Assessment frameworks

Eight rulebooks. One evidence standard.

Every federal cybersecurity obligation traces back to a framework — a certification, a control catalog, a process, or a clause. We work inside all of them daily. Here is what each one actually demands, who it binds, and the artifacts an assessment will ask for.

01 CMMC 2.0 02 SP 800-171 / 172 03 SP 800-53 04 FedRAMP & 20x 05 NIST RMF 06 CSF 2.0 07 DFARS Clauses 08 NIST AI RMF
8Frameworks 1,500+Requirements catalogued 6Practices applying them 1Evidence standard

Framework 01 · FWK-001

CMMC 2.0

The DoD's certification that contractor cybersecurity claims are true — enforced through contract awards, not audits after the fact.

Level 1 — 15 practices · Level 2 — 110 controls · Level 3 — +24 (DIBCAC) · Phase 2 paused Jul 2026

Documentation Official source ↗
Defense contractors Subcontractors at every tier Manufacturers Anyone holding FCI or CUI

CMMC 2.0 turns NIST SP 800-171 from an honor system into a certification — a condition of award, live in solicitations since Phase 1 began November 10, 2025. Level 1 (FCI) self-assesses annually against 15 basic safeguards; Level 2 (CUI) requires all 110 controls of 800-171; Level 3 adds SP 800-172 enhancements, government-assessed. On July 13, 2026, DoD suspended Phase 2 — the third-party certification mandate due November 10, 2026 — pending a 60-day reform review. The audit is paused; the standard is not: DFARS 252.204-7012, SPRS scores, and Phase 1 self-assessments all remain in force.

What it requires

Scoping and categorization of every asset in the boundary All 110 NIST SP 800-171 Rev 2 controls at Level 2 ~320 assessment objectives, each individually evidenced SSP and POA&M discipline — closeout inside 180 days Annual executive affirmation posted in SPRS C3PAO certification where contracts still require it (Phase 2 paused) Flow-down of the requirement to subcontractors FIPS-validated cryptography wherever CUI moves

Assessment artifacts

System Security Plan (SSP) POA&M with closeout dates Asset inventory & network diagrams Evidence per assessment objective Mock-assessment findings SPRS score & affirmation record C3PAO assessment report

Phased implementation — current status

Nov 10, 2025Phase 1 — Level 1 / Level 2 self-assessments required in applicable solicitationsIN FORCE
Jul 13, 2026Phase 2 — C3PAO certification mandate (due Nov 10, 2026) suspended; later milestones frozenPAUSED
Aug 14, 2026Reform RFI closed — industry input to the 60-day Task Force reviewDONE
~Sep 2026Task Force report — revised framework expected; deeper restructuring not ruled outPENDING
StandingDFARS 252.204-7012 · SPRS scores · Phase 1 affirmations — unaffected by the pauseIN FORCE

Where NSC comes in

A solicitation names a CMMC level  ·  The Phase 2 pause has leadership asking whether readiness spend should stop  ·  An executive must affirm and wants to know what they're signing.

Framework 02 · FWK-002

NIST SP 800-171 & 800-172

The control standard behind every CUI obligation — what "protect it" actually means, requirement by requirement.

110 controls (Rev 2) · 14 families · ~320 objectives (171A) · 800-172 enhanced set

Documentation Official source ↗
Non-federal systems with CUI DIB companies Universities & research labs Service providers in scope

SP 800-171 defines how CUI must be protected in systems the government doesn't own — yours. Rev 2's 110 requirements are what CMMC Level 2 certifies and what DFARS 252.204-7012 has required since 2017. Rev 3 (2024) restructures the set with organization-defined parameters, but DoD assessment today still runs against Rev 2. SP 800-172 layers enhanced requirements on top for CUI associated with critical programs — the basis of CMMC Level 3.

What it requires

Fourteen control families, access control to system integrity Every requirement decomposed into assessable objectives (800-171A) A System Security Plan describing how each control is met A POA&M for anything not yet implemented DoD scoring methodology — 110 points, weighted deductions Periodic reassessment and score currency in SPRS Isolation of CUI to defined, defensible boundaries Enhanced protections (800-172) where programs demand them

Assessment artifacts

SSP mapped to all 110 requirements 800-171A assessment workbook DoD Assessment Methodology score CUI data-flow & boundary diagrams POA&M Enclave architecture documentation

Where NSC comes in

A prime asks for your 800-171 posture with evidence  ·  Your SPRS score was posted from a template SSP  ·  CUI just appeared in a new contract.

Framework 03 · FWK-003

NIST SP 800-53 Rev 5

The federal control catalog everything else draws from — the common vocabulary of federal security.

20 families · Baselines: Low / Mod / High · Rev 5 + 53A / 53B · Overlays & tailoring

Documentation Official source ↗
Federal information systems FedRAMP cloud offerings RMF programs Contractors running federal systems

SP 800-53 is the master catalog: a thousand-plus controls and enhancements across twenty families, from which FedRAMP baselines, agency overlays, and most federal security requirements are assembled. You never implement "all of 800-53" — you implement a baseline selected by impact level (FIPS 199), tailored to the system, and assessed against 800-53A procedures. Fluency here is what makes every other federal framework legible.

What it requires

Categorization by impact — low, moderate, high (FIPS 199) Baseline selection from SP 800-53B Tailoring: scoping, parameters, and compensating controls Implementation of selected controls and enhancements Common controls and inheritance across systems Assessment against SP 800-53A procedures Documentation in the SSP and supporting artifacts Continuous monitoring of control effectiveness

Assessment artifacts

Tailored control baseline Control-implementation statements Common-control catalog Assessment procedures & results (53A) Responsibility matrix ConMon effectiveness reporting

Where NSC comes in

An agency or FedRAMP baseline lands on your roadmap  ·  Controls are implemented but nobody can say which baseline  ·  Inheritance is assumed and never mapped.

Framework 04 · FWK-004

FedRAMP & 20x

The gate between a commercial cloud product and federal customers — one certification, reused across agencies.

20x Classes A / B / C / D · KSIs & automated validation · 3PAO assessed · Rev5 sunset: Jun 2027

Documentation Official source ↗
Cloud service providers SaaS, PaaS & IaaS Agencies adopting cloud Assessors (3PAOs)

FedRAMP authorizes cloud services for federal use — one certification, reused across agencies via the public Marketplace. FedRAMP 20x is now the program itself: certification by class (A / B / C, with Class D piloting FY27) against Key Security Indicators and automated, machine-readable evidence instead of narrative packages. The Consolidated Rules for 2026 fix the requirements, the submission pipeline opens FY26 Q4 — and new Rev5 certifications end June 11, 2027, which puts every classic-path CSP on a transition clock. Continuous monitoring still starts the day certification is granted.

What it requires

A precisely defined Cloud Service Offering boundary Class selection — A, B, or C — matched to service risk and use Key Security Indicators validated by code, not narrative Machine-readable evidence regenerated on every release Independent 3PAO evaluation of security decisions Submission through the 20x pipeline (opens FY26 Q4) Continuous reporting with trended validation data Significant-change review before material changes ship

Assessment artifacts

CSO boundary diagrams KSI set & validation code 3PAO security assessment report Certification package (Marketplace) ConMon trending deliverables Class-selection & pathway memorandum

20x program timeline

FY25Phase 1 — Low pilot: 26 submissions proved automation-based validationDONE
FY26 Q1–Q2Phase 2 — Moderate pilot: first cohort certified March 6, 2026DONE
FY26 Q3–Q4Phase 3 — Wide-scale adoption: rules final; submission pipeline opens Q4ACTIVE
FY27 Q1–Q2Phase 4 — Class D (High) pilotEST.
FY27 Q3–Q4Phase 5 — New Rev5 intake ends June 11, 2027; transition paths publishedEST.

Where NSC comes in

An agency asks if you're in the Marketplace  ·  The class decision (A / B / C) is open and engineering wants an answer  ·  Rev5 sunsets June 2027 and there's no transition plan.

Framework 05 · FWK-005

NIST RMF — SP 800-37

The federal operating system for security decisions — how systems get categorized, controlled, assessed, and authorized.

7 steps: Prepare → Monitor · SP 800-37 Rev 2 · ATO decisions · Common controls

Documentation Official source ↗
Federal agencies DoD system owners Contractors operating federal systems Cloud via agency ATO

The RMF is the process wrapper around everything else: Prepare, Categorize (FIPS 199), Select (800-53), Implement, Assess (800-53A), Authorize, Monitor. Its output is the ATO — a named official personally accepting a system's risk. Done well, it's a reusable engine of categorizations, common controls, and living packages; done poorly, it's an eighteen-month document chase that expires in place. The difference is architecture and preparation, not paperwork volume.

What it requires

Organizational preparation — roles, risk strategy, common controls System categorization by information impact Control selection, tailoring, and allocation Implementation consistent with the architecture Independent assessment of control effectiveness A risk-based authorization decision by a named official Continuous monitoring tied to reassessment triggers Package reuse and inheritance across the portfolio

Assessment artifacts

Categorization memorandum SSP, SAR & POA&M (the package) Authorization decision document ConMon strategy Reciprocity & reuse documentation

Where NSC comes in

An ATO is expiring and the package is stale  ·  Every system change reopens authorization debate  ·  Categorizations were guessed years ago.

Framework 06 · FWK-006

NIST CSF 2.0

The executive lingua franca of cyber risk — six functions a board can govern by.

Govern (new in 2.0) · Identify · Protect · Detect · Respond · Recover · Profiles & tiers

Documentation Official source ↗
Boards & executives Enterprises of any size Critical infrastructure Anyone needing a common language

CSF 2.0 organizes cybersecurity into six functions — Govern, Identify, Protect, Detect, Respond, Recover — with the 2024 revision elevating governance to a function of its own: risk appetite, roles, oversight, and supply-chain accountability now sit at the top of the framework, not the appendix. It certifies nothing. Its power is translation: current-versus-target profiles turn technical posture into a roadmap executives can fund and boards can oversee.

What it requires

Governance: risk appetite, roles, and oversight (GV) Asset, risk, and supply-chain visibility (ID) Safeguards proportionate to what matters (PR) Detection matched to how you'd actually be attacked (DE) Response decisions rehearsed before they're needed (RS) Recovery that restores mission, not just servers (RC) Current and target profiles with a sequenced roadmap Implementation tiers as an honesty check, not a badge

Assessment artifacts

Current-state profile Target profile & gap analysis Executive roadmap tied to budget Governance charter (GV function) Board reporting framework Framework crosswalk (171 / 53 / ISO)

Where NSC comes in

The board asks "how do we compare?" and there's no common language  ·  Security reporting is a vulnerability count  ·  Strategy needs a frame investors recognize.

Framework 07 · FWK-007

DFARS Cybersecurity Clauses

The contract fine print that makes federal cybersecurity legally binding — obligation by clause, not by memo.

252.204-7012 · -7019 / -7020 · -7021 (CMMC) · FAR 52.204-21

Documentation Official source ↗
DoD contractors Subcontractors at every tier Suppliers receiving flow-downs COTS sellers (partial carve-outs)

The DFARS clauses are where cybersecurity stops being advice: -7012 requires 800-171 protection of covered defense information, 72-hour incident reporting, and FedRAMP-Moderate-equivalent clouds; -7019 and -7020 make your self-assessment score in SPRS current and give the government the right to check it; -7021 inserts CMMC itself as a condition of award. FAR 52.204-21 sits underneath with fifteen basic safeguards for FCI. Each clause flows down the supply chain verbatim — your customer's obligations become yours.

What it requires

Adequate security per NIST SP 800-171 (-7012) Rapid reporting: cyber incidents within 72 hours Cloud services at FedRAMP Moderate equivalency Current Basic self-assessment posted in SPRS (-7019) Government access to assess, and flow-down duties (-7020) CMMC level as a condition of award (-7021) Fifteen basic FCI safeguards (FAR 52.204-21) Malicious-software and media preservation duties on incident

Assessment artifacts

Clause register & obligations matrix SPRS posting & currency record Incident-reporting runbook (DIBNet) Cloud-equivalency determination Flow-down tracker by subcontract Preservation & forensics procedure

Where NSC comes in

A new award carries clauses nobody read  ·  An incident starts the 72-hour clock  ·  A sub's gap is about to become your non-compliance.

Framework 08 · FWK-008

NIST AI Risk Management Framework

The emerging reference for trustworthy AI — voluntary today, procurement language tomorrow.

Govern · Map · Measure · Manage · AI RMF 1.0 · GenAI Profile (600-1)

Documentation Official source ↗
AI builders AI deployers & integrators Federal AI programs Investors diligencing AI claims

The NIST AI RMF organizes AI risk into four functions: Govern (policies, roles, inventories), Map (context, intended use, failure modes), Measure (testing, evaluation, monitoring), Manage (respond, prioritize, retire). The 2024 Generative AI Profile extends it to GenAI-specific risks — confabulation, data leakage, prompt injection, provenance. Nothing certifies against it yet, but federal buyers, regulators, and diligence teams already use its vocabulary — and systems designed to it have answers when the questionnaire arrives.

What it requires

An inventory of AI systems, models, and their data pathways Documented intended use, context, and known failure modes Governance: who may deploy, approve, and retire AI Pre-deployment testing and evaluation appropriate to risk Monitoring for drift, misuse, and emergent behavior GenAI-specific controls: prompts, outputs, provenance Human oversight where consequences demand it Decommissioning criteria decided before deployment

Assessment artifacts

AI system & model inventory Risk map per system Testing & evaluation records AI governance charter GenAI usage policy & controls Board / investor AI assurance summary

Where NSC comes in

AI shipped faster than governance  ·  A customer questionnaire asks about the AI RMF by name  ·  Diligence wants the model inventory that doesn't exist.

Not sure which framework binds you?

Send us the solicitation, the clause, or the customer questionnaire — we'll tell you which requirements actually apply, what they cost, and what evidence they'll demand.

gmhardy@nationalsecurity.com