NIST 800-171 compliance fails more often from wrong sequencing than wrong intentions — shops buy tools before scoping, write policies before assessing, or post a score before doing either. Here are the twelve steps in the order that saves the most time and money. Each links to a deeper guide.
Phase 1 — Establish What You Actually Owe (Steps 1–3)
- Confirm the clause. Find DFARS 252.204-7012 (and 7019/7020) in your contracts. Present → continue. Absent, and no CUI → your obligation is likely the lighter Level 1 set; stop over-building.
- Determine whether you truly handle CUI. Most small contractors get this wrong in one direction or the other — both errors are expensive.
- Define your boundary. Decide where CUI is allowed to live and keep that footprint small — an enclave shrinks every remaining step. Write the boundary down; it's the opening section of your future SSP.
Phase 2 — Assess and Score (Steps 4–6)
- Assess all 110 requirements honestly. Met, not met, or justified N/A — judged against what each control actually asks, not the one-line summary. Resist optimism; every overclaim becomes someone else's discovery.
- Calculate your SPRS score. 110 minus the weight of every gap — the exact arithmetic. Don't be shocked by a negative first number; most honest first assessments land between −50 and +70.
- Prioritize remediation by weight. The 5-pointers (MFA, encryption, boundary protection) move the score five times faster than the 1-pointers — and several can't sit on a POA&M when certification resumes, so they're first either way.
Phase 3 — Document (Steps 7–9)
- Write the SSP — one concrete implementation statement per control, honest about gaps. This is the document your score is formally anchored to.
- Build the POA&M — every unmet control, with an owner and a date. The completion date feeds your SPRS entry directly.
- Adopt the 14 policies. Dozens of controls are only "met" when a written policy backs the setting — what each policy must contain.
Phase 4 — Post and Operate (Steps 10–12)
- Post your score to SPRS via PIEE — the complete submission walkthrough, portal quirks included.
- Stand up the recurring layer: security awareness training with records, log reviews, access recertifications, and evidence filed per control as you go — not the night before an assessment.
- Maintain it: re-assess on material change, update the score as gaps close, diarize the annual affirmation, and keep the three-year clock in view.
Steps 1–6, free — steps 7–8 generated
CMMC Map runs this exact sequence: scoping wizard, plain-English assessment of all 110, live SPRS score — free. The SSP, POA&M, and policies generate from your answers at $149/month when you reach the documentation phase.
Start the checklist free →