Last updated: July 26, 2026
Framework Crosswalk

HIPAA to CMMC 2.0: control mapping & evidence reuse

7 of 13 control domains map directly. See exactly where HIPAA and CMMC 2.0 overlap, which evidence carries over, and which engagement to run first.

How HIPAA and CMMC 2.0 relate

This crosswalk is for organizations that must satisfy both the HIPAA Security Rule and CMMC 2.0 Level 2 at the same time. That usually means health IT vendors, medical device makers, or research and services firms that handle protected health information (PHI) while also holding Department of Defense contracts that expose them to controlled unclassified information (CUI). The two regimes protect different data for different reasons, so meeting one does not automatically satisfy the other.

Structurally the frameworks are built differently. The HIPAA Security Rule (45 CFR Part 164, Subpart C) is a risk-based set of administrative, physical, and technical safeguards, with some requirements labeled required and others addressable; it has no certification and no mandated audit, and the HHS Office for Civil Rights enforces it. CMMC 2.0 Level 2 is a prescriptive set of 110 practices drawn directly from NIST SP 800-171 Rev. 2, organized into 14 control families, and it is verified through a formal assessment by an accredited C3PAO for many contracts.

The mappings below are AuditNex practical guidance to help teams plan combined work; they are not an official government crosswalk. Where the two frameworks squarely align we mark a row direct, where scope or rigor differ we mark it partial and say how, and where one framework has no meaningful requirement we mark it none and label the missing side as having no direct equivalent.

Domain-by-domain mapping

Each row pairs the closest HIPAA and CMMC 2.0 requirements for one control domain. This is practical audit-planning guidance, not an official crosswalk published by the standards bodies.

Direct matches
7
of 13 control domains
Partial overlap
4
scope or rigor differs
No equivalent
2
one framework only
Domains compared
13
same spine on every crosswalk

Across 13 control domains, 7 map directly between HIPAA and CMMC 2.0, 4 map partially, and 2 have no equivalent on one side. Counts are computed live from the mapping table below.

Control domainHIPAA referenceCMMC referenceMatch & notes
Governance & risk assessment §164.308(a)(1) security management process, incl. risk analysis (a)(1)(ii)(A) RA 3.11.x; CA 3.12.x Direct match
Both squarely require an ongoing, documented risk assessment. CMMC adds a formal security assessment and system security plan discipline that HIPAA leaves to the organization's judgment.
Policies & documentation §164.316 policies & documentation CA 3.12.x (system security plan) Partial
HIPAA has a dedicated documentation standard with a retention requirement, while CMMC embeds documentation across families and centers it on the system security plan. Both expect written, maintained policies.
Access control & identity §164.312(a) access control & unique user ID; §164.312(d) authentication; §164.308(a)(4) information access management AC 3.1.x; IA 3.5.x Direct match
Both require identity, authentication, and least-privilege access. CMMC's access control and identification families are more prescriptive than HIPAA's higher-level safeguards.
Change management No direct equivalent CM 3.4.3–3.4.4 No equivalent
HIPAA has no explicit change-management standard; any change discipline flows indirectly from the risk analysis. CMMC requires tracking and controlling changes under its configuration management family.
Data protection & encryption §164.312(a)(2)(iv) encryption; §164.312(e) transmission security; §164.312(c) integrity SC 3.13.x (incl. encryption of CUI) Direct match
Both call for protecting data in transit and at rest. HIPAA treats encryption as addressable, whereas CMMC expects cryptographic protection of CUI, so the rigor is higher on the CMMC side.
Logging & monitoring §164.312(b) audit controls AU 3.3.x; SI 3.14.x Direct match
Both require recording and reviewing system activity. HIPAA's audit controls are stated at a high level, while CMMC's audit and accountability and monitoring practices are far more specific.
Incident response §164.308(a)(6) security incident procedures IR 3.6.x Direct match
Both require documented procedures to detect, respond to, and report security incidents. CMMC adds explicit expectations for incident handling and reporting under the incident response family.
Vendor & third-party risk §164.308(b) & §164.314 business associate contracts AC 3.1.20 (external systems); DFARS 252.204-7012 flow-down Partial
HIPAA has an explicit business associate agreement regime, while CMMC has no dedicated vendor family and relies on external-system controls plus DFARS flow-down clauses. The mechanisms differ even though both address third parties.
Business continuity & availability §164.308(a)(7) contingency plan (data backup, DR, emergency mode) No direct equivalent No equivalent
HIPAA requires contingency planning with data backup, disaster recovery, and emergency-mode operations. NIST SP 800-171 has no continuity or backup family, so CMMC Level 2 has no direct equivalent.
Personnel security & training §164.308(a)(3) workforce security; §164.308(a)(5) security awareness & training PS 3.9.x; AT 3.2.x Direct match
Both require workforce screening and controls plus ongoing security awareness training. The personnel security and awareness families in CMMC map closely to HIPAA's workforce safeguards.
Asset & configuration management §164.310(d) device & media controls CM 3.4.x; MP 3.8.x Partial
HIPAA addresses device and media handling but has no configuration management standard. CMMC adds a full configuration management family and media protection practices, so coverage is broader on the CMMC side.
Physical & environmental security §164.310(a) facility access; §164.310(b)–(c) workstation use & security PE 3.10.x Direct match
Both require controlling physical access to facilities and workstations. CMMC's physical protection family and HIPAA's physical safeguards line up well on intent.
Vulnerability & patch management §164.308(a)(1) risk analysis; §164.308(a)(5)(ii)(B) malicious software protection SI 3.14.x (flaw remediation); RA 3.11.x (vulnerability scanning) Partial
HIPAA has no explicit vulnerability-scanning or patching requirement; it flows indirectly from the risk analysis and malicious-software protection. CMMC requires explicit vulnerability scanning and flaw remediation, so the CMMC obligation is more concrete.

Which should you do first?

For a company that touches PHI, HIPAA is a standing legal obligation the moment it acts as a covered entity or business associate, so its risk analysis and safeguards should be treated as the always-on baseline rather than a project with a finish line. CMMC 2.0 Level 2, by contrast, is contract-driven: the schedule is set by DoD acquisition timelines, and the assessment by a C3PAO is a gating event for winning or keeping work. In practice, the CMMC deadline is what forces most teams to act, so it tends to drive the calendar.

Because CMMC Level 2 (NIST SP 800-171) is more prescriptive on technical and configuration controls, building toward it will cover a large share of HIPAA's technical and administrative safeguards along the way. It will not, however, address HIPAA's contingency-planning and business-associate obligations, which sit outside the 800-171 families. A sensible order is to complete the HIPAA risk analysis first so you understand where PHI lives, then design the CUI environment to the 800-171 practices, reusing the shared controls.

Companies running both should first define scope carefully, because the PHI systems and the CUI enclave are often not the same boundary. Once boundaries are set, run the HIPAA risk analysis and remediation, then layer the more granular CMMC practices onto the CUI enclave, and keep HIPAA-only items such as contingency planning and business associate agreements maintained separately so nothing falls through the gap between the two programs.

Evidence you can reuse

Several artifacts carry across both efforts. A single risk assessment can anchor both HIPAA's security management process and the CMMC risk assessment family. Access control configurations, unique user IDs and multi-factor authentication, audit log settings, encryption configurations, incident response procedures, workforce training records, physical access records, and media and device handling controls all support requirements on both sides, and written policies satisfy HIPAA documentation while feeding the CMMC system security plan.

Some evidence does not transfer. CMMC-specific artifacts such as configuration management baselines, flaw-remediation and vulnerability-scanning cadence records, the system security plan, plan of action and milestones (POA&M), FIPS-validated cryptography evidence, and DFARS flow-down proof have no HIPAA counterpart. Going the other way, HIPAA's contingency plan, data backup and disaster recovery testing, and business associate agreements have no home in the 800-171 practice set, so plan to produce and maintain those independently.

Find auditors for each framework

No directory firm is currently confirmed for both HIPAA and CMMC 2.0 — browse each ranking separately, or submit one request covering both and let firms respond.

Best HIPAA auditors ›  ·  Best CMMC 2.0 auditors ›

Budget both engagements

AuditNex publishes first-party and industry rate data for each framework so you can plan the combined spend before talking to anyone.

HIPAA cost data ›  ·  CMMC 2.0 cost data ›  ·  All compliance audit costs ›

One request, both frameworks

Tell us your scope once — get transparent quotes from vetted firms that can run HIPAA and CMMC 2.0 together.

Get matched →

Sources: HHS HIPAA Security Rule, 45 CFR Part 164, Subpart C; NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems; CMMC 2.0 Model Overview, US Department of Defense; DFARS 252.204-7012, Safeguarding Covered Defense Information; NIST SP 800-66, Implementing the HIPAA Security Rule. Mapping maintained by the AuditNex research team; last reviewed July 26, 2026. This crosswalk is practical guidance for planning combined audits — it is not an official mapping published by AICPA, ISO, HHS, DoD, or the FedRAMP PMO, and your auditor makes the final scoping call.