Blog / US compliance
US compliance
NIST 800-171 Self-Assessment: Why an Honest 60 Beats a Fake 110
How a NIST 800-171 self assessment and SPRS score really work, why a false 110 is now a signed federal statement, and how to post a score you can defend.
The number nobody can explain
The new contracts officer at a 20-person engineering services firm in Huntsville inherits a login to SPRS on her second day. The score posted there is 110, a perfect score, dated three years ago. Beside it is a note from her predecessor: "IT did this, ask Greg."
Greg is the IT contractor. He remembers posting it. He says the firm "had most of it, and the rest was basically in place." She asks for the system security plan. He sends a 60-page document with the firm's name find-and-replaced into a template. Section 3.5.3, multifactor authentication: "The organization implements MFA for all local and network access." She checks. The engineers log into the file server with a password. Section 3.3.1, audit logs: "Retained for one year." The server keeps them for fourteen days.
Then she reads the part of the 48 CFR rule that says a senior official must affirm the score every year, and that the affirmation is a statement to the federal government. Her managing partner is the senior official. He is a structural engineer. He signed last year's affirmation because Greg said it was fine.
She sits with that for a minute. A false score three years ago was a mistake. A false affirmation this year, with her name on the file, is something a whistleblower could describe to a prosecutor. She opens the 110 requirements and starts at the top.
The score, in plain words
NIST SP 800-171 is the list of 110 security requirements for protecting controlled unclassified information, the sensitive-but-not-secret data the government shares with contractors.
A self-assessment is the contractor scoring itself against those 110 using the DoD methodology: start at 110, subtract one, three or five points for each requirement not met, depending on how much it matters. Miss MFA and you lose five. Miss a written policy and you lose one. The floor is minus 203.
SPRS is the Supplier Performance Risk System, the DoD database where the score lives and where primes and contracting officers look before award.
A POA&M is a plan of action and milestones: what you will fix, who owns it, by when.
The annual affirmation is a senior official stating, in SPRS, that the score is accurate. That is where the False Claims Act comes in: the federal law that lets the government, and whistleblowers, sue over false statements tied to federal money. A score you affirmed knowing it was wrong is exactly that.
So the arithmetic is simple. An honest 60 with a dated plan is a company doing the work. A fake 110 is a signature waiting to be examined.
The numbers that matter
Under the Department of Defense's 48 CFR CMMC rule, in force since 2025, Phase 1 contractors must post a self-assessment in SPRS and affirm it annually through a senior official. The affirmation is what turned this from an IT chore into an executive statement.
The DoD's own 2024 cost analysis for the CMMC rule estimated a Level 2 C3PAO assessment at roughly $76,743 for a small entity. That is the cost of the outside exam that Phase 2 would bring; the self-assessment is how you find out in advance if you would pass it, before paying for it.
The median time to patch a vulnerability was 43 days, according to the Verizon 2026 Data Breach Investigations Report. 800-171 expects timely remediation, and 43 days is the number an honest assessment writes down, not the one a template assumes.
What to do this week
- Build the asset list for everything that stores, processes or transmits CUI: every laptop, server, phone, cloud account and application, with an owner. If it is not on the list, it is not in your assessment, and if it handles CUI it should be on the list. (CIS 1 Inventory and Control of Enterprise Assets)
- Rescore from the asset list, one requirement at a time, with the evidence beside each answer: a screenshot, a config export, a policy with a date. "Greg says so" is not evidence. Write the real number down before anyone sees it. (CIS 1 Inventory and Control of Enterprise Assets)
- Put MFA on every account that can reach CUI, starting with the file server and email. This is a five-point requirement and it is the cheapest five points you will ever recover. (CIS 6 Access Control Management)
- Set audit log retention to at least a year on the in-scope systems and store the logs where an administrator cannot quietly delete them. (CIS 8 Audit Log Management)
- Fix the patch cadence: a monthly date, a named person, and a record of what was applied. If the assessment says 43 days, the plan says 30, and then the evidence says 30. (CIS 7 Continuous Vulnerability Management)
- Write the POA&M with an owner and a date on every open requirement, post the honest score to SPRS, and put the assessment and the evidence folder in front of the senior official before the affirmation. Nobody should sign what they have not read. (CIS 6 Access Control Management)
Where AccuSights fits
Our assessment is the self-assessment done properly: the asset list, the 110 requirements with evidence against each one, and a plan of action with dates you can defend. Our team implements the fixes at a reasonable rate, from MFA and logging to data loss prevention, scanning and protection of the in-scope assets, so the score rises because the controls exist, not because the template says they do. Start with the three-minute Cyber Hygiene Test, or book 15 minutes with an engineer who has scored a few hundred of these.
Questions people ask
What is a POA&M? A plan of action and milestones. It is the list of 800-171 requirements you do not yet meet, with what you will do about each, who owns it, and a completion date. It is not a place to park requirements you never intend to fix. The DoD expects the plan to close, and certain high-value requirements cannot sit on a POA&M at all if you want a conditional status.
Can you have a negative SPRS score? Yes. The DoD scoring methodology starts at 110 and subtracts one, three or five points for each unmet requirement depending on its weight, so a company missing the heavy ones can land well below zero, all the way to minus 203. A negative score that is true is a starting point. A 110 that is false is a problem of an entirely different kind.
Who signs the annual affirmation? A senior official at the contractor, someone with the authority to bind the company, affirms in SPRS each year that the score is accurate and the plan of action is being worked. It cannot be delegated to the IT contractor. Whoever signs should have read the assessment, understood the evidence behind each requirement, and be comfortable defending it, because that signature is what turns a self-assessment into a statement to the federal government.
In medicine we chart what we found, not what we hoped to find. Score your systems the same way, and the number will be one you can sign.
Controls this post maps to
CIS Controls v8.1. These are the same controls our assessment scores and the console watches.
Sources
Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the HIPAA and CMMC programs. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →
Keep reading
Three more from the same shelf.
CMMC in 2026: The Pause Is Not a Pardon
CMMC 2026 status: Phase 2 certification is suspended, but Phase 1 self-assessments, SPRS scores and DFARS 7012 are still in force. What to do now.
US complianceCMMC Watch: What the Return of Phase 2 Would Change, and Why None of the Readiness Work Is Wasted
CMMC Phase 2 return readiness: what changes when third-party assessment comes back, what conditional status at 88 means, and the work that counts either way.
US complianceCMMC in the Phase 2 Pause: What a Dallas Machine Shop Still Owes This Quarter
The CMMC Phase 2 pause suspended the C3PAO mandate on 13 July 2026. What a Dallas machine shop still owes on SPRS, DFARS 7012 and Phase 1 this quarter.
