A Plain-English Guide to CMMC, NIST, and DFARS for Manufacturers

Home
/
Blog
/
A Plain-English Guide to CMMC, NIST, and DFARS for Manufacturers

Your prime contractor’s last email had the word CMMC in the subject line, and you nodded along like you knew exactly what that meant. You didn’t, and neither did the plant manager two lines down from you who forwarded it hoping someone else would open it first. 

Nobody hands you a glossary. Everyone just assumes you already know the difference between CMMC, NIST 800-171, and DFARS. Here’s the plain-English version, with each term defined exactly once, so you can keep them straight after you close this tab. 

CMMC, NIST, and DFARS explained in plain English comes down to one sentence each. NIST SP 800-171 is the security checklist. DFARS 252.204-7012 is the contract clause that makes the checklist mandatory. CMMC is the audit that proves you actually followed it. If your plant supplies parts under a Department of Defense (DoD) contract, anywhere in the Defense Industrial Base (DIB) supply chain, all three probably apply to you, and only one of them, CMMC, determines whether an outside assessor shows up to check your work.

Selling Into the Defense Supply Chain?

Government contracts come with their own compliance rules, support requirements, and procurement expectations. See how Meriplex supports IT for DoD contractors and other government-facing organizations.

What Do CMMC, NIST, and DFARS Actually Mean?

In short: FCI is the baseline information every federal contract creates, CUI is the more sensitive technical data your contract might involve, NIST SP 800-171 is the 110-requirement standard for protecting CUI, DFARS 252.204-7012 is the clause that makes that standard mandatory, and CMMC is the certification that verifies you actually followed it. Each term builds directly on the one before it. 

Five pieces make up this puzzle, and once you know what each one is, you’ll notice they only ever get used one way after this. 

FCI: The Data You Already Have

Federal Contract Information (FCI) is any non-public information the government gives you, or that you create, while performing a federal contract. It’s the baseline covered by FAR 52.204-21, the underlying rule behind CMMC Level 1. A purchase order number, a delivery schedule, a spec sheet the government sent you to quote a job, that’s FCI. Almost every manufacturer with a government contract already has FCI sitting in an inbox somewhere, even if nobody’s bothered to label it that way. 

CUI: The Data That Changes Everything

Controlled Unclassified Information (CUI) is a step up from FCI. It’s not classified, but the government requires specific handling rules around it because it’s sensitive enough to matter. For a manufacturer, this usually shows up as technical drawings, engineering specs, or process details tied to a defense program. If a part you build ends up on a military aircraft, the drawing that tells you how to build it is very likely CUI. Get this one wrong and you’ll misjudge everything that follows: your CMMC level, your required controls, even whether an outside assessor ever knocks on your door. 

NIST SP 800-171: The Recipe Book

The National Institute of Standards and Technology publishes NIST SP 800-171, which sets specific, auditable controls for protecting CUI: multi-factor authentication for anyone touching CUI systems, FIPS-validated encryption for CUI at rest and in transit, and audit logs that show exactly who accessed what and when. The standard organizes 110 security requirements across 14 control families to protect Controlled Unclassified Information in nonfederal systems used by DoD contractors and subcontractors. NIST doesn’t enforce anything. It just writes the recipe. The next term decides whether you actually have to follow it. 

DFARS 252.204-7012: The Clause That Makes the Recipe Mandatory

DFARS stands for Defense Federal Acquisition Regulation Supplement, and the specific clause that matters here is DFARS 252.204-7012. This is the contract language buried in your DoD contracts that says, in effect, if you handle CUI, you must follow the NIST 800-171 recipe and report cyber incidents within 72 hours. DFARS is the legal mechanism. NIST 800-171 is what it points to. If your contract carries this clause, and most defense manufacturing contracts do, you’re already obligated to follow NIST 800-171, whether anyone’s checked yet or not. 

CMMC: The Inspector Who Checks Your Kitchen

CMMC, the Cybersecurity Maturity Model Certification, is the verification layer. For years, contractors proved compliance by self-assessment alone, and that model had a documented enforcement gap. A DoD Office of Inspector General audit of contractor CUI controls found that assessed contractors were deficient in required security controls, and that contracting offices lacked reliable procedures to even track which contractors were responsible for maintaining CUI in the first place. 

CMMC replaces self-reporting with actual verification. Depending on your level, that verification comes from a Cyber AB-authorized C3PAO (Certified Third-Party Assessment Organization), or from your own team posting a self-assessment score to the DoD’s Supplier Performance Risk System (SPRS). CMMC doesn’t add new security requirements on top of NIST 800-171. It just checks whether you actually did what you said you did, and the check now carries teeth self-attestation never had. 

NIST writes the recipe, DFARS makes the recipe mandatory, and CMMC checks whether you actually cooked it.

How These Four Things Chain Together

Read that chain again in order, and the whole thing clicks into place: you handle FCI at minimum, and possibly CUI. If you handle CUI, your contract almost certainly contains DFARS 252.204-7012, which requires you to implement NIST SP 800-171. CMMC is how the DoD verifies you actually did, under the framework finalized in 32 CFR Part 170. 

That’s the entire relationship. Everything else below just adds detail to that one sentence. 

Which CMMC Level Applies to Your Plant?

Run two quick questions. Does your work touch a DoD contract, directly or as a subcontractor? And does what you handle go beyond a basic purchase order, into drawings, specs, or process details? Two “no” answers usually mean Level 1. A “yes” on both usually means Level 2: all 110 NIST 800-171 requirements, verified by self-assessment or a C3PAO audit. 

Question one: does any part of your work involve a DoD contract, either directly or as a subcontractor to a prime? If no, none of this applies to you yet. If yes, move to question two. 

Question two: does anything you receive or produce for that contract include technical drawings, specs, or process details beyond a basic purchase order? If no, you’re likely FCI-only, which puts you at Level 1. If yes, you’re handling CUI, which puts you at Level 2. 

A third level exists, Level 3, adding NIST SP 800-172 enhanced controls on top of Level 2 for a narrow set of contractors on the most sensitive programs. If you’re not sure whether that’s you, it almost certainly isn’t, but ask your contracting officer to be sure. 

CMMC LevelWho It Applies ToRequirementsAssessment Type
Level 1FCI only15 practices (FAR 52.204-21)Annual self-assessment
Level 2CUI (most manufacturers)110 practices (NIST SP 800-171)Self-assessment or C3PAO audit every 3 years
Level 3Highest-sensitivity CUI programsLevel 2 plus NIST SP 800-172 enhanced controlsGovernment-led DIBCAC assessment

You can usually answer both scoping questions from memory in under a minute. If you can’tthat’s typically because a three-year-old email attachment is hiding the CUI, not because the answer is genuinely unclear. 

Not Sure Where Your Gaps Are?

A risk assessment gives you a clear, documented picture of where your current environment stands against NIST 800-171, before an assessor or a prime contractor asks.

What Parts of My Plant Does CMMC Actually Affect?

CMMC and NIST 800-171 typically touch five areas: engineering and CAD files holding CUI, your ERP or MES system, email, cloud storage that needs to meet the FedRAMP Moderate baseline, and access controls, since Access Control alone covers 22 of the 110 requirements. If any of these hold defense-related drawings or specs, they’re in scope. 

Your engineering and CAD files, if drawings or specs for a defense part live there. Your ERP or MES system, if it stores production data tied to a controlled part number. Your email, if anyone forwards a spec sheet or drawing outside your network without a second thought. Your cloud storage, specifically whether it meets the FedRAMP Moderate baseline that CUI handling requires: standard commercial Microsoft 365 doesn’t clear that bar, while Microsoft 365 GCC does. And your access controls, since Access Control alone accounts for 22 of the 110 NIST requirements, more than any other category. 

In a typical NIST 800-171 gap assessment, the first thing we usually find isn't a missing firewall rule. It's a shared drive folder, something like "Program Drawings" or "Customer Specs," set to open access for anyone with the link, holding CUI that's been sitting there since a project kicked off two years ago. Nobody meant to leave it exposed. It just never occurred to anyone to lock it down, because nobody had connected "engineering folder" to "regulated data" until an assessor did.

None of this is hypothetical timing, either. CMMC 2.0’s final rule, published as 32 CFR Part 170, took effect in starting in November 2026, and C3PAO assessment slots are already booking three to six months out, with that window lengthening as the deadline approaches. Starting the gap analysis after a prime contractor asks for your certification is starting late. December 2024, with enforcement phasing in through 2028. Third-party assessments become mandatory for most Level 2 contracts.

Where to Go From Here

Before you go further, watch for three assumptions that trip up manufacturers more than any technical gap does. Assuming good general IT security equals NIST 800-171 compliance doesn’t hold, since the specific documentation and control requirements are separate from general network hygiene. Assuming your MSP owns compliance because they manage your network doesn’t hold either: they can implement controls, but signing your System Security Plan and owning your incident response procedures stays with you. And assuming you can get compliant right before the assessment is the riskiest bet of the three, since a self-assessment is explicitly defined under the DFARS methodology as producing only a “Low” confidence score, precisely because it’s self-generated, and a third-party assessor is trained to look for evidence that controls operated consistently over time, not evidence that someone switched them on last week. 

You now know what CMMC, NIST 800-171, DFARS, FCI, and CUI actually mean, and roughly where your plant fits into that picture. The next useful step is finding exactly where the gaps sit between what you’re doing today and what your contract actually requires. 

Ready to Make Compliance Ongoing, Not One-Time?

Meriplex's Compliance as a Service keeps your NIST 800-171 controls documented, monitored, and audit-ready year over year, not just the week before an assessment.

Recent Posts

Essential Guides, Insights, and Case Studies for IT Solutions

Manufacturing operations manager reviewing printed technical drawings at a workbench inside a modern precision manufacturing facility with CNC machines in the background.

Your prime contractor’s last email had the word CMMC in the subject

Executives reviewing IT spending charts and benchmarks on screen, illustrating IT budget benchmarks for financial services firms

The IT budget benchmark most financial institutions use to plan next year’s

Dealership sales manager looking toward an unresponsive computer while a customer waits to sign paperwork at a desk inside a modern automotive showroom.

The desk is buttoned up. The customer’s ready to sign. Then the