WATCHUR6 // NIST 800-171 // AUDIT READINESS

110 controls stand between you
and your next DoD contract.

NIST 800-171 is the 110-control foundation DFARS 252.204-7012 requires of every contractor touching CUI — and the exact standard CMMC Level 2 certifies against. Your SPRS self-score is on the record, and after Phase 2 a C3PAO checks whether it's real. We make it real before they look.

Book a NIST 800-171 Strategy Call
110 CONTROLS // REV 2 SSP // POA&M // SPRS CMMC L2 FOUNDATION VETERAN-LED

// WHY 800-171, WHY NOW

A self-score isn't compliance. It's a claim someone will check.

110 / 14

Controls across 14 families

Revision 2 is the enforced standard — 110 requirements in 14 families. NIST published Rev 3, but the DoD hasn't authorized it for SPRS or CMMC, so Rev 2 is still the bar.

−203 to 110

Your SPRS score range

Scored by the DoD methodology with no partial credit, due before award and annually. Contracting officers read it in source selection — and after Phase 2, a C3PAO verifies it.

FALSE CLAIMS

Act exposure on a bad score

The senior-official SPRS affirmation carries False Claims Act liability. A score that isn't backed by a real SSP and implemented controls is the profile DoD enforcement targets.

// A SCORE ISN'T EVIDENCE

We posted an SPRS score, so we're compliant.
A number with no SSP behind it is a liability, not protection.

Posting a score satisfies the pre-award box — but an inaccurate or unsupported one is exposure, not cover. Contracting officers read SPRS scores in source selection, and the senior-official affirmation behind yours carries False Claims Act liability. DoD enforcement has repeatedly targeted contractors whose claimed scores weren't backed by a real System Security Plan and implemented controls — and after Phase 2, a C3PAO verifies the same 110 Rev 2 requirements directly.

// THE THREE ARTIFACTS

One master document. Two that derive from it.

Compliance lives in three documents every prime, DoD assessor, and C3PAO reads. The SSP is the master — it describes all 110 controls. The POA&M tracks its gaps, and the SPRS score is calculated from it.

SSP System Security Plan · the master document

Describes how each of the 110 Rev 2 controls is implemented in your environment — system boundary, CUI data flow, implementation status, and the evidence behind each. Everything else derives from it: the two artifacts below are read against the SSP, not on their own.

// DERIVES FROM SSP

POA&M

Plan of Action & Milestones — the remediation roadmap for every gap: action, owner, date, resources.

// DERIVES FROM SSP

SPRS Score

The −203 to +110 number from the DoD methodology, on file before award and refreshed annually.

A score with no SSP behind it is the #1 enforcement red flag.

Rev 2 · 110 CONTROLS / 14 FAMILIES DFARS 7012 · MANDATES 800-171 CMMC L2 · CERTIFIES THE SAME 110

// THE PATH

From flowdown to CMMC-ready.

800-171 readiness runs about four to six months and feeds straight into CMMC Level 2. The amber stages are where outside parties enter — your SPRS submission to the DoD, and the C3PAO assessment ahead.

Gap

110-Control Gap

MO 0–1

SSP

SSP Authoring

MO 1–2

POA&M

POA&M Development

MO 2–3

SPRS

Score Submission

MO 3–4

Remediate

Remediation

MO 4–6+

CMMC L2

C3PAO Bridge

PRE-NOV 2026

Amber stages are where outside parties enter — the SPRS submission the DoD reads, and the C3PAO assessment that certifies CMMC Level 2. The same 110 controls carry you all the way through.

// IS THIS YOU?

Three signs you need to move now.

// 01 // ESTIMATED SCORE

Your SPRS score was a guess

If your posted score was estimated, optimistic, or never tied to a documented SSP, it's False Claims Act exposure sitting on the record — not the protection you think it is.

// 02 // CUI + PHASE 2

You handle CUI on a DoD contract

DFARS 7012 already requires the 110 controls. Phase 2 on Nov 10, 2026 adds a C3PAO assessment of the same requirements — and the queue for assessors is the real deadline.

// 03 // FLOW-DOWN

A prime is asking for your status

Primes verify their subs' 800-171 posture before sharing CUI. If a prime asked for your SSP or score and you stalled, you're already behind the contractors who didn't.

// WHAT WE DO

The artifacts, the score, and the bridge to CMMC.

// Phase 01 · Assess

Gap Assessment & Scoping

We score you honestly against all 110 Rev 2 controls and draw the CUI boundary — the scope decision that drives your SPRS number more than anything else.

  • 110-control gap assessment to the DoD methodology
  • CUI boundary definition and asset inventory
  • Honest current SPRS score and prioritized gaps

// Phase 02 · Document

SSP, POA&M & SPRS

We build the three artifacts assessors read — a complete SSP, a real POA&M, and a defensible SPRS submission backed by evidence, not optimism.

  • System Security Plan authored control by control
  • POA&M with owners, dates, and resourcing
  • SPRS score calculation and submission support

// Phase 03 · Bridge

Remediation & CMMC L2

We close the gaps and carry the same work straight into CMMC Level 2 C3PAO readiness, so 800-171 compliance and certification are one effort, not two.

  • Remediation execution against the POA&M
  • Annual SPRS affirmation and maintenance
  • CMMC Level 2 C3PAO pre-assessment readiness

// THE SCORE IS ON THE RECORD

Make your SPRS score real before a C3PAO checks it for you.

Book a NIST 800-171 Strategy Call

// FREQUENTLY ASKED

The NIST 800-171 questions teams keep asking.

Revision 2 or Revision 3 — which version do we actually have to meet?

Revision 2. NIST published Rev 3 in May 2024 — consolidating to 97 requirements across 17 families and introducing Organizationally Defined Parameters — but the DoD has not authorized Rev 3 for compliance scoring, SPRS reporting, or CMMC. Under a standing Class Deviation, DFARS 7012 contractors stay on Rev 2: 110 requirements, 14 families.

That means SPRS scores are still calculated on Rev 2, CMMC Level 2 self-assessments use Rev 2, and C3PAOs benchmark against Rev 2. Aligning only to Rev 3 today is risky — controls satisfied under Rev 3 can show as unmet under Rev 2 and jeopardize an assessment. Be Rev 2 compliant now; map Rev 3 for later.

What are the SSP, POA&M, and SPRS score, and why do they matter?

They're the three artifacts every prime, DoD assessor, and C3PAO reads. The SSP (System Security Plan) is the master document describing how each of the 110 controls is implemented — boundary, CUI data flow, status, and evidence. The POA&M is the remediation roadmap for gaps, with an action, owner, date, and resources each.

The SPRS score ranges from -203 to +110, calculated by the DoD Assessment Methodology with no partial credit, on file before award and refreshed annually. Together they're the difference between claiming compliance and proving it — a score with no SSP behind it is the top enforcement red flag.

How does NIST 800-171 relate to CMMC and DFARS?

NIST 800-171 is the standard — the 110 requirements themselves. DFARS 252.204-7012 is the contract clause that mandates implementing them to protect CUI. CMMC is the program that verifies you actually meet them, enforced through DFARS 252.204-7021.

CMMC Level 2 maps directly to the 110 Rev 2 requirements and adds assessment and certification: where DFARS 7012 historically let you self-attest via SPRS, CMMC Level 2 requires — for most CUI contracts from Phase 2 on Nov 10, 2026 — an independent C3PAO assessment of those same controls. The 800-171 work is the CMMC work.

We posted an SPRS score already. Isn't that enough?

Having a score on file satisfies the pre-award requirement, but an inaccurate or unsupported score is a liability, not protection. Contracting officers review SPRS scores in source selection, and the senior-official affirmation carries False Claims Act exposure — DoD enforcement has repeatedly targeted contractors whose claimed scores weren't backed by a real SSP and implemented controls.

CMMC exists to verify those self-reported scores, and after Phase 2 a C3PAO checks. A score that was estimated or never tied to a documented SSP is exactly what turns into an enforcement problem. The safe position is a score calculated honestly against Rev 2, backed by a complete SSP and POA&M, and defensible if anyone asks for the evidence.

// THE NEXT MOVE

Build the foundation once. Carry it into CMMC.

Book a 30-minute NIST 800-171 strategy call with a WatchUr6 advisor. Bring the contract or prime driving this, your current SPRS score if you have one, and whether CMMC Level 2 is on your horizon. You'll walk away with an honest read on your real score, the gaps between you and a defensible position, and a path that doubles as CMMC readiness — whether you hire us or not.

Book a NIST 800-171 Strategy Call

SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED