Rev 2 is the operative standard · Phase 2 paused Jul 2026

The 800-171 → 800-53 → CMMC crosswalk

All 110 NIST SP 800-171 Rev 2 requirements — the ones DFARS actually pins you to — mapped to their CMMC Level 2 practice ID, their Rev 3 counterpart, and the underlying SP 800-53 Rev 5 controls. Built entirely from official NIST and eCFR sources, with the provenance of every mapping stated plainly. Nothing you do here leaves your browser.

Your searches never leave your browser. This page has no backend. The full dataset is embedded in the HTML, every filter and export runs locally, and there is no analytics on what you look up. It works offline once loaded. Open your network tab and check — that is rather the point.
Provenance

Where every mapping comes from

Accuracy over coverage. Each layer below is built from a primary source, and where a mapping is composed rather than published directly, this page says so.

  • The 110 Rev 2 requirements — NIST SP 800-171 Rev 2 (upd1) machine-readable requirements file, published by NIST CSRC.
  • CMMC Level 1 and Level 3 practices — read directly from 32 CFR Part 170 via the eCFR API. In-force regulation.
  • CMMC Level 2 practice IDsderived. 32 CFR 170.14(c)(3) states Level 2 requirements are identical to 800-171 Rev 2, and 170.14(c)(1) defines the ID grammar. IDs are generated from that grammar and were validated against the Level 2 IDs appearing literally in the regulation — zero mismatches.
  • Rev 2 to Rev 3 pairing and change classification — NIST SP 800-171 R2-to-R3 Change Analysis workbook.
  • Rev 3 to SP 800-53 Rev 5 controls — NIST SP 800-171r3 CUI Overlay, filtered to rows tailored as CUI.
  • 800-53 control titles — NIST SP 800-53 Rev 5.2.0 OSCAL catalog (current release, August 27, 2025).
On the 800-53 column. NIST has never published its Rev 2 to 800-53 table (Appendix D) in machine-readable form, and the version circulating in machine-readable form on NIST's own site is a private-sector submission rather than NIST's own work. Rather than pass that off as authoritative, this tool composes two genuinely NIST-authored mappings: Rev 2 to Rev 3, then Rev 3 to 800-53. Where a requirement was withdrawn in Rev 3 the chain legitimately ends, and the tool says so instead of guessing. 78 of 110 requirements carry an 800-53 path; the other 32 are exactly the withdrawn ones.

NIST and eCFR publications are US Government works in the public domain. BASTION is not affiliated with NIST, DoD, or the CMMC Accreditation Body, and nothing here is an endorsement by them. This is a planning reference, not legal advice.

Questions

Common questions

Is NIST 800-171 Rev 2 or Rev 3 currently required?

Revision 2. DoD Class Deviation 2024-O0013 hard-codes SP 800-171 Rev 2 into DFARS 252.204-7012 and states it remains in effect until rescinded, which overrides the clause's usual version-in-effect-at-solicitation language. Revision 3 is published but is not the operative standard for DoD contractors. This tool therefore treats Rev 2 as the baseline and shows Rev 3 as forward-looking context.

Does CMMC Level 2 include supply chain requirements?

No. CMMC Level 2 is built on the 110 requirements of NIST SP 800-171 Rev 2, which has no Supply Chain Risk Management (SR) family. Supply-chain obligations for small DoD contractors come from elsewhere: Section 889, FASCSA orders under FAR Subpart 4.23, and DFARS 252.204-7012 flow-down. NIST SP 800-171 Rev 3 adds an SR family at 3.17, but Rev 3 is not adopted.

How does a 800-171 requirement map to NIST 800-53?

Through two NIST-authored documents in sequence. The SP 800-171 R2-to-R3 Change Analysis pairs each Rev 2 requirement with its Rev 3 counterpart, and the SP 800-171r3 CUI Overlay maps Rev 3 requirements to SP 800-53 Rev 5 controls. This tool composes those two official mappings. NIST's own direct Rev 2 to 800-53 table exists only inside the Rev 2 PDF and is not published in machine-readable form.

What does withdrawn in Rev 3 mean for my compliance?

Nothing changes today. Thirty-two Rev 2 requirements were withdrawn or absorbed in Revision 3, but Revision 2 is the operative standard under DFARS, so those requirements still apply to your self-assessment and SPRS score. The withdrawal tag is forward-looking information about where the standard is heading, not permission to stop.

Does this tool send my data anywhere?

No. Everything runs in your browser. There are no accounts, no inputs to submit, and no analytics on what you search or export. The entire dataset is embedded in the page, so it works offline once loaded. You can verify this by opening your browser's network tab while using it.

Free checklist

The vendor vetting checklist

The 15-minute pre-purchase check to run before you buy any tool or piece of hardware — the six government lists to screen against, and what actually disqualifies a vendor. Plus practical CMMC guidance as the reform review develops.

We collect your email address, nothing else. No spam. Unsubscribe anytime.