Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
HIGH-LEVEL CROSSWALK

The IT Top 10, mapped to NIST 800-171 & CMMC

A high-level view of how each Brilliant at the Basics IT practice lines up with the NIST SP 800-171 control families and CMMC domains. Use it to orient — then open each practice guide for the specifics.

PracticePrimary NIST SP 800-171 familyCMMC domainAlso supports
IT-01 Phishing-Resistant MFAIdentification & Authentication (3.5)IAAccess ControlGuide →
IT-02 Asset InventoryConfiguration Management (3.4)CMRisk AssessmentGuide →
IT-03 Technical Debt ReductionSystem & Information Integrity (3.14)SI, CMRisk AssessmentGuide →
IT-04 Flexible Technology StackConfiguration Management (3.4)CMSystem & Comms ProtectionGuide →
IT-05 Logical SegmentationSystem & Communications Protection (3.13)SCAccess ControlGuide →
IT-06 Vulnerability ManagementRisk Assessment (3.11)RA, SISystem & Info IntegrityGuide →
IT-07 Security in the SDLCSystem & Information Integrity (3.14)SI, CMSecurity AssessmentGuide →
IT-08 Secure AI & Data ProtectionAccess Control (3.1) · SC Protection (3.13)AC, SCMedia ProtectionGuide →
IT-09 Backup & Disaster RecoveryMedia Protection (3.8)MPRecoveryGuide →
IT-10 Workforce ReadinessAwareness & Training (3.2)ATGuide →
Working the OT side too?

The OT Top 10 maps against NIST SP 800-82 and the CSF. See the OT Top 10 and the full framework mappings on each practice guide.

AUTHORITY CROSSWALK

Every authority on one map

The practice table above answers “what should I build?” This one answers “what am I actually obligated to, and what is its status right now?” — each clause’s trigger, core obligation, and current acquisition posture.

Posture changes; obligations persist

The right-hand column reflects the July 2026 CMMC Phase II suspension and will change after the program review — see the policy status timeline. The trigger and obligation columns are the durable part. Verify all clause applicability against your own contract and flowdowns.

AuthorityInformation / triggerCore obligationCurrent posture
FAR 52.204-21FCI in a contractor system15 basic safeguarding requirements; flows down to qualifying FCI subcontractsOperative when included / applicable
DFARS 252.204-7012CDI in a covered system, or operationally critical supportAdequate security, NIST SP 800-171 Rev 2, 72-hour incident report, 90-day media preservation, FedRAMP-Moderate-equivalent cloud, flowdownRemains in effect
DFARS 252.204-7019Offeror subject to 7012A current summary-level SPRS score before award (generally not more than three years old)Remains operative
DFARS 252.204-7020Covered systems and applicable subcontractsGovernment assessment access; Basic / Medium / High confidence levels; rebuttal process; subcontract award restrictionRemains operative
DFARS 252.204-7021A CMMC status is specified in the solicitation or contractHold and maintain the required status, CMMC UIDs, annual affirmation, flowdownLevel 1 (Self) / Level 2 (Self) may be designated during the suspension
CMMC Level 1FCIAnnual self-assessment of the 15 FAR requirements, with affirmationPermitted
CMMC Level 2CUI110 NIST SP 800-171 Rev 2 requirements; Self or C3PAO under the Program RuleOnly Level 2 (Self) may be designated during the suspension
CMMC Level 3CUI on a priority DoW programLevel 2 plus 24 selected NIST SP 800-172 requirements; DCMA DIBCAC assessmentDesignation suspended during the review
10 U.S.C. §3252 · DFARS Subpart 239.73Covered procurement / ICT source riskSource exclusion authority and contractor supply-chain risk mitigationIndependent gate — unaffected by CMMC status
ITAR / EARExport-controlled information, at any tierAuthorization, release, transfer, destination and foreign-person access restrictionsIndependent legal overlay — CMMC does not establish export compliance

Reviewed 2026-07-28 against primary sources.