NIST 800-171 for Small Government Contractors
What NIST 800-171 Actually Is
NIST Special Publication 800-171 is the U.S. government’s control catalog for how contractors must protect Controlled Unclassified Information (CUI). CUI is the sensitive-but-unclassified data the federal government shares with vendors — technical drawings, contract-performance data, personally identifiable information, and program-specific material that isn’t secret but isn’t public. If your contract touches CUI, you’re on the hook for 800-171.
For Department of Defense (DoD) contracts, 800-171 has been mandatory since 2017 through DFARS clause 252.204-7012, and since 2020 through the Cybersecurity Maturity Model Certification (CMMC) program that layers third-party assessments on top of it. For civilian agencies (VA, DHS, GSA), FAR contract clauses now increasingly reference 800-171 too. If you sell to the federal government and haven’t looked at this framework, that stops today.
The 110 Controls Across 14 Families
NIST 800-171 organizes 110 security controls into 14 families. Small contractors get overwhelmed by the count, but each family is a small handful of concrete practices — most of which a competent IT operation is already doing, at least partially.
Access Control (AC) — 22 controls. Who can log in, who can see what, how sessions expire. Multi-factor authentication for privileged users, least-privilege access, remote-access session management. If you’re using Microsoft 365 with Conditional Access properly configured, or a comparable identity platform, most of AC is already in place.
Awareness & Training (AT) — 3 controls. Security awareness training for all users, role-based training for privileged users, insider-threat awareness. Small contractors typically satisfy this with an annual training platform (KnowBe4, Ninjio, Wizer) plus documented completion.
Audit & Accountability (AU) — 9 controls. Log what happens on your systems and review the logs. This is where most small contractors fall short — you have to actually retain and review logs, not just enable logging. Solutions range from Microsoft 365 audit-log retention licensing to third-party log aggregation.
Configuration Management (CM) — 9 controls. Baseline configurations, change control, restricting software installation. If you have an RMM tool with a documented baseline image and a change-approval process, you’re close to satisfying CM.
Identification & Authentication (IA) — 11 controls. Unique user IDs, multi-factor authentication, password strength, session lock. Same tooling as Access Control; the requirements just get more specific here.
Incident Response (IR) — 3 controls. Documented incident response plan, incident-handling procedures, incident reporting to the government within 72 hours for DoD contracts. Your IR plan needs to be written down, tested, and referenced by the actual on-call team.
Maintenance (MA) — 6 controls. Controls on system maintenance, media used for maintenance, and personnel performing maintenance. This is the family most often overlooked — even something as simple as a repair technician plugging in a diagnostic USB stick needs a policy.
Media Protection (MP) — 9 controls. Physical and digital media handling, media transport, sanitization. Old hard drives get shredded, not thrown out. USB drives are inventoried and encrypted. Documented, tracked, evidence retained.
Personnel Security (PS) — 2 controls. Screen personnel before access; protect CUI during personnel actions like terminations. Coordinate with HR — this is where the offboarding checklist ties in.
Physical Protection (PE) — 6 controls. Access to facilities where CUI is stored. Locked office doors, badge access, visitor logs. Trivial for controlled office spaces; harder for hybrid/remote teams that need CUI-appropriate work-from-home policies.
Risk Assessment (RA) — 3 controls. Periodic risk assessments, vulnerability scans, remediation of identified vulnerabilities. Document your process, do it on a documented schedule, retain the evidence.
Security Assessment (CA) — 4 controls. Periodic security control assessments, action plans for weaknesses (POA&M), authorization to operate documentation. Your System Security Plan (SSP) plus your POA&M are the assessment artifacts you’ll produce.
System & Communications Protection (SC) — 16 controls. Boundary protection (firewalls), transmission security (TLS), cryptography (FIPS-validated), voice-over-IP protection. Most of this is standard IT operations for any contractor who takes security seriously.
System & Information Integrity (SI) — 7 controls. Flaw remediation (patching), malicious-code protection, security alerts, monitoring. Your endpoint-protection stack plus disciplined patching cadence satisfies this family.
The SSP and POA&M — Your Two Core Documents
Two documents drive the entire 800-171 compliance conversation with your customer: the System Security Plan (SSP) and the Plan of Action & Milestones (POA&M).
The SSP describes how your organization implements each of the 110 controls. It’s not a marketing document — it’s a technical inventory. For each control, you document how you satisfy it (or don’t), what tools implement it, and what evidence proves it. A small-contractor SSP typically runs 40–80 pages and takes 40–80 hours to write initially.
The POA&M is the honest gap list. For every control you don’t fully satisfy today, the POA&M documents the gap, the remediation plan, the owner, and the target completion date. This is where new contractors panic — they think the POA&M means they fail. It doesn’t. Contracting officers expect POA&Ms. What they don’t expect is a POA&M that never closes any items or an SSP that pretends every control is fully implemented.
SPRS Scoring and the DoD Assessment Requirement
For DoD contractors, DFARS 252.204-7020 requires you to complete a self-assessment, calculate a numeric score using NIST 800-171’s DoD Assessment Methodology, and submit the score into the Supplier Performance Risk System (SPRS). The maximum score is 110 (one point per control implemented). Each unimplemented control deducts 1, 3, or 5 points depending on impact — meaning a partial implementation can leave you with a NEGATIVE score, which is completely normal for firms starting the journey.
Contracting officers can see your SPRS score before award. A score of 88 with a clear POA&M and a demonstrated path to 110 is winnable. A blank SPRS record with no self-assessment isn’t. The self-assessment must be updated every 3 years or after any material change.
CMMC vs 800-171 — What’s the Difference
NIST 800-171 is the control catalog. CMMC (Cybersecurity Maturity Model Certification) is the assessment framework layered on top. At CMMC Level 2 — where most DoD contractors handling CUI will end up — the required controls ARE the 110 controls from NIST 800-171. What’s added by CMMC is: (a) a formal third-party assessment (C3PAO) instead of self-assessment for higher-risk contracts, and (b) documented maturity of practices, not just their existence.
If you’re 800-171-compliant with strong evidence and a mature process, you’re 80% of the way to CMMC Level 2. The remaining 20% is documentation polish and evidence retention discipline. Start with 800-171 either way. Our CMMC compliance guide for defense contractors covers the assessment layer in detail.
How Small Contractors Actually Get to 110
The path most first-time contractors take: start with a gap assessment against all 110 controls, produce an honest initial SPRS score (typically 50–90), draft the SSP that documents the current state, build the POA&M with 3–12 month remediation targets, remediate the highest-impact gaps first (typically MFA gaps, log retention, encryption, and incident response documentation), reassess after each remediation sprint, and update SPRS accordingly.
Budget-wise: a small contractor with an existing Microsoft 365 tenant can often reach a 90+ SPRS score with $10K–$50K in additional tooling and 200–400 hours of internal effort over 6–18 months. The tools are affordable; the effort is real.
Getting Help Without Getting Ripped Off
The NIST 800-171 consultant market is full of overpriced, underdelivered engagements. Small contractors get quoted $50K–$150K for what should be a 200-hour engagement. Ask for scope, deliverables, and evidence in writing before signing. If a consultant can’t explain why the price is what it is, walk. If you need help interpreting your specific stack, working through your SSP, or standing up a defensible POA&M for your business, Veteran Forge Strategies works with small defense contractors on 800-171 and CMMC readiness without the enterprise-consultant premium.
Key Takeaways
- NIST 800-171 = 110 controls across 14 families protecting Controlled Unclassified Information.
- DFARS 252.204-7012 makes it mandatory for DoD contracts handling CUI.
- The SSP documents your implementation; the POA&M documents the gaps you’re closing.
- SPRS scoring is required for DoD contracts (max 110; be honest, contracting officers expect POA&Ms).
- 800-171 compliance is 80% of CMMC Level 2 readiness.
- Small contractors can reach 90+ SPRS in 6–18 months with disciplined effort and modest tooling budget.
FAQ
Do I need to be 800-171 compliant to win a DoD contract? Not necessarily to win, but to perform. Some contracts allow compliance during performance; others require it before award. Read the solicitation carefully — DFARS 252.204-7012 has been standard clause language for years.
What’s the difference between CUI and classified information? Classified information is Confidential/Secret/Top Secret and requires clearances, facility clearance, and completely different handling. CUI is sensitive-but-unclassified — technical data, personally identifiable information, contractual information — that requires 800-171 protection but not clearances.
Can I self-assess forever, or do I need a third-party assessor? Under CMMC, higher-risk contracts require third-party (C3PAO) assessments at Level 2 and above. Lower-risk contracts allow self-assessment. Your contracting officer will specify.
This article is educational and general in nature; it is not legal or compliance advice. Verify current requirements at nist.gov and acquisition.gov, and consult qualified counsel for your specific contracts.