110 / 14
Controls across 14 families
Revision 2 is the enforced standard — 110 requirements in 14 families. NIST published Rev 3, but the DoD hasn't authorized it for SPRS or CMMC, so Rev 2 is still the bar.
NIST 800-171 is the 110-control foundation DFARS 252.204-7012 requires of every contractor touching CUI — and the exact standard CMMC Level 2 certifies against. Your SPRS self-score is on the record, and after Phase 2 a C3PAO checks whether it's real. We make it real before they look.
Book a NIST 800-171 Strategy Call →// WHY 800-171, WHY NOW
110 / 14
Revision 2 is the enforced standard — 110 requirements in 14 families. NIST published Rev 3, but the DoD hasn't authorized it for SPRS or CMMC, so Rev 2 is still the bar.
−203 to 110
Scored by the DoD methodology with no partial credit, due before award and annually. Contracting officers read it in source selection — and after Phase 2, a C3PAO verifies it.
FALSE CLAIMS
The senior-official SPRS affirmation carries False Claims Act liability. A score that isn't backed by a real SSP and implemented controls is the profile DoD enforcement targets.
// A SCORE ISN'T EVIDENCE
Posting a score satisfies the pre-award box — but an inaccurate or unsupported one is exposure, not cover. Contracting officers read SPRS scores in source selection, and the senior-official affirmation behind yours carries False Claims Act liability. DoD enforcement has repeatedly targeted contractors whose claimed scores weren't backed by a real System Security Plan and implemented controls — and after Phase 2, a C3PAO verifies the same 110 Rev 2 requirements directly.
// THE THREE ARTIFACTS
Compliance lives in three documents every prime, DoD assessor, and C3PAO reads. The SSP is the master — it describes all 110 controls. The POA&M tracks its gaps, and the SPRS score is calculated from it.
Describes how each of the 110 Rev 2 controls is implemented in your environment — system boundary, CUI data flow, implementation status, and the evidence behind each. Everything else derives from it: the two artifacts below are read against the SSP, not on their own.
// DERIVES FROM SSP
POA&M
Plan of Action & Milestones — the remediation roadmap for every gap: action, owner, date, resources.
// DERIVES FROM SSP
SPRS Score
The −203 to +110 number from the DoD methodology, on file before award and refreshed annually.
A score with no SSP behind it is the #1 enforcement red flag.
// THE PATH
800-171 readiness runs about four to six months and feeds straight into CMMC Level 2. The amber stages are where outside parties enter — your SPRS submission to the DoD, and the C3PAO assessment ahead.
Gap
110-Control Gap
MO 0–1
SSP
SSP Authoring
MO 1–2
POA&M
POA&M Development
MO 2–3
SPRS
Score Submission
MO 3–4
Remediate
Remediation
MO 4–6+
CMMC L2
C3PAO Bridge
PRE-NOV 2026
Amber stages are where outside parties enter — the SPRS submission the DoD reads, and the C3PAO assessment that certifies CMMC Level 2. The same 110 controls carry you all the way through.
// IS THIS YOU?
// 01 // ESTIMATED SCORE
If your posted score was estimated, optimistic, or never tied to a documented SSP, it's False Claims Act exposure sitting on the record — not the protection you think it is.
// 02 // CUI + PHASE 2
DFARS 7012 already requires the 110 controls. Phase 2 on Nov 10, 2026 adds a C3PAO assessment of the same requirements — and the queue for assessors is the real deadline.
// 03 // FLOW-DOWN
Primes verify their subs' 800-171 posture before sharing CUI. If a prime asked for your SSP or score and you stalled, you're already behind the contractors who didn't.
// WHAT WE DO
// Phase 01 · Assess
We score you honestly against all 110 Rev 2 controls and draw the CUI boundary — the scope decision that drives your SPRS number more than anything else.
// Phase 02 · Document
We build the three artifacts assessors read — a complete SSP, a real POA&M, and a defensible SPRS submission backed by evidence, not optimism.
// Phase 03 · Bridge
We close the gaps and carry the same work straight into CMMC Level 2 C3PAO readiness, so 800-171 compliance and certification are one effort, not two.
// THE SCORE IS ON THE RECORD
// FREQUENTLY ASKED
Revision 2. NIST published Rev 3 in May 2024 — consolidating to 97 requirements across 17 families and introducing Organizationally Defined Parameters — but the DoD has not authorized Rev 3 for compliance scoring, SPRS reporting, or CMMC. Under a standing Class Deviation, DFARS 7012 contractors stay on Rev 2: 110 requirements, 14 families.
That means SPRS scores are still calculated on Rev 2, CMMC Level 2 self-assessments use Rev 2, and C3PAOs benchmark against Rev 2. Aligning only to Rev 3 today is risky — controls satisfied under Rev 3 can show as unmet under Rev 2 and jeopardize an assessment. Be Rev 2 compliant now; map Rev 3 for later.
They're the three artifacts every prime, DoD assessor, and C3PAO reads. The SSP (System Security Plan) is the master document describing how each of the 110 controls is implemented — boundary, CUI data flow, status, and evidence. The POA&M is the remediation roadmap for gaps, with an action, owner, date, and resources each.
The SPRS score ranges from -203 to +110, calculated by the DoD Assessment Methodology with no partial credit, on file before award and refreshed annually. Together they're the difference between claiming compliance and proving it — a score with no SSP behind it is the top enforcement red flag.
NIST 800-171 is the standard — the 110 requirements themselves. DFARS 252.204-7012 is the contract clause that mandates implementing them to protect CUI. CMMC is the program that verifies you actually meet them, enforced through DFARS 252.204-7021.
CMMC Level 2 maps directly to the 110 Rev 2 requirements and adds assessment and certification: where DFARS 7012 historically let you self-attest via SPRS, CMMC Level 2 requires — for most CUI contracts from Phase 2 on Nov 10, 2026 — an independent C3PAO assessment of those same controls. The 800-171 work is the CMMC work.
Having a score on file satisfies the pre-award requirement, but an inaccurate or unsupported score is a liability, not protection. Contracting officers review SPRS scores in source selection, and the senior-official affirmation carries False Claims Act exposure — DoD enforcement has repeatedly targeted contractors whose claimed scores weren't backed by a real SSP and implemented controls.
CMMC exists to verify those self-reported scores, and after Phase 2 a C3PAO checks. A score that was estimated or never tied to a documented SSP is exactly what turns into an enforcement problem. The safe position is a score calculated honestly against Rev 2, backed by a complete SSP and POA&M, and defensible if anyone asks for the evidence.
// THE NEXT MOVE
Book a 30-minute NIST 800-171 strategy call with a WatchUr6 advisor. Bring the contract or prime driving this, your current SPRS score if you have one, and whether CMMC Level 2 is on your horizon. You'll walk away with an honest read on your real score, the gaps between you and a defensible position, and a path that doubles as CMMC readiness — whether you hire us or not.
Book a NIST 800-171 Strategy Call →SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED