Rev 3 ยท 110 requirements
NIST SP 800-171
800-171 is the control set underneath CMMC Level 2, and the obligation exists independently of it. If a DFARS clause applies, you owe a current self assessment score in SPRS whether or not a CMMC assessment has been scheduled.
What the engagement covers
Contractors and subcontractors handling CUI. Typical timeline: 3 to 9 months depending on the current SPRS gap.
- CUI identification and scoping, which determines everything downstream
- Self assessment against all 110 requirements, scored to the DoD methodology
- SPRS score calculation and posting
- System Security Plan and Plan of Action and Milestones
- Remediation of the requirements that most often fail: MFA, audit logging, FIPS validated encryption, media protection
Phases
Where an engagement sits at any point, in the language your assessor uses.
- CUI scoping and self assessment
- SPRS score posted, POA&M opened
- Remediation
- Score closed out, CMMC ready
Related reading
- Placeholder: NIST SP 800-171 article
Pulled from the legacy archive until this section is migrated.
- Placeholder: NIST SP 800-171 article
Legacy URL preserved.
Common questions
What is the difference between 800-171 and CMMC?
800-171 is the control set. CMMC is the programme that verifies you implemented it, with an assessment by a certified third party at Level 2. Doing 800-171 properly is doing most of CMMC, which is why we scope them together.
What happens if our SPRS score is negative?
Negative scores are normal at the start and are not a disqualifier on their own. What matters is that a score is posted, that it is honest, and that a POA&M shows how it closes. Posting nothing is worse than posting a low number.
Does Rev 3 change what we already did?
It reorganises and consolidates requirements rather than starting over. Work done against Rev 2 largely carries across, but the mapping needs checking rather than assuming, particularly where requirements were merged or withdrawn.
START HERE
Do not guess how far away you are.
A scored assessment against the NIST SP 800-171 control set gives you your gap, your timeline and your cost. Fixed price from $15,000, two to four weeks, quoted before any work starts. Most clients then continue into a Virtual CISO engagement or managed compliance, but nothing obliges you to.
Start with a scope
Bring the deadline and who is asking for it. Thirty minutes.