You are probably already obligated
This surprises contractors constantly. DFARS 252.204-7012 has required NIST 800-171 implementation for years, along with 72-hour cyber incident reporting to DIBNet and flow-down to subcontractors. DFARS 252.204-7019 and 7020 added the requirement to post a self-assessment score to SPRS.
CMMC did not create a new obligation so much as it created enforcement for an existing one. If you have been holding DFARS 7012 clauses without an implemented 800-171 program and a current SPRS score, the gap is already there — CMMC just makes it visible.
The 14 control families
The 110 requirements are grouped into 14 families. Some are heavily technical, some are almost entirely procedural, and contractors consistently underestimate the second category.
- Access Control (22 requirements)
- Awareness and Training (3)
- Audit and Accountability (9)
- Configuration Management (9)
- Identification and Authentication (11)
- Incident Response (3)
- Maintenance (6)
- Media Protection (9)
- Personnel Security (2)
- Physical Protection (6)
- Risk Assessment (3)
- Security Assessment (4)
- System and Communications Protection (16)
- System and Information Integrity (7)
How SPRS scoring actually works
The DoD Assessment Methodology assigns each of the 110 requirements a weight of 5, 3, or 1 based on how much risk its absence introduces. You start at 110 and subtract the weight of every requirement you have not fully implemented. Full implementation of everything scores 110. Implementing nothing scores -203.
Two things follow from this that matter commercially. First, the highest-weighted controls are worth attacking first — a handful of 5-point items can move your score substantially. Second, primes look at SPRS scores when selecting subcontractors, so a low or stale score costs you bids regardless of enforcement timing.
SSP and POA&M are deliverables, not paperwork
Your System Security Plan describes your boundary, your environment, and how each of the 110 requirements is met. Your POA&M tracks what is not yet met and when it will be. Assessors read both closely, and a thin or generic SSP is one of the fastest ways to fail an assessment even with decent technical controls in place.
We write these against your actual environment. Template SSPs with your company name substituted in do not survive contact with a C3PAO.

