Keyfactor Tech Days 2027 – Be Part of The Trust Security Conference in San Diego Register now!

CMMC 2.0 / NIST SP 800-171:

Cryptography and PKI for the Defense Industrial Base

Updated: August 24, 2026
Region United States (applies to any organization in the Defense Industrial Base handling DoD information, regardless of company size) 
Applicability Prime/Subcontractors: any organization in the Defense Industrial Base (DIB) that processes, stores, or transmits Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on DoD contracts Cloud and Managed Service Providers: providers hosting CUI on behalf of DIB contractors, expected to meet FedRAMP Moderate equivalent protections C3PAOs and Assessors: third-party organizations accredited to conduct CMMC Level 2 certification assessments on behalf of the Cyber AB 
Relevant sections NIST SP 800-171 Rev. 2, §3.13: System and Communications Protection, covering cryptographic protection and key management NIST SP 800-171 Rev. 2, §3.5: Identification and Authentication DFARS 252.204-7021: CMMC certification requirements clause, effective November 10, 2025 

Overview

CMMC 2.0 is the Department of Defense’s tiered verification program layered on top of NIST SP 800-171 Revision 2, replacing a decade of contractor self-attestation with independently assessed evidence that Controlled Unclassified Information is actually protected. The Defense Federal Acquisition Regulation Supplement (DFARS) final rule implementing the program took effect on November 10, 2025, and rolls out in four phases through November 2028. 

In practical terms, Level 1 (FCI only) remains a self-assessment against 15 basic safeguarding practices; Level 2 (CUI) requires implementation of all 110 NIST SP 800-171 controls, most commonly verified by a Certified Third-Party Assessment Organization (C3PAO) every three years; and Level 3 adds 24 enhanced requirements from NIST SP 800-172, assessed directly by DoD’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) for the most sensitive programs. 

Why It Matters 

DoD estimates well over 80,000 contractors and subcontractors will need Level 2 or Level 3 certification, and CMMC status is now a condition of contract award rather than a paperwork exercise: contracting officers can require a current CMMC status and a Supplier Performance Risk System (SPRS) score before a bid is even considered. 

The System and Communications Protection family, §3.13, carries the direct cryptographic obligations, and it is consistently one of the hardest families for contractors to pass because assessors distinguish sharply between an encryption algorithm that is merely FIPS-compliant and a cryptographic module that is formally FIPS-validated under NIST’s Cryptographic Module Validation Program. 

How This Maps to Cryptography 

NIST SP 800-171 addresses cryptography primarily through the System and Communications Protection (§3.13) and Identification and Authentication (§3.5) control families. The key control areas with direct cryptographic implications are: 

Section FunctionWhat it says Products
§3.13.11: Employ FIPS-validated cryptography to protect the confidentiality of CUI FIPS-Validated Cryptography Issuance and management of certificates backed by FIPS 140-2/140-3 validated cryptographic modules, not merely FIPS-compliant algorithms EJBCA 
§3.13.10: Establish and manage cryptographic keys for cryptography employed in organizational systems Cryptographic Key Establishment and Management Documented key generation, distribution, storage, and destruction procedures across the full CUI environment Command 
§3.13.8, §3.13.16: Cryptographic protection of CUI in transit and at rest Transmission and At-Rest Confidentiality Certificate-backed TLS encryption for CUI in transit, with PKI-issued keys protecting stored CUI EJBCA 
§3.5.1–3.5.3: Identification and Authentication of organizational users and devices Device and User Authentication Certificate-based authentication replacing shared passwords for access to CUI systems Command 
§3.13.7, §3.1.12: Cryptographic protection of remote access sessions Remote Access Session Protection Mutually authenticated, certificate-backed VPN and remote session connections into CUI environments EJBCA 
Supports assessment objectives across §3.13 Cryptographic Asset Inventory for Assessment Evidence Inventory of cryptographic algorithms and libraries in use, supporting System Security Plan and POA&M evidence for C3PAO review AgileSec 

Audit Readiness 

CMMC Level 2 assessments, whether self-conducted or performed by a C3PAO, focus on verified implementation of all 110 controls rather than documentation alone. Key areas that assessors probe: 

  • FIPS Validation Evidence: Can the organization demonstrate that cryptographic modules protecting CUI confidentiality are formally FIPS 140-2 or 140-3 validated, not merely built on approved algorithms? 
  • Key Management Documentation: Are cryptographic key generation, distribution, storage, and destruction procedures documented and consistently followed per §3.13.10? 
  • CUI Boundary Encryption: Is CUI encrypted at rest and in transit across all system boundaries, including cloud environments and remote endpoints? 
  • Device and User Authentication Evidence: Can the organization show unique, certificate-based credentials in place of shared passwords for systems that process CUI? 
  • System Security Plan and POA&M Accuracy: Does the SSP accurately reflect implemented cryptographic controls, with any gaps tracked in a current Plan of Action and Milestones? 
  • Assessment-Ready Evidence Package: Is evidence organized and current enough to withstand a full Level 2 third-party assessment covering all 110 controls?