NIST SP 800-171 self-assessment
A self-assessment under NIST SP 800-171 is how a defense contractor measures its own implementation of the 110 security requirements, turns that into a single number, and posts it to the Supplier Performance Risk System (SPRS).
The method is not left to you. The Department of Defense published the NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1, dated June 24, 2020, and DFARS 204.7303 points contractors at it. Using your own scoring scheme is not an option.
This page covers the three assessment types, how the score is calculated, what you actually post, and the mistakes that produce a score you cannot defend.
Three assessment types
The methodology defines three, which differ in who performs them and how much confidence the government places in the result.
| Type | Who performs it | What it examines | Confidence |
|---|---|---|---|
| Basic | The contractor, as a self-assessment | Your system security plan, reviewed against the 110 requirements | Low |
| Medium | The government | Your system security plan, with a government review of how each requirement is described | Medium |
| High | The government, usually the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) | The plan plus a review of evidence that the requirements are implemented | High |
Only the Basic assessment is yours to run. A Medium or High assessment is scheduled by the government, and DFARS 252.204-7020 obliges you to provide access to your facilities, systems, and personnel when one is conducted.
The confidence level is part of the record. A Basic score sits in SPRS marked as a self-assessment, and a contracting officer reads it knowing nobody checked it.
How the score is calculated
Start at 110, which is the number of requirements and also the maximum score. For each requirement that is not implemented, subtract its weight.
| Weight | What it means |
|---|---|
| 5 points | The requirement, if not implemented, is likely to result in significant exploitation of the network or significant exfiltration of CUI |
| 3 points | The requirement has a specific and confined effect on the security of the network and its data |
| 1 point | The requirement has a limited or indirect effect on the security of the network and its data |
Two requirements carry partial credit rather than all-or-nothing scoring, both in Annex A of the methodology: multifactor authentication at 3.5.3 and FIPS-validated cryptography at 3.13.11. In each case a partial implementation costs fewer points than none at all. Read Annex A rather than assuming.
Because the weights are subtracted and there are more than 22 five-point requirements, the score can go well below zero. The floor defined by the methodology is -203. A negative score is not a data-entry error, and it is common for an organization starting out.
| Score | What it says |
|---|---|
| 110 | Every requirement implemented |
| Between 0 and 110 | Partial implementation, with the gaps on a plan of action |
| Below 0 | More unimplemented weight than the 110 starting points |
| -203 | Nothing implemented |
A score of 110 is the only score with no plan of action behind it. Every other score should have one. See plan of action and milestones.
What "implemented" means
The scoring question is binary for most requirements, and the methodology does not recognize "in progress." A requirement counts as implemented when it is actually implemented, not when it is planned, budgeted, or documented as an intention.
This is where most self-assessments go wrong. A system security plan that describes the intended state rather than the current state produces a score that will not survive a High assessment, and the gap between the two is what a False Claims Act case is built from. See SPRS score for the enforcement history.
Assess against NIST SP 800-171A, which gives the assessment objectives for each requirement. A requirement is met when every objective under it is met.
What you post to SPRS
The summary level score is not just a number. The record carries:
| Field | Note |
|---|---|
| Standard assessed | NIST SP 800-171 Rev. 2 |
| Assessment date | The date the assessment was completed |
| Summary level score | The calculated value, 110 down to -203 |
| Scope | Enterprise, or the specific contractor information systems covered |
| System security plan | Name, version, and date of the plan the assessment was performed against |
| Included CAGE codes | Every Commercial and Government Entity code the score covers |
| Plan of action completion date | The date by which you expect a score of 110 |
A Basic assessment is current if it is not more than three years old, unless the solicitation specifies less. Post it before award, not after.
SPRS is reached through the Procurement Integrated Enterprise Environment. See SPRS score for who can submit and how the affirmation works.
Subcontractor flowdown
DFARS 252.204-7020 requires you to insert the substance of the clause into subcontracts and other contractual instruments where DFARS 252.204-7012 applies, excluding contracts solely for commercially available off-the-shelf items. Before you award, the subcontractor must have a current summary level score posted in SPRS.
That is a check you perform, not a promise you accept.
Common mistakes
- Scoring the intent rather than the implementation. The most expensive one. "We have a policy that says we do this" is not the same as doing it.
- A stale system security plan. The score is tied to a named plan at a named version. If the plan no longer describes the environment, the score describes nothing.
- An enterprise score that covers systems that were never assessed. Scope the assessment to what you actually examined and say so in the scope field.
- Leaving the score alone after the environment changes. A score is a point-in-time measurement. A material change in your systems means a new assessment, not an annotation.
- Treating a plan of action completion date as aspirational. The date is part of the record a contracting officer reads.
- Missing the external service providers. Cloud services and managed providers that handle CUI are in scope. Decide how they are covered before you score.
- Assuming the CMMC suspension removed the obligation. It did not. See CMMC Phase 2.
How the kit relates to a self-assessment
| Item | Kit role |
|---|---|
| Run the access control, identification and authentication, and audit controls the requirements describe | Performs |
| Keep dated records of what ran, when, and for whom | Records |
| Show the current state of configuration against a baseline | Performs |
| Map evidence to the requirement it supports | Assists |
| Track plan-of-action items and closure dates | Assists |
| Calculate your summary level score | Organization |
| Write or maintain your system security plan | Organization |
| Submit anything to SPRS, or sign an affirmation | Organization |
| Decide what is in scope | Organization |
The kit shortens the evidence hunt. It does not score you and it does not file for you. See AIC CMMC Complete™.
Common questions
Can I do the assessment myself?
A Basic assessment is a self-assessment, so yes. A Medium or High assessment is performed by the government.
How often do I have to reassess?
A Basic assessment is current for up to three years, unless the solicitation says less. A material change to your systems should trigger a new one sooner.
Is a negative score a problem?
It is a true score. Posting an inflated one is the problem. A negative score with a credible plan of action is a position you can defend.
Does a 110 mean I am certified?
No. A score is a self-reported measurement under DFARS 252.204-7019 and 252.204-7020. Certification is a separate process under DFARS 252.204-7021.
Which revision of 800-171 do I assess against?
DFARS 252.204-7012 currently points at NIST SP 800-171 Rev. 2. Check your clause rather than assuming the newest publication applies.
What if a requirement does not apply to us?
The methodology does not have a not-applicable category for scoring. If a requirement genuinely cannot apply, document the reasoning in the system security plan and be ready to explain it.
Who signs for the score?
Submission to SPRS is controlled by your organization's SPRS access roles. The annual CMMC affirmation is signed by a named affirming official under DFARS 252.204-7021.
Related pages
- SPRS score: where the score lives and what it commits you to
- NIST SP 800-171: the 110 requirements, by family
- DFARS 252.204-7012: the clause that requires implementation
- DFARS 252.204-7021: the CMMC clause
- CMMC Phase 2: what the suspension changed
- Plan of action and milestones
- Controlled unclassified information
- CMMC Level 2: the same 110 requirements under CMMC
- Configuration compliance
- AIC CMMC Complete™ and pricing
- Glossary
Sources
- NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1, June 24, 2020
- DFARS 204.73, Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements
- NIST SP 800-171 Rev. 2
- NIST SP 800-171A
- Supplier Performance Risk System