CMMC 2.0 / NIST SP 800-171:
Cryptography and PKI for the Defense Industrial Base
| Region | United States (applies to any organization in the Defense Industrial Base handling DoD information, regardless of company size) |
| Applicability | Prime/Subcontractors: any organization in the Defense Industrial Base (DIB) that processes, stores, or transmits Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on DoD contracts Cloud and Managed Service Providers: providers hosting CUI on behalf of DIB contractors, expected to meet FedRAMP Moderate equivalent protections C3PAOs and Assessors: third-party organizations accredited to conduct CMMC Level 2 certification assessments on behalf of the Cyber AB |
| Relevant sections | NIST SP 800-171 Rev. 2, §3.13: System and Communications Protection, covering cryptographic protection and key management NIST SP 800-171 Rev. 2, §3.5: Identification and Authentication DFARS 252.204-7021: CMMC certification requirements clause, effective November 10, 2025 |
Overview
CMMC 2.0 is the Department of Defense’s tiered verification program layered on top of NIST SP 800-171 Revision 2, replacing a decade of contractor self-attestation with independently assessed evidence that Controlled Unclassified Information is actually protected. The Defense Federal Acquisition Regulation Supplement (DFARS) final rule implementing the program took effect on November 10, 2025, and rolls out in four phases through November 2028.
In practical terms, Level 1 (FCI only) remains a self-assessment against 15 basic safeguarding practices; Level 2 (CUI) requires implementation of all 110 NIST SP 800-171 controls, most commonly verified by a Certified Third-Party Assessment Organization (C3PAO) every three years; and Level 3 adds 24 enhanced requirements from NIST SP 800-172, assessed directly by DoD’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) for the most sensitive programs.
Why It Matters
DoD estimates well over 80,000 contractors and subcontractors will need Level 2 or Level 3 certification, and CMMC status is now a condition of contract award rather than a paperwork exercise: contracting officers can require a current CMMC status and a Supplier Performance Risk System (SPRS) score before a bid is even considered.
The System and Communications Protection family, §3.13, carries the direct cryptographic obligations, and it is consistently one of the hardest families for contractors to pass because assessors distinguish sharply between an encryption algorithm that is merely FIPS-compliant and a cryptographic module that is formally FIPS-validated under NIST’s Cryptographic Module Validation Program.
How This Maps to Cryptography
NIST SP 800-171 addresses cryptography primarily through the System and Communications Protection (§3.13) and Identification and Authentication (§3.5) control families. The key control areas with direct cryptographic implications are:
| Section | Function | What it says | Products |
|---|---|---|---|
| §3.13.11: Employ FIPS-validated cryptography to protect the confidentiality of CUI | FIPS-Validated Cryptography | Issuance and management of certificates backed by FIPS 140-2/140-3 validated cryptographic modules, not merely FIPS-compliant algorithms | EJBCA |
| §3.13.10: Establish and manage cryptographic keys for cryptography employed in organizational systems | Cryptographic Key Establishment and Management | Documented key generation, distribution, storage, and destruction procedures across the full CUI environment | Command |
| §3.13.8, §3.13.16: Cryptographic protection of CUI in transit and at rest | Transmission and At-Rest Confidentiality | Certificate-backed TLS encryption for CUI in transit, with PKI-issued keys protecting stored CUI | EJBCA |
| §3.5.1–3.5.3: Identification and Authentication of organizational users and devices | Device and User Authentication | Certificate-based authentication replacing shared passwords for access to CUI systems | Command |
| §3.13.7, §3.1.12: Cryptographic protection of remote access sessions | Remote Access Session Protection | Mutually authenticated, certificate-backed VPN and remote session connections into CUI environments | EJBCA |
| Supports assessment objectives across §3.13 | Cryptographic Asset Inventory for Assessment Evidence | Inventory of cryptographic algorithms and libraries in use, supporting System Security Plan and POA&M evidence for C3PAO review | AgileSec |
Audit Readiness
CMMC Level 2 assessments, whether self-conducted or performed by a C3PAO, focus on verified implementation of all 110 controls rather than documentation alone. Key areas that assessors probe:
- FIPS Validation Evidence: Can the organization demonstrate that cryptographic modules protecting CUI confidentiality are formally FIPS 140-2 or 140-3 validated, not merely built on approved algorithms?
- Key Management Documentation: Are cryptographic key generation, distribution, storage, and destruction procedures documented and consistently followed per §3.13.10?
- CUI Boundary Encryption: Is CUI encrypted at rest and in transit across all system boundaries, including cloud environments and remote endpoints?
- Device and User Authentication Evidence: Can the organization show unique, certificate-based credentials in place of shared passwords for systems that process CUI?
- System Security Plan and POA&M Accuracy: Does the SSP accurately reflect implemented cryptographic controls, with any gaps tracked in a current Plan of Action and Milestones?
- Assessment-Ready Evidence Package: Is evidence organized and current enough to withstand a full Level 2 third-party assessment covering all 110 controls?
TAKE THIS TO MANAGEMENT
CMMC 2.0 ended the decade in which we could self-attest to NIST SP 800-171 compliance. Since November 10, 2025, Level 2 requires an independent C3PAO to verify all 110 controls, including FIPS-validated cryptography and documented key management, before we can bid on CUI-bearing DoD contracts. Losing that certification means losing contract eligibility outright.
The two control areas that most often fail a DIBCAC or C3PAO assessment are cryptographic: FIPS-validated modules and documented key lifecycle management. If we can’t prove our cryptography is validated, not just compliant, we don’t pass. That’s a solvable gap if we close it now, and a very expensive one if we discover it in the middle of an assessment window.


