NIST 800-171A is the document an assessor actually works from. SP 800-171 states the security requirements for protecting Controlled Unclassified Information; SP 800-171A decomposes each one into assessment objectives — the determination statements an assessor must find satisfied — and lists the methods and objects used to reach each finding.
A requirement is met when every objective under it is met, which is why a contractor that has read only 800-171 is surprised by an assessment: the 110 Revision 2 requirements assess as 320 objectives, and the 97 Revision 3 requirements decompose into several hundred determination statements, 88 of them about the parameter values the organization has to define. This guide explains how an 800-171A procedure is built, how the objectives are scored under the DoD methodology and CMMC, what changed in the Revision 3 companion, and how to use the objectives as the checklist your own self-assessment is written against.

What NIST 800-171A is
SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information, is the companion to SP 800-171. The current edition is Revision 3, published May 2024 alongside SP 800-171 Rev 3; it supersedes the June 2018 edition, which is the one that pairs with Revision 2. The procedures are “flexible and can be customized to the needs of organizations and assessors” — NIST’s phrase — and they are used three ways: by the organization for its own self-assessment, by a third party such as a C3PAO, and by a government assessor such as DCMA’s DIBCAC.
Which edition applies follows which revision of 800-171 you owe: DoD’s DFARS and CMMC obligations remain on Revision 2, so the 2018 edition and its 320 objectives are what the DoD Assessment Methodology and CMMC Level 2 score. Our guide to NIST 800-171 Rev 3 vs Rev 2 covers the revision question.
The anatomy of an NIST 800-171A assessment procedure
| Element | What it is | Example (Rev 3, requirement 03.01.06 Least Privilege – Privileged Accounts) |
|---|---|---|
| Assessment objective | One or more determination statements, each traceable to a part of the requirement | A.03.01.06.a: privileged accounts on the system are restricted to the defined personnel or roles; A.03.01.06.b: users with privileged accounts use non-privileged accounts for non-security functions |
| ODP determination statement | Where the requirement contains an organization-defined parameter, the objective begins by determining that the parameter is defined | A.03.01.06.ODP[01]: personnel or roles to which privileged accounts are to be restricted are defined |
| Assessment methods | Examine, interview, test — with depth and coverage attributes that set rigor and scope | Examine: access control policy, list of privileged accounts, audit records; Interview: personnel with account management responsibilities; Test: mechanisms implementing least privilege |
| Assessment objects | Specifications (documents), mechanisms (hardware/software safeguards), activities (actions people perform), individuals | The SSP and policy are specifications; the directory’s privileged group is a mechanism; the quarterly review is an activity |
| Finding | Satisfied, or other than satisfied | Other than satisfied also covers the case where the assessor could not obtain enough evidence to decide |
Two features decide most outcomes. First, the determination statements are granular: Revision 2’s 3.1.1 (limit system access to authorized users, processes and devices) has six objectives, [a] to [f], and all six must be satisfied. Second, a finding of other than satisfied is not only a control failure — it is the result whenever the evidence was not produced. An organization that has implemented a control but cannot show the assessor the mechanism, the record and the person who operates it will receive the same finding as one that never implemented it.
How the NIST 800-171A objectives are scored
| Regime | Unit scored | Rule |
|---|---|---|
| DoD Assessment Methodology (SPRS) | Requirement (110) | Start at 110; subtract 1, 3 or 5 points per requirement not fully implemented; floor −203. A requirement is implemented only if all its 800-171A objectives are met |
| CMMC Level 2 (32 CFR Part 170) | Requirement, assessed by objective | Each requirement is MET, NOT MET or N/A; MET requires every applicable objective satisfied. Conditional status allows a POA&M for a restricted set of not-met requirements if the score is at least 88 of 110 |
| Self-assessment for a civilian contract | As the agreement states | Usually the 800-171A objectives for the revision the agreement names |
The consequence is that the objectives, not the requirements, are the real checklist. A self-assessment that marks 3.1.1 implemented because access is limited to authorized users, without checking that processes acting on behalf of users and connecting devices are identified and limited, scores a requirement that a C3PAO would not. Our guide to the SPRS score covers the point values; the C3PAO guide covers who assesses and how.
What changed in NIST 800-171A Revision 3
- Procedures follow the new requirements. 97 procedures replace 110, mirroring SP 800-171 Rev 3’s consolidation and its three new families.
- ODP statements come first. Every requirement with organization-defined parameters begins its objective with a determination that each parameter is defined — 88 such statements across 50 requirements. If the value is not set, the objective fails before the control is examined.
- Syntax aligned to SP 800-53A. Identifiers are A.03.01.06.a, sub-statements are decomposed with square brackets (A.03.01.12.a[01]), and each procedure carries a references section pointing to the source procedures in SP 800-53A.
- Depth and coverage made explicit. The methods carry the SP 800-53A depth and coverage attributes, so the assessment plan states how rigorous the examine, interview and test activities will be.
- Guidance on conducting assessments added. Chapter 3 covers preparing, developing the plan, conducting and reporting — including the instruction to optimize procedures to reduce duplication.
Using NIST 800-171A as your own checklist
- Build the self-assessment at objective level. One row per determination statement, not per requirement — 320 rows for Revision 2. Record the finding, the evidence and the person who can speak to it.
- Map evidence to the three methods. For each objective, name the specification the assessor will examine, the individual they will interview and the mechanism or activity they will test. A row with only a policy against it is a row that fails the test method.
- Set and record the ODPs (Revision 3). Session timeouts, lockout thresholds, review frequencies, retention periods — defined in policy and cited in the SSP, so the first determination statement of each parameterized requirement is satisfied on paper before the assessor arrives.
- Score honestly against all objectives. A requirement with one unsatisfied objective is not implemented. Enter it in the POA&M with a date rather than in the SSP as done; the SPRS score and the CMMC status both depend on it.
- Rehearse the interviews. The individuals named as assessment objects must be able to describe the activity in their own words. An administrator who cannot explain the account review process fails an objective the documentation passes.
- Keep the assessment plan. 800-171A Rev 3 expects a plan that tailors methods, objects, depth and coverage; the same plan, kept and updated, is the evidence for the annual affirmation and the next assessment.
Frequently asked questions
What is the difference between NIST 800-171 and 800-171A?
800-171 states the security requirements; 800-171A states how to assess them — the objectives an assessor must find satisfied, and the examine, interview and test methods and objects used to reach each finding. A requirement is met only when all its objectives are met.
How many assessment objectives are there?
320 in the 2018 edition that pairs with Revision 2 — the edition the DoD Assessment Methodology and CMMC Level 2 use. The Revision 3 companion decomposes the 97 requirements into several hundred determination statements, including 88 that check organization-defined parameter values are set.
Which edition should I use?
The one matching the SP 800-171 revision you owe. DoD contractors under DFARS 252.204-7012 and CMMC use the 2018 edition with Revision 2; agreements that name Revision 3 use 800-171A Revision 3.
Is a self-assessment allowed to use 800-171A?
It is expected to. The DoD methodology and CMMC self-assessments score against the objectives, and NIST wrote the procedures to be used by organizations, third parties and government assessors alike.
What does ‘other than satisfied’ mean?
That the assessor either found the objective not met or could not obtain enough evidence to decide. Undocumented implementation produces the same finding as no implementation.
Where this leaves you
Read NIST 800-171A before the assessor does: build the self-assessment one determination statement at a time, attach a specification, an individual and a mechanism to each, set the parameter values if Revision 3 applies, and score a requirement as implemented only when every objective under it is. The requirements are the promise; the objectives are the test.
References
- NIST SP 800-171A Rev. 3 — Assessing Security Requirements for Controlled Unclassified Information — May 2024; supersedes the June 2018 edition. Section 2 on procedure structure and findings; Chapter 3 on conducting assessments.
- NIST SP 800-171A (2018) — the edition paired with Revision 2 — The 320 objectives scored by the DoD Assessment Methodology and CMMC Level 2.
- NIST FAQ: SP 800-171r3 and SP 800-171Ar3 — The changes between 800-171A and 800-171A Rev 3.
More on NIST SP 800-171
- NIST 800-171A — you are here
- NIST SP 800-171: the complete guide
- NIST 800-171 Rev 3 vs Rev 2
- Your SPRS score explained
- Choosing a C3PAO
- CMMC scoping: what is in the assessment
The objective-level self-assessment workbook, the System Security Plan, the POA&M and the evidence register keyed to the 110 Revision 2 requirements are in the NIST SP 800-171 CUI Protection Toolkit, or start with the free templates.