The scoring arithmetic
Under the DoD Assessment Methodology you start at 110 and subtract for every requirement you have not implemented. Deductions are weighted by how much the Department believes that requirement matters:
- 5 points: the requirements considered most critical to protecting CUI. These are also the ones that can never be deferred onto a POA&M.
- 3 points: significant contributors to a defensible posture.
- 1 point: important, but lower individual impact.
The floor is -203, and companies genuinely start there. The practical consequence of the weighting is that remediation order matters enormously: closing three 5-point requirements moves your score further than closing fifteen 1-point items, and those same 5-point requirements are the ones you cannot defer. Sequence accordingly.
The fourteen families
110 requirements in total. The distribution is lopsided. Access Control alone accounts for a fifth of them, while Personnel Security has just two.
| Ref | Family | Requirements |
|---|---|---|
| 3.1 | Access Control | 22 |
| 3.2 | Awareness and Training | 3 |
| 3.3 | Audit and Accountability | 9 |
| 3.4 | Configuration Management | 9 |
| 3.5 | Identification and Authentication | 11 |
| 3.6 | Incident Response | 3 |
| 3.7 | Maintenance | 6 |
| 3.8 | Media Protection | 9 |
| 3.9 | Personnel Security | 2 |
| 3.10 | Physical Protection | 6 |
| 3.11 | Risk Assessment | 3 |
| 3.12 | Security Assessment | 4 |
| 3.13 | System and Communications Protection | 16 |
| 3.14 | System and Information Integrity | 7 |
| Total | 110 |
3.1 Access Control (22 requirements)
The largest family by some distance. Who can reach CUI, from where, on what device, with what privileges, and proving that limitation is enforced by the system rather than by a policy nobody reads.
Where points go missing: Remote access, wireless, mobile devices, and external systems are where points get lost. Shared accounts on shop-floor workstations are a perennial finding.
3.2 Awareness and Training (3 requirements)
Users, managers, and administrators must understand the risks and their responsibilities, including insider threat awareness.
Where points go missing: The requirement is not "we bought a training platform". It is records showing role-appropriate training was delivered and completed.
3.3 Audit and Accountability (9 requirements)
Create audit records, protect them, keep clocks synchronised, retain them, and then review and analyse them. That last step is the one everyone skips.
Where points go missing: A SIEM nobody looks at is not a control. Assessors ask who reviewed last week's logs and what they did about it.
3.4 Configuration Management (9 requirements)
Baseline configurations, change control, least functionality, allow-listing, and control over user-installed software.
Where points go missing: Application allow-listing is technically demanding in engineering environments and is frequently deferred until it becomes urgent.
3.5 Identification and Authentication (11 requirements)
Unique identities, multifactor authentication, replay-resistant authentication, password complexity, and protection of authenticators.
Where points go missing: Multifactor authentication is heavily weighted and can never be deferred to a POA&M. Partial deployment is treated as non-implementation.
3.6 Incident Response (3 requirements)
An operational incident-handling capability covering preparation, detection, analysis, containment, recovery, and reporting, and then testing it.
Where points go missing: Few contractors can produce evidence of an actual test. An annual tabletop with an after-action report closes this cheaply.
3.7 Maintenance (6 requirements)
Controlling who performs maintenance, sanitising equipment before off-site repair, and supervising external maintenance personnel.
Where points go missing: Third-party service technicians on machine tools and test equipment are routinely overlooked entirely.
3.8 Media Protection (9 requirements)
Protecting, marking, transporting, sanitising, and controlling removable media containing CUI, including backups.
Where points go missing: USB control and documented sanitisation procedures for disposed drives are common gaps in manufacturing environments.
3.9 Personnel Security (2 requirements)
Screening individuals before granting access to CUI, and protecting CUI during personnel transfers and terminations.
Where points go missing: Offboarding evidence matters. If an account stayed active for three weeks after a departure, that shows up.
3.10 Physical Protection (6 requirements)
Limiting physical access, escorting visitors, maintaining audit logs of physical access, and protecting alternate work sites.
Where points go missing: Remote and hybrid working made alternate work sites a live issue. Home offices handling CUI need addressing explicitly.
3.11 Risk Assessment (3 requirements)
Periodically assessing risk, scanning for vulnerabilities, and remediating what the scans find.
Where points go missing: Scanning is easy to evidence. Demonstrating a remediation programme over time is where contractors fall short.
3.12 Security Assessment (4 requirements)
Periodically assessing your controls, producing and updating a System Security Plan, and running a plan of action to correct deficiencies.
Where points go missing: This family is where the SSP requirement lives. An SSP that does not match reality damages you across every other family.
3.13 System and Communications Protection (16 requirements)
Boundary protection, network segmentation, cryptographic protection of CUI, session management, and controlling collaborative computing devices.
Where points go missing: FIPS-validated cryptography is the trap. "Encrypted" is not sufficient. The module must be validated, and this cannot be deferred.
3.14 System and Information Integrity (7 requirements)
Flaw remediation, malicious code protection, security alert monitoring, and detecting unauthorised use.
Where points go missing: Patch timeliness against a documented standard is what gets tested, not merely whether patching happens.
What the list does not tell you
Reading the requirements gives you a checklist. It does not give you the two things that actually determine whether an assessment goes well.
The first is scope. Every requirement applies to every in-scope asset. Halving your boundary halves the work, and it is the only lever that moves cost by an order of magnitude. That is what our CUI enclave service is built around.
The second is evidence. Implementation without artefacts scores the same as no implementation. Screenshots, configuration exports, log samples, signed policies, training records, ticket histories, captured as you go, organised by objective. Contractors who leave this to the end pay for it several times over.
Next steps
If you have not scored yourself yet, work through the self-assessment walkthrough. If an assessment is coming, read what a C3PAO assessment involves. If you would rather someone just did this, that is our Level 2 programme.