NIST 800-171 compliance fails more often from wrong sequencing than wrong intentions — shops buy tools before scoping, write policies before assessing, or post a score before doing either. Here are the twelve steps in the order that saves the most time and money. Each links to a deeper guide.

Phase 1 — Establish What You Actually Owe (Steps 1–3)

  1. Confirm the clause. Find DFARS 252.204-7012 (and 7019/7020) in your contracts. Present → continue. Absent, and no CUI → your obligation is likely the lighter Level 1 set; stop over-building.
  2. Determine whether you truly handle CUI. Most small contractors get this wrong in one direction or the other — both errors are expensive.
  3. Define your boundary. Decide where CUI is allowed to live and keep that footprint small — an enclave shrinks every remaining step. Write the boundary down; it's the opening section of your future SSP.

Phase 2 — Assess and Score (Steps 4–6)

  1. Assess all 110 requirements honestly. Met, not met, or justified N/A — judged against what each control actually asks, not the one-line summary. Resist optimism; every overclaim becomes someone else's discovery.
  2. Calculate your SPRS score. 110 minus the weight of every gap — the exact arithmetic. Don't be shocked by a negative first number; most honest first assessments land between −50 and +70.
  3. Prioritize remediation by weight. The 5-pointers (MFA, encryption, boundary protection) move the score five times faster than the 1-pointers — and several can't sit on a POA&M when certification resumes, so they're first either way.

Phase 3 — Document (Steps 7–9)

  1. Write the SSPone concrete implementation statement per control, honest about gaps. This is the document your score is formally anchored to.
  2. Build the POA&Mevery unmet control, with an owner and a date. The completion date feeds your SPRS entry directly.
  3. Adopt the 14 policies. Dozens of controls are only "met" when a written policy backs the setting — what each policy must contain.

Phase 4 — Post and Operate (Steps 10–12)

  1. Post your score to SPRS via PIEE — the complete submission walkthrough, portal quirks included.
  2. Stand up the recurring layer: security awareness training with records, log reviews, access recertifications, and evidence filed per control as you go — not the night before an assessment.
  3. Maintain it: re-assess on material change, update the score as gaps close, diarize the annual affirmation, and keep the three-year clock in view.
The one step you can't defer: honesty at step 4. Every downstream document — score, SSP, POA&M, affirmation — inherits whatever fiction enters the assessment. With third-party certification paused, your self-assessment is the compliance mechanism, and an inflated one is False Claims Act exposure with your signature on it.

Steps 1–6, free — steps 7–8 generated

CMMC Map runs this exact sequence: scoping wizard, plain-English assessment of all 110, live SPRS score — free. The SSP, POA&M, and policies generate from your answers at $149/month when you reach the documentation phase.

Start the checklist free →
Free to assess · No credit card · Documents $149/mo