NIST 800-171 self-assessment: how to score your SPRS and close gaps
A plain-English guide for defense contractors on how the NIST SP 800-171 self-assessment score works, what SPRS actually stores.
Read articleCompliance
A plain-English CMMC guide for small defense contractors covering what Level 2 means in 2026, what actually drives cost, how the rollout works.
If you are a small defense contractor, the short answer is this: CMMC is no longer a future problem. DoD says Phase 1 began on November 10, 2025, and Level 2 now shows up in solicitations. Your real work is scoping CUI correctly, closing the ugly 800-171 gaps, and producing evidence that survives assessment.
Sources: DoD CMMC program, DoD CIO CMMC overview, SPRS NIST SP 800-171 page
The two dates that matter are not vague.
DoD says the final DFARS rule was published on September 10, 2025, took effect on November 10, 2025, and started a three-year rollout of CMMC requirements into contracts. Under DoD's phased schedule, Phase 1 runs roughly one year from November 10, 2025 and focuses primarily on Level 1 and Level 2 self-assessments, while still allowing some Level 2 C3PAO requirements earlier in specific procurements.
That means many small contractors are now in the awkward middle period: the assessment requirement is real, but the exact assessment type still depends on the solicitation.
DoD's current Level 2 model is still tied to the 110 security requirements in NIST SP 800-171 Revision 2. The DoD CIO CMMC page is explicit about that. It also says Level 2 requires either:
In both cases, annual affirmation is still required.
That detail matters because owners often hear "CMMC" and assume every small contractor needs to buy a third-party assessment immediately. That is not the current rule. Some do. Some do not. The contract decides.
If your immediate problem is the SPRS score behind that assessment, a NIST 800-171 self-assessment and SPRS scoring guide is the more tactical next read.
Small contractors usually ask the wrong cost question first.
The expensive part is not just "what does the assessment cost?" The more useful question is "what will it take to make our environment assessable?"
For most small firms, cost shows up in four buckets:
If you have never drawn a hard line around where CUI lives, the first cost is time. Bad scoping creates fake savings early and very expensive remediation later. The smaller you can credibly keep the CUI boundary, the less you have to harden, monitor, document, and defend.
This is where the money usually goes. Common gap areas are MFA coverage, privileged access, endpoint coverage on every in-scope asset, log review, secure configuration, backup testing, and vendor access control. If your current environment already meets the operational bar discussed in what controls cyber insurers require in 2026, your CMMC remediation list is usually shorter, not because the frameworks are the same, but because the hygiene is real.
A small contractor can have decent controls and still fail the "show me" part. The system security plan, policies, diagrams, account-management evidence, training records, restore-test evidence, and POA&M discipline all take labor. This is where many MSP-only environments start to wobble.
Once you are actually ready, then the assessment cost matters. If the solicitation requires a self-assessment, your direct external spend can be lower. If it requires a C3PAO assessment, budget pressure goes up and weak preparation becomes expensive.
A realistic timeline is usually shorter than people fear if the environment is already disciplined, and much longer than they expect if access sprawl and undocumented exceptions have piled up for years.
Use this working model:
Identify which systems actually process, store, or transmit CUI and which systems protect them. If you cannot answer that cleanly, stop there first. Everything else depends on scope.
Run the self-assessment against the current DoD methodology, not against the version of your environment you wish you had. Build the SSP and POA&M from what is true now. Remember that SPRS stores the result; it does not perform the assessment for you.
Fix the control failures that change the outcome of an assessment: identity, admin access, endpoint visibility, logging, configuration management, backups, and documented response. For many firms, this is where managed detection and response and managed ITDR stop being tool purchases and start being evidence-producing controls.
Before you affirm anything, make sure the evidence matches the answer. Underwriters, assessors, and contracting officers all punish the same weakness: saying Yes to a control that only exists on paper.
Yes, but not as a parking lot for unfinished basics.
The DoD CIO page says POA&Ms are permitted for Level 2 under the rule in 32 CFR Part 170, must meet the rule's limits, and must be closed through a closeout assessment within 180 days of the conditional status date. It also points out that some critical requirements cannot be placed on a POA&M.
That means a POA&M is a narrow remediation bridge, not a strategy for entering assessments half-built.
If you want the plain-English order of operations, use this:
Three mistakes cause most schedule slips:
That last one is costly. The SSP is not a brochure. It is the map of what you are claiming exists.
The practical help most small contractors need is not a giant compliance binder. It is tightening the operating environment so the compliance story becomes defensible: endpoint coverage, identity monitoring, access discipline, restore evidence, and plain-English documentation.
That is why the useful adjacent pages here are managed detection and response, managed ITDR, and cyber insurance readiness. Different frameworks, same reality: if the evidence is weak, the answer is weak.
Yes. DoD says Phase 1 began on November 10, 2025 and contracting officers now include CMMC requirements in new solicitations and contracts during the rollout.
No. The DoD CIO guidance says Level 2 may be a self-assessment or a C3PAO assessment depending on what the solicitation requires.
DoD says Level 2 status is valid for three years from the status date, with annual affirmation required in between.
No. SPRS stores NIST SP 800-171 assessment results. The SPRS site says the Basic Assessment itself is not performed in SPRS.
Start with scope and identity. If you do not know where CUI lives or who has admin-level access into that environment, every later answer gets weaker.
Last updated
June 16, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
If your DoD solicitation requires Level 2 because your systems will process, store, or transmit controlled unclassified information, yes. In Phase 1, many solicitations rely on Level 2 self-assessments, while some can still require a C3PAO assessment earlier depending on the procurement.
The biggest cost drivers are scoping mistakes, access-control cleanup, logging and evidence collection, endpoint and identity coverage, and the labor required to write and maintain the SSP and POA&M. The assessment itself is usually not the only or even the largest cost bucket.
Yes, but only in the limited way allowed by the CMMC rule. Level 2 POA&Ms must meet 32 CFR Part 170 requirements and must be closed through a closeout assessment within 180 days of the conditional status date.
DoD says Level 2 self-assessments or C3PAO assessments happen every three years, depending on what the solicitation requires, with annual affirmations in between.
Operationally, Level 2 is built around the 110 security requirements in NIST SP 800-171 Revision 2, plus the CMMC program's assessment, affirmation, status, and remediation rules.
Related reading
A plain-English guide for defense contractors on how the NIST SP 800-171 self-assessment score works, what SPRS actually stores.
Read articleIf you make anything for the defense supply chain — even as a sub-tier subcontractor — CMMC may now gate your contracts.
Read articleWhat the SIG Lite questionnaire is, who sends it, how it differs from SIG Core, and how a small business answers it honestly without a security team.
Read article