Rate Us:

NIST 800-171 and CMMC: What Your MSP Can and Cannot Certify

Share this post

man working on computer at a desk in his office

If you hold a federal contract and handle controlled unclassified information, you have probably been told you need to get “NIST 800-171 certified.”

There is no such thing. Nobody issues that certificate – not NIST, not your MSP, not anyone. If a provider offers to certify you for 800-171, that is a good reason to slow down and ask what they actually mean, because the answer will tell you how well they know this space.

The confusion is understandable. There is a real certification here, it is built directly on 800-171, and getting the relationship between the two right matters more than it sounds like it should – especially now, with the certification program itself in the middle of a pause.

What 800-171 actually is

NIST Special Publication 800-171 is a set of security controls for protecting controlled unclassified information on systems the federal government does not own. In other words: your systems, holding the government’s sensitive-but-unclassified data.

For defense contractors it is not optional. DFARS clause 252.204-7012 makes implementing those controls a contractual obligation for anyone handling CUI. It is in your contract, which means falling short is a contract problem before it is ever a security problem.

It is not only a defense issue. The same control set flows down through civilian agency contracts too, and that is where the version question starts to matter.

Which version applies to you. Revision 2 contains 110 controls across 14 families. Revision 3, published in May 2024, reorganized those into 97 requirements across 17 families. DoD Class Deviation 2024-O0013 keeps Revision 2 in force for DFARS assessments – so when you see “the 110 controls,” that is Revision 2, and it is still what the Department of War requires.

Civilian agencies are not bound by that deviation. If your contract is with GSA or another civilian agency, you may already be looking at Revision 3, depending on how the contract is written. Read the clause rather than assuming the 110 applies.

But NIST itself is a standards body. It publishes the control catalog. It does not audit organizations and it does not issue certificates for anything.

So how do you show you comply?

You assess yourself.

You score your environment against the controls using the DoD scoring methodology, and you post that score to the Supplier Performance Risk System – SPRS. You also maintain a System Security Plan describing how each control is implemented, and a Plan of Action and Milestones for the ones that are not fully in place yet.

That self-attested score is what a contracting officer sees. There is no certificate at the end of it, and there was never meant to be.

Which is exactly the gap CMMC was created to close.

CMMC is the real certification

The Cybersecurity Maturity Model Certification exists because self-attestation alone turned out not to be enough assurance for the defense supply chain. It is a genuine certification with genuine assessors, and the levels differ in ways worth knowing:

  • Level 1 covers basic protection of federal contract information. Annual self-assessment.
  • Level 2 covers CUI and is built on the same 110 controls from 800-171. Most Level 2 contracts require assessment by a C3PAO – a CMMC Third-Party Assessment Organization, accredited to do this work independently. Some lower-risk Level 2 contracts allow self-assessment.
  • Level 3 covers the highest-priority programs and is assessed by the government itself.

So the honest version of the sentence everyone gets wrong: 800-171 is the control set. CMMC is the certification built on top of it. Meet 800-171 properly and you have done most of the work a Level 2 certification asks for. But the certificate comes from a C3PAO, not from implementing the controls.

Where CMMC stands right now

On July 13, 2026, the Department of War suspended CMMC Phase 2, which had been scheduled to take effect on November 10. Phases 3 and 4 and all remaining implementation milestones are frozen until further notice. A 60-day CMMC Reform Task Force is reviewing the program, with responses to a public request for information due August 14, 2026.

Read the suspension carefully, because it is narrower than the headlines suggest. This is a policy pause, not a regulatory change. The CMMC Program rule was not repealed. The DFARS was not amended. Phase 1 self-assessments, SPRS score submissions, and your obligations under DFARS 252.204-7012 all remain fully in force.

It is also genuinely open-ended. Officials have declined to rule out deeper restructuring, or cancellation, once the review concludes. Anyone telling you confidently when this resumes is guessing.

Here is what actually changed for you, and it is not a reprieve.

With third-party assessment paused, the only thing standing behind your compliance is your own signature on your SPRS score. The assessor who would have found your gaps before a contracting officer did is not coming. That attestation is still legally binding, and the Department of Justice has pursued False Claims Act cases against contractors that misrepresented compliance with required cybersecurity controls – including a settlement with an Alabama defense contractor in June 2026.

The pause did not lower the stakes. It removed the safety net and left the liability exactly where it was.

What your MSP can and cannot do

Here is where the marketing gets loose, so let us be direct about it.

Your MSP cannot certify you. C3PAOs are accredited specifically to perform CMMC assessments, and independence is the entire point. An assessor cannot evaluate an environment they built and operate. If your MSP configured your tenant, deployed your controls, and wrote your documentation, that same MSP sitting in judgment of the result would defeat the purpose of having an assessment at all.

Any provider advertising that they will certify you either does not understand the framework or is describing something else and calling it certification.

What a good MSP can do is most of the work. Gap assessment against every control that applies to you. Remediation – identity, access control, encryption, logging, media protection, incident response. Writing and maintaining the System Security Plan and the POA&M so they hold up under scrutiny rather than reading like they were produced the week before. Assembling the evidence an assessor will ask for. And then keeping all of it accurate, because compliance drifts the moment someone onboards a new user or stands up a new system.

That is the difference between arriving at an assessment prepared and arriving hopeful.

The part most articles skip

If your MSP touches your CUI, your MSP is inside your assessment boundary.

External service providers that store, process, or transmit controlled unclassified information on your behalf are in scope. So are some that only provide security protection for those systems. Your provider’s own security posture, their access controls, how their technicians reach your environment, what they log – all of it becomes part of what you are assessed on.

This is the question worth asking any provider before you sign. Not “can you certify us,” but “what happens to our assessment because you are in it?” A provider who has thought about that will have an answer ready. One who has not will change the subject.

Where Envision fits

We are not a C3PAO and we will not tell you we can certify you.

What we do is the work that gets a federal contractor ready to be assessed, and keeps them there: scoring your environment honestly against the controls that apply to your contracts, closing the gaps that score exposes, building documentation that survives an assessor reading it closely, and maintaining the whole thing as your business changes. When it is time for a CMMC assessment, we help you prepare and work alongside the assessor you select.

We have been doing security and compliance work for government contractors in the DC region since 2001. If someone has told you that you need to be “800-171 certified,” we can tell you what you actually need, which contract clause is driving it, and what it will take.

Happy to jump on a call.

Share this post

Other Related Blogs

Articles, Blog
The biggest HIPAA rewrite in more than a decade slipped to 2027. The rule you are already bound by did not change. Here is what HIPAA compliant IT services actually means, and what to ask any provider before you sign.
Articles, Blog, Compliance
Most of what CMMC Level 2 costs comes from how much of your company is in scope. If CUI only touches part of your business, an enclave can shrink that footprint — and the bill with it.
Articles, Blog
Looking for IT support in Northern Virginia? Envision Consulting shares real lessons from 25 years serving Arlington, Fairfax, and Tysons businesses.

Support Ticket

What can we do better?

We love to hear from our clients, please let us know if there are any areas that you think we could improve upon.