ISO/IEC 17020 accredited inspection body · Cleared facility (FCL)
Home / Services / NIST SP 800-171 Compliance

Defense industrial base

NIST SP 800-171 Compliance

Gap assessment against the 110 requirements, defensible SPRS scoring, and the documentation to support both.

DFARS 252.204-7012 · NIST SP 800-171

The obligation is contractual, and it applies whether or not anyone comes to check.

DFARS 252.204-7012 requires contractors whose systems process, store or transmit Covered Defense Information to implement NIST SP 800-171, report a self-assessment score in the Supplier Performance Risk System, and report cyber incidents within 72 hours. The clause flows down to subcontractors.

Most contractors we assess have a score in SPRS. Far fewer have the evidence to defend it. The score was often calculated years ago against an environment that has since changed, by someone reading the requirements optimistically, with no system security plan behind it.

DASATECH assesses the 110 requirements against evidence, corrects a score you cannot currently substantiate, and produces the SSP and POA&M that make the corrected score defensible if it is ever examined.

Score-killers we find repeatedly
  • CUI never formally identified, so the assessment scope is guesswork
  • A flat network where enclaving would have cut scope dramatically
  • MFA deployed to some access paths but not all
  • Encryption in use, but not FIPS-validated cryptography
  • Audit logs generated and never reviewed by anyone
  • A score submitted years ago and never revisited
  • POA&M entries with no owner, no date and no plan
BEFORE: FLAT NETWORK 40 assets in scope Every host must meet all 110 requirements AFTER: CUI ENCLAVE 6 assets in scope Remaining 34 fall outside the boundary CUI ENCLAVE
Scoping decides cost. Confining CUI to an enclave removes most of your estate from assessment.

Asset counts are examples; the pattern is not. Scope reduction here is the single biggest cost decision in the engagement.

How it runs

Engagement sequence

CUI scoping

1 week

We identify where CUI and FCI actually enter, live and leave your environment, and categorize assets accordingly. Scope reduction here saves more than any other step.

Requirement assessment

2–4 weeks

All 110 requirements are assessed against evidence, through configuration review, interviews and artifact examination rather than a questionnaire.

Scoring and reporting

1 week

You receive a defensible score, a findings report and a POA&M sequenced by score impact and remediation effort.

Remediation support

Variable

We advise on implementation, review your work and retest closed items so the score you report is one you can evidence.

Sustainment

Ongoing

Annual review, score maintenance and support when a prime or the government asks you to substantiate your position.

Deliverables

Assessment and documentation deliverables

Every document is produced in the template the receiving party expects, and is written to be read by an assessor rather than filed.

  • SARAssessment report against all 110 requirements, with per-objective results
  • SPRSDefensible score calculation and the supporting worksheet behind it
  • POA&MPlan of Action & Milestones with owners, dates and remediation detail
  • SSPSystem Security Plan scoped to the CUI environment
  • SCOPECUI data flow, asset categorization and enclave boundary documentation
  • POLICYPolicies and procedures written to the 14 requirement families
  • IRPIncident Response Plan meeting DoD 72-hour reporting expectations
  • ISCPInformation System Contingency Plan
  • CMPConfiguration Management Plan and secure baseline documentation
-203-10005588110 TYPICAL START  42 TARGET 110 SPRS SELF-ASSESSMENT SCORE One score. Every unmet requirement subtracts. SUBSTANTIAL GAPS
The SPRS scale runs from −203 to 110. Partial implementation subtracts, weighted by requirement.

The scale and its weighting are real; the marked position is an example. We calculate a score you can evidence, then sequence remediation by point value.

Outcome

Where this leaves you

  • A score you can substantiate if it is ever examined
  • A CUI environment scoped deliberately rather than by default
  • Documentation that matches the environment an assessor would actually see
  • Readiness for a government-led assessment without a scramble
  • A credible answer when a prime asks about your compliance posture

Tell us what the contract requires. We’ll tell you what it takes.

A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.