NIST 800-171 Assessment: Types, Scoring, and How to Prepare
Table of Contents
- TL;DR
- What Is a NIST 800-171 Assessment?
- Why the Assessment Exists: DFARS and CMMC
- 3 Types of NIST 800-171 Security Assessment
- The DoD Assessment Methodology and Scoring
- The 14 Control Families That Protect Controlled Unclassified Information
- Assessing Security Requirements: How to Run Your Self-Assessment
- Submitting Your Score to the Supplier Performance Risk System
- Rev 2 vs Rev 3: Which Version Applies to Your Assessment
- Simplify NIST 800-171 Assessments With MotherBear
- FAQs About NIST 800-171 Assessment
If your company handles sensitive government data under a defense contract, a NIST 800-171 assessment is how you prove your security measures actually exist.
The concept is simple. The standard lists 110 security requirements. The assessment checks how many your organization has implemented, and produces a score that the Department of Defense (DoD) can see.
The details are where contractors get lost. There are three assessment types with different levels of rigor, a scoring system that can go deep into negative numbers, two versions of the standard in circulation, and a certification program built on top of it, currently in the middle of a program review.
This guide walks through all of it in plain terms: what a NIST 800-171 assessment is, who conducts each type, how the scoring works, and how to run and submit your own without tripping over the fine print.
TL;DR
- A NIST 800-171 assessment measures how well an organization has implemented the 110 security requirements for protecting Controlled Unclassified Information (CUI) on its systems.
- There are three types. The Basic Assessment is a self-assessment, while Medium and High Assessments are conducted by the government. Most contractors only ever deal with the Basic.
- Scoring starts at 110 points and subtracts weighted deductions for every requirement not in place. The result goes into the Supplier Performance Risk System (SPRS), where DoD contracting officials can see it.
- The assessment feeds directly into CMMC. With the program's Phase 2 suspended as of July 2026, self-assessed scores are currently the main way contractors demonstrate compliance.
- MotherBear keeps your control status, evidence, and documentation in one workspace, so your score reflects reality and holds up when someone checks.
What Is a NIST 800-171 Assessment?
NIST 800-171 is a standard published by the National Institute of Standards and Technology (NIST). Its full title explains its job: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.
In plain language: when a private company's systems hold sensitive federal information, this standard defines the 110 security requirements those systems must meet.
A NIST 800-171 assessment measures how many of those requirements you've actually implemented. It reviews your System Security Plan (SSP), checks the contractor's implementation of each security control, and produces a score.
The assessment doesn't add requirements or change them. It only verifies what's in place, and turns that into a number federal agencies can use to judge risk before awarding work.
Why the Assessment Exists: DFARS and CMMC
The requirement chain has three links, and it helps to see them in order:
- DFARS 252.204-7012: This Defense Federal Acquisition Regulation Supplement (DFARS) clause sits in defense contracts involving CUI. It obligates contractors to implement the cybersecurity requirements in NIST 800-171. For years, that obligation ran on trust, since nothing checked whether contractors had actually done the work.
- The DoD Assessment Methodology: The assessment closed that gap. Since late 2020, DFARS clauses have required contractors to assess their own implementation, score it, and post the result to SPRS before contract award.
- The Cybersecurity Maturity Model Certification (CMMC): CMMC adds verification on top. Rather than introducing new security requirements, CMMC checks that the ones from NIST 800-171 are genuinely met, through self-assessments at some levels and independent assessments at others.
The third link is currently in flux. In July 2026, the DoD suspended CMMC Phase 2, which was expected to introduce mandatory third-party assessments for many contracts, pending a program review.
Until that review concludes, self-assessed scores in SPRS carry the compliance weight, and the CMMC self-attestation behind each score remains a binding legal declaration.
3 Types of NIST 800-171 Security Assessment
The DoD Assessment Methodology defines three assessment types. They measure the same requirements but differ in who conducts them and how much confidence the result carries.
1. Basic Assessment: The Self-Assessment You Control
The Basic Assessment is a self-assessment. Your organization reviews the System Security Plans covering each covered contractor information system, scores its implementation against the methodology, and submits the result.
Because the score is self-generated, it carries a confidence level of "Low." That's a label about who did the checking, not a judgment on your security.
This is the assessment nearly every defense contractor performs. If a contract requires a current score in SPRS, the Basic Assessment is how you produce one.
2. Medium Assessment: A Government Review
A Medium Assessment is conducted by government personnel. They review your submitted materials and discuss them with you to clarify how requirements are implemented, without visiting your environment.
The result carries a "Medium" confidence level and is posted by the government, not by you. Contractors don't request these; the DoD selects based on program criticality and risk.
3. High Assessment: Full Government Verification
The High Assessment is the most rigorous. Government assessors verify, examine, and demonstrate your implementation on-site or virtually, working from the official assessment procedures for the standard.
The resulting score replaces your self-assessed one in SPRS at a "High" confidence level. Like the Medium, it happens at the government's initiative, typically for contractors supporting higher-risk programs.
The DoD Assessment Methodology and Scoring
The scoring rules come from one document: the NIST 800-171 DoD Assessment Methodology. It's short, public, and worth reading once, because your score is only as defensible as your understanding of how it's calculated.
The mechanics work like this:
- Start at 110: Every organization begins with a perfect score, one point for each security requirement.
- Subtract for gaps: Each requirement not yet implemented deducts a weighted value of 1, 3, or 5 points. The weights reflect how critical a requirement is to protecting CUI, so basic protections cost more when missing.
- Expect no partial credit: A requirement is implemented or it isn't. The methodology builds in partial scoring for only a few cases, such as multi-factor authentication.
- Know the floor: With every requirement missing, the score bottoms out at -203. A negative score isn't a failure grade; it's a precise statement of how much work remains.
Two things the score is not. It isn't a pass/fail test, since no minimum score is required to submit. It also isn't permanent, since you can reassess and update as you close gaps, which makes the score a useful way to evaluate the effectiveness of your remediation over time.
What matters is accuracy. The score you post is a representation to a government entity, and inflating it creates the same False Claims Act exposure as any other false compliance claim.
The 14 Control Families That Protect Controlled Unclassified Information
The 110 CUI security requirements are organized into 14 families, each covering one area of protection. Together, they describe what a security program that can protect CUI actually looks like.
|
Family |
What It Covers |
|
Access Control |
Who can reach systems and data, and under what conditions |
|
Awareness and Training |
Making sure employees understand security risks and their duties |
|
Audit and Accountability |
Keeping records of system activity and tying actions to users |
|
Configuration Management |
Controlling how systems are set up and how changes happen |
|
Identification and Authentication |
Verifying that users and devices are who they claim to be |
|
Incident Response |
Detecting, reporting, and responding to security incidents |
|
Maintenance |
Performing system maintenance without introducing new risk |
|
Media Protection |
Handling, storing, and destroying media that holds CUI |
|
Personnel Security |
Screening people before access and acting when they leave |
|
Physical Protection |
Limiting physical access to systems, equipment, and facilities |
|
Risk Assessment |
Identifying vulnerabilities and weighing threats to operations |
|
Security Assessment |
Reviewing whether controls work and fixing what doesn't |
|
System and Communications Protection |
Securing data as it moves between and within systems |
|
System and Information Integrity |
Spotting flaws, malicious code, and unauthorized changes |
Your assessment walks every applicable requirement in every family. That's why scoping is crucial: a family like Media Protection may look small until you count every laptop, drive, and backup that touches CUI.
The families also explain why an assessment can't be rushed. Requirements span technology, people, and process, so no single team can answer for all 14 alone.
Assessing Security Requirements: How to Run Your Self-Assessment
The self-assessment doesn't need to be reinvented from scratch. Two official documents do the heavy lifting: NIST 800-171A, which provides assessment procedures for every requirement, and the DoD Assessment Methodology, which turns your findings into the score.
A workable process looks like this:
- Establish your scope: Identify every system, location, and person that touches CUI. The assessment covers all of them, and nothing outside them.
- Assess each requirement: NIST 800-171A gives three methods: examine your documentation, interview the people responsible, and test the controls. Use all three where it matters, since a policy nobody follows fails two of them.
- Document as you go: Record how each requirement is met in your SSP. For gaps you've identified, address them now or capture them in a Plan of Action and Milestones (POA&M) with a completion date.
- Score and recheck: Apply the methodology's weighted values to every unimplemented requirement, then have someone who didn't run the assessment sanity-check the math before it goes anywhere official.
The most common failure isn't a bad process. It's treating the assessment as a one-time event, letting the SSP drift from reality, and rediscovering the gap three years later. Maintaining compliance between assessments is cheaper than rebuilding it each cycle.
Submitting Your Score to the Supplier Performance Risk System
SPRS is the DoD's database for supplier and product performance information, and it's where your assessment result lives. Contracting officials check it before award, so an assessment that never reaches SPRS might as well not have happened.
The submission is compact. You'll enter the score, the assessment date, the scope, the SSP name, and the date you expect to reach 110 if a POA&M is open. Access runs through a Procurement Integrated Enterprise Environment (PIEE) account with the SPRS Cyber Vendor role.
The government may follow up for additional information or clarification, particularly if a Medium or High Assessment comes into play later. Keep the working papers from your self-assessment; they're the answer to most questions before they're asked.
Before your score becomes official, the Affirming Official completes the CMMC self-attestation that turns a database entry into a legal declaration.
Rev 2 vs Rev 3: Which Version Applies to Your Assessment
NIST publishes updates to its standards, and 800-171 currently exists in two versions. Revision 3, released in May 2024, restructured the requirements. Revision 2 is the version defense contracts still run on.
That's not an oversight. The DoD issued a class deviation in 2024 directing contractors under DFARS 252.204-7012 to comply with Revision 2 until further notice, so assessments, scores, and CMMC level requirements all point at Rev 2 today.
The practical guidance: assess against Rev 2, and don't rebuild your program around Rev 3 ahead of an official transition. The DoD is expected to give notice before any switch, though no timeline has been announced.
If a prime or a tool vendor tells you Rev 3 compliance is required right now, ask them for the contract clause that specifically says so. For DoD work, it doesn't exist yet.
Simplify NIST 800-171 Assessments With MotherBear

An assessment is only as smooth as the state of your documentation when it starts. That's the part MotherBear fixes.
MotherBear gives contractors and consultants one workspace where control status, evidence, and the SSP stay current together, so the assessment becomes a readout instead of an archaeology project.
Book a demo and see how MotherBear makes maintaining compliance between assessments manageable.
FAQs About NIST 800-171 Assessment
What is a NIST 800-171 assessment?
It's an evaluation of how well an organization has implemented the 110 security requirements for protecting CUI on its systems. The assessment reviews the System Security Plan, checks each security control, and produces a weighted score that gets posted to SPRS, where DoD officials can view it.
How do I get a NIST 800-171 assessment?
For the Basic Assessment, you conduct it yourself: review your SSP, apply the DoD Assessment Methodology, and submit the score through SPRS. Medium and High Assessments are conducted by the government at its own initiative, so contractors don't request those. Many organizations bring in a consultant for a readiness review before self-assessing.
What is the passing score for NIST 800-171?
There isn't one for the Basic Assessment, since DFARS requires a current score on file, not a minimum number. The implementation target is 110, meaning every requirement in place. Separate thresholds exist within CMMC: Level 2 status has its own scoring rules, including conditional status for high scores with an approved POA&M.
Want More Confidence in Your Self-Assessment?
Book a demo of MotherBear to see how you can simplify self-assessments