All Guides
International Frameworks

CMMC, NIST and CIS Controls explained for Australian businesses

Match the framework to the contract before buying an assessment. This guide explains CMMC's current Phase I position, why Revision 2 still matters for Level 2, how to use NIST CSF profiles, and where CIS Controls complement Australian security requirements without replacing them.

Last updated 4 October 202616 min read

Why this matters in Australia

Australian businesses are increasingly being asked about US cyber security frameworks. Sometimes that comes from a US-based parent company, sometimes from a multinational customer, and sometimes from a US Defence prime contractor flowing down DFARS 252.204-7012 and a CMMC clause. The four frameworks that come up in almost every conversation are CMMC, NIST Cybersecurity Framework 2.0, NIST SP 800-171 and the CIS Critical Security Controls.

None of these frameworks replace the ASD Information Security Manual, the Essential Eight, the Privacy Act 1988 or the Security of Critical Infrastructure Act 2018. They sit alongside them. The good news is that they overlap heavily. With the right approach you can produce one set of evidence and reuse it across multiple framework conversations.

3

Levels in the broader CMMC model; the current rollout is paused in Phase I

110

NIST SP 800-171 Revision 2 requirements used in the current CMMC Level 2 baseline

6

NIST CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover

18

CIS Controls in v8.1, with 153 safeguards across three Implementation Groups

CMMC: the US Defence supply chain assurance program

The Cybersecurity Maturity Model Certification (CMMC) program is run by the US Department of Defense (DoD). Its purpose is to assure the protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) shared with contractors and subcontractors across the US Defense Industrial Base (DIB). It enforces the security requirements of 32 CFR Part 2002, DFARS 252.204-7012 and DoDI 5200.48, and operationalises NIST SP 800-171.

Phase I began on 10 November 2025. On 13 July 2026, the US programme announced that Phase II, previously scheduled for 10 November 2026, was suspended for review. Phase I self-assessment requirements remain in force. Do not rely on the earlier third-party certification timetable when budgeting or answering a tender. Check the official CMMC status notice and the instructions attached to your contract.

On 13 July 2026 the US Department of War announced the immediate suspension of the CMMC Phase II requirements, halting the transition to third-party certification for defence contractors handling Controlled Unclassified Information, so the previously scheduled 10 November 2026 expansion is no longer an active deadline and Phase I self-assessment duties remain in force. US Department of War, 13 July 2026.

In September 2026 a new class deviation moved the CMMC Phase II pause from policy into an enforceable binding regulation, so the suspension is now locked into the acquisition framework rather than a temporary directive a future administration could reverse, which means contractors should plan around Phase I self-assessments remaining the operative baseline for the foreseeable term. Washington Technology, September 2026.

The three CMMC levels

Level 1: safeguarding FCI

The current official Phase I guidance specifies the 15 FAR 52.204-21 requirements, annual self-assessment and affirmation. Results are entered in the Supplier Performance Risk System (SPRS). Level 1 does not allow a Plan of Action and Milestones.

Level 2: protecting CUI

The current Phase I baseline is 110 NIST SP 800-171 Revision 2 requirements. A self-assessment is required every three years, with annual affirmation. Limited eligible gaps may use a Plan of Action and Milestones, with closeout within 180 days.

Level 3: enhanced protection model

The broader CMMC model includes enhanced protection for high-priority programmes. Do not treat its earlier rollout timetable as active: the official programme is paused in Phase I while Phase II is reviewed. Check the current contract and contracting officer instructions.

Scope follows the information, not your company name. Identify where FCI or CUI is received, stored, processed and sent. Include email, engineering files, staff devices, backups, supplier support and remote administration where they touch that information. A controlled environment can reduce exposure, but a boundary diagram must reflect actual data flows rather than a preferred audit boundary.

Keep a system security plan that explains how each requirement is met, backed by configuration records, interviews and tests. A Plan of Action and Milestones is a managed remediation record, not permission to leave any control unfinished. Current programme guidance permits limited Level 2 gaps with closeout conditions and requires continuing affirmation. Confirm eligibility and current rules before using that route.

Australian relevance: CMMC only applies if you are in the US DoD supply chain. If your customers are Australian, including Australian Defence and government, you should be looking at the ASD Information Security Manual and the Defence Industry Security Program (DISP), not CMMC.

NIST Cybersecurity Framework 2.0

The NIST Cybersecurity Framework (CSF) is a voluntary framework published by the US National Institute of Standards and Technology. Version 2.0, released in 2024, is widely used internationally as a common language for describing cyber security posture. It is not a certification.

CSF 2.0 organises cyber security activity into six functions. The biggest change from version 1.1 is the new Govern function, which sits at the centre and explicitly covers strategy, policy, roles, supply chain risk and oversight. Australian readers will notice that the structure is essentially identical to the ASD ISM.

Govern (new in 2.0)

Cyber security strategy, policy, roles, supply chain risk and oversight.

Identify

Asset, risk, threat and vulnerability identification across the business.

Protect

Identity, access control, data protection, secure configuration, awareness training.

Detect

Continuous monitoring, anomaly detection and event analysis.

Respond

Incident response planning, communications, mitigation and improvements.

Recover

Recovery planning, system restoration and lessons learned.

Turn the six functions into decisions using NIST's Current and Target Profiles. A Current Profile records the outcomes you achieve now; a Target Profile describes the outcomes needed for your business, threats and obligations. Comparing them produces a gap list that can be assigned to owners, budgets and review dates.

NIST CSF 2.0 is an outcome-based risk management framework rather than a certification, so a Current Profile records the outcomes you achieve now and a Target Profile describes the outcomes needed for your business, threats and obligations, and comparing the two produces a gap list that can be assigned to owners, budgets and review dates without ever claiming a NIST CSF certificate. NIST CSF Profiles.

For example, a business may already have endpoint protection but lack a tested response process. Record the protection outcome separately from the response gap instead of reporting a single reassuring score. Board reporting should explain the business impact, the next decision and the evidence behind each status. CSF gives that reporting structure; it does not prescribe a particular vendor or certify the result.

NIST SP 800-171: protecting Controlled Unclassified Information

NIST SP 800-171 provides requirements for protecting Controlled Unclassified Information in non-federal systems, including components that protect those systems. NIST published Revision 3 in May 2024 with 17 control families and organisation-defined parameters. It is the current NIST publication, but it is not automatically the revision required by every US contract.

Current CMMC Level 2 guidance still uses the 110 requirements from Revision 2. Before assessing, record the contract clause, required revision, assessment method and in-scope environment. If a customer separately asks for Revision 3, document that as a different requirement. Do not substitute a newer publication for an older contractual baseline without written confirmation.

Revision 3 includes planning, system and services acquisition, and supply chain risk management alongside familiar access, configuration, audit, personnel and incident controls. Organisation-defined parameters require specific values to be set or supplied by the applicable agreement. A policy that leaves those values undefined is not a complete implementation. Use NIST's publication and assessment companion for the revision actually required.

NIST published SP 800-171 Revision 3 in May 2024 with 17 control families and organisation-defined parameters, but publication of a newer standard does not automatically replace the version incorporated into a contract or assessment programme, so current CMMC Level 2 still uses the 110 requirements from Revision 2 and a customer that separately requires Revision 3 must document that as a distinct obligation. NIST SP 800-171 Revision 3.

CIS Critical Security Controls v8.1

The CIS Controls are a prioritised set of safeguards published by the Center for Internet Security, a US non-profit. Version 8.1 (the current version) contains 18 Controls and 153 individual Safeguards, grouped into three Implementation Groups (IGs) so organisations can scale based on size, risk and capability.

IG1 : Essential cyber hygiene

56 foundational safeguards for small businesses with limited IT and cyber expertise. The realistic baseline for most Australian SMBs.

IG2 : Risk-managed

IG1 plus 74 additional safeguards. Suits organisations with multiple departments, regulated data and a dedicated IT function.

IG3 : Highly defended

All 153 safeguards. For organisations facing targeted attacks, with mature security operations and incident response capability.

Start with the safeguards that match your risk and assign each an owner. Asset inventories need a process for new and retired devices. Access reviews need a record of decisions. Backup needs evidence of a restore. Installing software covers only part of the work: configuration, monitoring and repeatable operating procedures establish whether the safeguard is actually effective.

CIS Controls and CIS Benchmarks do different jobs. Controls describe the security activities an organisation should perform; Benchmarks provide product-specific configuration recommendations. A benchmark scan can support secure configuration evidence, but it cannot prove incident planning, staff training or supplier oversight. CIS recommends starting with IG1 and adding safeguards according to complexity, data sensitivity and risk.

CIS Controls v8.1 contains 18 controls and 153 safeguards across three Implementation Groups, with IG1 holding 56 foundational safeguards suited to small businesses with limited IT and cyber expertise, IG2 adding 74 safeguards for organisations with regulated data and a dedicated IT function, and IG3 comprising all 153 safeguards for organisations facing targeted attacks, so selection should follow complexity, data sensitivity and risk rather than headcount alone. CIS Implementation Groups.

Side by side comparison

Four frameworks, four different audiences. This is how we usually summarise them on the first call with an Australian client.

Separate the operating model, technical requirements and assurance method in your proposal. CSF can explain the risk programme to a board, CIS can organise day-to-day safeguards, and a contract can still require a specific NIST SP 800-171 assessment. Choosing one as the internal reporting structure does not cancel the others where they are explicitly required.

Compare scope before comparing scores. An assessment of a small project environment does not establish the security of every company system. Likewise, a well-configured cloud service does not prove that staff devices, external administrators or file exports meet the same requirements. State what was assessed, which revision was used and what remains outside the claim.

FrameworkOriginAudienceAudit / certificationAustralian relevance
CMMCUS defence acquisition programmeSuppliers with applicable FCI or CUI contract requirementsCurrent Phase I self-assessments and affirmation; Phase II suspended for reviewRelevant where a US contract or subcontract requires it, not because a business is Australian Defence-adjacent.
NIST SP 800-171NISTNon-federal systems handling CUI or protecting CUI componentsUse the revision and assessment method incorporated into the agreementCurrent CMMC Level 2 uses Revision 2, even though NIST has published Revision 3.
NIST CSF 2.0NISTOrganisations of any size or sectorOutcome-based framework; no NIST certificationUseful for risk reporting, Current and Target Profiles, and a prioritised improvement plan.
CIS Controls v8.1Center for Internet SecurityOrganisations selecting safeguards according to risk and resourcesImplementation guidance; distinguish Controls from configuration BenchmarksUseful alongside Australian mitigation requirements, with evidence mapped requirement by requirement.

How they map to Australian frameworks

The most important practical point: you do not need to run separate cyber programs for each framework. The control families overlap heavily. We typically build evidence once against ASD Essential Eight and the ISM, then map it across to whichever international framework a customer or insurer is asking about.

NIST CSF and ASD ISM

Both use Govern, Identify, Protect, Detect, Respond and Recover. Use that common structure for reporting, then verify the exact controls and evidence within each system scope.

CIS Controls and Essential Eight

Patching, access, configuration and recovery overlap. CIS also covers broader inventory, training and service provider activities. Neither assessment automatically establishes the other's maturity.

NIST SP 800-171 and ISM

Control families overlap, but CUI and Australian information classifications are not interchangeable. Confirm the required revision, data handling rules and assessment boundary before reusing evidence.

CMMC and DISP

These are separate US and Australian assurance arrangements. Membership or assessment under one does not establish compliance with the other. A supplier may need to meet both when different contracts apply.

A practical evidence record links the requirement to a policy, a live configuration and a test result. For access control, that might include the approved role design, current account and group membership, an access review and a leaver test. Reuse those records where appropriate, but document why they meet each mapped requirement rather than simply copying the same status across every framework.

Identify shared supplier controls separately from controls you operate yourself. The provider's assurance needs to cover the service and period in question, while your evidence covers permissions, administration and information handling in your environment. If a mapping is partial, state the gap and treatment instead of reporting full compliance on the basis of a similar control name.

Our pragmatic recommendation

For Australian businesses, build on Essential Eight and SMB1001 first

Choose the required outcomes first. Essential Eight mitigation work and an appropriate SMB1001 tier may suit local business uplift; NIST CSF can organise reporting and CIS can guide implementation. Reuse evidence only where the requirements match. A framework mapping is a starting point for review, not proof that the customer will accept it.

Which framework do you actually need?

A short decision guide based on the conversations we have most weeks.

Your obligations are Australian

Start with the contract, legislation and business risks. Essential Eight, SMB1001 or selected ISM controls may be appropriate; US frameworks are not automatic requirements.

You supply a US defence contract

Confirm whether FCI or CUI is involved and what the current clause requires. Use the specified level, revision and assessment method. Phase II is suspended; Phase I duties remain.

A multinational asks for NIST CSF

Agree the requested outcomes and evidence. Use a Current Profile and Target Profile rather than promising a non-existent NIST CSF certificate.

You need an implementation reference

CIS Controls provides a prioritised safeguard library. Start at IG1 and select further safeguards according to risk and capability; use Benchmarks for product-specific hardening.

You operate critical infrastructure or handle government information

Confirm the applicable Australian requirements and classification. NIST and CIS can supplement implementation, but do not replace legislation, contracts or system authorisation.

Ask the customer for the exact clause, version, assessment boundary, evidence format and deadline. Then distinguish a legal or contractual requirement from a preferred reference framework. That stops a general request for a NIST-aligned security programme turning into an unnecessary CMMC certification project.

Use Real Bytes as your MSP and MSSP

Real Bytes operates as a combined Managed Service Provider (MSP) and Managed Security Service Provider (MSSP), based in Australia, with engineers and analysts you deal with by name. We help Australian businesses that are being asked about US frameworks turn the request into a single, evidence-led program of work that satisfies multiple audiences at once.

How we cover NIST, CIS and CMMC alongside Australian frameworks

Framework areaHow Real Bytes covers it
NIST CSF 2.0 Govern and IdentifyCyber security policy stack, risk register, asset and identity inventory, supplier assurance, board reporting cadence.
CIS IG1 / IG2 safeguardsMicrosoft Entra ID, Conditional Access, Intune baselines, Defender for Endpoint, patch management, secure backup design and testing.
NIST SP 800-171 contractual baselineConfirm the required revision and scope, then assess access, configuration, logging, incident handling and other applicable requirements.
CMMC Level 2 readinessCurrent Revision 2 gap assessment, system security plan, evidence register and eligible remediation planning. No claim to issue CMMC certification.
Detection and responseCentralised logging, SOC monitoring, EDR alerting, OAIC notifiable data breach support, incident response runbook.
Australian regulatory alignmentASD Essential Eight uplift, SMB1001 (CyberCert) preparation, DISP readiness support, Privacy Act 1988 and SOCI Act considerations.

A practical seven-step action plan

If a customer or prime contractor has just sent you a security questionnaire referencing CMMC, NIST or CIS, this is the order we usually recommend.

Obtain the exact customer clause, required revision, assessment method and deadline. Distinguish contractual obligations from a preferred framework.
Map the information: where FCI, CUI or Australian sensitive data is received, stored, processed and transmitted. Include providers and administrative access.
Define the system boundary and control owners before buying tools or an assessment. Document inherited responsibilities as well as your own.
For current CMMC Level 2, assess the Revision 2 baseline and check the official Phase I instructions. Do not assume the suspended Phase II timetable still applies.
For general risk management, compare NIST CSF Current and Target Profiles. Use CIS IG1 safeguards and relevant Australian requirements to organise implementation.
Maintain one evidence register with a separate mapping to each requirement. Record scope, test dates, exceptions and whether the evidence satisfies that requirement.
Review continuing affirmation, contract and framework changes. Close eligible gaps on time and retain evidence that controls remain operational.

Budget for the whole operating cycle: gap analysis, technical remediation, policy and evidence work, the required assessment, and ongoing review. Buying a tool or completing an initial questionnaire is not the finish line. Controls need owners during staff changes, supplier changes and incidents, and current CMMC affirmation requires confidence that implementation continues after the assessment date.

Before signing a readiness proposal, check which baseline it uses and what the provider will deliver. A useful scope identifies the contract revision, system boundary, evidence register, remediation responsibilities and exclusions. Keep independent assessment separate from implementation support, and do not accept a promise that a generic cloud licence or a framework mapping guarantees contract eligibility.

Frequently asked questions

Does an Australian business need CMMC?

Only when an applicable US defence contract or subcontract requires it. Confirm the information you handle, contract clauses, required level and system scope with the prime contractor. Australian Defence work does not automatically require CMMC, and DISP membership is not a CMMC substitute.

Is CMMC Phase II still starting on 10 November 2026?

No. The official CMMC programme announced the suspension of Phase II on 13 July 2026. Phase I self-assessment requirements remain in place. Check current contracting instructions rather than relying on the earlier third-party certification timetable.

Does CMMC Level 2 use NIST SP 800-171 Revision 2 or Revision 3?

The current CMMC Level 2 baseline uses the 110 requirements in Revision 2. NIST published Revision 3 in May 2024, but publication of a newer standard does not automatically replace the version incorporated into a contract or assessment programme. Confirm the required revision before commissioning a gap assessment.

Is the NIST Cybersecurity Framework a certification?

No. NIST CSF 2.0 is an outcome-based risk management framework. Use a Current Profile to record your position and a Target Profile to describe the outcomes you need. The difference becomes a prioritised improvement plan, not a claim of NIST certification.

Should we use CIS Controls or the Essential Eight?

Use the Essential Eight for the Australian mitigation requirements relevant to your business, and CIS Controls as a broader implementation reference. CIS IG1 contains 56 foundational safeguards. Coverage overlaps, but completing one does not prove compliance with the other; assess each requirement and its evidence separately.

Can we reuse Australian compliance evidence for CMMC?

Yes, when the scope, implementation and assessment requirements match. Access reviews, configuration records, training and incident exercises may be reusable. A mapping is not automatic acceptance. Real Bytes can help organise a scoped readiness assessment and technical remediation; we do not issue CMMC certification or act as a C3PAO.

Sources and further reading

All references in this guide are drawn from publicly available US and Australian government and standards sources.

Selling into the US Defence supply chain or asked about NIST?

Real Bytes is an Australian MSP and MSSP. We run gap assessments and uplift programs against CMMC, NIST CSF 2.0, NIST SP 800-171 and CIS Controls, and we map the work back to ASD Essential Eight and SMB1001 so you only do it once.