BlueSteel Cybersecurity

Rev 3 ยท 110 requirements

NIST SP 800-171

800-171 is the control set underneath CMMC Level 2, and the obligation exists independently of it. If a DFARS clause applies, you owe a current self assessment score in SPRS whether or not a CMMC assessment has been scheduled.

What the engagement covers

Contractors and subcontractors handling CUI. Typical timeline: 3 to 9 months depending on the current SPRS gap.

  • CUI identification and scoping, which determines everything downstream
  • Self assessment against all 110 requirements, scored to the DoD methodology
  • SPRS score calculation and posting
  • System Security Plan and Plan of Action and Milestones
  • Remediation of the requirements that most often fail: MFA, audit logging, FIPS validated encryption, media protection

Phases

Where an engagement sits at any point, in the language your assessor uses.

  • CUI scoping and self assessment
  • SPRS score posted, POA&M opened
  • Remediation
  • Score closed out, CMMC ready

Related reading

Common questions

What is the difference between 800-171 and CMMC?

800-171 is the control set. CMMC is the programme that verifies you implemented it, with an assessment by a certified third party at Level 2. Doing 800-171 properly is doing most of CMMC, which is why we scope them together.

What happens if our SPRS score is negative?

Negative scores are normal at the start and are not a disqualifier on their own. What matters is that a score is posted, that it is honest, and that a POA&M shows how it closes. Posting nothing is worse than posting a low number.

Does Rev 3 change what we already did?

It reorganises and consolidates requirements rather than starting over. Work done against Rev 2 largely carries across, but the mapping needs checking rather than assuming, particularly where requirements were merged or withdrawn.

START HERE

Do not guess how far away you are.

A scored assessment against the NIST SP 800-171 control set gives you your gap, your timeline and your cost. Fixed price from $15,000, two to four weeks, quoted before any work starts. Most clients then continue into a Virtual CISO engagement or managed compliance, but nothing obliges you to.

See what an assessment covers

5.0 out of 5

Across 17 verified client reviews on Clutch.

  • Quality 4.9
  • Schedule 5.0
  • Cost 4.9
  • Willing to refer 5.0

Read the reviews

Start with a scope

Bring the deadline and who is asking for it. Thirty minutes.