Skip to main content

Elevate

NIST 800-171 Assessment: Methodology, Scoring, and Evidence

A NIST 800-171 assessment is the evaluation of your environment against the 110 security requirements in NIST SP 800-171, and it is the assessment that produces the score the government sees and that underpins CMMC Level 2. For any defense contractor handling controlled unclassified information, it is the measurement that matters, because the standard behind it sits in your contract through DFARS clause 252.204-7012 and the same requirements form the control set for CMMC. This guide explains the methodology behind the assessment, how it is scored, what evidence it expects, and how the result flows into the Supplier Performance Risk System and CMMC.

The assessment is also the live obligation right now. Under the 2026 suspension of third-party certification assessment, the NIST 800-171 self-assessment is what most contractors are required to perform, and the score it produces is one you attest to with real consequences. Understanding the methodology is therefore not preparation for some future event; it is preparation for the assessment you are expected to run today.

What a NIST 800-171 Assessment Is

A NIST 800-171 assessment measures how completely your environment implements the 110 requirements of NIST SP 800-171, the standard for protecting controlled unclassified information in nonfederal systems. It is the assessment named in DFARS 252.204-7012, and because CMMC Level 2 is built on the same 110 requirements, the 800-171 assessment and the CMMC Level 2 assessment examine the same control set. The output is a score that represents how much of the standard you meet, and that score is submitted to the Supplier Performance Risk System where the government can see it.

The assessment can be performed at different levels of rigor and by different parties, which matters for how much weight the result carries. A contractor can perform the assessment itself, and the government can perform a more thorough review, and under the current suspension the self-assessment is the live requirement for most contractors while government-led assessments continue. What does not change with the level is the standard being measured: every version of the assessment evaluates the same 110 requirements, so the difference is who checks the work and how deeply, not what is being checked.

800-171 Rev 2 Today, Rev 3 Later

Assessments today are conducted against Revision 2 of NIST SP 800-171, which defines the 110 requirements currently in force. A move to Revision 3 is expected through future rulemaking, and it will change some of the requirements when it arrives, but there is no finalized deadline for that transition. The practical implication is to build your program against Revision 2 as it stands while staying aware that a revision is coming, rather than trying to assess against a standard that is not yet in effect.

The DoD Assessment Methodology

The scoring behind a NIST 800-171 assessment follows the DoD Assessment Methodology, which defines how the assessment is conducted and how the resulting score is calculated. The methodology sets out three assessment levels that differ in who performs the assessment and how much confidence the result carries, and understanding them clarifies what your self-assessed score means relative to a government review.

Assessment levelWho performs itConfidence in the result
BasicThe contractor, as a self-assessmentLower, because it is self-reported
MediumThe government, reviewing the assessmentHigher
HighThe government, through a thorough on-site reviewHighest

The table shows why a self-assessment, while it is the live requirement during the suspension, is also the level the government trusts least on its own. A Basic self-assessment is your own honest measurement, and the government retains the ability to perform Medium and High assessments to verify it. This is one reason accuracy in a self-assessment matters so much: the score is self-reported, but it is not beyond scrutiny, and a self-assessment that a government review later contradicts is a serious problem.

Self-Assessment and Government Assessment: What Each Involves

The three levels are not just labels for confidence; they describe genuinely different exercises, and knowing what each involves clarifies what your own self-assessment does and does not settle. A Basic assessment is the one you perform yourself: you evaluate your environment against the 110 requirements, calculate your score, and submit it to the Supplier Performance Risk System. It is the live requirement for most contractors under the current suspension, and it is entirely self-reported, which is exactly why the methodology assigns it the lowest confidence. A Basic self-assessment is your honest measurement of your own posture, and it is an attestation you are held to, but it is not verification.

A Medium or High assessment is where the government does the checking. In a Medium assessment, the government reviews and validates the Basic self-assessment you submitted, which raises the confidence in the result. In a High assessment, the government conducts a thorough on-site evaluation, examining evidence, interviewing the people who operate the controls, and observing implementation directly, which is why it carries the highest confidence of the three. These government-led assessments continue during the suspension, because it is the third-party certification route that is paused, not the government’s own ability to assess.

The practical implication for a contractor is that a self-assessment is not the end of the story, and it should not be treated as one. Because the government can review or independently conduct an assessment, the gap between the score you self-report and the score a government assessor would reach is a real and exposed risk rather than a private matter. An inflated self-assessment is not hidden; it is simply waiting to be contradicted, with the attestation attached to it. This is what makes accuracy in the Basic assessment protective rather than optional, and it is why the evidence behind your score matters as much as the score itself.

How Scoring Works

The DoD Assessment Methodology produces a numeric score that reflects how much of the standard you meet. It begins from a maximum of 110, one point for each of the 110 requirements, and subtracts the weighted value of every requirement that is not met. The result is the score submitted to the Supplier Performance Risk System, and because the deductions are weighted, that score can fall below zero for an environment with significant gaps.

The Point Weights

Not every requirement is worth the same. Under the methodology, and as codified in the CMMC rule at 32 CFR 170.24, each unmet requirement subtracts one, three, or five points depending on the risk its absence creates. A requirement whose absence could lead to significant exploitation of the network or exfiltration of controlled unclassified information subtracts five points. One whose absence has a specific and confined effect on the security of the network subtracts three. The remaining requirements, whose absence has a limited or indirect effect, subtract one. This is why two organizations with the same number of gaps can hold very different scores: the weight of the gaps, not merely their count, drives the number.

The Two Requirements That Allow Partial Credit

The methodology is built to credit full implementation rather than partial effort, with exactly two exceptions. For multifactor authentication, requirement 3.5.3, three points are subtracted rather than five if multifactor authentication is in place for remote and privileged users but not all users, and the full five points are subtracted only if it is not implemented for anyone. For FIPS-validated cryptography, requirement 3.13.11, three points are subtracted if encryption is used but is not FIPS-validated, and five points if no encryption is employed at all. No other requirement earns partial credit; every other control is scored as met or not met.

What the Methodology Does Not Say

Two claims that circulate widely are not supported by the governing documents, and repeating them undermines an otherwise sound score. The methodology sets no fixed floor, so a specific minimum score that some sources cite is not established anywhere in the rule or the methodology; the score simply reduces by each unmet requirement and can go negative. And while the point value for every requirement is enumerated in 32 CFR 170.24, the methodology does not publish a tidy count of how many requirements sit at each weight, so any such count is a reader’s arithmetic over those lists rather than a stated figure. Precision on these points is part of what separates a trustworthy assessment from one that repeats the common errors in this area.

The practical consequence is that your score is a direct, weighted function of your gaps, which means not all remediation moves the number equally. Closing a five-point gap improves the score far more than closing a one-point gap, so understanding the weighting is what lets you prioritize remediation for both security and score. For a fuller walk through the calculation and what a maximum score requires, the SPRS score and the perfect 110 guide covers the mechanics, and the self-scoring resource lets you translate your own assessment into a score.

Evidence Expectations

An assessment is only as good as the evidence behind it, and this is where many contractors lose points they did not expect to. For each requirement, the assessment looks for proof that the control is genuinely implemented, not just an assertion that it is, and that proof lives in your documentation and your systems. The System Security Plan is central, because it describes how each requirement is met, and the Plan of Action and Milestones records what is not yet met and how you intend to close it.

The rule that catches organizations off guard is that a control which works in practice but cannot be evidenced is treated, for assessment purposes, as a control that is not met. Real security that is undocumented does not earn the score, because the assessment measures demonstrable implementation rather than good intentions. Building the evidence as you implement each control, rather than reconstructing it before an assessment, is what keeps your assessed score aligned with your actual security posture.

How Results Flow into SPRS and CMMC

The score a NIST 800-171 assessment produces does not sit in isolation; it flows into two systems that matter to your business. First, it is submitted to the Supplier Performance Risk System, where it becomes the number the government relies on to judge your posture, and submitting it is an attestation you are held to. Because that submission is a representation the government acts on, a self-assessment carries False Claims Act exposure if the score is knowingly or recklessly overstated, which is why accuracy is not optional.

Second, because CMMC Level 2 is built on the same 110 requirements, your 800-171 assessment is effectively your CMMC Level 2 posture. Under the current suspension, the 800-171 self-assessment is the live mechanism, and it is the foundation a future third-party CMMC assessment would build on when third-party assessment resumes. Getting the 800-171 assessment right is therefore getting your CMMC readiness right at the same time. To turn an assessment result into a prioritized plan, a CMMC gap assessment converts the findings into a remediation roadmap, and a broader CMMC readiness assessment places the whole effort in context. Elevate helps contractors run the assessment accurately and act on the result as part of its CMMC advisory services.

Conclusion

A NIST 800-171 assessment is the measurement at the center of defense compliance: it evaluates your environment against the 110 requirements, produces a score through the DoD Assessment Methodology, and sends that score into SPRS and, by extension, into your CMMC Level 2 standing. During the current suspension it is the live obligation, performed as a self-assessment and attested to with real legal weight, which makes understanding the methodology, the scoring, and the evidence expectations a present necessity rather than a future one.

The contractors who assess well treat evidence as something built alongside each control and treat the score as a direct, weighted function of their gaps that they can improve deliberately. To run an accurate NIST 800-171 assessment and turn the result into a plan you can act on, book a call with an Elevate advisor.

Key Takeaways

A NIST 800-171 assessment measures your environment against the 110 requirements, scores it through the DoD Assessment Methodology, and feeds the result into SPRS and CMMC.

  • It is the live obligation now: under the 2026 suspension the 800-171 self-assessment is what most contractors must perform, and the score is attested to with real consequences.
  • The methodology defines three levels: a Basic self-assessment carries the lowest confidence, while government-led Medium and High assessments can verify it, so self-reported accuracy matters.
  • Scoring is weighted: the score starts from full implementation of all 110 requirements and deducts weighted points for gaps, so heavily weighted gaps move the number most and should be prioritized.
  • Evidence is the difference: a control that cannot be evidenced is treated as not met, so the System Security Plan, the POA&M, and demonstrable implementation determine the score as much as the controls themselves.
  • Results flow into SPRS and CMMC: the score is submitted to SPRS as an attestation with False Claims Act exposure, and because CMMC Level 2 shares the same 110 requirements, the assessment is effectively your Level 2 posture.

FAQs

Q1. What is a NIST 800-171 assessment? A NIST 800-171 assessment is an evaluation of how completely your environment implements the 110 security requirements in NIST SP 800-171, the standard for protecting controlled unclassified information. It is the assessment named in DFARS 252.204-7012, and because CMMC Level 2 uses the same 110 requirements, it also reflects your CMMC Level 2 posture. The assessment produces a score that is submitted to the Supplier Performance Risk System, where the government can see it.

Q2. How is a NIST 800-171 assessment scored? It is scored using the DoD Assessment Methodology, and the same weights are codified in the CMMC rule at 32 CFR 170.24. The score begins at 110, one point per requirement, and each unmet requirement subtracts one, three, or five points depending on the risk its absence creates. Only two requirements allow partial credit: multifactor authentication (3.5.3) and FIPS-validated cryptography (3.13.11). Because the deductions are weighted, the score can go negative, and closing a five-point gap improves the score far more than closing a one-point gap.

Q3. Who performs a NIST 800-171 assessment? The DoD Assessment Methodology defines three levels. A Basic assessment is performed by the contractor as a self-assessment and carries the lowest confidence because it is self-reported. Medium and High assessments are performed by the government and carry higher confidence, with High involving a thorough review. Under the 2026 suspension of third-party certification assessment, the Basic self-assessment is the live requirement for most contractors, while government-led assessments continue.

Q4. What evidence does a NIST 800-171 assessment require? The assessment looks for proof that each requirement is genuinely implemented, principally through your System Security Plan, which describes how each control is met, and your Plan of Action and Milestones, which records what is not yet met. The key rule is that a control which works but cannot be evidenced is treated as not met, so undocumented security does not earn the score. Building evidence as you implement each control, rather than reconstructing it before an assessment, keeps your assessed score aligned with your real posture.

Q5. How does a NIST 800-171 assessment relate to SPRS and CMMC? The score from the assessment is submitted to the Supplier Performance Risk System, where it becomes the number the government relies on, and that submission is an attestation carrying False Claims Act exposure if it is overstated. Because CMMC Level 2 is built on the same 110 requirements, the 800-171 assessment is effectively your CMMC Level 2 posture, and under the current suspension the self-assessment is the live mechanism. When third-party assessment resumes, the 800-171 foundation is what a CMMC assessment would build on.