Most self-assessments fail on one word. You read a requirement, you recognize the thing it describes, you think yes, we do that, and you mark it implemented. Then an assessor or a prime asks a follow-up question you cannot answer, and the requirement turns out to have been four or five separate questions all along.

The NIST 800-171A assessment objectives are those questions, written down. NIST Special Publication 800-171A, published in June 2018 as the companion to NIST SP 800-171 Revision 2, breaks all 110 security requirements into 320 numbered assessment objectives. Each objective produces one of exactly two findings: satisfied, or other than satisfied. For the requirement to count, every applicable objective has to land on satisfied.

The short version. Under the CMMC scoring rule at 32 CFR 170.24, a requirement is MET only when all applicable objectives are satisfied based on evidence, and that evidence must be in final form, not draft. One objective short and the whole requirement is NOT MET, with its full point value subtracted from your score.

What NIST 800-171A assessment objectives actually are

800-171A gives each of the 110 requirements an assessment procedure with three parts. First the assessment objective, a list of determination statements lettered [a], [b], [c] and so on. Then the potential assessment methods: examine (look at documents and configurations), interview (talk to the people who run the system), and test (exercise the mechanism and watch what it does). Then the assessment objects those methods apply to, such as policies, account lists, audit records, and administrators.

Eighty-seven of the 110 requirements are split into lettered objectives. The other 23 are single-statement requirements where the objective is the requirement itself. Add them up and you get 320 determinations. That number, not 110, is the real size of a Level 2 self-assessment.

The split matters because most requirements bundle an administrative act with a technical one. You are usually asked to identify something first, then to enforce something about it. Shops tend to do the enforcement and skip the identification, because firewalls and group policy are visible and lists are not.

Worked example one: 3.1.1, six objectives hiding in one sentence

Requirement 3.1.1 reads: limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems). It is a basic requirement worth five points. Here is what 800-171A actually asks.

ObjectiveThe questionWhat usually satisfies it
3.1.1[a]Authorized users are identifiedA current user list tied to real people, reconciled against HR or payroll, with terminations removed
3.1.1[b]Processes acting on behalf of authorized users are identifiedA list of service accounts, scheduled tasks and integrations, each with an owner
3.1.1[c]Devices (and other systems) authorized to connect are identifiedAn asset inventory: laptops, machines on the shop floor, the CAM workstation, the vendor VPN
3.1.1[d]Access is limited to authorized usersDirectory enforcement, no shared logins, disabled accounts for leavers
3.1.1[e]Access is limited to processes acting on behalf of usersService accounts scoped and not domain admin, API keys restricted
3.1.1[f]Access is limited to authorized devicesDevice compliance rules or network access control, guest wifi off the CUI network

A shop with Microsoft 365, a domain, and no shared passwords satisfies [d] comfortably. The same shop usually cannot produce a service account list for [b] or an asset inventory for [c]. Two objectives short means 3.1.1 is not implemented, and five points come off the top of your score. The identification objectives are also the cheapest to fix, which is why they belong at the front of the queue, not the back.

Worked example two: 3.5.3, the one requirement with partial credit

Requirement 3.5.3 reads: use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts. 800-171A splits it four ways.

Objective [a] is a list. Objective [b] is the one people miss: local access means signing in at the keyboard of the machine itself, not through the network, and most small shops have multifactor authentication on email and the VPN but not on the console of the domain controller or the server in the closet.

3.5.3 is also the headline exception to an otherwise brutal scoring rule. The NIST SP 800-171 DoD Assessment Methodology (version 1.2.1, June 24, 2020) says the methodology is not designed to credit partial implementation, then carves out multifactor authentication: subtract 5 points if it is not implemented, subtract 3 if it is implemented for remote and privileged users but not the general user. That is the whole allowance. There is more on how the arithmetic works in our guide to calculating your SPRS score, and you can run the numbers without an account on the free SPRS calculator.

Partly done is not done

The same DoD methodology settles the question every owner asks when a rollout is in flight. Its words: if the initial roll-out of 3.5.3, multifactor authentication, is only 75 percent complete, and there is a plan of action still being implemented, 3.5.3 will be considered not implemented. A plan of action is not a substitute for a completed requirement.

Two narrow exits exist under CMMC, and both are defined in 32 CFR 170.4. An enduring exception is a system where full compliance is not feasible, such as test equipment, operational technology, or a machine that has to replicate a fielded configuration. It is assessed as MET when it is described in the system security plan along with its mitigations, and it needs no plan of action. A temporary deficiency is a condition that arises after implementation, where a fix exists or is in progress, documented in an operational plan of action. It is explicitly not an excuse for an initial rollout that never finished.

Draft documents do not count. 32 CFR 170.24 rules out working papers, drafts, and unofficial or unapproved policies as evidence. A policy nobody signed and a procedure that exists only in a folder called Templates will both be read as an objective that is not satisfied.

Where the objectives sit in the three self-assessed paths

All three things a defense subcontractor can do for itself right now run on the same objectives. CMMC Level 1 (Self) covers the 15 basic safeguarding requirements of FAR 52.204-21 as 17 practices, and it is pass or fail: 32 CFR 170.24 requires every Level 1 requirement to be fully implemented, with no plan of action permitted. CMMC Level 2 (Self) covers all 110 requirements and is scored. The SPRS score you post for DFARS 252.204-7020 uses the same implemented or not implemented judgment on the same requirements. One honest pass through the objectives feeds all three. If you have not decided which applies to you, start with the Level 1 checklist and our walkthrough of doing a self-assessment properly.

A note on revisions, because it confuses people. NIST withdrew the June 2018 edition of 800-171A on May 14, 2024, superseded by 800-171A Revision 3, which pairs with NIST SP 800-171 Revision 3. Your contracts have not moved. Revision 2 remains the contractual baseline under the DoD class deviation, 32 CFR 170.24 scores against Revision 2, and the CMMC assessment guides carry the Revision 2 objectives. Use the 2018 objectives until a contract tells you otherwise, and keep an eye on what changes if Rev 3 arrives.

What to do this week

  1. Pull the objectives for your five-point requirements first. They cost the most when they fail. 3.1.1, 3.1.2, 3.5.1, 3.5.2, 3.5.3, 3.4.1, 3.4.2, 3.6.1 and the rest of the five-pointers are listed in 32 CFR 170.24 and in the DoD methodology template.
  2. Write the three lists. Users, service accounts and processes, devices. Those three artifacts alone satisfy or support objectives across 3.1.1, 3.4.1, 3.5.1 and 3.12.4.
  3. Check local access on multifactor authentication. Sign in at the console of a server and see whether anything asks for a second factor. If nothing does, 3.5.3[b] is not satisfied no matter how good your email setup is.
  4. Sign the drafts. Anything you intend to hand an assessor needs a date, an approver, and a version. Draft evidence is treated as no evidence.
  5. Record the objective, not the requirement. When you mark something done, write down which objective the evidence answers and where the evidence lives. That note is the difference between a score you can defend and a number you guessed.

CMMC Map, CMMC compliance software for small defense contractors, walks the 110 requirements objective by objective and keeps the evidence pointer next to each one. The assessment and the live SPRS score are free forever. The generated system security plan, plan of action, policies and readiness report are the one paid plan at $149 a month. There is also a full breakdown of all 110 requirements in plain English if you would rather read first.

This is explanatory content about contractual requirements, not legal advice. Your contract clauses and your prime's flowdown letter govern.

Find out which requirements you can actually evidence

The CMMC Map assessment walks all 110 requirements and gives you a live SPRS score, free, with no credit card.

Start free in CMMC Map
Free to assess · Documents $149/mo · No credit card