All Guides
International Frameworks

CMMC, NIST and CIS Controls explained for Australian businesses

The US frameworks Australian businesses keep being asked about. What CMMC, NIST CSF 2.0, NIST SP 800-171 and CIS Controls v8.1 actually require, who needs each, and how they line up with ASD ISM, Essential Eight and SMB1001.

Last reviewed September 202614 min read

Why this matters in Australia

Australian businesses are increasingly being asked about US cyber security frameworks. Sometimes that comes from a US-based parent company, sometimes from a multinational customer, and sometimes from a US Defence prime contractor flowing down DFARS 252.204-7012 and a CMMC clause. The four frameworks that come up in almost every conversation are CMMC, NIST Cybersecurity Framework 2.0, NIST SP 800-171 and the CIS Critical Security Controls.

None of these frameworks replace the ASD Information Security Manual, the Essential Eight, the Privacy Act 1988 or the Security of Critical Infrastructure Act 2018. They sit alongside them. The good news is that they overlap heavily. With the right approach you can produce one set of evidence and reuse it across multiple framework conversations.

3

CMMC certification levels: Foundational, Advanced, Expert

110

Security requirements in NIST SP 800-171 Rev. 3 protecting CUI

6

NIST CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover

18

CIS Controls in v8.1, with 153 safeguards across three Implementation Groups

CMMC: the US Defence supply chain assurance program

The Cybersecurity Maturity Model Certification (CMMC) program is run by the US Department of Defense (DoD). Its purpose is to assure the protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) shared with contractors and subcontractors across the US Defense Industrial Base (DIB). It enforces the security requirements of 32 CFR Part 2002, DFARS 252.204-7012 and DoDI 5200.48, and operationalises NIST SP 800-171.

CMMC is implemented through US Defence acquisition contracts. Once the rulemaking process completes, CMMC compliance becomes a condition of contract award. Companies may be allowed to receive contract awards with a limited time Plan of Actions and Milestones (POA&M) in place to complete remaining requirements, but a baseline number of requirements must be met before award and a small subset cannot be on a POA&M at all.

The three CMMC levels

Level 1 : Foundational

17 basic safeguarding practices drawn from FAR 52.204-21. Annual self-assessment. Suits handling Federal Contract Information (FCI) only.

Level 2 : Advanced

All 110 requirements from NIST SP 800-171 Rev. 2. Triennial third-party assessment by a Certified Third-Party Assessor Organisation (C3PAO) for most CUI. Self-assessment allowed for limited cases.

Level 3 : Expert

NIST 800-171 plus a subset of NIST SP 800-172 enhanced controls. Government-led assessment by DCMA DIBCAC. Reserved for the most sensitive CUI on priority programs.

Australian relevance: CMMC only applies if you are in the US DoD supply chain. If your customers are Australian, including Australian Defence and government, you should be looking at the ASD Information Security Manual and the Defence Industry Security Program (DISP), not CMMC.

NIST Cybersecurity Framework 2.0

The NIST Cybersecurity Framework (CSF) is a voluntary framework published by the US National Institute of Standards and Technology. Version 2.0, released in 2024, is widely used internationally as a common language for describing cyber security posture. It is not a certification.

CSF 2.0 organises cyber security activity into six functions. The biggest change from version 1.1 is the new Govern function, which sits at the centre and explicitly covers strategy, policy, roles, supply chain risk and oversight. Australian readers will notice that the structure is essentially identical to the ASD ISM.

Govern (new in 2.0)

Cyber security strategy, policy, roles, supply chain risk and oversight.

Identify

Asset, risk, threat and vulnerability identification across the business.

Protect

Identity, access control, data protection, secure configuration, awareness training.

Detect

Continuous monitoring, anomaly detection and event analysis.

Respond

Incident response planning, communications, mitigation and improvements.

Recover

Recovery planning, system restoration and lessons learned.

For Australian boards, NIST CSF 2.0 is often the easiest framework to use as a reporting structure because customers, insurers and primes recognise it. We typically map an Australian client's existing ISM and Essential Eight evidence into CSF 2.0 categories so the same controls answer two different audiences.

NIST SP 800-171: protecting Controlled Unclassified Information

NIST SP 800-171 defines the security requirements that non-federal organisations must meet when they store, process or transmit Controlled Unclassified Information (CUI) for the US government. The current version is Revision 3 (May 2024), which contains 110 requirements organised into 17 control families.

NIST 800-171 is the technical baseline that CMMC Level 2 assesses against. If you have a US Defence prime flow-down clause referencing DFARS 252.204-7012, you are required to implement NIST 800-171 and self-score against the DoD Assessment Methodology. CMMC Level 2 then adds a third-party assessment requirement on top.

The 17 control families in NIST 800-171 cover access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, planning, risk assessment, security assessment, system and communications protection, and system and information integrity. Australian readers will recognise almost all of these as ISM principles under different names.

CIS Critical Security Controls v8.1

The CIS Controls are a prioritised set of safeguards published by the Center for Internet Security, a US non-profit. Version 8.1 (the current version) contains 18 Controls and 153 individual Safeguards, grouped into three Implementation Groups (IGs) so organisations can scale based on size, risk and capability.

IG1 : Essential cyber hygiene

56 foundational safeguards for small businesses with limited IT and cyber expertise. The realistic baseline for most Australian SMBs.

IG2 : Risk-managed

IG1 plus 74 additional safeguards. Suits organisations with multiple departments, regulated data and a dedicated IT function.

IG3 : Highly defended

All 153 safeguards. For organisations facing targeted attacks, with mature security operations and incident response capability.

CIS is not a certification. It is a free, vendor-neutral control library and is one of the most practical day-to-day references for Australian SMBs. The 18 controls cover inventory, data protection, secure configuration, account management, access control, vulnerability management, audit logging, email and browser protections, malware defences, data recovery, network management, awareness training, service provider management, application software security, incident response, and penetration testing.

Side by side comparison

Four frameworks, four different audiences. This is how we usually summarise them on the first call with an Australian client.

FrameworkOriginAudienceAudit / certificationAustralian relevance
CMMCUS Department of DefenseUS DIB suppliers and subcontractors handling FCI / CUISelf-assessment (L1), C3PAO third-party (L2), DIBCAC (L3)Australian suppliers in the US Defence supply chain. Otherwise rarely required.
NIST SP 800-171NIST (US Department of Commerce)Non-federal organisations handling US Controlled Unclassified InformationUnderpins CMMC Level 2. Self-assessment scored against the DoD Assessment Methodology.Mostly relevant to Australian suppliers in US Defence flow-down clauses (DFARS 252.204-7012).
NIST CSF 2.0NISTAny organisation, any sector, internationallyNo formal certification. Self-assessment, advisor-led or used as a board-level framework.Widely used by Australian boards, insurers and primes as a common language. Pairs cleanly with the ISM and Essential Eight.
CIS Controls v8.1Center for Internet Security (US non-profit)Any organisation, prioritised by Implementation GroupNo formal certification. CIS provides self-assessment tooling (CIS-CAT, CIS RAM).Excellent practical control library for Australian SMBs. Maps neatly to ASD Essential Eight and SMB1001.

How they map to Australian frameworks

The most important practical point: you do not need to run separate cyber programs for each framework. The control families overlap heavily. We typically build evidence once against ASD Essential Eight and the ISM, then map it across to whichever international framework a customer or insurer is asking about.

NIST CSF 2.0 ↔ ASD ISM

The ISM aligns its six functions (Govern, Identify, Protect, Detect, Respond, Recover) directly with NIST CSF 2.0. If you already use the ISM, NIST CSF reads like the same framework with different phrasing.

CIS Controls ↔ Essential Eight

The Essential Eight maps cleanly onto CIS IG1 and parts of IG2. Patch management, MFA, application control, admin restrictions and backup all appear in both. Most Australian SMBs at Essential Eight Maturity Level 1 are close to CIS IG1.

NIST SP 800-171 ↔ ISM PROTECTED

NIST 800-171 Rev. 3 has 110 requirements protecting CUI. ASD ISM at OFFICIAL: Sensitive and PROTECTED level covers the same control families with Australian terminology and additional governance principles.

CMMC ↔ DISP

CMMC is the US Defence supply chain assurance program. DISP (Defence Industry Security Program) is its Australian equivalent. DISP draws on the ISM rather than CMMC, but the intent (assured suppliers handling sensitive Defence information) is the same.

Our pragmatic recommendation

For Australian businesses, build on Essential Eight and SMB1001 first

Unless you have a binding US Defence supply chain obligation, NIST and CIS are reference libraries, not destinations. Get to a defensible Essential Eight maturity, certify SMB1001 at Gold or higher, and use NIST CSF 2.0 as the language you speak with international customers. The work counts in every direction.

Which framework do you actually need?

A short decision guide based on the conversations we have most weeks.

You only sell to Australian customers

You almost certainly do not need CMMC or NIST 800-171. Focus on ASD Essential Eight, SMB1001 (Gold or above) and selectively the ISM if you handle government data.

You sell to US Defence primes or subcontractors

CMMC is in scope. Most Australian suppliers in this position need at least Level 2 once a CMMC clause appears in the prime contract. NIST SP 800-171 is the underlying technical baseline.

You sell to multinational customers using NIST CSF

NIST CSF 2.0 is the most useful common language. It is not a certification and it pairs naturally with ISM, ISO 27001 and Essential Eight evidence you already produce.

You want a practical control library, not a certification

CIS Controls v8.1 is the most actionable. Start at IG1, layer to IG2 as you mature, and use CIS-CAT or RAM for self-assessment. Pairs well with SMB1001 evidence.

You operate critical infrastructure or hold government data

The ASD Information Security Manual remains the primary reference in Australia. NIST CSF and CIS Controls can supplement, but do not replace, the ISM and the SOCI Act CIRMP obligations.

Use Real Bytes as your MSP and MSSP

Real Bytes operates as a combined Managed Service Provider (MSP) and Managed Security Service Provider (MSSP), based in Australia, with engineers and analysts you deal with by name. We help Australian businesses that are being asked about US frameworks turn the request into a single, evidence-led program of work that satisfies multiple audiences at once.

How we cover NIST, CIS and CMMC alongside Australian frameworks

Framework areaHow Real Bytes covers it
NIST CSF 2.0 Govern and IdentifyCyber security policy stack, risk register, asset and identity inventory, supplier assurance, board reporting cadence.
CIS IG1 / IG2 safeguardsMicrosoft Entra ID, Conditional Access, Intune baselines, Defender for Endpoint, patch management, secure backup design and testing.
NIST SP 800-171 Rev. 3 baselineAccess control, audit and accountability, configuration management, incident response, media protection, system and information integrity.
CMMC Level 2 readinessGap assessment against the 110 requirements, evidence collection, System Security Plan (SSP) and Plan of Action and Milestones (POA&M) preparation.
Detection and responseCentralised logging, SOC monitoring, EDR alerting, OAIC notifiable data breach support, incident response runbook.
Australian regulatory alignmentASD Essential Eight uplift, SMB1001 (CyberCert) preparation, DISP readiness support, Privacy Act 1988 and SOCI Act considerations.

A practical seven-step action plan

If a customer or prime contractor has just sent you a security questionnaire referencing CMMC, NIST or CIS, this is the order we usually recommend.

Confirm whether you actually have a US Defence supply chain obligation. If not, deprioritise CMMC and NIST SP 800-171.
Pick one primary framework as your operating model. For most Australian businesses that is ASD Essential Eight plus SMB1001, with NIST CSF 2.0 as the board-level language.
Use CIS Controls v8.1 (IG1 then IG2) as your detailed control library. It is free, prioritised and maps to your existing Essential Eight evidence.
If you need CMMC Level 2, start with a NIST SP 800-171 Rev. 3 gap assessment. Document a System Security Plan and POA&M before engaging a C3PAO.
Map your existing controls once. Reuse the same evidence across NIST CSF, CIS, ISM, Essential Eight and SMB1001. Do not run parallel programs.
Document supplier assurance. Both CMMC and NIST CSF 2.0 (Govern function) now require active management of supply chain cyber risk.
Review annually against the most recent published version of each framework. NIST and CIS update materially every two to three years.

Frequently asked questions

Does an Australian business need to comply with CMMC?

Only if you sell into the US Defence Industrial Base, either as a direct supplier to the US Department of Defense or as a subcontractor to a US prime that flows down DFARS 252.204-7012 and a CMMC clause. Most Australian businesses do not need CMMC. The Australian equivalent is the Defence Industry Security Program (DISP), which is governed by the ASD Information Security Manual rather than CMMC.

What is the difference between CMMC and NIST SP 800-171?

NIST SP 800-171 is the underlying technical standard that defines 110 security requirements for protecting Controlled Unclassified Information (CUI). CMMC is the US Department of Defense certification program that assesses contractors against those requirements (and a few additional practices at Level 3). In short: NIST 800-171 is the rulebook, CMMC is the audit program.

Is NIST Cybersecurity Framework (CSF) a certification?

No. NIST CSF 2.0 is a voluntary framework, not a certification. It is widely used by boards, insurers and prime contractors as a common language for describing cyber security posture. In Australia, it pairs well with the ASD Information Security Manual, ISO 27001 and the Essential Eight.

How does NIST CSF 2.0 differ from version 1.1?

The biggest change is the new Govern function, which sits alongside Identify, Protect, Detect, Respond and Recover. Govern explicitly covers strategy, policy, roles, supply chain risk and oversight. Version 2.0 also expands guidance on small and medium enterprises and on supply chain cyber security risk management.

Should we use CIS Controls or Essential Eight?

For Australian businesses, the Essential Eight is the starting point because it is the framework Australian insurers, primes and government bodies refer to. ASD is evolving it into a new Essentials series over the next two years, but the eight mitigation strategies stay the same and it remains current guidance throughout the transition. CIS Controls v8.1 is an excellent companion: it provides a broader, prioritised control library (153 safeguards across three Implementation Groups) and maps cleanly onto the Essential Eight. We commonly use CIS as the detailed implementation guide and Essential Eight as the reporting framework.

Can Real Bytes help us prepare for CMMC if we sell to a US prime?

Yes. We are an Australian MSP and MSSP. We help Australian suppliers prepare for CMMC Level 2 by running a NIST SP 800-171 Rev. 3 gap assessment, building the System Security Plan (SSP) and Plan of Action and Milestones (POA&M), and implementing the technical controls inside Microsoft 365, Entra ID, Intune and Defender. We do not act as a Certified Third-Party Assessor Organisation (C3PAO); we get you ready for one.

Sources and further reading

All references in this guide are drawn from publicly available US and Australian government and standards sources.

Selling into the US Defence supply chain or asked about NIST?

Real Bytes is an Australian MSP and MSSP. We run gap assessments and uplift programs against CMMC, NIST CSF 2.0, NIST SP 800-171 and CIS Controls, and we map the work back to ASD Essential Eight and SMB1001 so you only do it once.