A NIST 800-171 self-assessment is what stands behind the score every DoD contractor with DFARS 252.204-7012 in its contracts posts in the Supplier Performance Risk System (SPRS). In July 2026 the Department suspended the CMMC requirements for third-party assessments, and a class deviation in September stripped them from contracts. The self-assessment did not go away. If anything, it now carries more weight, because for most contractors it is the only assessment there is, and an inaccurate one is a False Claims Act risk.
This guide walks through how to run a NIST 800-171 self-assessment that will stand up, step by step: which revision to use, how to scope it, how the score is calculated, and what to post. For how the scoring rules work in detail, see our companion article on the SPRS score.
Which revision does a NIST 800-171 self-assessment use?
Revision 2. NIST published Revision 3 on 14 May 2024, with 97 requirements in 17 families, and now lists Revision 2 as withdrawn. But DoD Class Deviation 2024-O0013 keeps DFARS 252.204-7012 tied to Revision 2, and the CMMC program rule at 32 CFR Part 170 is built on it too. Your contract, not the NIST website, decides the baseline. Our article on which NIST SP 800-171 revision your contract names explains how to check.
| Revision 2 | Revision 3 | |
|---|---|---|
| Published | February 2020, updated January 2021 | May 2024 |
| Requirements | 110 in 14 families | 97 in 17 families |
| Required by DFARS 252.204-7012 today | Yes, under the class deviation | No |
| Basis of CMMC Level 2 | Yes | No |
Step 1: Find your CUI and draw the boundary
A NIST 800-171 self-assessment covers the systems that process, store or transmit controlled unclassified information, and the systems that protect them. Start by listing the CUI you receive and create, where it lives and how it moves. Then draw the boundary as tightly as you can. A dedicated enclave means the 110 requirements apply to a few dozen assets; a flat network means they apply to everything on it.
Check your cloud services at the same time. DFARS 252.204-7012 requires any cloud service that stores or processes covered defense information to meet the FedRAMP Moderate baseline or its equivalent, and the DoD CIO’s December 2023 memo sets a high bar for equivalency.
Step 2: Write or refresh the system security plan
Requirement 3.12.4 asks for a system security plan describing the boundary, the environment and how each requirement is met. It is also the one document without which there is no score at all. Write the SSP before you assess, not after, and assess against what it says. Our guide to the NIST 800-171 system security plan covers what goes in it.
Step 3: Assess each requirement against evidence
Work family by family, using the assessment objectives in NIST SP 800-171A. For each requirement, decide whether it is fully met, and record the evidence: a configuration, a log, a record, a policy that people follow. “Partly met” is not met for scoring purposes, apart from the two partial-credit cases in step 4.
The requirements that most often fail a NIST 800-171 self-assessment are:
- 3.5.3, multifactor authentication, in place for remote access but not for local access to privileged accounts.
- 3.13.11, FIPS-validated cryptography, where encryption is used but the modules are not validated.
- 3.3.1 and 3.3.5, audit logging and review, with logs collected but nobody reviewing them.
- 3.11.2, vulnerability scanning, run occasionally rather than on a schedule.
- 3.12.4, the SSP, describing a system that has since changed.
Step 4: Calculate the score
The DoD Assessment Methodology starts at 110 and deducts the weight of each requirement that is not met: 5, 3 or 1 point. The lowest possible score is -203. Only two requirements give partial credit: 3.5.3 multifactor authentication and 3.13.11 FIPS-validated cryptography, where using encryption that is not FIPS-validated costs 3 points rather than 5.
| Item | Rule |
|---|---|
| Starting score | 110 |
| Deductions | 5, 3 or 1 point per requirement not met |
| Lowest possible score | -203 |
| Partial credit | 3.5.3 and 3.13.11 only |
| No SSP | No score can be calculated |
Step 5: Plan the gaps and post the result
Every requirement that is not met needs a plan of action with milestones under 3.12.2: what will be done, by whom and by when. Then post the summary in SPRS: the score, the date of the assessment, the scope and the SSP it relates to. DFARS 252.204-7019 and 7020 require an assessment no more than three years old before award, and a material change to the system is a reason to reassess sooner.
Whoever signs off the score should be able to explain it. Primes increasingly ask for the evidence behind a score, not just the score.
Step 6: Keep the DFARS duties around it working
A NIST 800-171 self-assessment covers the 110 requirements, but DFARS 252.204-7012 adds duties that sit outside them:
- report cyber incidents affecting covered defense information to the DoD within 72 hours of discovery, through the DIBNet portal, which needs a medium assurance certificate;
- preserve images of affected systems and relevant monitoring data for at least 90 days;
- submit any malicious software found to the DoD Cyber Crime Center;
- flow the clause down to subcontractors whose work involves covered defense information.
The requirement text itself is on the NIST page for SP 800-171 Revision 2.
Common mistakes in a NIST 800-171 self-assessment
Most problems with a NIST 800-171 self-assessment are not about the technical controls. They are about how the assessment was done.
- Scoring the policy, not the practice. A requirement is met when it operates, and you can show it. A policy that says logs are reviewed weekly is not evidence that they are.
- Assessing the wrong boundary. CUI found later on a laptop or a shared drive outside the enclave puts every requirement on that asset in scope.
- Counting plans as progress. A requirement with a plan of action is still not met for scoring. The plan matters, but it does not earn points.
- Forgetting the service providers. A managed service provider with administrative access to the enclave is inside the boundary, and so are its tools.
- Posting and forgetting. The score in SPRS describes the system on the day it was assessed. Change the system and the score can quietly become untrue.
How long a NIST 800-171 self-assessment takes
For a small contractor with a defined enclave and an up-to-date SSP, the assessment itself takes a few days of work spread over two or three weeks, most of it spent gathering evidence. Without an SSP, or with CUI spread across the business, expect the scoping and documentation to take longer than the assessment. The fixes then take as long as the gaps demand, and multifactor authentication, FIPS-validated encryption and log review are usually the longest.
Plan for the people as well as the systems. IT can answer most of the technical families, but physical protection, personnel security, training and incident response need facilities, HR and management. A NIST 800-171 self-assessment run by one person in isolation tends to overstate the result, because nobody challenges the answers.
Run a free NIST 800-171 self-assessment
The free NIST SP 800-171 gap assessment works through all 110 requirements family by family, plus the scoping questions and eight DFARS obligations above, and saves as you go. It uses an evidence-based scale rather than the SPRS deductions, so treat anything short of “implemented and evidenced” as not met when you calculate your SPRS score. The optional full report adds a prioritized gap list and a 30/60/90-day plan.
If the gaps are documents, the NIST SP 800-171 Toolkit has 33 templates built on Revision 2, including the SSP, the POA&M, all 14 family policies and the SP 800-171A assessment plan and report.
Frequently asked questions
Is a NIST 800-171 self-assessment still required after the CMMC suspension?
Yes. The July 2026 suspension and the September class deviation removed the CMMC requirements for third-party assessments. DFARS 252.204-7012, 7019 and 7020 still apply, including the self-assessment and the score in SPRS.
How often do we need to repeat it?
The score in SPRS must be no more than three years old at award. Reassess sooner after a significant change to the system or the boundary.
Can we get credit for a requirement that is partly met?
Only for 3.5.3 multifactor authentication and 3.13.11 FIPS-validated cryptography. Everything else is met or not met.
Do subcontractors need their own NIST 800-171 self-assessment?
Yes, if their work involves covered defense information. DFARS 252.204-7012 flows down to them, and 7019 and 7020 require each contractor to have its own current assessment in SPRS. Your score does not cover their systems, so ask for theirs before you share CUI.
Can we use our CMMC preparation for this?
Yes. CMMC Level 2 is built on the same 110 Revision 2 requirements, so evidence gathered for CMMC serves the self-assessment, and the reverse. The CMMC-specific questions on scoping and plans of action sit on top.
What happens if our score is wrong?
An inflated self-assessment can lead to False Claims Act liability, and the Department of Justice has settled cases over inaccurate cybersecurity representations. Keep the evidence behind every requirement you mark as met.