The Department of Defense published an interim DFARS rule (DFARS Case 2019-D041) on September 29, 2020. It takes effect on November 30, 2020. If you handle Controlled Unclassified Information (CUI) under a contract with DFARS 252.204-7012, you'll need a current NIST SP 800-171 DoD Assessment score posted in the Supplier Performance Risk System (SPRS) to be considered for award. For most companies, that means a self-assessment scored out of 110 using DoD's methodology. The rule also puts the Cybersecurity Maturity Model Certification (CMMC) into the DFARS, phased in over five years.

Clause 252.204-7012 has required contractors to implement NIST SP 800-171 since December 31, 2017. Until now, you could largely assert compliance without anyone checking a number. This rule gives DoD a number.

What does the DFARS interim rule require?

The rule adds three new DFARS clauses. You can read the full text in the Federal Register.

Clause Title What it does
252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements Solicitation provision. Tells offerors that must implement NIST SP 800-171 that they need a current assessment on record in SPRS to be considered for award
252.204-7020 NIST SP 800-171 DoD Assessment Requirements Contract clause. Requires you to give DoD access to facilities, systems and personnel for Medium or High assessments, and to flow the requirement down to subcontractors
252.204-7021 Cybersecurity Maturity Model Certification Requirements Contract clause. Requires you to hold and maintain the CMMC level the contract specifies

Key dates:

  • September 29, 2020: Interim rule published
  • November 30, 2020: Rule takes effect, and public comments are due
  • Through September 30, 2025: CMMC phase-in period
  • October 1, 2025 onward: CMMC requirements will apply broadly to DoD solicitations and contracts

None of the new clauses apply to contracts or subcontracts exclusively for commercially available off-the-shelf (COTS) items.

What are Basic, Medium and High assessments?

The NIST SP 800-171 DoD Assessment comes in three levels. Each reflects how deeply the score has been checked and how much confidence DoD can place in it.

Assessment Who performs it What it involves Confidence level
Basic You (self-assessment) Your own review of your implementation of NIST SP 800-171, scored with DoD's methodology Low
Medium DoD Review of your Basic Assessment, a thorough document review and discussions with you Medium
High DoD Everything in a Medium assessment, plus verification, examination and demonstration of your system security plan, using NIST SP 800-171A High

Most contractors will only ever do a Basic Assessment. DoD may choose to conduct a Medium or High Assessment based on how critical a program is or how sensitive the information you handle is.

If DoD does perform a Medium or High Assessment, you'll see the results before they're posted. You then have 14 business days to provide additional information showing you meet requirements the assessors didn't observe, or to rebut their findings.

How does NIST 800-171 scoring work?

The rule relies on the NIST SP 800-171 DoD Assessment Methodology (Version 1.2.1, June 24, 2020), developed by the Defense Contract Management Agency at DoD's direction. It works like this:

  • You start at 110, the score for fully implementing all 110 security requirements in NIST SP 800-171.
  • Every requirement you haven't implemented costs you points. Each requirement is weighted 5, 3 or 1 depending on how much its absence would expose your network or CUI.
  • The lowest possible score is -203, if nothing at all is implemented.

A requirement is either implemented or not. A couple of requirements allow partial credit:

  • Multi-factor authentication (3.5.3): You lose 5 points if MFA isn't implemented, or 3 if it's implemented for remote and privileged users but not general users.
  • FIPS-validated cryptography (3.13.11): You lose 5 points if you don't use encryption where required, or 3 if you use encryption that isn't FIPS-validated.

A score below 110 doesn't mean you're out of the running. The rule requires a current assessment on record; it doesn't set a minimum score for award. But your score is now visible to DoD, and it can be verified.

What gets posted in SPRS?

For a Basic Assessment, you post a summary, not your detailed results. The clause lists what's included:

  • The standard assessed (NIST SP 800-171)
  • The organization that conducted the assessment (for example, a contractor self-assessment)
  • For each system security plan supporting a DoD contract, all associated CAGE codes and a brief description of the plan's architecture if you have more than one plan
  • The date the assessment was completed
  • The summary score (for example, 95 out of 110, not the value for each requirement)
  • The date by which you expect to implement all requirements, meaning reach a score of 110, based on your plans of action

You can post the summary directly in SPRS or send it by encrypted email to the address given in the clause. Scores in SPRS are available to DoD personnel, and you can view your own organization's results.

How current does your score need to be?

The assessment must be no more than three years old, unless the solicitation specifies a shorter period. Contracting officers will check SPRS before award.

What about subcontractors?

You have to flow the substance of 252.204-7020 down to subcontractors that handle CUI. Before awarding a subcontract that requires NIST SP 800-171, you must make sure the subcontractor has completed at least a Basic Assessment within the last three years and posted it in SPRS. Each company posts its own score.

How do the SSP and POA&M affect your score?

Two documents underpin everything: the system security plan (SSP) and the plan of action, often called a POA&M.

The system security plan

NIST SP 800-171 requirement 3.12.4 calls for an SSP describing your system boundary, environment and how each requirement is implemented. Under the methodology, the SSP is the foundation of the assessment. If you don't have one, the result is a finding that an assessment couldn't be completed because of incomplete information and noncompliance with DFARS 252.204-7012.

Your SSP and your score have to tell the same story. A Medium Assessment is largely a document review. If your SSP describes a control you scored as implemented but can't show evidence for, expect DoD's score to differ from yours.

The plan of action

Requirement 3.12.2 requires plans of action to correct deficiencies and reduce or eliminate vulnerabilities. The methodology is explicit that a plan of action isn't a substitute for implementation. A requirement listed on your POA&M still counts as not implemented and still costs you its points.

The POA&M does matter for SPRS, though. It's where your "date all requirements will be implemented" comes from. Make that date realistic and backed by planned work, because it's part of the record DoD sees.

How do you calculate your own SPRS score?

Here's a practical sequence for a Basic Assessment:

  1. Define your scope. Identify the covered contractor information systems that process, store or transmit CUI. Each SSP gets its own score, tied to its CAGE codes.
  2. Get the source documents. You need NIST SP 800-171, NIST SP 800-171A (the assessment procedures, published June 2018) and the DoD Assessment Methodology, which lists the point value for each requirement.
  3. Update your SSP first. Make sure it accurately describes the current environment and how each requirement is met.
  4. Assess each of the 110 requirements. Use the assessment objectives in NIST SP 800-171A. Record evidence for each: configurations, policies, logs, screenshots.
  5. Score honestly. Mark a requirement as implemented only if every objective is met. Apply partial credit only for 3.5.3 and 3.13.11, as the methodology describes.
  6. Do the math. Add up the point values of every requirement not implemented and subtract the total from 110.
  7. Update your POA&M. Record each gap with an owner, the planned fix and a target date. Use it to set the date you'll reach 110.
  8. Post the summary in SPRS and keep your working papers. You'll need them if DoD conducts a Medium or High Assessment.

To see how the arithmetic works, suppose you've implemented everything except three items: MFA isn't deployed for anyone (-5), your encryption isn't FIPS-validated (-3), and two 1-point requirements are still open (-2). Your score is 110 - 10 = 100.

How does CMMC fit in?

CMMC builds on the NIST SP 800-171 DoD Assessment Methodology but adds certification. Instead of assessing yourself, you'll be assessed by an accredited CMMC Third Party Assessment Organization (C3PAO), with certificates issued through the independent CMMC Accreditation Body.

CMMC has five cumulative levels. Level 1 covers the 15 basic safeguarding requirements already in FAR 52.204-21. Level 3 covers all 110 NIST SP 800-171 requirements plus additional practices. Levels 4 and 5 add more on top. A certificate can be no more than three years old, and results will be recorded in SPRS.

The rollout is gradual:

  • Through September 30, 2025: The CMMC clause will appear only in solicitations approved by the Office of the Under Secretary of Defense for Acquisition and Sustainment.
  • From October 1, 2025: CMMC will apply to DoD solicitations and contracts above the micro-purchase threshold, except those exclusively for COTS items.

Until CMMC appears in your contracts, the NIST SP 800-171 DoD Assessment is the requirement that affects you. Work you do now, especially on your SSP and evidence, carries straight over to CMMC Level 3.

This post summarizes the rule; confirm how it applies to your specific contracts with counsel or your contracting officer.

Frequently asked questions

Do we need an SPRS score if we don't handle CUI?

The assessment requirements in 252.204-7019 and 252.204-7020 apply when you're required to implement NIST SP 800-171, which comes from handling CUI under 252.204-7012. If you only handle Federal Contract Information, they shouldn't apply. CMMC Level 1 may apply once it appears in your contracts.

Does a low or negative score disqualify us?

Not under the rule's text. It requires a current score in SPRS, not a minimum score. That said, DoD can see the score and the date you've committed to for reaching 110, and it may choose to verify both.

How long is a Basic Assessment valid?

Up to three years, unless a solicitation requires a more recent one.

Can we score a requirement as met if it's on our POA&M?

No. The methodology says requirements that aren't implemented are scored as not implemented, whether or not a plan of action is in place.

Next steps

  • Confirm which of your systems process, store or transmit CUI and which CAGE codes they support.
  • Bring your SSP up to date before you score anything.
  • Score all 110 requirements against NIST SP 800-171A and the DoD Assessment Methodology.
  • Build a POA&M with realistic dates for every gap, and use it to set your target date for 110.
  • Post your summary score in SPRS before November 30, 2020, so it's on record when new solicitations arrive.
  • Check that your CUI-handling subcontractors have posted their own scores.
  • Keep your evidence organized for a possible Medium or High Assessment, and for CMMC later.