If you hold a DoD contract with DFARS 252.204-7012 in it, you owe the government a NIST SP 800-171 score, and you post it yourself. The third-party CMMC assessment requirements were suspended in July 2026, but the self-assessment, the SPRS score and the 72-hour incident reporting duty were not. A score that cannot be backed by evidence is now the risk, not the absence of a certificate.

This assessment scores all 110 requirements of NIST SP 800-171 Revision 2, plus the DFARS obligations around them, and asks what you could evidence today. It is free, it saves as you go, and you can stop and come back to it.

Premium report

See what the premium NIST SP 800-171 gap assessment report looks like

A worked sample for a fictional organization: readiness by area, every open gap in a remediation plan, an AI-assisted analysis with priorities and a 30/60/90-day roadmap, plus the live Excel workbook.

What is a NIST SP 800-171 gap assessment?

A NIST SP 800-171 gap assessment compares how you protect controlled unclassified information (CUI) with the 110 security requirements in the standard, family by family, and records what is missing. It is the working step behind the Basic self-assessment that DFARS 252.204-7019 and 7020 require you to post in the Supplier Performance Risk System (SPRS).

It uses Revision 2, because that is what your contract requires. NIST published Revision 3 in May 2024, with 97 requirements in 17 families, but a DoD class deviation keeps DFARS 252.204-7012 tied to Revision 2, and CMMC Level 2 is built on it too.

What this assessment covers

123 items: the 110 requirements, five scoping questions and eight DFARS obligations.

AreaItemsWhat it asks about
Scope and programme5CUI identification, the system boundary, ownership, cloud providers and FedRAMP Moderate equivalency, subcontractor flow-down
3.1 Access Control22Authorised access, least privilege, remote and wireless access, mobile devices, CUI flow
3.2 Awareness and Training3Security awareness, role-based training, insider threat
3.3 Audit and Accountability9Audit logs, review, correlation, protection and time synchronisation
3.4 Configuration Management9Baselines, inventory, change control, least functionality, software restrictions
3.5 Identification and Authentication11Identifiers, multifactor authentication, replay resistance, password rules
3.6 Incident Response3Incident handling, tracking and reporting, testing
3.7 Maintenance6Controlled maintenance, tools, media, remote maintenance, supervision
3.8 Media Protection9Marking, access, sanitisation, transport, removable media, backups
3.9 Personnel Security2Screening, and protecting CUI when staff leave or move
3.10 Physical Protection6Physical access, visitors, logs, access devices, alternate work sites
3.11 Risk Assessment3Risk assessment, vulnerability scanning, remediation
3.12 Security Assessment4Periodic assessment, plans of action, monitoring, the system security plan
3.13 System and Communications Protection16Boundary protection, segmentation, encryption in transit and at rest, FIPS-validated cryptography
3.14 System and Information Integrity7Flaw remediation, malicious code protection, alerts, monitoring
DFARS obligations and SPRS8The SPRS score and how it is calculated, plans of action, 72-hour reporting, image preservation, exceptions, programme changes

How the SPRS score works

The DoD Assessment Methodology starts you at 110 and deducts 5, 3 or 1 point for each requirement that is not met, depending on its weight. The lowest possible score is -203. Two requirements earn partial credit: multifactor authentication (3.5.3) and FIPS-validated cryptography (3.13.11). If you have no system security plan (3.12.4), there is no score at all.

This assessment uses its own evidence-based scale, shown below, so you can see how far each requirement has got. Anything short of “implemented and evidenced” should be treated as not met when you calculate the SPRS score.

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the boundary, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records an assessor could sample
Not applicable—A justified exclusion, removed from the score

The requirements that fail most often

  • 3.12.4, the system security plan, missing or describing a system that no longer exists. No SSP means no score.
  • 3.5.3, multifactor authentication, in place for remote access but not for local access to privileged and network accounts.
  • 3.13.11, FIPS-validated cryptography, where encryption is used but the modules are not validated.
  • 3.3.1 and 3.3.5, audit logging and review, with logs collected but nobody reviewing them.
  • Cloud services holding CUI without FedRAMP Moderate authorisation or evidenced equivalency.

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every requirement with your status and notes, the score broken down by family, a prioritised gap list, an AI-assisted analysis with a 30/60/90-day roadmap, and the NIST SP 800-171 Toolkit documents that close each gap, as a PDF and a working Excel file.

How long does it take?

About 50 minutes if you know your CUI environment. Answers save as you go, so IT, facilities and HR can each answer their own families.

Frequently asked questions

Is this assessment really free?

Yes. Every requirement, your family breakdown and your overall score cost nothing. The $39 full report is optional.

How is this different from the CMMC gap assessment?

Both score the same 110 requirements. The CMMC gap assessment adds the CMMC-specific questions on assessment scope, POA&M eligibility and affirmation. This one adds the DFARS duties every contractor with 252.204-7012 owes today, whether or not a CMMC level is in the contract, and maps to the NIST SP 800-171 Toolkit.

Does it cover Revision 3?

No. It is built on Revision 2, which DFARS 252.204-7012 and CMMC Level 2 require. If a contract specifically calls for Revision 3, check the three families Revision 3 added: planning, system and services acquisition, and supply chain risk management.

Does the CMMC suspension mean we do not need this?

No. The July 2026 suspension removed the third-party assessment requirements. The self-assessment, the score in SPRS and the incident reporting duty still apply, and false self-assessments have led to False Claims Act settlements.

Is a high score the same as being compliant?

No. It is a structured self-assessment, not an assessment under the DoD methodology or a certification. It tells you where the documented gaps are.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.