Free · no signup · nothing leaves your browser

SPRS score calculator for NIST SP 800-171

Mark each of the 110 controls Met, Not met, or N/A. Your score updates live, from 110 down to -203, using the DoD Assessment Methodology v1.2.1 weights. Every control is explained in plain English.

-203of 110
0 met110 open313 points deducted
Save this in CMMC Map

Unanswered controls count as Not met, the way DoD scores them. Controls marked N/A deduct nothing, but only if your SSP explains why they do not apply. Rows tinted gold are also CMMC Level 1 controls.

Access Control (AC)0 / 22 met
3.1.1
5 pts
LEVEL 1
Authorized Access Control
Only people you have approved can get into systems holding CUI, each with their own account, on devices you control.
Official requirement and what Met looks like
NIST SP 800-171 3.1.1: Limit information system access to authorized users, processes acting on behalf of authorized users, or devices.
Met means: Every user is listed and approved, no shared logins, and only company-managed devices reach CUI.
3.1.2
5 pts
LEVEL 1
Transaction & Function Control
People can only do what their job requires, a bookkeeper should not be able to change security settings.
Official requirement and what Met looks like
NIST SP 800-171 3.1.2: Limit information system access to the types of transactions and functions that authorized users are permitted to execute.
Met means: Permissions follow roles; nobody has more access than their job needs.
3.1.3
1 pt
CUI Flow Enforcement
Control where CUI is allowed to move, it must not flow to personal email, random cloud apps, or anywhere outside your approved systems.
Official requirement and what Met looks like
NIST SP 800-171 3.1.3: Control the flow of CUI in accordance with approved authorizations.
Met means: CUI stays inside approved systems (e.g., PreVeil); outside sharing is blocked or forbidden in writing and actually followed.
3.1.4
1 pt
Separation of Duties
Split risky duties so no one person can do damage alone, e.g., the person making admin changes is not the only one reviewing what admins did.
Official requirement and what Met looks like
NIST SP 800-171 3.1.4: Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
Met means: Admin and user duties separated; in a tiny shop, separate accounts plus the owner reviewing admin activity.
3.1.5
3 pts
Least Privilege
Give everyone the least access needed, including admins, who should hold admin rights only where required.
Official requirement and what Met looks like
NIST SP 800-171 3.1.5: Employ the principle of least privilege, including for specific security functions and privileged accounts.
Met means: Access reviewed and trimmed to minimum; admin rights limited to named people.
3.1.6
1 pt
Non-Privileged Account Use
Admins use a normal account for email and browsing, and a separate admin account only for admin tasks.
Official requirement and what Met looks like
NIST SP 800-171 3.1.6: Use non-privileged accounts or roles when accessing nonsecurity functions.
Met means: Two accounts per admin; the admin account is never used for daily work.
3.1.7
1 pt
Privileged Function Logging
Regular users technically cannot run admin functions, and admin actions get logged.
Official requirement and what Met looks like
NIST SP 800-171 3.1.7: Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.
Met means: Standard users have no admin rights; admin activity shows up in audit logs.
3.1.8
1 pt
Unsuccessful Logon Attempts
Lock accounts after repeated wrong passwords so attackers cannot guess forever.
Official requirement and what Met looks like
NIST SP 800-171 3.1.8: Limit unsuccessful logon attempts.
Met means: Account locks after a set number of failed tries (e.g., 10) for a set time.
3.1.9
1 pt
Privacy & Security Notices
Show a notice at sign-in telling users the system is for authorized use and may be monitored.
Official requirement and what Met looks like
NIST SP 800-171 3.1.9: Provide privacy and security notices consistent with applicable CUI rules.
Met means: A login banner or sign-in message appears before access.
3.1.10
1 pt
Session Lock
Screens lock automatically when idle and hide whatever was showing.
Official requirement and what Met looks like
NIST SP 800-171 3.1.10: Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.
Met means: Auto-lock at 15 minutes or less, password to resume, on every device that touches CUI.
3.1.11
1 pt
Session Termination
Sessions end by themselves after a defined condition, nobody stays logged in forever.
Official requirement and what Met looks like
NIST SP 800-171 3.1.11: Terminate (automatically) a user session after a defined condition.
Met means: Web/app sessions expire on a defined rule and require re-login.
3.1.12
5 pts
Remote Access Control
Remote access happens only through approved doors you can watch, no random remote-desktop tools.
Official requirement and what Met looks like
NIST SP 800-171 3.1.12: Monitor and control remote access sessions.
Met means: Remote access only via your approved platform; sign-ins are logged and reviewable.
3.1.13
5 pts
Remote Access Encryption
Remote sessions are encrypted, period.
Official requirement and what Met looks like
NIST SP 800-171 3.1.13: Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
Met means: All remote access rides TLS or VPN encryption, no unencrypted paths.
3.1.14
1 pt
Remote Access Routing
All remote access funnels through specific, controlled entry points.
Official requirement and what Met looks like
NIST SP 800-171 3.1.14: Route remote access via managed access control points.
Met means: One defined gateway (cloud sign-in or VPN concentrator), no side doors.
3.1.15
1 pt
Privileged Remote Access
Decide in advance who may run admin commands remotely, and write it down.
Official requirement and what Met looks like
NIST SP 800-171 3.1.15: Authorize remote access for privileged commands and security-relevant information.
Met means: Named admins only, documented, working from managed devices.
3.1.16
5 pts
Wireless Access Authorization
Approve Wi-Fi networks before they are allowed anywhere near CUI systems.
Official requirement and what Met looks like
NIST SP 800-171 3.1.16: Authorize wireless access prior to allowing such connections.
Met means: Each Wi-Fi network documented and authorized; guest Wi-Fi separate. N/A only if truly no wireless.
3.1.17
5 pts
Wireless Access Protection
Wi-Fi requires a password AND strong encryption (WPA2/WPA3).
Official requirement and what Met looks like
NIST SP 800-171 3.1.17: Protect wireless access using authentication and encryption.
Met means: No open or outdated (WEP) Wi-Fi anywhere CUI is used, home office included.
3.1.18
5 pts
Mobile Device Connection
Decide which phones and tablets may connect, and control them.
Official requirement and what Met looks like
NIST SP 800-171 3.1.18: Control connection of mobile devices.
Met means: Only enrolled/approved mobile devices reach CUI; everything else blocked. N/A if mobile never touches CUI.
3.1.19
3 pts
Mobile Device Encryption
If CUI can land on a phone or laptop, it must be encrypted there.
Official requirement and what Met looks like
NIST SP 800-171 3.1.19: Encrypt CUI on mobile devices and mobile computing platforms.
Met means: Device encryption on (BitLocker / FileVault / phone encryption) wherever CUI can land.
3.1.20
1 pt
LEVEL 1
External System Connections
Check and limit connections to systems you do not control, personal devices, other companies’ networks.
Official requirement and what Met looks like
NIST SP 800-171 3.1.20: Verify and control/limit connections to and use of external information systems.
Met means: CUI accessed only from your own systems; any exception verified and approved in writing.
3.1.21
1 pt
Portable Storage Use
Do not put CUI on portable drives for use on outside systems.
Official requirement and what Met looks like
NIST SP 800-171 3.1.21: Limit use of portable storage devices on external systems.
Met means: Policy plus practice: no CUI on USB sticks headed anywhere external.
3.1.22
1 pt
LEVEL 1
Publicly Accessible Content
Make sure nobody posts CUI on your website or social media.
Official requirement and what Met looks like
NIST SP 800-171 3.1.22: Control information posted or processed on publicly accessible information systems.
Met means: Someone who knows what CUI is reviews public posts before they go live.
Awareness & Training (AT)0 / 3 met
3.2.1
5 pts
Security Awareness
Everyone who touches CUI gets security awareness training, before access, then yearly.
Official requirement and what Met looks like
NIST SP 800-171 3.2.1: Ensure managers, administrators, and users are aware of security risks and applicable policies.
Met means: Training completed and recorded for all staff; new people trained before CUI access.
3.2.2
5 pts
Role-Based Training
People are trained for their specific security duties (admin work, CUI handling), not just generic awareness.
Official requirement and what Met looks like
NIST SP 800-171 3.2.2: Ensure personnel are trained to carry out their assigned information security-related duties.
Met means: Role-specific training delivered and documented for each duty.
3.2.3
1 pt
Insider Threat Awareness
Yearly training covers spotting and reporting insider threats.
Official requirement and what Met looks like
NIST SP 800-171 3.2.3: Provide security awareness training on recognizing and reporting potential indicators of insider threat.
Met means: Insider-threat content included in training, completion recorded.
Audit & Accountability (AU)0 / 9 met
3.3.1
5 pts
System Auditing
Systems keep logs of who did what, logins, file access, changes, and you keep those logs.
Official requirement and what Met looks like
NIST SP 800-171 3.3.1: Create and retain audit logs to enable monitoring, analysis, investigation, and reporting of unauthorized activity.
Met means: Logging enabled on CUI systems and retained about 12 months.
3.3.2
3 pts
User Accountability
Logs can tie every action to one specific person, which requires individual accounts.
Official requirement and what Met looks like
NIST SP 800-171 3.3.2: Ensure actions can be uniquely traced to individual users.
Met means: No shared accounts anywhere; logs show the individual user.
3.3.3
1 pt
Event Review
Once a year, sanity-check that you are logging the right kinds of events.
Official requirement and what Met looks like
NIST SP 800-171 3.3.3: Review and update logged events.
Met means: A documented annual review of what gets logged.
3.3.4
1 pt
Audit Failure Alerting
Get alerted if logging breaks or storage fills up.
Official requirement and what Met looks like
NIST SP 800-171 3.3.4: Alert in the event of an audit logging process failure.
Met means: An alert fires when logs stop collecting, and someone responds.
3.3.5
5 pts
Audit Record Correlation
Actually review the logs, connecting dots across systems to spot suspicious activity.
Official requirement and what Met looks like
NIST SP 800-171 3.3.5: Correlate audit review, analysis, and reporting to support investigation of suspicious activities.
Met means: Documented log review at least monthly.
3.3.6
1 pt
Audit Reduction & Reporting
Be able to search, filter, and report on logs when investigating.
Official requirement and what Met looks like
NIST SP 800-171 3.3.6: Provide audit record reduction and report generation for on-demand analysis.
Met means: Your tools can search and export log data on demand.
3.3.7
1 pt
Authoritative Time Source
All system clocks sync to a standard time source so log timestamps line up.
Official requirement and what Met looks like
NIST SP 800-171 3.3.7: Synchronize system clocks with authoritative source for audit timestamps.
Met means: Automatic time sync everywhere (cloud systems do this by default).
3.3.8
1 pt
Audit Protection
Logs are protected: users cannot edit or delete them.
Official requirement and what Met looks like
NIST SP 800-171 3.3.8: Protect audit information from unauthorized access, modification, and deletion.
Met means: Only admins can reach log settings; platform logs are tamper-resistant.
3.3.9
1 pt
Audit Management Protection
Only a small, named set of admins can manage the logging itself.
Official requirement and what Met looks like
NIST SP 800-171 3.3.9: Limit management of audit logging to privileged users.
Met means: Log management limited to specific people, listed in your SSP.
Configuration Management (CM)0 / 9 met
3.4.1
5 pts
System Baselining
Keep a baseline: what “correctly configured” looks like, plus an inventory of your hardware and software.
Official requirement and what Met looks like
NIST SP 800-171 3.4.1: Establish and maintain baseline configurations and inventories.
Met means: A written baseline and a current inventory, updated when things change.
3.4.2
5 pts
Security Configuration Enforcement
Enforce secure settings with tools, not habit.
Official requirement and what Met looks like
NIST SP 800-171 3.4.2: Establish and enforce security configuration settings.
Met means: Security settings pushed by policy (M365/Intune or similar), not manual goodwill.
3.4.3
1 pt
System Change Tracking
Track and approve changes to CUI systems before making them.
Official requirement and what Met looks like
NIST SP 800-171 3.4.3: Track, review, approve, and log changes.
Met means: A change log exists: what changed, who approved it, when.
3.4.4
1 pt
Security Impact Analysis
Before any change, ask “does this affect security?” and write the answer down.
Official requirement and what Met looks like
NIST SP 800-171 3.4.4: Analyze security impact of changes prior to implementation.
Met means: Change records include a security-impact note.
3.4.5
5 pts
Access Restrictions for Change
Only authorized people can make changes, physically and logically.
Official requirement and what Met looks like
NIST SP 800-171 3.4.5: Enforce physical and logical access restrictions for changes.
Met means: Standard users cannot change configurations; change rights are documented.
3.4.6
5 pts
Least Functionality
Turn off what you do not use, features, services, ports.
Official requirement and what Met looks like
NIST SP 800-171 3.4.6: Configure systems to provide only essential capabilities.
Met means: Unused services and features disabled in your baseline.
3.4.7
5 pts
Nonessential Functionality Restriction
Specifically identify and restrict nonessential programs, ports, and services.
Official requirement and what Met looks like
NIST SP 800-171 3.4.7: Restrict nonessential programs, ports, protocols, and services.
Met means: Your baseline review names what was evaluated and restricted.
3.4.8
5 pts
Application Execution Policy
Only approved software can run, deny by default.
Official requirement and what Met looks like
NIST SP 800-171 3.4.8: Apply deny-by-exception or deny-all, permit-by-exception policy.
Met means: An approved-software list plus technical blocking of everything else.
3.4.9
1 pt
User-Installed Software
Users cannot install their own software.
Official requirement and what Met looks like
NIST SP 800-171 3.4.9: Control and monitor user-installed software.
Met means: Installs require admin rights that users do not have.
Identification & Authentication (IA)0 / 11 met
3.5.1
5 pts
LEVEL 1
User Identification
Every user, device, and process has its own identity.
Official requirement and what Met looks like
NIST SP 800-171 3.5.1: Identify users, processes, and devices.
Met means: Individual accounts for everyone; devices identified through enrollment.
3.5.2
5 pts
LEVEL 1
Device & Process Authentication
Verify identity before granting access, real authentication everywhere.
Official requirement and what Met looks like
NIST SP 800-171 3.5.2: Authenticate identities before allowing access.
Met means: Passwords plus MFA via your identity platform; no factory-default credentials anywhere.
3.5.3
5 pts
Multifactor Authentication
MFA on privileged accounts always, and on any network access for everyone else.
Official requirement and what Met looks like
NIST SP 800-171 3.5.3: Use MFA for local and network access.
Met means: MFA enforced on every account that can reach CUI. Use ◐ Partial if only remote/admins have it today.
3.5.4
1 pt
Replay-Resistant Authentication
Sign-ins resist capture-and-replay attacks, modern cloud login with MFA already does this.
Official requirement and what Met looks like
NIST SP 800-171 3.5.4: Employ replay-resistant authentication.
Met means: Modern authentication (M365/PreVeil) with legacy protocols turned off.
3.5.5
1 pt
Identifier Reuse Prevention
Do not recycle usernames to new people for a long time.
Official requirement and what Met looks like
NIST SP 800-171 3.5.5: Prevent reuse of identifiers.
Met means: Departed users’ accounts disabled and their identifiers not reused for ~2 years.
3.5.6
1 pt
Identifier Inactivity
Disable accounts nobody has used in 90 days.
Official requirement and what Met looks like
NIST SP 800-171 3.5.6: Disable identifiers after inactivity period.
Met means: Inactive accounts disabled automatically or caught in a quarterly review.
3.5.7
1 pt
Password Complexity
Enforce password strength rules whenever passwords are created or changed.
Official requirement and what Met looks like
NIST SP 800-171 3.5.7: Enforce minimum password complexity.
Met means: Minimum length/complexity enforced by the system (e.g., 12+ characters).
3.5.8
1 pt
Password Reuse Prevention
Block reuse of recent passwords.
Official requirement and what Met looks like
NIST SP 800-171 3.5.8: Prohibit password reuse.
Met means: Password history enforced (e.g., last 10 blocked).
3.5.9
1 pt
Temporary Passwords
Temporary passwords must be changed immediately at first sign-in.
Official requirement and what Met looks like
NIST SP 800-171 3.5.9: Require immediate change from temporary passwords.
Met means: The system forces a reset on first use.
3.5.10
5 pts
Cryptographic Password Storage
Passwords are stored and sent only in protected (hashed/encrypted) form: never plain-text files.
Official requirement and what Met looks like
NIST SP 800-171 3.5.10: Store and transmit only cryptographically-protected passwords.
Met means: Your identity platform handles it; no passwords living in spreadsheets or sticky notes.
3.5.11
1 pt
Obscured Authentication Feedback
Hide passwords as they are typed, and do not reveal which half of a failed login was wrong.
Official requirement and what Met looks like
NIST SP 800-171 3.5.11: Obscure feedback of authentication information.
Met means: Standard masked entry: default in modern systems.
Incident Response (IR)0 / 3 met
3.6.1
5 pts
Incident Handling
Have a working plan to detect, contain, and recover from security incidents, with people who know their roles.
Official requirement and what Met looks like
NIST SP 800-171 3.6.1: Establish incident-handling capability across all phases.
Met means: A written IR plan, current contact list, and tested backups.
3.6.2
5 pts
Incident Reporting & Tracking
Track and document incidents, and report them to the right people, including DoD via DIBNet within 72 hours when CUI is involved.
Official requirement and what Met looks like
NIST SP 800-171 3.6.2: Track, document, and report incidents.
Met means: An incident log plus a written DIBNet reporting procedure with the 72-hour clock.
3.6.3
1 pt
Incident Response Testing
Test the plan at least yearly, a tabletop walkthrough counts.
Official requirement and what Met looks like
NIST SP 800-171 3.6.3: Test incident response capability.
Met means: A dated exercise record with lessons learned.
Maintenance (MA)0 / 6 met
3.7.1
3 pts
System Maintenance
Maintain your systems: patches, repairs: and document the work.
Official requirement and what Met looks like
NIST SP 800-171 3.7.1: Perform maintenance on systems.
Met means: Patching happens on schedule and a maintenance log exists.
3.7.2
5 pts
Maintenance Control
Control the tools, methods, and people doing maintenance.
Official requirement and what Met looks like
NIST SP 800-171 3.7.2: Control maintenance tools, techniques, and personnel.
Met means: Approved tools and vendors only, documented.
3.7.3
1 pt
Offsite Maintenance Sanitization
Wipe CUI off equipment before it leaves the building for repair.
Official requirement and what Met looks like
NIST SP 800-171 3.7.3: Sanitize equipment removed for off-site maintenance.
Met means: Drives wiped or removed before off-site service, and recorded.
3.7.4
3 pts
Maintenance Media Inspection
Scan diagnostic tools and media for malware before they touch CUI systems.
Official requirement and what Met looks like
NIST SP 800-171 3.7.4: Check media for malicious code before use.
Met means: Antivirus scan of vendor tools or USB before use.
3.7.5
5 pts
Remote Maintenance MFA
Remote maintenance sessions require MFA and get shut down when the work is done.
Official requirement and what Met looks like
NIST SP 800-171 3.7.5: Require MFA for remote maintenance sessions.
Met means: Vendor remote sessions use MFA, then get closed and their credentials revoked.
3.7.6
1 pt
Maintenance Personnel Supervision
Supervise maintenance people who are not cleared for CUI.
Official requirement and what Met looks like
NIST SP 800-171 3.7.6: Supervise unauthorized maintenance personnel.
Met means: An escort/supervision rule that is actually followed and noted.
Media Protection (MP)0 / 9 met
3.8.1
3 pts
Media Protection
Protect and securely store anything that holds CUI, paper or digital.
Official requirement and what Met looks like
NIST SP 800-171 3.8.1: Protect system media containing CUI.
Met means: Locked storage for paper and media; encrypted storage for digital.
3.8.2
3 pts
Media Access Restriction
Only authorized people can get at CUI media.
Official requirement and what Met looks like
NIST SP 800-171 3.8.2: Limit access to CUI on media.
Met means: Keys and codes limited to CUI-authorized staff.
3.8.3
5 pts
LEVEL 1
Media Sanitization
Destroy or properly wipe CUI media before disposal, shred the paper, wipe the drives.
Official requirement and what Met looks like
NIST SP 800-171 3.8.3: Sanitize or destroy media before disposal.
Met means: Cross-cut shredder plus documented drive wiping; nothing with CUI goes in the trash.
3.8.4
1 pt
Media Marking
Label CUI media so people know what they are holding.
Official requirement and what Met looks like
NIST SP 800-171 3.8.4: Mark media with CUI markings.
Met means: CUI markings on printed documents; labels on any authorized media.
3.8.5
1 pt
Media Accountability
Track and control CUI media that leaves your site.
Official requirement and what Met looks like
NIST SP 800-171 3.8.5: Maintain accountability for media during transport.
Met means: Hand-carry or tracked courier plus a transport record. Rare event for a COTS shop.
3.8.6
1 pt
Portable Storage Encryption
Encrypt CUI on media in transit unless it is physically guarded the whole way.
Official requirement and what Met looks like
NIST SP 800-171 3.8.6: Encrypt CUI on digital media during transport.
Met means: Encrypted drive or encrypted container for anything shipped or carried.
3.8.7
5 pts
Removable Media Control
Control the use of USB and removable media on CUI systems.
Official requirement and what Met looks like
NIST SP 800-171 3.8.7: Control use of removable media.
Met means: USB storage blocked by default, or restricted to approved encrypted devices.
3.8.8
3 pts
Unidentified Media Prohibition
Never use a storage device whose owner you cannot identify.
Official requirement and what Met looks like
NIST SP 800-171 3.8.8: Prohibit unidentifiable portable storage.
Met means: Found or unknown drives never get plugged in, policy plus training.
3.8.9
1 pt
Backup Media Protection
Backups containing CUI are protected too.
Official requirement and what Met looks like
NIST SP 800-171 3.8.9: Protect backup CUI confidentiality.
Met means: Encrypted backups with restricted access.
Personnel Security (PS)0 / 2 met
3.9.1
3 pts
Personnel Screening
Screen people (background check) before giving them CUI access.
Official requirement and what Met looks like
NIST SP 800-171 3.9.1: Screen individuals prior to CUI access.
Met means: Documented screening before access, for everyone who touches CUI.
3.9.2
5 pts
Personnel Actions
When someone leaves or changes roles, cut their CUI access fast and get the equipment back.
Official requirement and what Met looks like
NIST SP 800-171 3.9.2: Protect CUI during personnel actions.
Met means: Offboarding checklist: access revoked within ~24 hours, gear recovered.
Physical Protection (PE)0 / 6 met
3.10.1
5 pts
LEVEL 1
Physical Access Limitation
Limit who can physically reach the computers and papers holding CUI.
Official requirement and what Met looks like
NIST SP 800-171 3.10.1: Limit physical access to systems and equipment.
Met means: Locked office or room with keys held only by authorized people. Home office: a private, lockable space.
3.10.2
5 pts
Facility Protection
Protect and keep an eye on the facility itself.
Official requirement and what Met looks like
NIST SP 800-171 3.10.2: Protect and monitor the physical facility.
Met means: Locks plus alarm or monitoring appropriate to the space.
3.10.3
1 pt
LEVEL 1
Visitor Escort
Escort visitors anywhere CUI lives.
Official requirement and what Met looks like
NIST SP 800-171 3.10.3: Escort visitors and monitor activity.
Met means: No unescorted visitors: rule known and followed.
3.10.4
1 pt
LEVEL 1
Physical Access Logs
Keep a record of physical access, a visitor log counts.
Official requirement and what Met looks like
NIST SP 800-171 3.10.4: Maintain physical access audit logs.
Met means: A visitor log, retained about 12 months.
3.10.5
1 pt
LEVEL 1
Physical Access Devices
Track keys, badges, and door codes, and recover them when people leave.
Official requirement and what Met looks like
NIST SP 800-171 3.10.5: Control physical access devices.
Met means: An issuance list; lost keys mean changed locks.
3.10.6
1 pt
Alternative Work Site Security
Protect CUI at home offices and on travel with the same intent as at the office.
Official requirement and what Met looks like
NIST SP 800-171 3.10.6: Enforce safeguards at alternate work sites.
Met means: Written telework rules: private workspace, encrypted devices, screens shielded from view.
Risk Assessment (RA)0 / 3 met
3.11.1
3 pts
Risk Assessments
At least yearly, step back and assess: what could hurt our CUI, and how likely is it?
Official requirement and what Met looks like
NIST SP 800-171 3.11.1: Periodically assess organizational risk.
Met means: A dated risk assessment write-up exists.
3.11.2
5 pts
Vulnerability Scanning
Scan systems for vulnerabilities regularly, and when big new ones hit the news.
Official requirement and what Met looks like
NIST SP 800-171 3.11.2: Scan for vulnerabilities periodically.
Met means: Quarterly scan results (your endpoint tool or M365 secure score reporting counts).
3.11.3
1 pt
Vulnerability Remediation
Fix the vulnerabilities you find, ordered by severity.
Official requirement and what Met looks like
NIST SP 800-171 3.11.3: Remediate vulnerabilities per risk assessments.
Met means: Findings tracked to closure with timelines (critical in ~15 days).
Security Assessment (CA)0 / 4 met
3.12.1
5 pts
Security Control Assessment
Test your own controls at least yearly, are they real and working?
Official requirement and what Met looks like
NIST SP 800-171 3.12.1: Periodically assess security controls.
Met means: An annual self-assessment record (this app’s reports count).
3.12.2
3 pts
Plan of Action
Keep a POA&M: a dated to-do list for every gap, with owners and deadlines.
Official requirement and what Met looks like
NIST SP 800-171 3.12.2: Develop plans to correct deficiencies.
Met means: POA&M current and reviewed monthly.
3.12.3
5 pts
Continuous Monitoring
Monitor continuously: small recurring checks like log reviews, access reviews, and scans.
Official requirement and what Met looks like
NIST SP 800-171 3.12.3: Monitor controls on an ongoing basis.
Met means: A monitoring calendar with completed entries.
3.12.4
no points · gates the SPRS submission
System Security Plan
Have a System Security Plan describing your boundary and how each control is handled.
Official requirement and what Met looks like
NIST SP 800-171 3.12.4: Develop, document, and update the SSP.
Met means: A current SSP: you need one even to submit a SPRS score.
System & Communications Protection (SC)0 / 16 met
3.13.1
5 pts
LEVEL 1
Boundary Protection
Guard the borders of your network and systems, firewall on-prem, controlled sign-in for cloud.
Official requirement and what Met looks like
NIST SP 800-171 3.13.1: Monitor, control, and protect communications at boundaries.
Met means: Firewall with default-deny inbound; cloud access only through your controlled login.
3.13.2
5 pts
Security Engineering
Build security in when you buy or configure systems, do not bolt it on later.
Official requirement and what Met looks like
NIST SP 800-171 3.13.2: Employ architectural designs promoting security.
Met means: Secure-by-default choices documented: FedRAMP cloud services, hardened settings.
3.13.3
1 pt
Role-Based Security
Separate everyday use from system administration.
Official requirement and what Met looks like
NIST SP 800-171 3.13.3: Separate user from management functionality.
Met means: Admin portals and admin accounts separate from daily-use accounts.
3.13.4
1 pt
Shared Resource Control
Stop information from leaking between users through shared resources.
Official requirement and what Met looks like
NIST SP 800-171 3.13.4: Prevent unauthorized transfer via shared resources.
Met means: Cloud tenant isolation plus per-user profiles, largely platform-provided.
3.13.5
5 pts
LEVEL 1
Public Network Protection
Anything public-facing sits separated from your internal systems.
Official requirement and what Met looks like
NIST SP 800-171 3.13.5: Separate publicly accessible components.
Met means: Public website hosted outside the CUI environment. Often an easy Met for a COTS shop.
3.13.6
5 pts
Network Communication by Exception
Network traffic is denied by default and allowed only by exception.
Official requirement and what Met looks like
NIST SP 800-171 3.13.6: Deny by default, allow by exception.
Met means: Firewall blocks all inbound except what is documented as needed.
3.13.7
1 pt
Split Tunneling Prevention
No split tunneling: a remote device must not bridge your protected path and the open internet around your controls.
Official requirement and what Met looks like
NIST SP 800-171 3.13.7: Prevent split tunneling.
Met means: VPN configured against split tunnel, or all CUI access terminates at the cloud platform over TLS.
3.13.8
3 pts
CUI in Transit Encryption
Encrypt CUI whenever it travels across a network.
Official requirement and what Met looks like
NIST SP 800-171 3.13.8: Encrypt CUI during transmission.
Met means: TLS everywhere CUI moves; no plain FTP/HTTP, no unencrypted email for CUI.
3.13.9
1 pt
Network Disconnect
Network connections close when sessions end or sit idle.
Official requirement and what Met looks like
NIST SP 800-171 3.13.9: Terminate connections after inactivity.
Met means: Session and idle timeouts configured.
3.13.10
1 pt
Cryptographic Key Management
Manage your encryption keys, including device recovery keys, deliberately.
Official requirement and what Met looks like
NIST SP 800-171 3.13.10: Manage cryptographic keys.
Met means: Recovery keys escrowed somewhere safe; key handling written down.
3.13.11
5 pts
FIPS-Validated Cryptography
The encryption protecting CUI must be FIPS-validated, the specific certified kind. This one trips up almost everyone.
Official requirement and what Met looks like
NIST SP 800-171 3.13.11: Use FIPS-validated cryptography for CUI.
Met means: FIPS-validated modules in use and noted in the SSP (PreVeil qualifies). ◐ Partial if encrypted but not FIPS-validated.
3.13.12
1 pt
Collaborative Device Control
Cameras and microphones must not be remotely switched on without the user knowing.
Official requirement and what Met looks like
NIST SP 800-171 3.13.12: Prohibit remote activation of collaborative devices.
Met means: Conferencing tools with indicator lights and no remote activation, usually an easy Met.
3.13.13
1 pt
Mobile Code Control
Control risky active content, macros, plug-ins, scripts.
Official requirement and what Met looks like
NIST SP 800-171 3.13.13: Control mobile code.
Met means: Internet-sourced macros blocked; browser extensions restricted.
3.13.14
1 pt
Voice over IP
Control VoIP phone technology if you use it.
Official requirement and what Met looks like
NIST SP 800-171 3.13.14: Control VoIP.
Met means: Approved VoIP services only. N/A if you have no VoIP.
3.13.15
5 pts
Communication Authenticity
Protect sessions from hijacking, modern authenticated TLS handles this.
Official requirement and what Met looks like
NIST SP 800-171 3.13.15: Protect communication authenticity.
Met means: A modern cloud auth platform typically means Met.
3.13.16
1 pt
CUI at Rest Encryption
Encrypt CUI where it is stored (at rest).
Official requirement and what Met looks like
NIST SP 800-171 3.13.16: Protect CUI at rest.
Met means: Disk and cloud encryption everywhere CUI sits, including that desktop.
System & Information Integrity (SI)0 / 7 met
3.14.1
5 pts
LEVEL 1
Flaw Remediation
Patch security flaws promptly.
Official requirement and what Met looks like
NIST SP 800-171 3.14.1: Identify, report, and correct flaws timely.
Met means: Updates applied on a schedule (critical in ~15 days) and verified.
3.14.2
5 pts
LEVEL 1
Malicious Code Protection
Run malware protection where it matters, every computer, plus email.
Official requirement and what Met looks like
NIST SP 800-171 3.14.2: Provide malicious code protection.
Met means: AV/EDR on every machine; email filtering on.
3.14.3
5 pts
Security Alerts & Advisories
Watch security alerts (CISA, vendors) and act on the ones that apply to you.
Official requirement and what Met looks like
NIST SP 800-171 3.14.3: Monitor and respond to security alerts.
Met means: Someone checks advisories regularly and records what was done.
3.14.4
5 pts
LEVEL 1
Malicious Code Updates
Keep malware protection itself up to date.
Official requirement and what Met looks like
NIST SP 800-171 3.14.4: Update malicious code protection.
Met means: Auto-updates on, spot-checked periodically.
3.14.5
3 pts
LEVEL 1
System & File Scanning
Scan on a schedule, and scan files from outside in real time.
Official requirement and what Met looks like
NIST SP 800-171 3.14.5: Perform periodic and real-time scans.
Met means: Real-time scanning on, plus periodic full scans.
3.14.6
5 pts
Inbound/Outbound Traffic Monitoring
Watch traffic and systems for signs of attack.
Official requirement and what Met looks like
NIST SP 800-171 3.14.6: Monitor traffic for attacks.
Met means: EDR or cloud alerts on anomalies, and someone reviews them.
3.14.7
3 pts
Unauthorized Use Detection
Be able to spot unauthorized use of your systems.
Official requirement and what Met looks like
NIST SP 800-171 3.14.7: Identify unauthorized use.
Met means: Alerts and reviews that would catch odd sign-ins or strange activity.

Where your points went

Biggest deductions first. Fixing the 5-point controls moves the score fastest, and they are the ones DoD will not let you leave open on a POA&M.

    How the SPRS score works

    The Supplier Performance Risk System score is DoD's shorthand for how much of NIST SP 800-171 Revision 2 you have actually implemented. It is a self-assessment: you score it, your Affirming Official signs it, and it goes into SPRS under DFARS 252.204-7019 and 7020 before any contract that involves CUI can be awarded.

    110the starting score, one point per control, and the only score that means "fully implemented"
    5 · 3 · 1the weights in DoD Assessment Methodology v1.2.1. Each unmet control subtracts its weight
    -203the floor if nothing is implemented. Most first assessments land well below zero

    Partial credit, and the one control with no points

    Only two controls earn partial credit, and only while a plan is in progress: multi-factor authentication (3.5.3) and FIPS-validated cryptography (3.13.11) deduct 3 instead of 5. Control 3.12.4, the System Security Plan, carries no points at all because DoD will not accept a submission without a current SSP. It is the document every other answer hangs on.

    What the number does not tell you

    A score below 110 is allowed only with a Plan of Action and Milestones that gives every open control a date. Under the CMMC Level 2 self-assessment rules, 5-point and 3-point controls cannot stay on a POA&M at all. So "we're at 74 with a POA&M" can still be a failing self-assessment. And because certification is paused and the score is signed, an overstated score is a False Claims Act exposure rather than an audit finding.

    Scoring here uses NIST SP 800-171 Revision 2 and DoD Assessment Methodology v1.2.1, the basis DoD uses for SPRS. Revision 3 has not been adopted for scoring.

    Frequently asked

    How is an SPRS score calculated?
    Start at 110 and subtract the weight of every NIST SP 800-171 control that is not fully implemented: 5 points for the highest-impact controls, 3 for the next tier, 1 for the rest. The lowest possible score is -203. Two controls get partial credit while a plan is in progress: multi-factor authentication (3.5.3) and FIPS-validated cryptography (3.13.11) deduct 3 instead of 5. Control 3.12.4, the System Security Plan, has no point value, but DoD will not accept an SPRS submission without one.
    What is a good SPRS score?
    110 means every control is implemented. Anything below 110 is allowed only with a Plan of Action and Milestones that gives a date for each open control. Under the CMMC Level 2 self-assessment rules, 5-point and 3-point controls cannot stay open on a POA&M, so a score that relies on them is not the same as a passing self-assessment.
    Do I have to submit my SPRS score?
    Yes, if you handle Controlled Unclassified Information under DFARS 252.204-7012. DFARS 252.204-7019 and 7020 require a current NIST SP 800-171 self-assessment score in the Supplier Performance Risk System before award, and the score must be no more than three years old. Your Affirming Official signs it, so an overstated score is a False Claims Act exposure, not just an audit finding.
    Does this calculator save or send my answers?
    No. Scoring runs in your browser. Your selections stay in this browser's local storage so you can come back to them, and you can clear them with Reset. To keep a scored assessment with evidence, a gap list, and generated documents, open the same 110 controls in CMMC Map, which is free to assess.
    Which version of NIST SP 800-171 does this use?
    Revision 2, with the 110 controls and weights in the DoD Assessment Methodology version 1.2.1. DoD has not adopted Revision 3 for CMMC assessments or SPRS scoring, so contractors should build to Revision 2 today.

    Turn this score into an SSP and a POA&M

    CMMC Map walks the same 110 controls with evidence checklists, keeps your answers, and writes the System Security Plan, POA&M and 14 policies from them. The assessment is free.

    Start free See example documents

    Free to assess · No credit card · Documents from $149/mo