- NIST 800-171 Assessment: How to Score and Submit to SPRS
- What Is a NIST 800-171 Assessment?
- DoD Assessment Methodology and SPRS Scoring
- NIST 800-171 Assessment Levels: Basic, Medium, and High
- How to Conduct a NIST 800-171 Assessment
- How to Simplify NIST 800-171 Assessments
- Key Takeaways
-
NIST 800-171 Assessment FAQs
- How do I get a NIST SP 800-171 assessment?
- How much does a NIST 800-171 assessment cost?
- What is the score for the NIST 800-171 DoD Assessment Methodology?
- What does it mean to be NIST 800-171 compliant?
- What is the difference between a Basic, Medium, and High Assessment?
- How often is a NIST 800-171 assessment required?
- Where do I submit my NIST 800-171 assessment score?
NIST 800-171 Assessment: How to Score and Submit to SPRS
NIST 800-171 assessments measure how completely an organization has implemented the security requirements to protect Controlled Unclassified Information (CUI) in nonfederal systems. Even though NIST SP 800-171 Revision 3 is the most recent version of the standard, the Department of Defense still uses the requirements in NIST SP 800-171 Revision 2 for Cybersecurity Maturity Model Certification (CMMC).
Most often, defense contractors conduct NIST 800-171 self-assessments to produce an annual score for the Supplier Performance Risk System (SPRS). Here, compliance is self-attested rather than certified by an auditor. DoD contractors and the compliance teams running these assessments must repeat them as their systems and contracts change.
This guide explains how to conduct a NIST 800-171 assessment, score it for SPRS, and submit it for CMMC. It covers the DoD Assessment Methodology, the three assessment levels, and the gap-to-remediation workflow that ties them all together. For more about the broader standard and who it applies to, start with our complete guide to NIST 800-171.
What Is a NIST 800-171 Assessment?
A NIST SP 800-171 assessment evaluates how effectively a nonfederal organization has implemented the security controls that protect Controlled Unclassified Information (CUI). Because covered contractor systems must adhere to NIST SP 800-171 requirements under DFARS 252.204-7012, assessments are a contractual obligation for DoD suppliers.
NIST 800-171 assessments evaluate how completely an organization has implemented the security requirements in NIST SP 800-171 to protect Controlled Unclassified Information. Under the DoD Assessment Methodology, it produces a score from -203 to 110 that contractors submit to the Supplier Performance Risk System (SPRS) to meet DFARS requirements for CMMC.
Usually, the first step of an 800-171 assessment is to draw a boundary around covered systems by scoping CUI and FCI. Rather than a pass or fail audit, however, a NIST 800-171 assessment is a scored review of a covered system. Contractors submit that score to the SPRS, and the DoD uses it to certify their CMMC status. To clarify:
- NIST SP 800-171 is the control set itself.
- A NIST 800-171 assessment is the scored evaluation of how well those controls are implemented.
- CMMC is a separate DoD program that adds a certification on top of the same baseline.
For CMMC, assessments run against the revision the DoD requires, currently NIST 800-171 Revision 2. Even though NIST published Revision 3 in May 2024, DoD Class Deviation 2024-O0013 keeps Revision 2 in force for all DFARS assessments.
Two artifacts anchor NIST 800-171 assessments for CMMC:
- The System Security Plan (SSP) documents how each requirement is met and is the primary artifact an assessment reviews.
- The Plan of Action and Milestones (POA&M) records the requirements that are not yet met and tracks them to closure.
DoD Assessment Methodology and SPRS Scoring
The NIST SP 800-171 DoD Assessment Methodology scores a program on a scale from -203 to 110. A fully implemented program starts at 110. Each requirement the organization has not met subtracts a weighted value, and enough unmet requirements can push the total below zero. The result is a single score that the contractor submits to the Supplier Performance Risk System (SPRS).
Published in June 2020, the DoD methodology assigns each requirement its own deduction weight based on how much the gap affects security, with higher-impact gaps subtracting more from the total. Because the standard covers many requirements, a program with a modest number of gaps can still post a low or negative score.
The SPRS record is what primes and contracting officers filter on:
- A missing record is disqualifying.
- A score below 88 implies more than 22 unmet requirements.
- A negative score can remove a supplier from consideration.
Under DFARS 252.204-7019, a federal contractor and its subcontractors must have a “current” assessment posted in SPRS to be considered for award (no more than three years old). Generally speaking, organizations conduct a new assessment whenever the SSP changes or if they close a gap.
NIST 800-171 Assessment Levels: Basic, Medium, and High
NIST 800-171 assessments come in three levels. Each assessment differs by who performs the review and how much confidence the result carries.
- A Basic Assessment is the contractor’s own self-assessment and carries a “Low” confidence level.
- The Medium and High Assessments are conducted by the Government using NIST SP 800-171A, and they carry “Medium” and “High” confidence.
- A High Assessment adds on-site verification, examination, and demonstration of the controls.
Basic is the only level at which an organization assesses itself. For more on this topic, see our complete guide to NIST 800-171 Basic assessments.
The Defense Contract Management Agency’s (DCMA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) performs the Government Medium and High Assessments. SPRS records four confidence categories for these results: High On-site, High Virtual, Medium, and Basic.
| Level | Who Performs It | Method | Confidence |
| Basic | Self-assessment | NIST SP 800-171 | Low |
| Medium | Government (DCMA DIBCAC) | NIST SP 800-171A | Medium |
| High | Government (DCMA DIBCAC) | NIST SP 800-171A + On-site verification | High |
SPRS Scores: Self-Reported vs. Audited
The difference between a self-reported score and an audited score can be significant. In most cases, self-reported scores sit above what an audit actually produces.
For example, in March 2025, defense contractor MORSECORP agreed to pay $4.6 million to settle a False Claims Act case. The company had self-reported an SPRS score of 104 while non-compliant with 78% of the required controls, and a July 2022 third-party assessment of the same environment produced a score of -142. The two figures differed by well over 200 points — exactly the kind of gap an enforcement review exposes.
DIBCAC’s own assessment data shows the most-failed requirements cluster around a few technical controls. In its 2023 briefing on the top “other than satisfied” requirements, DCMA ranked FIPS-validated cryptography as the single most-failed requirement, with multi-factor authentication (MFA) close behind.
Policy without proof of enforcement is another common reason a score falls apart under review. A credible self-assessment depends on evidence that a control is current and operational. Still, under 32 CFR 170.21, six requirements cannot be placed on a POA&M and must be fully met for a score to hold.
How to Conduct a NIST 800-171 Assessment
A NIST 800-171 assessment runs as a repeatable workflow. It includes a gap assessment against the requirements, a score with the DoD Methodology, submission to SPRS, a POA&M for the remaining gaps, and remediation followed by a rescore.
Across these stages, assessment data often lives in fragmented spreadsheets and email threads. That leaves teams unable to prove what they did when an auditor or a prime asks.
Step 1: Run a Gap Assessment
Evaluate each NIST 800-171 requirement against your current environment and record which controls are met, partially met, or not met. This finding set is the input to every later stage.
Step 2: Score the Results
Apply the DoD Assessment Methodology to convert the gap findings into a number. The score reflects the weighted value of each unmet requirement on a scale of -203 to 110.
Step 3: Submit the Score to SPRS
Post the assessment date, score, scope, SSP name, version, and date, the CAGE code, and the confidence level to the Supplier Performance Risk System. Because SPRS stores the results only, the Basic Assessment itself cannot be performed there.
Step 4: Document Gaps in a POA&M
Record each unmet requirement, its owner, and its target date in a Plan of Action and Milestones.
Step 5: Remediate and Rescore
Close the gaps, gather evidence, recalculate the score, and update SPRS. A gap or self-assessment commonly runs four to eight weeks. But a full end-to-end effort for a mid-size contractor with real gaps can take 12 to 24 months. Most of that time goes to remediation rather than to the scoring itself.
How to Simplify NIST 800-171 Assessments
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
For a NIST 800-171 program spread across systems and business units, fragmented spreadsheets make an assessment hard to defend. Isora GRC replaces them with structured workflows and a connected evidence trail.
Assessment Management
Teams organize, distribute, and track self-assessments across departments, systems, and vendors from one place. Isora maps to the scoring stage of the workflow, with campaign-based targeting, live completion tracking, and real-time scoring metrics. A program owner can see where every requirement stands without chasing email updates.
Questionnaires & Surveys
Collect control evidence from the people who own each control, without asking them to train on the tool first. Isora’s prebuilt library covers frameworks including NIST, CIS, HIPAA, GLBA, and HECVAT. Respondents upload evidence inline, linked to the question it supports.
Risk Management
Isora GRC turns assessment findings into register entries with full lineage from the questionnaire item to the control to the framework. Each finding carries an owner, a remediation plan, and a status the whole team can see.
Reports & Scorecards
Generate reports and scorecards from live assessment data, with drill-down to individual responses and evidence. The output is an audit-ready record produced without manual assembly.
Isora GRC assesses control implementation, collects evidence at scale, supports gap identification and the POA&M, and reports gaps across units. It does not implement controls, guarantee a score, issue a certification, or perform the Government’s Medium or High assessment.
See the GRC Assessment Platform in action →
Key Takeaways
A NIST 800-171 assessment is a scored evaluation that moves through a set order. That order is:
- Pick the level
- Apply the DoD Methodology
- Submit the score to SPRS
- Track gaps in a POA&M
- Remediate
The three levels set who performs the review and how much confidence the result carries, and the DoD Methodology sets the -203 to 110 score behind it.
For most teams, we recommend running the gap or self-assessment first and posting a current SPRS score. A missing or stale record is disqualifying for award. From there, the work is steady. Document the environment, score it, record what is unmet, and close the gaps on a schedule.
See the GRC Assessment Platform in action →
NIST 800-171 Assessment FAQs
How do I get a NIST SP 800-171 assessment?
A NIST SP 800-171 assessment usually starts with a Basic Assessment, which is a self-assessment. The organization reviews its System Security Plan against the requirements using the DoD Assessment Methodology, calculates a score, and submits it to SPRS. Medium and High Assessments are not requested by the contractor — the Government conducts them, through DCMA’s DIBCAC.
How much does a NIST 800-171 assessment cost?
A Basic Assessment does not have a fee because it is a self-assessment. The real cost is internal staff time, and a gap or self-assessment typically runs four to eight weeks. Costs rise with remediating unmet controls, where a full end-to-end effort for a mid-size contractor can take 12 to 24 months. Government-conducted Medium and High Assessments carry no charge to the contractor. There is no fixed published price.
What is the score for the NIST 800-171 DoD Assessment Methodology?
The DoD Assessment Methodology scores an organization on a scale from -203 to 110. A fully implemented program starts at 110, and each unmet requirement subtracts a weighted value, which can push the total negative. The score, rather than a pass or fail grade, is what the contractor submits to SPRS.
What does it mean to be NIST 800-171 compliant?
Being NIST 800-171 compliant means implementing the security requirements in NIST SP 800-171, documenting that implementation in a System Security Plan, and tracking any gaps in a Plan of Action and Milestones. Compliance is self-attested through an SPRS score under DFARS 252.204-7020, not a certification. Six specific controls cannot be placed on a POA&M and must be fully met.
What is the difference between a Basic, Medium, and High Assessment?
A Basic Assessment is the contractor’s own self-assessment and carries a “Low” confidence level. Medium and High Assessments are conducted by the Government using NIST SP 800-171A and carry “Medium” or “High” confidence, with the High Assessment adding on-site verification and demonstration of controls. DCMA’s DIBCAC performs the Government assessments.
How often is a NIST 800-171 assessment required?
A NIST SP 800-171 DoD Assessment must be current, meaning not more than three years old, for a contractor to remain eligible for award under DFARS 252.204-7019. Organizations generally reassess when the System Security Plan changes materially or when a POA&M item is closed.
Where do I submit my NIST 800-171 assessment score?
Assessment scores are submitted to the Supplier Performance Risk System (SPRS). SPRS stores the assessment date, score, scope, SSP name, version, and date, the CAGE code, and the confidence level. The Basic Assessment itself cannot be performed in SPRS — SPRS only stores the results.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.