Nationwide CMMC & NIST 800-171 implementation for the Defense Industrial Base

NIST SP 800-171 Compliance

800-171 is the control set underneath CMMC Level 2 — and it has been contractually required under DFARS since long before CMMC existed. If you hold a DFARS 7012 clause, this already applies to you.

Get a real SPRS baseline

Most contractors have never had their 110 controls assessed against their live environment. We will score it and show you the highest-weighted gaps first.

Not sure? That's the most common answer — and it's the first thing we work out with you.

No cost. No obligation. NDA available on request.

We respond within 1 business hour · We are not a C3PAO and do not perform certification assessments

Level 1
achieved for an industrial robotics manufacturer
Defense
software built for defense contractors
Federal
law-enforcement task force under active support
Regulated
HIPAA, IRS WISP & FTC Safeguards work

The short answer

NIST SP 800-171 defines 110 security requirements across 14 families for protecting Controlled Unclassified Information in nonfederal systems. Defense contractors holding DFARS clause 252.204-7012 have been contractually obligated to implement it, report cyber incidents to DIBNet within 72 hours, and post a self-assessment score to SPRS under DFARS 252.204-7019/7020. CMMC does not replace 800-171 — it adds verification that you actually implemented it.

You are probably already obligated

This surprises contractors constantly. DFARS 252.204-7012 has required NIST 800-171 implementation for years, along with 72-hour cyber incident reporting to DIBNet and flow-down to subcontractors. DFARS 252.204-7019 and 7020 added the requirement to post a self-assessment score to SPRS.

CMMC did not create a new obligation so much as it created enforcement for an existing one. If you have been holding DFARS 7012 clauses without an implemented 800-171 program and a current SPRS score, the gap is already there — CMMC just makes it visible.

The 14 control families

The 110 requirements are grouped into 14 families. Some are heavily technical, some are almost entirely procedural, and contractors consistently underestimate the second category.

  • Access Control (22 requirements)
  • Awareness and Training (3)
  • Audit and Accountability (9)
  • Configuration Management (9)
  • Identification and Authentication (11)
  • Incident Response (3)
  • Maintenance (6)
  • Media Protection (9)
  • Personnel Security (2)
  • Physical Protection (6)
  • Risk Assessment (3)
  • Security Assessment (4)
  • System and Communications Protection (16)
  • System and Information Integrity (7)

How SPRS scoring actually works

The DoD Assessment Methodology assigns each of the 110 requirements a weight of 5, 3, or 1 based on how much risk its absence introduces. You start at 110 and subtract the weight of every requirement you have not fully implemented. Full implementation of everything scores 110. Implementing nothing scores -203.

Two things follow from this that matter commercially. First, the highest-weighted controls are worth attacking first — a handful of 5-point items can move your score substantially. Second, primes look at SPRS scores when selecting subcontractors, so a low or stale score costs you bids regardless of enforcement timing.

SSP and POA&M are deliverables, not paperwork

Your System Security Plan describes your boundary, your environment, and how each of the 110 requirements is met. Your POA&M tracks what is not yet met and when it will be. Assessors read both closely, and a thin or generic SSP is one of the fastest ways to fail an assessment even with decent technical controls in place.

We write these against your actual environment. Template SSPs with your company name substituted in do not survive contact with a C3PAO.

We do the work. We don't grade it.

Smith Network Solutions is not a C3PAO and not a registered RPO. We are the engineering and managed-services partner that closes your gaps, writes your System Security Plan, and gets your SPRS score where it needs to be. Your assessment is performed by an independent, authorized C3PAO — and that separation is deliberate. Under CMMC independence rules your assessor cannot remediate what they assess, so you need an implementation partner either way. We are that partner, and we will introduce you to C3PAOs when you are ready.

Get a real SPRS baseline

Most contractors have never had their 110 controls assessed against their live environment. We will score it and show you the highest-weighted gaps first.

Nationwide remote delivery · Response within 1 business hour

NIST 800-171 FAQs

What is the difference between NIST 800-171 and CMMC?

NIST SP 800-171 is the control catalog — the 110 requirements themselves. CMMC is the DoD program that verifies you have implemented them, through self-assessment at Level 1 and third-party assessment at Level 2 for most contracts. You can think of 800-171 as the test and CMMC as the proctor.

What is a good SPRS score?

110 is a perfect score and means every requirement is fully implemented. Anything meaningfully below that signals unimplemented controls. Because primes use SPRS scores as a selection input, contractors often find that improving their score has a faster commercial payoff than the compliance deadline itself would suggest.

Do we have to report cyber incidents?

Yes, if you hold DFARS 252.204-7012. You must report cyber incidents affecting covered defense information to DIBNet within 72 hours of discovery, preserve affected media, and support DoD damage assessment. This obligation exists independently of your CMMC level.

Does 800-171 apply to our subcontractors too?

Yes. DFARS 7012 requires flow-down to subcontractors who will handle covered defense information. Your compliance posture includes your supply chain, and primes increasingly audit that flow-down.