The IT Top 10, mapped to NIST 800-171 & CMMC
A high-level view of how each Brilliant at the Basics IT practice lines up with the NIST SP 800-171 control families and CMMC domains. Use it to orient — then open each practice guide for the specifics.
This shows the primary family each practice supports. Real 800-171 / CMMC compliance touches many controls per practice and depends on your environment. Independent mappings are aids, not authoritative equivalence or compliance determinations.
| Practice | Primary NIST SP 800-171 family | CMMC domain | Also supports | |
|---|---|---|---|---|
| IT-01 Phishing-Resistant MFA | Identification & Authentication (3.5) | IA | Access Control | Guide → |
| IT-02 Asset Inventory | Configuration Management (3.4) | CM | Risk Assessment | Guide → |
| IT-03 Technical Debt Reduction | System & Information Integrity (3.14) | SI, CM | Risk Assessment | Guide → |
| IT-04 Flexible Technology Stack | Configuration Management (3.4) | CM | System & Comms Protection | Guide → |
| IT-05 Logical Segmentation | System & Communications Protection (3.13) | SC | Access Control | Guide → |
| IT-06 Vulnerability Management | Risk Assessment (3.11) | RA, SI | System & Info Integrity | Guide → |
| IT-07 Security in the SDLC | System & Information Integrity (3.14) | SI, CM | Security Assessment | Guide → |
| IT-08 Secure AI & Data Protection | Access Control (3.1) · SC Protection (3.13) | AC, SC | Media Protection | Guide → |
| IT-09 Backup & Disaster Recovery | Media Protection (3.8) | MP | Recovery | Guide → |
| IT-10 Workforce Readiness | Awareness & Training (3.2) | AT | — | Guide → |
The OT Top 10 maps against NIST SP 800-82 and the CSF. See the OT Top 10 and the full framework mappings on each practice guide.
Every authority on one map
The practice table above answers “what should I build?” This one answers “what am I actually obligated to, and what is its status right now?” — each clause’s trigger, core obligation, and current acquisition posture.
The right-hand column reflects the July 2026 CMMC Phase II suspension and will change after the program review — see the policy status timeline. The trigger and obligation columns are the durable part. Verify all clause applicability against your own contract and flowdowns.
| Authority | Information / trigger | Core obligation | Current posture |
|---|---|---|---|
| FAR 52.204-21 | FCI in a contractor system | 15 basic safeguarding requirements; flows down to qualifying FCI subcontracts | Operative when included / applicable |
| DFARS 252.204-7012 | CDI in a covered system, or operationally critical support | Adequate security, NIST SP 800-171 Rev 2, 72-hour incident report, 90-day media preservation, FedRAMP-Moderate-equivalent cloud, flowdown | Remains in effect |
| DFARS 252.204-7019 | Offeror subject to 7012 | A current summary-level SPRS score before award (generally not more than three years old) | Remains operative |
| DFARS 252.204-7020 | Covered systems and applicable subcontracts | Government assessment access; Basic / Medium / High confidence levels; rebuttal process; subcontract award restriction | Remains operative |
| DFARS 252.204-7021 | A CMMC status is specified in the solicitation or contract | Hold and maintain the required status, CMMC UIDs, annual affirmation, flowdown | Level 1 (Self) / Level 2 (Self) may be designated during the suspension |
| CMMC Level 1 | FCI | Annual self-assessment of the 15 FAR requirements, with affirmation | Permitted |
| CMMC Level 2 | CUI | 110 NIST SP 800-171 Rev 2 requirements; Self or C3PAO under the Program Rule | Only Level 2 (Self) may be designated during the suspension |
| CMMC Level 3 | CUI on a priority DoW program | Level 2 plus 24 selected NIST SP 800-172 requirements; DCMA DIBCAC assessment | Designation suspended during the review |
| 10 U.S.C. §3252 · DFARS Subpart 239.73 | Covered procurement / ICT source risk | Source exclusion authority and contractor supply-chain risk mitigation | Independent gate — unaffected by CMMC status |
| ITAR / EAR | Export-controlled information, at any tier | Authorization, release, transfer, destination and foreign-person access restrictions | Independent legal overlay — CMMC does not establish export compliance |
Reviewed 2026-07-28 against primary sources.