The prime wants your SPRS score. It is only as good as 110 answers.
Each answer is a NIST SP 800-171 requirement with a point weight and objectives an assessor will test. Look any of them up below, free; when you want the work done, MacTech implements each one and ties it to its evidence.
We score our own enclave against this reference, all 320 objectives bound to named evidence. See how ours scores.
Why 800-171 is the foundation of every modern DoD contract
- DFARS 252.204-7012 has required 800-171 since 2017 - but enforcement was self-attested and routinely ignored.
- CMMC 2.0 closes that loophole: Level 2 = all 110 controls + third-party assessment by a C3PAO.
- Even before CMMC reaches your contract, primes are filtering subs on SPRS score - a poor score loses bids today.
01 - The 14 families
All 110 requirements, mapped to 14 control families
110 total requirements per NIST SP 800-171 Rev 2. Rev 3, published 2024, restructures the catalog but does not yet apply to DoD contracts; DFARS continues to reference Rev 2.
03 - The reference
Every requirement, its SPRS weight, and what an assessor checks
3.1Access Control
22 requirements · 54 points- 3.1.1Authorized access control5 ptsnot eligible
- 3.1.2Transaction and function control5 ptsnot eligible
- 3.1.3Control CUI flow1 ptPOA&M-eligible
- 3.1.4Separation of duties1 ptPOA&M-eligible
- 3.1.5Least privilege3 ptsnot eligible
- 3.1.6Non-privileged accounts for non-security functions1 ptPOA&M-eligible
- 3.1.7Prevent and log privileged functions1 ptPOA&M-eligible
- 3.1.8Limit unsuccessful logon attempts1 ptPOA&M-eligible
- 3.1.9Privacy and security notices1 ptPOA&M-eligible
- 3.1.10Session lock1 ptPOA&M-eligible
- 3.1.11Session termination1 ptPOA&M-eligible
- 3.1.12Monitor remote access5 ptsnot eligible
- 3.1.13Encrypt remote access5 ptsnot eligible
- 3.1.14Managed remote access points1 ptPOA&M-eligible
- 3.1.15Authorize remote privileged commands1 ptPOA&M-eligible
- 3.1.16Authorize wireless access5 ptsnot eligible
- 3.1.17Protect wireless access5 ptsnot eligible
- 3.1.18Control mobile device connections5 ptsnot eligible
- 3.1.19Encrypt CUI on mobile devices3 ptsnot eligible
- 3.1.20External connections1 ptnot eligible
- 3.1.21Portable storage on external systems1 ptPOA&M-eligible
- 3.1.22CUI on public systems1 ptnot eligible
3.2Awareness & Training
3 requirements · 11 points- 3.2.1Security awareness for all users5 ptsnot eligible
- 3.2.2Role-based security training5 ptsnot eligible
- 3.2.3Insider threat awareness1 ptPOA&M-eligible
3.3Audit & Accountability
9 requirements · 19 points- 3.3.1System audit logs5 ptsnot eligible
- 3.3.2User accountability in audit records3 ptsnot eligible
- 3.3.3Review and update logged events1 ptPOA&M-eligible
- 3.3.4Alert on audit logging failure1 ptPOA&M-eligible
- 3.3.5Correlate audit review and reporting5 ptsnot eligible
- 3.3.6Audit reduction and report generation1 ptPOA&M-eligible
- 3.3.7Synchronized system clocks1 ptPOA&M-eligible
- 3.3.8Protect audit information1 ptPOA&M-eligible
- 3.3.9Limit audit management to privileged users1 ptPOA&M-eligible
3.4Configuration Management
9 requirements · 33 points- 3.4.1Baseline configuration5 ptsnot eligible
- 3.4.2Security configuration enforcement5 ptsnot eligible
- 3.4.3Change control1 ptPOA&M-eligible
- 3.4.4Security impact analysis of changes1 ptPOA&M-eligible
- 3.4.5Access restrictions for change5 ptsnot eligible
- 3.4.6Least functionality5 ptsnot eligible
- 3.4.7Restrict nonessential programs and services5 ptsnot eligible
- 3.4.8Deny-by-exception software policy5 ptsnot eligible
- 3.4.9Control user-installed software1 ptPOA&M-eligible
3.5Identification & Authentication
11 requirements · 27 points- 3.5.1Identify users, processes and devices5 ptsnot eligible
- 3.5.2Authenticate users, processes and devices5 ptsnot eligible
- 3.5.3Multifactor authentication5 ptsnot eligible
- 3.5.4Replay-resistant authentication1 ptPOA&M-eligible
- 3.5.5Prevent identifier reuse1 ptPOA&M-eligible
- 3.5.6Disable inactive identifiers1 ptPOA&M-eligible
- 3.5.7Password complexity1 ptPOA&M-eligible
- 3.5.8Prohibit password reuse1 ptPOA&M-eligible
- 3.5.9Temporary passwords1 ptPOA&M-eligible
- 3.5.10Cryptographically protected passwords5 ptsnot eligible
- 3.5.11Obscure authentication feedback1 ptPOA&M-eligible
3.6Incident Response
3 requirements · 11 points- 3.6.1Incident handling5 ptsnot eligible
- 3.6.2Track, document and report incidents5 ptsnot eligible
- 3.6.3Test incident response1 ptPOA&M-eligible
3.7Maintenance
6 requirements · 18 points- 3.7.1Perform system maintenance3 ptsnot eligible
- 3.7.2Control maintenance tools5 ptsnot eligible
- 3.7.3Sanitize equipment for off-site maintenance1 ptPOA&M-eligible
- 3.7.4Check diagnostic media for malicious code3 ptsnot eligible
- 3.7.5MFA for nonlocal maintenance5 ptsnot eligible
- 3.7.6Supervise maintenance personnel1 ptPOA&M-eligible
3.8Media Protection
9 requirements · 23 points- 3.8.1Protect media containing CUI3 ptsnot eligible
- 3.8.2Limit access to CUI on media3 ptsnot eligible
- 3.8.3Media sanitization5 ptsnot eligible
- 3.8.4Mark media with CUI markings1 ptPOA&M-eligible
- 3.8.5Control media during transport1 ptPOA&M-eligible
- 3.8.6Encrypt CUI on media in transport1 ptPOA&M-eligible
- 3.8.7Control removable media5 ptsnot eligible
- 3.8.8Prohibit portable storage with no owner3 ptsnot eligible
- 3.8.9Protect backup CUI1 ptPOA&M-eligible
3.9Personnel Security
2 requirements · 8 points- 3.9.1Screen individuals before access3 ptsnot eligible
- 3.9.2Protect CUI during personnel actions5 ptsnot eligible
3.10Physical Protection
6 requirements · 14 points- 3.10.1Limit physical access5 ptsnot eligible
- 3.10.2Protect and monitor the facility5 ptsnot eligible
- 3.10.3Escort visitors1 ptnot eligible
- 3.10.4Physical access logs1 ptnot eligible
- 3.10.5Manage physical access devices1 ptnot eligible
- 3.10.6Safeguard CUI at alternate work sites1 ptPOA&M-eligible
3.11Risk Assessment
3 requirements · 9 points- 3.11.1Periodic risk assessment3 ptsnot eligible
- 3.11.2Vulnerability scanning5 ptsnot eligible
- 3.11.3Remediate vulnerabilities1 ptPOA&M-eligible
3.12Security Assessment
4 requirements · 13 points- 3.12.1Periodic security control assessment5 ptsnot eligible
- 3.12.2Plans of action (POA&M)3 ptsnot eligible
- 3.12.3Continuous monitoring5 ptsnot eligible
- 3.12.4System security planno ptsnot eligible
3.13System & Communications Protection
16 requirements · 42 points- 3.13.1Boundary protection5 ptsnot eligible
- 3.13.2Security engineering principles5 ptsnot eligible
- 3.13.3Separate user and management functions1 ptPOA&M-eligible
- 3.13.4Prevent transfer via shared resources1 ptPOA&M-eligible
- 3.13.5Subnetworks for public components5 ptsnot eligible
- 3.13.6Deny by default, allow by exception5 ptsnot eligible
- 3.13.7Prevent split tunneling1 ptPOA&M-eligible
- 3.13.8Encrypt CUI in transit3 ptsnot eligible
- 3.13.9Terminate network connections1 ptPOA&M-eligible
- 3.13.10Cryptographic key management1 ptPOA&M-eligible
- 3.13.11FIPS-validated cryptography5 ptsnot eligible
- 3.13.12Collaborative computing devices1 ptPOA&M-eligible
- 3.13.13Control mobile code1 ptPOA&M-eligible
- 3.13.14Control VoIP1 ptPOA&M-eligible
- 3.13.15Protect session authenticity5 ptsnot eligible
- 3.13.16Encrypt CUI at rest1 ptPOA&M-eligible
3.14System & Information Integrity
7 requirements · 31 points- 3.14.1Flaw remediation5 ptsnot eligible
- 3.14.2Malicious code protection5 ptsnot eligible
- 3.14.3Monitor security alerts and advisories5 ptsnot eligible
- 3.14.4Update malicious code protection5 ptsnot eligible
- 3.14.5Periodic and real-time scans3 ptsnot eligible
- 3.14.6Monitor systems and communications5 ptsnot eligible
- 3.14.7Identify unauthorized system use3 ptsnot eligible
03 - Implementation
How MacTech implements NIST 800-171
Boundary first, controls second
We define the CUI boundary before we touch a control. A tight boundary lets you scope 800-171 to a manageable surface; a sprawling boundary turns every requirement into a multi-system implementation.
Inherit everything inheritable
Customers running CUI inside MacTech's enclave inherit a documented set of controls from the underlying FedRAMP-aligned platform - physical security, baseline configuration, network protection, and several others. Shorter SSP, faster assessment.
Evidence on the same surface as the work
Trust Codex links every requirement to the artifacts that prove it. STIG scans, MFA enrollment reports, encryption attestations, training records - all in one place, all keyed to a control ID.
SSP and POAM as living documents
Your SSP regenerates from the evidence library. Your POAM tracks what is open, who owns it, and when it closes. No frantic week of binder-building the month before a C3PAO arrives.
05 - Questions
NIST 800-171 - frequently asked
What is NIST SP 800-171?
NIST Special Publication 800-171 Rev 2 is a federal control catalog of 110 security requirements organized into 14 families (Access Control, Audit and Accountability, Configuration Management, etc.). It defines the minimum protections non-federal organizations must apply to Controlled Unclassified Information (CUI) when handling it on behalf of the U.S. government.
Is NIST 800-171 mandatory?
For any organization with a contract or subcontract that flows down DFARS 252.204-7012, yes. The clause has been in DoD contracts since 2017 and is the legal hook that requires 800-171 implementation. With the CMMC 2.0 rule, the requirement is now also enforced through third-party assessment, not just contractor self-attestation.
What is the difference between NIST 800-171 and CMMC?
NIST 800-171 is the control catalog - the list of 110 requirements. CMMC is the assessment framework that verifies you actually meet them. CMMC Level 2 implements all 110 NIST 800-171 controls and adds a third-party assessment by a C3PAO. So if you are doing CMMC Level 2, you are doing NIST 800-171.
How many controls are in NIST 800-171?
110 security requirements, grouped into 14 families. Each requirement also has assessment objectives published in NIST SP 800-171A - the document a C3PAO assessor actually scores against. A common contractor mistake is implementing the requirement but not the underlying objectives, then failing the assessment on technicalities.
What is a System Security Plan (SSP) under NIST 800-171?
The SSP is the master document that describes your system, defines its boundary, identifies CUI flows, and explains how each of the 110 controls is implemented. It is the first thing a C3PAO assessor reads and the document everything else (POAM, evidence library, shared-responsibility matrices) ties back to. NIST 800-171 requirement 3.12.4 specifically requires an SSP.
What is a POAM and when is one required?
A Plan of Action and Milestones (POAM) is the tracking document for any control you have not fully implemented. Under the original 800-171 self-assessment model, almost any control could be POAMed. Under CMMC 2.0 Level 2, only a narrow subset of controls (worth fewer SPRS points) can remain on a POAM at certification - and only for 180 days.
What is the SPRS score?
The Supplier Performance Risk System (SPRS) score is a numeric assessment of NIST 800-171 implementation, calculated by deducting points from a starting score of 110 based on the controls you have not yet implemented. Primes increasingly look at SPRS scores when awarding subcontracts, even for contracts that do not formally require CMMC certification yet.
Can I do a NIST 800-171 self-assessment?
For most contracts written before the CMMC 2.0 final rule, yes - you self-assess, post your SPRS score, and re-attest annually. For contracts that flow down CMMC Level 2, you also need a C3PAO assessment every three years. The trajectory is clear: third-party assessment becomes the norm.
From the newsletter
NIST 800-171, from the field
An Incident Response Tabletop Exercise That Satisfies 3.6.3
An incident response tabletop exercise counts for NIST 800-171 3.6.3 only if it leaves evidence. How to seat, script, and document one an assessor accepts.
NIST 800-171 Rev 3 vs Rev 2: It Depends Who Signed the Contract
NIST 800-171 Rev 3 vs Rev 2: DoD still binds and scores Rev 2 while civilian CUI heads to Rev 3. What changed, the ID trap, and how to map once.
CMMC Class Deviation: The Phase 2 Pause Is Now in the Rulebook
The CMMC class deviation moved the Phase 2 pause from a policy memo into DFARS. A dated timeline of what each step changed, and what stays in force.
From MacZine
Working notes on the 110
Three issues on requirements that trip up more programs than the rest put together.
Get a real NIST 800-171 readiness picture
A readiness scan gives you a per-family score, a prioritized remediation backlog, and an honest timeline to C3PAO assessment. No 200-row spreadsheets you will never finish.