Does ISO 27001 Count Toward CMMC?

The direct answer: no. There is no formal reciprocity mechanism in the CMMC program for ISO 27001, and none for SOC 2 either. An ISO 27001 certificate earns you no assessment credit, no scope reduction, and no exemption from SPRS scoring or the annual affirmation. But the certificate is far from worthless in a defense context. CMMC Level 2 is built on NIST SP 800-171, and practitioners who run both programs commonly estimate that a mature ISO 27001 ISMS already addresses roughly 80 percent of the Level 2 territory. That figure is a practitioner estimate, not an official DoD mapping, so treat it as directional. The real work is the remaining slice, and it is not random: the gap is concentrated in CUI-specific requirements that ISO 27001 was never designed to touch.
Status verified August 27, 2026. This page is updated when the regulatory status changes.
This question comes up constantly in defense-supplier procurement, usually from a company that built ISO 27001 for commercial customers and then received a flow-down letter from a prime. The honest framing is that you are closer than a company starting from zero, and further than your certificate makes you feel.
Why there is no reciprocity
The two programs answer different questions for different audiences. ISO 27001 certifies that you operate a risk-based information security management system: you chose your controls from Annex A based on your own risk assessment, documented the choices in a Statement of Applicability, and an accredited certification body confirmed the management system works. The current baseline is ISO 27001:2022 with Amendment 1 from 2024, and the transition from the 2013 edition closed on October 31, 2025.
CMMC verifies something narrower and more prescriptive: that a defense contractor implements a fixed set of controls protecting a specific data type, Controlled Unclassified Information, inside a defined boundary. There is no choosing. CMMC Level 2 is scored against the 110 controls of NIST SP 800-171 Rev 2, the assessment scope is drawn around where CUI lives and flows, and the results feed a DoD system of record. A certification body attesting that your management system is sound tells DoD nothing about whether your CUI enclave meets each of the 110 requirements. That is the structural reason no reciprocity mechanism exists, and as of August 2026 none has been proposed. The latest practitioner analysis on reciprocity reaches the same conclusion: mapping, yes; credit, no.
Note that this differs from the ISO 27001 versus SOC 2 relationship, where the two frameworks at least share a commercial-assurance purpose and heavy control overlap. We cover that pairing in ISO 27001 vs SOC 2. CMMC sits in a different lane entirely: it is a condition of doing defense business, not a market signal.
What actually carries over
The overlap is real and substantial. If your ISMS is mature, you already run most of the operational machinery Level 2 expects: access control and identity management, asset inventory, configuration discipline, security awareness training, supplier risk management, logging and monitoring, an incident response process, and a governance rhythm that produces evidence on a schedule. Just as important, you already know how to live inside an audit: scoping, evidence collection, findings, and corrective action are familiar motions. Companies coming to CMMC from ISO 27001 consistently move faster than companies coming from nothing, and side-by-side comparisons of the two frameworks show why: the control families rhyme even where the requirements differ in precision.
What does not carry over is anything specific to CUI. ISO 27001 has no concept of Controlled Unclassified Information, no federal incident reporting duty, and no government scoring system. That is the delta, and it is worth being precise about it.
The CUI delta: what Level 2 requires beyond a mature ISMS
| Gap area | What ISO 27001 gave you | What CMMC Level 2 requires |
|---|---|---|
| Cryptography | Encryption chosen by your own risk assessment | FIPS-validated cryptographic modules for protecting CUI. Strong commercial encryption that lacks FIPS validation does not count |
| CUI marking and flow | Generic information classification of your choosing | Identifying, marking, and controlling CUI as it flows through systems, people, and subcontractors, with the assessment boundary drawn around it |
| Incident reporting | An internal response process with self-defined notification rules | Rapid reporting of cyber incidents to DoD within 72 hours under DFARS 252.204-7012, a duty that remains fully in effect through the current pause |
| Scoring and affirmation | A certificate from your certification body | A self-assessment score posted in SPRS on the -203 to 110 scale, plus an annual affirmation of continuous compliance by a named Affirming Official under 32 CFR 170.22 |
| Baseline and documentation | Statement of Applicability against Annex A | A system security plan and POA&Ms against all 110 controls of NIST SP 800-171 Rev 2, the baseline pinned by DoD's May 2024 class deviation |
Two of these gaps deserve emphasis because they routinely surprise ISO-certified companies. First, the FIPS requirement is binary: the question is not whether your encryption is strong but whether the module is validated, and remediation can mean replacing products, not reconfiguring them. Second, the affirmation is personal. A named executive affirms continuous compliance, a current affirmation is a prerequisite to contract award, and a false one carries False Claims Act exposure with treble damages. Nothing in an ISO surveillance audit prepares an executive for that signature. The Affirming Official role is a client-side statutory role; an outside partner can prepare the evidence behind it, but the affirmation is yours.
Holding ISO 27001 and staring at a CMMC flow-down letter?
A Z Cyber advisor can map your Statement of Applicability to the 110 controls of 800-171 Rev 2 and brief you on exactly which CUI gaps remain.
Does the CMMC pause change the answer?
No, and this is where ISO-certified companies most often miscalculate. On July 13, 2026, DoD suspended the Phase 2 rollout that would have made third-party Level 2 certification a condition of award starting November 10, 2026. We track that situation, the reform task force, and the expected timeline in our CMMC Phase 2 suspension status page, so we will not re-answer it here. What matters for this question is what the pause did not touch.
Phase 1 remains fully in force: self-assessments, SPRS score posting, and the annual affirmation are still mandatory, and DFARS 252.204-7021 still appears in contracts. Per DLA Piper's August 2026 analysis, a current affirmation is a prerequisite to contract award and option exercise. The 72-hour incident reporting duty under DFARS 7012 is unaffected. And large primes are still demanding CMMC readiness, and in some cases certification, from subcontractors by contract regardless of DoD's timeline. Contract terms do not pause because a regulator does. So an ISO 27001 certificate during the pause buys you exactly what it bought you before the pause: a head start, not a hall pass.
The practical sequence for an ISO-certified company
If you hold ISO 27001 and defense revenue is on the table, the path runs in four steps. First, scope the CUI environment: what CUI you receive or create, where it lives, and who touches it. This boundary decision drives everything downstream, and shrinking it with an enclave is often the single highest-leverage move. Second, map your Statement of Applicability to NIST SP 800-171 Rev 2 and score honestly against all 110 controls. If the distinction between 800-171 compliance and CMMC assessment still feels fuzzy, our breakdown of NIST 800-171 vs CMMC covers how the control set relates to the program that verifies it. Third, remediate the CUI delta: FIPS-validated crypto, CUI marking and flow control, and DoD incident reporting wired into the response process your ISMS already runs. Fourth, post your SPRS score, document POA&Ms for open items, and put the affirmation in front of an executive who understands what the signature means.
An ISO-mature company can move through this sequence much faster than the market assumes, precisely because the management system, the evidence habits, and most of the operational controls already exist. The mistake is skipping the mapping because the certificate feels like enough. It is not, and no reciprocity mechanism is coming to make it enough. If you want a second set of eyes on the mapping and the delta, talk to a Z Cyber advisor: we run this exact crosswalk for dual-market companies that built their program for commercial customers and now need it to hold up in a defense supply chain.
What to watch next
Two dates govern how long this answer stays stable. The CMMC Reform Task Force reports to the Department of War chief information officer on or about September 13, 2026, and formal determinations are not expected before mid-October 2026. Neither is likely to create ISO 27001 reciprocity, since the gap is statutory and CUI-specific rather than a question of assessment rigor. What could change is which assessment type applies to you, and that changes the cost of the delta rather than its content. This page is updated when the program status moves.
Frequently Asked Questions
Does ISO 27001 certification count toward CMMC?
Not formally. The CMMC program has no reciprocity mechanism for ISO 27001, and none for SOC 2 either. An ISO 27001 certificate does not reduce your CMMC assessment scope, substitute for any requirement, or change your SPRS obligations. What it does provide is a running management system that already covers much of the same control territory, because CMMC Level 2 is built on NIST SP 800-171. You still have to map your controls to 800-171, close the CUI-specific gaps, and complete the CMMC assessment process on its own terms.
How much of CMMC Level 2 does ISO 27001 cover?
Practitioners who run both programs commonly estimate that a mature ISO 27001 ISMS addresses roughly 80 percent of CMMC Level 2 territory. That figure is a practitioner estimate, not an official DoD mapping, but the direction is right: access control, asset management, incident response process, supplier management, and awareness training carry over well. The remaining gap is concentrated in CUI-specific requirements: FIPS-validated cryptography, CUI marking and flow control, DoD incident reporting under DFARS 252.204-7012, and SPRS scoring with an annual affirmation.
What does CMMC require that ISO 27001 does not?
Four things stand out. FIPS-validated cryptography: ISO 27001 lets you choose your own encryption approach, while protecting CUI requires FIPS-validated modules. CUI marking and flow control: ISO has no concept of Controlled Unclassified Information or its handling rules. DoD incident reporting: DFARS 252.204-7012 requires rapid reporting of cyber incidents to DoD within 72 hours, which no ISO process satisfies by default. And SPRS: a self-assessment score posted in the Supplier Performance Risk System plus an annual affirmation of continuous compliance by a named Affirming Official.
Is there CMMC reciprocity for SOC 2?
No. The CMMC program recognizes neither SOC 2 nor ISO 27001 as a substitute for its own assessment requirements. A SOC 2 Type II report demonstrates that an auditor tested your controls against the AICPA Trust Services Criteria over a period, which is valuable in commercial sales, but CMMC Level 2 is scored against the 110 controls of NIST SP 800-171 Rev 2 within a defined CUI boundary. The evidence and the operating discipline behind a SOC 2 report help you prepare, but you get no formal credit for holding one.
Do I still need to work toward CMMC if I have ISO 27001 and the program is paused?
Yes, if you handle federal contract information or CUI. The July 13, 2026 suspension paused the Phase 2 third-party assessment rollout, but Phase 1 remains fully in force: Level 1 and Level 2 self-assessments, SPRS score posting, and the annual affirmation are still mandatory, and a current affirmation is a prerequisite to contract award. A false affirmation carries False Claims Act exposure. Many primes are also still demanding CMMC readiness from subcontractors by contract regardless of the pause. ISO 27001 helps you get there faster; it does not exempt you.
Subscribe for Updates
Get cybersecurity insights delivered to your inbox.


