Why this matters in Australia
Australian businesses are increasingly being asked about US cyber security frameworks. Sometimes that comes from a US-based parent company, sometimes from a multinational customer, and sometimes from a US Defence prime contractor flowing down DFARS 252.204-7012 and a CMMC clause. The four frameworks that come up in almost every conversation are CMMC, NIST Cybersecurity Framework 2.0, NIST SP 800-171 and the CIS Critical Security Controls.
None of these frameworks replace the ASD Information Security Manual, the Essential Eight, the Privacy Act 1988 or the Security of Critical Infrastructure Act 2018. They sit alongside them. The good news is that they overlap heavily. With the right approach you can produce one set of evidence and reuse it across multiple framework conversations.
3
CMMC certification levels: Foundational, Advanced, Expert
110
Security requirements in NIST SP 800-171 Rev. 3 protecting CUI
6
NIST CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover
18
CIS Controls in v8.1, with 153 safeguards across three Implementation Groups
CMMC: the US Defence supply chain assurance program
The Cybersecurity Maturity Model Certification (CMMC) program is run by the US Department of Defense (DoD). Its purpose is to assure the protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) shared with contractors and subcontractors across the US Defense Industrial Base (DIB). It enforces the security requirements of 32 CFR Part 2002, DFARS 252.204-7012 and DoDI 5200.48, and operationalises NIST SP 800-171.
CMMC is implemented through US Defence acquisition contracts. Once the rulemaking process completes, CMMC compliance becomes a condition of contract award. Companies may be allowed to receive contract awards with a limited time Plan of Actions and Milestones (POA&M) in place to complete remaining requirements, but a baseline number of requirements must be met before award and a small subset cannot be on a POA&M at all.
The three CMMC levels
Level 1 : Foundational
17 basic safeguarding practices drawn from FAR 52.204-21. Annual self-assessment. Suits handling Federal Contract Information (FCI) only.
Level 2 : Advanced
All 110 requirements from NIST SP 800-171 Rev. 2. Triennial third-party assessment by a Certified Third-Party Assessor Organisation (C3PAO) for most CUI. Self-assessment allowed for limited cases.
Level 3 : Expert
NIST 800-171 plus a subset of NIST SP 800-172 enhanced controls. Government-led assessment by DCMA DIBCAC. Reserved for the most sensitive CUI on priority programs.
Australian relevance: CMMC only applies if you are in the US DoD supply chain. If your customers are Australian, including Australian Defence and government, you should be looking at the ASD Information Security Manual and the Defence Industry Security Program (DISP), not CMMC.
NIST Cybersecurity Framework 2.0
The NIST Cybersecurity Framework (CSF) is a voluntary framework published by the US National Institute of Standards and Technology. Version 2.0, released in 2024, is widely used internationally as a common language for describing cyber security posture. It is not a certification.
CSF 2.0 organises cyber security activity into six functions. The biggest change from version 1.1 is the new Govern function, which sits at the centre and explicitly covers strategy, policy, roles, supply chain risk and oversight. Australian readers will notice that the structure is essentially identical to the ASD ISM.
Govern (new in 2.0)
Cyber security strategy, policy, roles, supply chain risk and oversight.
Identify
Asset, risk, threat and vulnerability identification across the business.
Protect
Identity, access control, data protection, secure configuration, awareness training.
Detect
Continuous monitoring, anomaly detection and event analysis.
Respond
Incident response planning, communications, mitigation and improvements.
Recover
Recovery planning, system restoration and lessons learned.
For Australian boards, NIST CSF 2.0 is often the easiest framework to use as a reporting structure because customers, insurers and primes recognise it. We typically map an Australian client's existing ISM and Essential Eight evidence into CSF 2.0 categories so the same controls answer two different audiences.
NIST SP 800-171: protecting Controlled Unclassified Information
NIST SP 800-171 defines the security requirements that non-federal organisations must meet when they store, process or transmit Controlled Unclassified Information (CUI) for the US government. The current version is Revision 3 (May 2024), which contains 110 requirements organised into 17 control families.
NIST 800-171 is the technical baseline that CMMC Level 2 assesses against. If you have a US Defence prime flow-down clause referencing DFARS 252.204-7012, you are required to implement NIST 800-171 and self-score against the DoD Assessment Methodology. CMMC Level 2 then adds a third-party assessment requirement on top.
The 17 control families in NIST 800-171 cover access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, planning, risk assessment, security assessment, system and communications protection, and system and information integrity. Australian readers will recognise almost all of these as ISM principles under different names.
CIS Critical Security Controls v8.1
The CIS Controls are a prioritised set of safeguards published by the Center for Internet Security, a US non-profit. Version 8.1 (the current version) contains 18 Controls and 153 individual Safeguards, grouped into three Implementation Groups (IGs) so organisations can scale based on size, risk and capability.
IG1 : Essential cyber hygiene
56 foundational safeguards for small businesses with limited IT and cyber expertise. The realistic baseline for most Australian SMBs.
IG2 : Risk-managed
IG1 plus 74 additional safeguards. Suits organisations with multiple departments, regulated data and a dedicated IT function.
IG3 : Highly defended
All 153 safeguards. For organisations facing targeted attacks, with mature security operations and incident response capability.
CIS is not a certification. It is a free, vendor-neutral control library and is one of the most practical day-to-day references for Australian SMBs. The 18 controls cover inventory, data protection, secure configuration, account management, access control, vulnerability management, audit logging, email and browser protections, malware defences, data recovery, network management, awareness training, service provider management, application software security, incident response, and penetration testing.
Side by side comparison
Four frameworks, four different audiences. This is how we usually summarise them on the first call with an Australian client.
| Framework | Origin | Audience | Audit / certification | Australian relevance |
|---|---|---|---|---|
| CMMC | US Department of Defense | US DIB suppliers and subcontractors handling FCI / CUI | Self-assessment (L1), C3PAO third-party (L2), DIBCAC (L3) | Australian suppliers in the US Defence supply chain. Otherwise rarely required. |
| NIST SP 800-171 | NIST (US Department of Commerce) | Non-federal organisations handling US Controlled Unclassified Information | Underpins CMMC Level 2. Self-assessment scored against the DoD Assessment Methodology. | Mostly relevant to Australian suppliers in US Defence flow-down clauses (DFARS 252.204-7012). |
| NIST CSF 2.0 | NIST | Any organisation, any sector, internationally | No formal certification. Self-assessment, advisor-led or used as a board-level framework. | Widely used by Australian boards, insurers and primes as a common language. Pairs cleanly with the ISM and Essential Eight. |
| CIS Controls v8.1 | Center for Internet Security (US non-profit) | Any organisation, prioritised by Implementation Group | No formal certification. CIS provides self-assessment tooling (CIS-CAT, CIS RAM). | Excellent practical control library for Australian SMBs. Maps neatly to ASD Essential Eight and SMB1001. |
How they map to Australian frameworks
The most important practical point: you do not need to run separate cyber programs for each framework. The control families overlap heavily. We typically build evidence once against ASD Essential Eight and the ISM, then map it across to whichever international framework a customer or insurer is asking about.
NIST CSF 2.0 ↔ ASD ISM
The ISM aligns its six functions (Govern, Identify, Protect, Detect, Respond, Recover) directly with NIST CSF 2.0. If you already use the ISM, NIST CSF reads like the same framework with different phrasing.
CIS Controls ↔ Essential Eight
The Essential Eight maps cleanly onto CIS IG1 and parts of IG2. Patch management, MFA, application control, admin restrictions and backup all appear in both. Most Australian SMBs at Essential Eight Maturity Level 1 are close to CIS IG1.
NIST SP 800-171 ↔ ISM PROTECTED
NIST 800-171 Rev. 3 has 110 requirements protecting CUI. ASD ISM at OFFICIAL: Sensitive and PROTECTED level covers the same control families with Australian terminology and additional governance principles.
CMMC ↔ DISP
CMMC is the US Defence supply chain assurance program. DISP (Defence Industry Security Program) is its Australian equivalent. DISP draws on the ISM rather than CMMC, but the intent (assured suppliers handling sensitive Defence information) is the same.
Our pragmatic recommendation
For Australian businesses, build on Essential Eight and SMB1001 first
Unless you have a binding US Defence supply chain obligation, NIST and CIS are reference libraries, not destinations. Get to a defensible Essential Eight maturity, certify SMB1001 at Gold or higher, and use NIST CSF 2.0 as the language you speak with international customers. The work counts in every direction.
Which framework do you actually need?
A short decision guide based on the conversations we have most weeks.
You only sell to Australian customers
You almost certainly do not need CMMC or NIST 800-171. Focus on ASD Essential Eight, SMB1001 (Gold or above) and selectively the ISM if you handle government data.
You sell to US Defence primes or subcontractors
CMMC is in scope. Most Australian suppliers in this position need at least Level 2 once a CMMC clause appears in the prime contract. NIST SP 800-171 is the underlying technical baseline.
You sell to multinational customers using NIST CSF
NIST CSF 2.0 is the most useful common language. It is not a certification and it pairs naturally with ISM, ISO 27001 and Essential Eight evidence you already produce.
You want a practical control library, not a certification
CIS Controls v8.1 is the most actionable. Start at IG1, layer to IG2 as you mature, and use CIS-CAT or RAM for self-assessment. Pairs well with SMB1001 evidence.
You operate critical infrastructure or hold government data
The ASD Information Security Manual remains the primary reference in Australia. NIST CSF and CIS Controls can supplement, but do not replace, the ISM and the SOCI Act CIRMP obligations.
Use Real Bytes as your MSP and MSSP
Real Bytes operates as a combined Managed Service Provider (MSP) and Managed Security Service Provider (MSSP), based in Australia, with engineers and analysts you deal with by name. We help Australian businesses that are being asked about US frameworks turn the request into a single, evidence-led program of work that satisfies multiple audiences at once.
How we cover NIST, CIS and CMMC alongside Australian frameworks
| Framework area | How Real Bytes covers it |
|---|---|
| NIST CSF 2.0 Govern and Identify | Cyber security policy stack, risk register, asset and identity inventory, supplier assurance, board reporting cadence. |
| CIS IG1 / IG2 safeguards | Microsoft Entra ID, Conditional Access, Intune baselines, Defender for Endpoint, patch management, secure backup design and testing. |
| NIST SP 800-171 Rev. 3 baseline | Access control, audit and accountability, configuration management, incident response, media protection, system and information integrity. |
| CMMC Level 2 readiness | Gap assessment against the 110 requirements, evidence collection, System Security Plan (SSP) and Plan of Action and Milestones (POA&M) preparation. |
| Detection and response | Centralised logging, SOC monitoring, EDR alerting, OAIC notifiable data breach support, incident response runbook. |
| Australian regulatory alignment | ASD Essential Eight uplift, SMB1001 (CyberCert) preparation, DISP readiness support, Privacy Act 1988 and SOCI Act considerations. |
Managed IT & Cyber Security
Full MSP / MSSP managed service. Helpdesk, infrastructure and SOC under one roof.
Co-managed IT
Augment your internal team. Map evidence once, reuse it across NIST, CIS, ISM and Essential Eight.
Virtual CISO (vCISO)
Senior security leadership on retainer. Board reporting in NIST CSF 2.0 language with ISM evidence underneath.
A practical seven-step action plan
If a customer or prime contractor has just sent you a security questionnaire referencing CMMC, NIST or CIS, this is the order we usually recommend.
Frequently asked questions
Does an Australian business need to comply with CMMC?
Only if you sell into the US Defence Industrial Base, either as a direct supplier to the US Department of Defense or as a subcontractor to a US prime that flows down DFARS 252.204-7012 and a CMMC clause. Most Australian businesses do not need CMMC. The Australian equivalent is the Defence Industry Security Program (DISP), which is governed by the ASD Information Security Manual rather than CMMC.
What is the difference between CMMC and NIST SP 800-171?
NIST SP 800-171 is the underlying technical standard that defines 110 security requirements for protecting Controlled Unclassified Information (CUI). CMMC is the US Department of Defense certification program that assesses contractors against those requirements (and a few additional practices at Level 3). In short: NIST 800-171 is the rulebook, CMMC is the audit program.
Is NIST Cybersecurity Framework (CSF) a certification?
No. NIST CSF 2.0 is a voluntary framework, not a certification. It is widely used by boards, insurers and prime contractors as a common language for describing cyber security posture. In Australia, it pairs well with the ASD Information Security Manual, ISO 27001 and the Essential Eight.
How does NIST CSF 2.0 differ from version 1.1?
The biggest change is the new Govern function, which sits alongside Identify, Protect, Detect, Respond and Recover. Govern explicitly covers strategy, policy, roles, supply chain risk and oversight. Version 2.0 also expands guidance on small and medium enterprises and on supply chain cyber security risk management.
Should we use CIS Controls or Essential Eight?
For Australian businesses, the Essential Eight is the starting point because it is the framework Australian insurers, primes and government bodies refer to. ASD is evolving it into a new Essentials series over the next two years, but the eight mitigation strategies stay the same and it remains current guidance throughout the transition. CIS Controls v8.1 is an excellent companion: it provides a broader, prioritised control library (153 safeguards across three Implementation Groups) and maps cleanly onto the Essential Eight. We commonly use CIS as the detailed implementation guide and Essential Eight as the reporting framework.
Can Real Bytes help us prepare for CMMC if we sell to a US prime?
Yes. We are an Australian MSP and MSSP. We help Australian suppliers prepare for CMMC Level 2 by running a NIST SP 800-171 Rev. 3 gap assessment, building the System Security Plan (SSP) and Plan of Action and Milestones (POA&M), and implementing the technical controls inside Microsoft 365, Entra ID, Intune and Defender. We do not act as a Certified Third-Party Assessor Organisation (C3PAO); we get you ready for one.
Sources and further reading
All references in this guide are drawn from publicly available US and Australian government and standards sources.
Selling into the US Defence supply chain or asked about NIST?
Real Bytes is an Australian MSP and MSSP. We run gap assessments and uplift programs against CMMC, NIST CSF 2.0, NIST SP 800-171 and CIS Controls, and we map the work back to ASD Essential Eight and SMB1001 so you only do it once.

Remote Support