying guidance are issued, confirm their applicability, parameter values, and assessment instructions. The current Level 2 baseline remains Revision 2.

What a gap analysis should cover

  1. Compare the requirements

    Start with your current Revision 2 implementation and NIST’s change analysis. Record new, changed, reorganized, and withdrawn requirements, then read the full Revision 3 text. A matching control name or number does not establish equivalent coverage.

  2. Check controls and configurations

    Review the systems that handle or protect CUI, the safeguards actually deployed, and their settings. Identify where a technical change, a process update, or additional coverage may be needed.

  3. Resolve organization-defined parameters

    ODPs specify values such as time periods or review frequencies. Record the applicable government-assigned value or permitted organizational choice, who approves it, and how it is implemented and demonstrated.

  4. Review evidence and responsibilities

    Compare NIST’s published assessment procedures with your System Security Plan, policies, configurations, logs, reports, and test results. Identify what your organization, IT provider, and Network Box must each implement and document within the agreed scope.

  5. Prioritize the work

    For each gap, record the affected requirement, current implementation, evidence needed, action owner, priority, and planned completion date. Track dependencies on the CMMC amendment separately so provisional assumptions can be revisited.

Turn findings into an actionable plan.

The useful outcome is a requirement-by-requirement record of existing coverage, gaps, evidence, and assigned actions. Network Box’s service mappings can help frame the managed-security contribution; your organization’s assessment must consider the complete environment and its responsibilities.

Review the current Revision 2 mapping

Where we contribute

A managed security layer within a broader compliance program.

CMMC verifies cybersecurity practices within a defined contractor assessment scope; it is not a product certification. Network Box managed network security, vulnerability management, SIEM, MDR/XDR, email and web protection, awareness training, and 24/7 SOC services can implement and document important technical outcomes, but they do not independently make an organization CMMC compliant or certified.

Current implementation status

Reviewed September 7, 2026

Phase I is active. Phase II is suspended.

On July 13, 2026, the Department suspended the planned Phase II certification requirements while it conducts a broader program review. The suspension does not remove existing contractual duties to protect covered information.

Read the Department's current CMMC guidance ↗
  • Phase I Level 1 and Level 2 self-assessment requirements remain in effect.
  • The broader rollout of Level 2 C3PAO certification requirements is suspended.
  • Level 1 uses 15 FAR 52.204-21 safeguards with annual self-assessment and affirmation.
  • Level 2 self-assessment uses 110 NIST SP 800-171 Revision 2 requirements every three years, with annual affirmation.
  • Contractors must still follow applicable solicitation, contract, DFARS, safeguarding, reporting, and SPRS obligations.

Standing CMMC model

Understand the levels and the Phase II suspension.

The regulatory model still defines three levels, but current Phase 1 implementation may require only Level 1 and Level 2 self-assessments. Always confirm the controlling solicitation and contract.

Level 1 · Self

Basic safeguarding of FCI

Annual self-assessment and affirmation against the 15 requirements in FAR 52.204-21. POA&Ms are not permitted.

Level 2 · Self

Broad protection of CUI

Self-assessment every three years against 110 NIST SP 800-171 Revision 2 requirements, plus annual affirmation and limited POA&M use.

Level 2 · C3PAO

Third-party assurance for CUI

Uses the same 110 requirements under the standing model, but the broader Phase II certification rollout is currently suspended.

Level 3 · DIBCAC

Enhanced protection

Standing model adds 24 selected NIST SP 800-172 requirements after Final Level 2 status; rollout is not active while implementation remains in Phase I.

Level 1 · FCI

Basic safeguarding across six domains.

The 15 Level 1 requirements come from FAR 52.204-21. These domain mappings show where managed security can contribute without replacing the contractor's annual self-assessment.

Select a framework area to explore its detailed control mapping.
Framework areaNetwork Box contributionRelevant servicesCoverage
Managed network controls and secure connectivity help restrict system and external access.
UTM+Network segmentationVPNAccess policiesDirectory integration
Partial
Authentication integrations and logs support access to managed services and remote connectivity.
VPNDirectory integrationMFA supportAuthentication loggingSIEM
Partial
Managed access and handling controls protect security data inside the Network Box service scope.
Managed security-data handlingAccess controlsSecure connectivity
Supporting
Available service and assurance records can support due diligence for Network Box facilities and operations.
Service documentationAssurance documentationSOC operational controls
Supporting
Managed boundaries, segmentation, and secure connectivity protect communications within the deployed architecture.
UTM+Network segmentationVPNSecure SD-WANWAF24/7 monitoring
Strong
Layered threat prevention and monitoring identify malicious code, attacks, and system flaws within scope.
UTM+IDS/IPSAnti-malwareManaged Cloud Email SecuritySecure Web GatewayNBX: MDR, EDR, XDRVulnerability Management24/7 SOC
Strong

These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.

Control mapping

Level 2 domains and Network Box support.

Level 2 self-assessment currently evaluates 110 NIST SP 800-171 Revision 2 requirements across 14 domains. Each requirement and assessment objective must be evaluated individually within the contractor's documented scope.

Authoritative sourceCMMC resources and documentation ↗
Select a framework area to explore its detailed control mapping.
Framework areaNetwork Box contributionRelevant servicesCoverage
Managed enforcement, segmentation, secure remote access, and telemetry support least privilege and controlled connections.
UTM+VPNSecure SD-WANNetwork segmentationSecure Web GatewayWAFDirectory integrationSIEM
Partial
Awareness education, phishing simulations, and reporting support workforce security responsibilities when subscribed.
Security Awareness TrainingPhishing simulationsTraining and campaign reports
Strong
Centralized logs, correlation, alerting, retention, investigations, and reporting support auditability within scope.
SIEMNBX: MDR, EDR, XDRManaged-device logging24/7 SOCCorrelationSecurity reporting
Strong
Controlled configurations, updates, administrative restrictions, and change records protect managed security systems.
UTM+Secure SD-WANSecure Web GatewayWAFManaged Cloud Email SecurityNBX: MDR, EDR, XDRVulnerability ManagementChange records
Partial
Directory integration, VPN authentication, MFA support, administrative controls, and logs protect managed access paths.
VPNMFA/TOTP supportDirectory integrationManaged administrative accessSIEM
Partial
The 24/7 SOC detects, validates, investigates, documents, escalates, and assists with incidents within scope.
24/7 SOCNBX: MDR, EDR, XDRSIEMIncident triageInvestigationContainment assistanceIncident reporting
Strong
Secure administration and documented maintenance protect the managed security systems Network Box supplies.
Managed security maintenanceSecure remote administrationMFA supportChange recordsService records
Partial
Secure transport, access controls, and monitored handling protect in-scope security data used by managed services.
Secure connectivityAccess controlsSIEMManaged security-data handling
Supporting
Defined service roles and assurance information can support due diligence for Network Box as an external provider.
Service rolesAuthorized support accessContractual documentationAssurance documentation
Supporting
Service and assurance documentation can support evaluation of facilities used to deliver managed services.
Service documentationAssurance documentationSOC operational controls
Supporting
Recurring vulnerability assessment, threat intelligence, event analysis, and guidance identify technical risk when subscribed.
Vulnerability ManagementNBX: MDR, EDR, XDRSIEMThreat intelligence24/7 SOCSecurity reporting
Strong
Monitoring records, findings, configuration evidence, incidents, reports, and reviews support assessment preparation.
SIEM reportsVulnerability reportsManaged configurationsIncident recordsSOC reportingService reviews
Partial
Layered boundary, segmentation, connectivity, application, email, web, and monitoring controls protect communications.
UTM+VPNSecure SD-WANNetwork segmentationIDS/IPSSecure Web GatewayWAFManaged Cloud Email Security24/7 monitoring
Strong
Managed prevention, monitoring, vulnerability findings, and SOC response identify and address attacks and flaws.
UTM+IDS/IPSNBX: MDR, EDR, XDRSIEMSecure Web GatewayWAFManaged Cloud Email SecurityVulnerability ManagementThreat intelligence24/7 SOC
Strong

These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.

CMMC assessment scope

Design managed services into the boundary.

External Service Providers may enter the assessment scope when they process, store, or transmit CUI or Security Protection Data such as logs and configuration information. Before deployment, the contractor, MSP, and Network Box should document data flows, implicated assets and facilities, service responsibilities, required evidence, and the Customer Responsibility Matrix in the System Security Plan.

Architecture-specific verification

Product capability is not assessment evidence by itself.

These requirements depend on the actual architecture, validated technologies, operating procedures, and assessment scope, rather than a general product claim.

01

FIPS-validated cryptography

Encryption, TLS, or VPN capability alone does not prove compliance. Verify the exact module, version, operating mode, and CUI use case.

02

CUI at rest

Boundary protection does not establish protection for CUI on endpoints, servers, databases, cloud services, backups, or removable media.

03

Enterprise MFA

MFA for VPN or Network Box administration does not demonstrate coverage for every required privileged and non-privileged access scenario.

04

Incident reporting

Network Box can investigate and escalate, while the contractor retains government reporting, preservation, and legal coordination duties.

05

System Security Plan

Reports and service documentation support the SSP but do not replace the contractor's complete boundary and requirement implementation narrative.

06

Penetration testing

Vulnerability scanning, IDS/IPS, SIEM, and MDR do not substitute for penetration testing wherever the applicable requirement calls for it.

Assessment evidence

Show that safeguards are operating.

Available evidence depends on deployed services, configured log sources, agreed scope, format, and retention period.

  1. 01Service descriptions and a documented Customer Responsibility Matrix
  2. 02Managed security asset and service inventories
  3. 03Network architecture and security-boundary information
  4. 04Firewall, segmentation, VPN, and access-policy configurations
  5. 05Administrative access and authentication records
  6. 06Security configuration and change records
  7. 07Centralized security logs and log-source status
  8. 08SIEM alerts, correlations, searches, dashboards, and reports
  9. 09Vulnerability findings, priorities, and remediation recommendations
  10. 10IDS/IPS, malware, email, web, and application-security events
  11. 11Security-awareness participation and phishing-simulation results
  12. 12SOC procedures, investigations, escalation histories, and incident reports
  13. 13Records of containment or other response actions performed within scope
  14. 14Periodic service reviews and security recommendations

Coverage key

What each label means.

Strong

Network Box can directly deliver and operate a substantial part of this technical outcome when the relevant services are in scope.

Partial

Network Box contributes meaningful controls, but the requirement also depends on the client's systems, configuration, people, or processes.

Supporting

Network Box provides useful security operations or evidence, but does not satisfy the requirement by itself.

Client responsibility

This area primarily remains with the MSP and client, their assessors, or other qualified parties.

Shared responsibility

Network Box helps operate the controls. The organization owns the compliance program.

The contractor identifies FCI and CUI, defines the assessment boundary, maintains its System Security Plan and evidence, implements every applicable requirement, scopes external providers, remediates findings, completes assessments and SPRS submissions, and makes required affirmations.

CMMC / NIST 800-171 FAQ

Questions about scope, evidence, and responsibility.

What is CMMC / NIST 800-171?

Build an operational security foundation for protecting Federal Contract Information and Controlled Unclassified Information.

How can Network Box USA support CMMC / NIST 800-171?

Network Box USA can operate managed technical safeguards, monitor the subscribed environment, investigate and escalate security activity, maintain managed configurations, and produce service evidence that may support applicable CMMC / NIST 800-171 requirements.

Does using Network Box USA make an organization CMMC / NIST 800-171 compliant?

No. A managed security service can contribute controls, operations, and evidence, but it cannot guarantee compliance or replace the organization's governance, complete scope, legal interpretation, assessment, or formal certification and attestation work.

How should the CMMC / NIST 800-171 control mapping be used?

Use the mapping as a scoping and evidence-planning aid. Each row explains the requirement, the potential Network Box contribution, available evidence, the coverage level, and the work that remains with the organization.

What evidence may be available for a CMMC / NIST 800-171 assessment?

Depending on the deployed services and agreed retention, evidence may include managed configurations, logs, alerts, incident records, vulnerability findings, change records, service reports, and recurring operational reviews. The assessor determines whether evidence is sufficient.

What remains the organization's responsibility under CMMC / NIST 800-171?

The contractor identifies FCI and CUI, defines the assessment boundary, maintains its System Security Plan and evidence, implements every applicable requirement, scopes external providers, remediates findings, completes assessments and SPRS submissions, and makes required affirmations.

Explore another frameworkReturn to the Compliance Center →

Security stack review

Map the technical foundation before the assessment starts.

Request a Security Stack Review