Skip to content

Documentation and scoring

NIST SP 800-171 Compliance, SSP, POA&M & SPRS Scoring

DFARS 252.204-7019 has required contractors to post a NIST SP 800-171 self-assessment score in SPRS since 2020. Many companies posted a 110 they could not defend, and now face a CMMC assessment against the same requirements. We fix that carefully, and without creating a false-claims problem along the way.
  • Assessment against all 320 objectives using the DoD Assessment Methodology
  • A System Security Plan describing your environment, not a template
  • A POA&M with owners, dates, and realistic milestones
  • Correct SPRS submission and annual affirmation support
Analyst reviewing compliance documentation and scoring data on screen

Your SPRS score is a representation to the government

This is the part that makes people uncomfortable, and it should. A score posted in SPRS is a representation made in connection with federal contracts. Posting a score you cannot substantiate is not a paperwork problem. It has been the basis of False Claims Act settlements against contractors.

If your current score was produced by a vendor questionnaire, a rushed spreadsheet, or an optimistic reading of what your MSP told you, the responsible move is to re-assess honestly and post a corrected score along with a genuine POA&M. A lower, defensible score with a credible remediation plan is a far stronger position than a 110 that evaporates under examination.

How the scoring actually works

The DoD Assessment Methodology starts you at 110 and deducts points for unimplemented requirements: 5 points for the highest-impact controls, 3 for significant ones, and 1 for the rest. Two requirements have partial-credit provisions. The floor is -203, and yes, plenty of companies genuinely start there.

Because the deductions are weighted, remediation sequencing matters enormously. Closing three 5-point requirements moves your score more than closing fifteen 1-point items, and the 5-point requirements are also the ones that can never be deferred onto a POA&M under CMMC. We plan around that arithmetic.

  • 5-point requirements: the controls the DoD considers most critical to protecting CUI
  • 3-point requirements: significant contributors to a defensible security posture
  • 1-point requirements: important, but lower individual impact on the score
  • Partial credit exists for a small number of requirements, and we apply it correctly rather than optimistically

A System Security Plan that survives contact with an assessor

The most common SSP failure is a document that describes an idealized environment instead of the one you actually operate. Assessors compare the SSP to reality. When they diverge, the SSP becomes evidence against you.

We write your SSP from the environment outward: system boundary, architecture, data flows, and then a control-by-control description of how each requirement is implemented here: which product, which setting, which policy, who is responsible. It is longer and less pretty than a template. It is also the version that holds up.

  • System description, boundary definition, and network architecture
  • Inventory of in-scope assets, including specialized and contractor-risk-managed assets
  • Control-by-control implementation narratives tied to real configuration
  • Roles, responsibilities, and named accountable individuals
  • Change history so the document demonstrably stays current

POA&M discipline

A POA&M is not a place to park inconvenient requirements indefinitely. Under CMMC the rules are strict: you must already be at 88 of 110 or better, only lower-weighted requirements are eligible, and everything has to close within 180 days with verification.

We build POA&Ms that are actually executable, giving each item a named owner, a resource estimate, a milestone date, and a defined closure artifact. Then we drive them to closure rather than handing you a spreadsheet and walking away.

What you get

Concrete deliverables, not a slide deck

Every engagement produces artefacts you own, that live in your environment, and that an assessor can read.

  • 01

    Objective-level gap assessment

    All 320 assessment objectives evaluated with evidence notes, not a 110-row checklist.

  • 02

    Scored assessment report

    Your current DoD Assessment Methodology score with the exact deductions and what each one costs you.

  • 03

    System Security Plan

    A complete, environment-specific SSP written to be read by an assessor.

  • 04

    POA&M

    Owners, milestones, resource estimates, and closure criteria for every open requirement.

  • 05

    SPRS submission support

    Correct entry of your score, assessment date, scope, and plan-of-action completion date, plus annual affirmation reminders.

  • 06

    Policy and procedure library

    The written policies the requirements demand, tailored to how your company operates.

Straight answers

NIST SP 800-171 & SPRS: questions we get asked

Ask us something else

We already posted a score. Can it be changed?

Yes. Scores in SPRS are updated as you reassess, and that is expected and normal. Correcting an over-stated score with a documented reassessment and a real POA&M is a defensible action. Leaving a score you know to be wrong in place is the risk.

What is the difference between NIST 800-171 and CMMC?

NIST SP 800-171 is the standard, the 110 requirements themselves. CMMC is the verification program the DoD built on top of it, adding assessment levels, third-party assessors, annual affirmations, and consequences for non-compliance. If you implement 800-171 properly, you are implementing the substance of CMMC Level 2.

Can you write our SSP if someone else does the remediation?

We can, and sometimes that is the right split. We will be direct with you though: an SSP written about controls that are not really implemented is worse than no SSP at all. We document what exists.

Next step

Ready to talk about nist sp 800-171 & sprs?

Tell us your size, your contracts, and where you are today. We will tell you what it takes and roughly what it costs, usually on the first call.