AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

NIST 800-171 Self-Assessment: Why an Honest 60 Beats a Fake 110

How a NIST 800-171 self assessment and SPRS score really work, why a false 110 is now a signed federal statement, and how to post a score you can defend.

Dr. Kashmala KhalidDr. Kashmala Khalid Dr. KashCo-Founder, healthcare and defense programsSeptember 2, 2026 · 6 min read

The number nobody can explain

The new contracts officer at a 20-person engineering services firm in Huntsville inherits a login to SPRS on her second day. The score posted there is 110, a perfect score, dated three years ago. Beside it is a note from her predecessor: "IT did this, ask Greg."

Greg is the IT contractor. He remembers posting it. He says the firm "had most of it, and the rest was basically in place." She asks for the system security plan. He sends a 60-page document with the firm's name find-and-replaced into a template. Section 3.5.3, multifactor authentication: "The organization implements MFA for all local and network access." She checks. The engineers log into the file server with a password. Section 3.3.1, audit logs: "Retained for one year." The server keeps them for fourteen days.

Then she reads the part of the 48 CFR rule that says a senior official must affirm the score every year, and that the affirmation is a statement to the federal government. Her managing partner is the senior official. He is a structural engineer. He signed last year's affirmation because Greg said it was fine.

She sits with that for a minute. A false score three years ago was a mistake. A false affirmation this year, with her name on the file, is something a whistleblower could describe to a prosecutor. She opens the 110 requirements and starts at the top.

The score, in plain words

NIST SP 800-171 is the list of 110 security requirements for protecting controlled unclassified information, the sensitive-but-not-secret data the government shares with contractors.

A self-assessment is the contractor scoring itself against those 110 using the DoD methodology: start at 110, subtract one, three or five points for each requirement not met, depending on how much it matters. Miss MFA and you lose five. Miss a written policy and you lose one. The floor is minus 203.

SPRS is the Supplier Performance Risk System, the DoD database where the score lives and where primes and contracting officers look before award.

A POA&M is a plan of action and milestones: what you will fix, who owns it, by when.

The annual affirmation is a senior official stating, in SPRS, that the score is accurate. That is where the False Claims Act comes in: the federal law that lets the government, and whistleblowers, sue over false statements tied to federal money. A score you affirmed knowing it was wrong is exactly that.

So the arithmetic is simple. An honest 60 with a dated plan is a company doing the work. A fake 110 is a signature waiting to be examined.

The numbers that matter

Under the Department of Defense's 48 CFR CMMC rule, in force since 2025, Phase 1 contractors must post a self-assessment in SPRS and affirm it annually through a senior official. The affirmation is what turned this from an IT chore into an executive statement.

The DoD's own 2024 cost analysis for the CMMC rule estimated a Level 2 C3PAO assessment at roughly $76,743 for a small entity. That is the cost of the outside exam that Phase 2 would bring; the self-assessment is how you find out in advance if you would pass it, before paying for it.

The median time to patch a vulnerability was 43 days, according to the Verizon 2026 Data Breach Investigations Report. 800-171 expects timely remediation, and 43 days is the number an honest assessment writes down, not the one a template assumes.

What to do this week

  1. Build the asset list for everything that stores, processes or transmits CUI: every laptop, server, phone, cloud account and application, with an owner. If it is not on the list, it is not in your assessment, and if it handles CUI it should be on the list. (CIS 1 Inventory and Control of Enterprise Assets)
  2. Rescore from the asset list, one requirement at a time, with the evidence beside each answer: a screenshot, a config export, a policy with a date. "Greg says so" is not evidence. Write the real number down before anyone sees it. (CIS 1 Inventory and Control of Enterprise Assets)
  3. Put MFA on every account that can reach CUI, starting with the file server and email. This is a five-point requirement and it is the cheapest five points you will ever recover. (CIS 6 Access Control Management)
  4. Set audit log retention to at least a year on the in-scope systems and store the logs where an administrator cannot quietly delete them. (CIS 8 Audit Log Management)
  5. Fix the patch cadence: a monthly date, a named person, and a record of what was applied. If the assessment says 43 days, the plan says 30, and then the evidence says 30. (CIS 7 Continuous Vulnerability Management)
  6. Write the POA&M with an owner and a date on every open requirement, post the honest score to SPRS, and put the assessment and the evidence folder in front of the senior official before the affirmation. Nobody should sign what they have not read. (CIS 6 Access Control Management)

Where AccuSights fits

Our assessment is the self-assessment done properly: the asset list, the 110 requirements with evidence against each one, and a plan of action with dates you can defend. Our team implements the fixes at a reasonable rate, from MFA and logging to data loss prevention, scanning and protection of the in-scope assets, so the score rises because the controls exist, not because the template says they do. Start with the three-minute Cyber Hygiene Test, or book 15 minutes with an engineer who has scored a few hundred of these.

Questions people ask

What is a POA&M? A plan of action and milestones. It is the list of 800-171 requirements you do not yet meet, with what you will do about each, who owns it, and a completion date. It is not a place to park requirements you never intend to fix. The DoD expects the plan to close, and certain high-value requirements cannot sit on a POA&M at all if you want a conditional status.

Can you have a negative SPRS score? Yes. The DoD scoring methodology starts at 110 and subtracts one, three or five points for each unmet requirement depending on its weight, so a company missing the heavy ones can land well below zero, all the way to minus 203. A negative score that is true is a starting point. A 110 that is false is a problem of an entirely different kind.

Who signs the annual affirmation? A senior official at the contractor, someone with the authority to bind the company, affirms in SPRS each year that the score is accurate and the plan of action is being worked. It cannot be delegated to the IT contractor. Whoever signs should have read the assessment, understood the evidence behind each requirement, and be comfortable defending it, because that signature is what turns a self-assessment into a statement to the federal government.

In medicine we chart what we found, not what we hoped to find. Score your systems the same way, and the number will be one you can sign.

Controls this post maps to

CIS 1 Inventory and Control of Enterprise AssetsCIS 6 Access Control ManagementCIS 8 Audit Log Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the HIPAA and CMMC programs. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.