top of page

Beyond Compliance: What NIST's Victoria Pillitteri Wants Defense Contractors to Understand About CMMC and NIST SP 800-171

  • Jun 23
  • 8 min read

For many organizations in the Defense Industrial Base (DIB), conversations about CMMC and NIST SP 800-171 often revolve around assessments, documentation, and compliance requirements. Yet according to Victoria Pillitteri, Supervisory Computer Scientist at NIST and co-author of NIST SP 800-171 and NIST SP 800-172, that perspective misses the larger purpose behind the framework.


During a recent episode of Bytes & Brew, Pillitteri joined Cape Endeavors CEO Terry McGraw to discuss the origins of NIST SP 800-171, the evolution of CMMC, and the future of cybersecurity requirements for organizations handling Controlled Unclassified Information (CUI). One message emerged clearly throughout the conversation: compliance was never intended to be the destination.


Why NIST SP 800-171 Exists


Many organizations first encounter NIST SP 800-171 after discovering it is a contractual requirement tied to government contracts or CMMC certification. As a result, the framework is often viewed primarily as a compliance obligation rather than a cybersecurity initiative. During the discussion, however, Victoria Pillitteri provided important context about the origins of the publication and the problem it was designed to solve.


Federal agencies have long relied on NIST SP 800-53 to protect sensitive information within government-owned systems. While highly effective for federal environments, those controls were developed with government agencies in mind and often contained requirements that did not translate well to commercial businesses, academic institutions, research organizations, and defense contractors. As more Controlled Unclassified Information began moving outside federal networks and into non-federal systems, the government recognized the need for a more practical approach to safeguarding that information.


To address this challenge, NIST partnered with the Department of Defense and the National Archives and Records Administration (NARA) to develop NIST SP 800-171. Rather than creating an entirely new cybersecurity framework, NIST tailored a subset of controls from NIST 800-53 that could provide appropriate protection for CUI while remaining practical for implementation by non-federal organizations. The result was a framework specifically designed to protect sensitive government information regardless of where it resides.


Understanding this history is important because it reinforces a distinction that remains relevant today. NIST SP 800-171 was not created as a compliance framework for its own sake. It was created to establish a consistent and practical set of security requirements capable of protecting Controlled Unclassified Information throughout the broader government and defense ecosystem. Compliance became the mechanism for enforcement, but the underlying objective has always been improving the security of sensitive information and reducing risk across interconnected organizations.


Compliance Is the Floor, Not the Goal


One of the most important observations from the discussion centered on the relationship between compliance and risk management.

Pillitteri summarized NIST's philosophy succinctly: "Compliance is always the floor. Good risk management is really what we're looking for."

NIST has never viewed cybersecurity through the lens of checklist compliance. Instead, NIST publications are designed to help organizations understand risk, evaluate their environments, and implement security measures appropriate to their unique circumstances. This philosophy often gets lost in conversations about CMMC.


Many organizations approach certification by asking, "What controls do we need to pass an assessment?" A more effective question is, "What risks exist within our environment, and how should we manage them?"


Organizations that focus on understanding and managing risk naturally position themselves to satisfy compliance requirements. Conversely, organizations that focus solely on passing an assessment often struggle to maintain security maturity after certification. This distinction becomes increasingly important as cyber threats continue to evolve.


Security Threats Move Faster Than Compliance Frameworks


One of the realities acknowledged during the conversation is that cybersecurity standards will always trail technological innovation to some degree. The threat landscape evolves continuously, and organizations must contend with adversaries that are constantly refining their tactics, techniques, and procedures. The rapid advancement of artificial intelligence has only accelerated this trend, enabling threat actors to automate reconnaissance, scale phishing campaigns, identify vulnerabilities more efficiently, and develop increasingly sophisticated attack methods.


At the same time, the process of developing cybersecurity standards requires research, stakeholder engagement, public comment periods, and consensus-building across government, industry, and academia. While this deliberate approach may appear slower than the pace of technological change, it is necessary to ensure that standards remain practical, broadly applicable, and capable of serving a wide range of organizations and use cases.


Recognizing this challenge, NIST has historically focused on defining security outcomes rather than prescribing specific technologies. Rather than requiring a particular product or implementation approach, NIST frameworks are designed to establish the objectives organizations should achieve while allowing flexibility in how those objectives are met. This philosophy helps ensure that the guidance remains relevant even as technologies continue to evolve.


Authentication provides a useful example. Over time, organizations have moved from traditional passwords to multi-factor authentication, and many are now exploring passkeys and other emerging identity technologies. While the mechanisms continue to change, the underlying security objective remains the same: ensuring that users can be uniquely identified and authenticated before accessing sensitive information and systems. By emphasizing enduring security principles rather than specific technical solutions, NIST seeks to create requirements that can adapt alongside innovation while continuing to support effective risk management.


The Challenge Facing Small and Mid-Sized Contractors


One of the most common criticisms of CMMC is that the requirements place a significant burden on small and mid-sized defense contractors. Pillitteri acknowledged that many organizations within the DIB are not cybersecurity companies. Their expertise lies in engineering, manufacturing, logistics, software development, or other mission-critical functions. Cybersecurity can be complex, resource-intensive, and expensive, particularly for organizations without dedicated security teams. At the same time, she emphasized an important reality: the value of CUI does not change based on the size of the company handling it.


As Pillitteri explained, "Controlled Unclassified Information must be protected at a certain level. It doesn't matter if it's a federal agency. It doesn't matter if it's a large defense contractor. It doesn't matter if it's a two-person shop. That information still has the same value to our adversary."

Whether information resides within a major defense prime or a two-person subcontractor, it often carries the same value to adversaries seeking access to sensitive government information.

From a national security perspective, the information must be protected regardless of where it resides. This reality helps explain why CMMC exists in the first place; the defense supply chain is only as secure as its weakest link.


Why CUI Scoping Matters More Than Most Organizations Realize


One of the recurring themes throughout the discussion was the importance of understanding information before attempting to secure it. At its core, risk management begins with visibility. Organizations cannot effectively protect Controlled Unclassified Information if they do not understand where it exists, how it moves throughout the business, who has access to it, and which systems process, store, or transmit it.


This is one of the reasons CUI discovery and scoping have become such critical components of a successful CMMC strategy. While many organizations assume they have a clear understanding of their CUI footprint, that assumption is frequently challenged once detailed interviews, business process reviews, and data discovery exercises begin. It is not uncommon for organizations to uncover CUI stored in locations they did not anticipate, shared through undocumented workflows, or residing in systems that were never intended to be part of the compliance boundary.


These discoveries have significant implications for both cybersecurity and compliance. Without a clear understanding of where CUI resides and how it flows through the organization, companies often create assessment boundaries that are larger and more complex than necessary. This can increase implementation costs, expand the number of systems subject to compliance requirements, and create ongoing operational burdens that persist long after certification is achieved.


For this reason, accurate CUI scoping remains one of the most effective ways to reduce both cybersecurity risk and the overall cost of certification. By identifying the systems, users, and processes that truly interact with Controlled Unclassified Information, organizations can focus their security investments where they matter most while avoiding unnecessary complexity elsewhere in the environment. In many cases, the organizations that achieve the most efficient path to CMMC compliance are not those that deploy the most technology, but those that first take the time to understand their data.


What's Changing in NIST SP 800-171 Revision 3


The transition from NIST SP 800-171 Revision 2 to Revision 3 represents more than a routine update. According to Pillitteri, one of the primary goals of Revision 3 was to provide greater clarity for implementers.


Organizations consistently reported that some Revision 2 requirements were so broadly written that implementation and assessment outcomes varied significantly. Larger organizations with mature cybersecurity programs often understood the intent behind the controls. Smaller organizations frequently struggled to determine what was expected. Revision 3 addresses this challenge by introducing additional specificity while maintaining flexibility for organizations to make risk-based decisions.


NIST's objective was to make requirements clearer without becoming overly prescriptive. The result is a framework that should be easier to implement consistently while still supporting a wide variety of environments and operational models.


Supply Chain Security Has Become a Core Requirement


Another significant development within NIST SP 800-171 Revision 3 is the increased emphasis on supply chain risk management. This reflects the reality that modern organizations no longer operate in isolation. Nearly every company relies on a complex network of third-party software providers, cloud platforms, managed service providers, subcontractors, hardware manufacturers, and technology vendors to support day-to-day operations.


As Pillitteri noted, organizations rarely build every component themselves. The software they deploy, the infrastructure they operate, and many of the services they consume often originate from external sources. While these relationships provide operational efficiencies and specialized capabilities, they also introduce additional attack surfaces that organizations must understand and manage.


For this reason, cybersecurity can no longer focus exclusively on internal systems and controls. Organizations must evaluate the security posture of their suppliers, service providers, and technology partners because vulnerabilities introduced anywhere within the supply chain can ultimately impact the confidentiality and security of sensitive information. This reality is particularly important within the Defense Industrial Base, where a compromise affecting a single supplier can have cascading effects across multiple contractors, programs, and government agencies.


The increased focus on supply chain security within Revision 3 reflects a broader shift in cybersecurity strategy. Protecting Controlled Unclassified Information is no longer limited to securing individual systems; it also requires understanding the broader ecosystem of organizations and technologies that interact with that information throughout its lifecycle.


The Bigger Lesson for Defense Contractors


Perhaps the most important takeaway from the discussion is that cybersecurity maturity cannot be measured solely by an assessment score. While certification, compliance, and contractual obligations are undeniably important, they were never intended to be the ultimate objective. As Pillitteri emphasized throughout the conversation, the underlying purpose of NIST SP 800-171 is to help organizations understand and manage risk in a way that protects sensitive information and supports mission success.


Organizations that achieve the greatest success under CMMC typically begin with a clear understanding of where their Controlled Unclassified Information resides, how it moves throughout the business, and which people, systems, and processes interact with it. From there, they can define an appropriate assessment scope, make informed investments in security controls, and build a compliance program that reflects their actual risk profile rather than simply satisfying a checklist.


This distinction is becoming increasingly important as cyber threats evolve, supply chains become more interconnected, and defense contractors face greater scrutiny over how they protect government information. Companies that view CMMC as a one-time certification exercise often find themselves struggling to maintain compliance over time. In contrast, organizations that embrace a risk-based approach are better positioned to adapt to changing threats, respond to new requirements, and sustain compliance as their business grows.


The conversation with Pillitteri serves as a reminder that NIST SP 800-171 was never intended to be merely a compliance framework. It is a cybersecurity framework designed to help organizations make informed decisions about protecting information that is valuable not only to their business, but also to the national security interests of the United States. As NIST continues to refine its guidance and the Department of Defense advances CMMC implementation, organizations that focus on understanding risk, securing CUI, and strengthening their cybersecurity foundations will be best positioned for long-term success.


Cape Endeavors designs, builds, and operates fully managed CMMC secure enclaves aligned with NIST SP 800-171, helping defense contractors reduce scope, protect CUI, and accelerate certification readiness. Learn More

 
 
 

Recent Posts

See All

Comments


bottom of page