That's a great question!
Essentially, the CMMC takes the
best practices of all of these requirements and rolls them into one, uniformed model. To be honest, there is a lot of overlapping, anyways, and it just makes sense to simplify them all:
- FAR Clause 52.204-21
- NIST SP 800-171 Rev 1
- Draft NIST SP 800-171B
- CIS Controls v7.1
- NIST Framework for Improving Critical Infrastructure Cybersecurity (CSF) v1.1
- CERT Resilience Management Model (CERT RMM) v1.2
- NIST SP 800-53 Rev 4
- Others such as:
- UK NCSC Cyber Essentials
- AU ACSC Essential Eight