Every cybersecurity requirement a small defense contractor faces — the SPRS score your prime asks about, the SSP an assessor reads, CMMC itself — sits on one document: NIST Special Publication 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations." Understand it and the rest of the alphabet soup falls into place. Here's the whole thing in plain English.

The Problem It Solves

The government shares sensitive-but-unclassified information with contractors constantly — engineering drawings, technical specs, logistics data. That's CUI, and it lives on contractor laptops and servers the government doesn't control. NIST 800-171 is the government's answer to an obvious question: if our sensitive data sits on your systems, what's the minimum you must do to protect it? The answer is 110 specific security requirements.

Who Has to Comply

The standard binds through contracts, not statute. For defense work, DFARS 252.204-7012 requires implementing all 110 requirements and reporting cyber incidents within 72 hours; DFARS 252.204-7019/7020 add the scored self-assessment posted to SPRS and the government's right to verify. Primes must flow these down to subcontractors who touch CUI — which is why the request often arrives as a prime's questionnaire rather than anything from the government directly. Only handle FCI, not CUI? Then your obligation is the lighter Level 1 set, not 800-171.

What's Actually in It: 14 Families, 110 Requirements

The requirements group into 14 families — access control, authentication, audit logging, configuration management, incident response, media protection, physical security, and so on. Each requirement is one specific, checkable obligation ("limit unsuccessful logon attempts"), not a vague principle. We keep a plain-English translation of all 110 if you want to read the whole set in one sitting — with the point value each carries.

Point values, because compliance here is scored: the DoD Assessment Methodology weights every requirement 1, 3, or 5 points by security impact. You start at 110 and subtract for every gap, down to a floor of −203. That number is your SPRS score, and it must be posted — and no more than three years old — for you to win contracts carrying the clause.

The Paperwork the Standard Expects

Where CMMC and SPRS Fit

Think of it as one standard with three layers. NIST 800-171 says what to implement. SPRS is how you report it — the self-assessed score. CMMC is how the government verifies it — third-party assessment of the same 110 controls at Level 2 (the mapping is identity). The CMMC verification layer is suspended as of July 2026 pending reform; the implementation and reporting layers never paused. Whatever the reform produces, it will almost certainly still stand on this standard — which is why work against 800-171 is the safest investment in the whole space.

Rev 2 vs Rev 3, in One Paragraph

NIST published Revision 3 in 2024 (97 restructured requirements, 17 families), but DoD formally retained Revision 2 as the basis for DFARS compliance, SPRS, and CMMC until future rulemaking. Build to Rev 2 today; here's the full comparison and what to watch.

Getting Started, Realistically

  1. Confirm it applies: look for DFARS 252.204-7012 in your contracts and figure out whether you actually handle CUI.
  2. Scope tightly: the 110 requirements apply to systems touching CUI — a small boundary is the biggest cost lever you have.
  3. Assess honestly against all 110, score it, and post the score.
  4. Document: SSP, POA&M, policies, evidence.
  5. Operate: the recurring reviews and training that keep the score true, plus the annual affirmation.

The standard, as a guided walkthrough

CMMC Map turns NIST SP 800-171 into plain-English questions about your shop, scores you live against the DoD methodology, and generates the SSP and POA&M from your answers. The assessment is free — see where you stand before spending anything.

Start the free assessment →
Free to assess · No credit card · Documents $149/mo