compli.ai
From the blog

NIST 800-171 Self-Assessment Checklist (r2→r3)

A family-by-family NIST 800-171 self-assessment checklist for the 14 Rev 2 families, how to score honestly, common failures, and Rev 3 changes.

A NIST 800-171 self-assessment is you scoring your own implementation of the 110 requirements — the same exercise the Department of War (DoW) requires before you can post a score to SPRS and pursue CMMC Level 2. Done honestly, it tells you your real SPRS score and exactly which gaps to close. Done as a box-ticking exercise, it produces a number you cannot defend when an assessor reviews it. This post gives you a family-by-family checklist for all 14 Rev 2 families, shows how to score without fooling yourself, flags the requirements that fail most often, and notes what shifts under Rev 3.

Two things up front. First, you assess against Revision 2, the version the Department assesses against for contracts and CMMC today (Rev 3 is final but not adopted; more below). Second, a requirement counts only when it is fully met. The scoring methodology allows partial credit in just two places: multifactor authentication (3.5.3) and encryption that is not FIPS-validated (3.13.11).

How a self-assessment actually works

You are running the DoD Assessment Methodology on yourself. For each of the 110 requirements, you decide: is this fully implemented, yes or no? Then you calculate your SPRS score by starting at 110 and subtracting the weighted value (1, 3, or 5) of every requirement not met, and you document the gaps on a POA&M. The output of a good self-assessment is three things: a score, a POA&M, and an SSP that matches both.

The trap is grading on a curve. "We kind of do that" is a no. "We have a policy but don't enforce it" is a no. The methodology rewards implementation, not intention.

The 14 families of NIST 800-171 Rev 2

Rev 2 organizes its 110 requirements into 14 families. Use this as your top-level map, and record a met or not-met status for each requirement as you go.

#FamilyFocusWhat "met" looks like
1Access Control (AC)Who can access whatLeast-privilege access, enforced authorizations, controlled remote access and session management
2Awareness & Training (AT)People know their roleSecurity awareness training delivered and tracked; role-based training for privileged users
3Audit & Accountability (AU)Logging and reviewAudit logs generated, protected, and actually reviewed on a cadence; actions traceable to individuals
4Configuration Management (CM)Systems built to a known baselineBaseline configurations, change control, restriction of unnecessary software and ports
5Identification & Authentication (IA)Proving who you areUnique user IDs, MFA, strong authenticator management
6Incident Response (IR)When something goes wrongAn incident response capability that is documented, tested, and tied to 72-hour DoW reporting
7Maintenance (MA)Servicing systems safelyControlled maintenance, sanitization of equipment, oversight of maintenance personnel
8Media Protection (MP)Protecting CUI on mediaMarking, access control, sanitization, and controlled transport of media holding CUI
9Personnel Security (PS)Trustworthy peopleScreening before CUI access; protecting CUI during personnel transfers and terminations
10Physical Protection (PE)Doors and facilitiesLimited physical access, escorting visitors, protecting physical devices and facilities
11Risk Assessment (RA)Knowing your exposurePeriodic risk assessments and vulnerability scanning with remediation
12Security Assessment (CA)Checking your own controlsAssessing controls, building POA&Ms, and maintaining the SSP — the self-assessment lives here
13System & Communications Protection (SC)Protecting data in transit and boundariesBoundary protection, FIPS-validated encryption, network segmentation
14System & Information Integrity (SI)Catching and fixing flawsFlaw remediation, malicious-code protection, monitoring and alerting

How to score honestly

The value of a self-assessment is entirely in its honesty. A dishonest one just moves the failure to a more expensive moment: a government-led or third-party assessment, or worse, a False Claims Act problem after you attest to it. Rules for scoring straight:

  • Fully met or not met — no middle. If you cannot point to the control working and evidence it works, mark it not met.
  • Policy is not implementation. Having a document is necessary but not sufficient. The requirement is met when the control operates, not when it is written down.
  • "Sometimes" is "no." Audit logs reviewed when someone remembers, MFA on some systems but not all — these are gaps, not partial passes.
  • Score against every assessment objective. Each requirement decomposes into assessment objectives in NIST SP 800-171A, 320 in all in the June 2018 edition DoW still assesses against. Missing one objective means the requirement is not met, even if the others are.
  • Write down the evidence as you go. If you cannot name the artifact that proves a control, you have not really met it — and you will need that artifact for the SSP anyway.

Then do the math: 110 minus your weighted deductions equals your score. That number is what you post to SPRS. If you would be embarrassed to defend it to an assessor, fix the gaps before you submit.

The requirements that fail most often

Across self-assessments, the same requirements come up short. If you are triaging, look here first, because most of them carry high weights and hurt your score the most:

  • Multifactor authentication (IA family). Deployed on some systems but not all, or missing for local/privileged access. A −5 when missing, or −3 when it covers remote and privileged users but not yet general users.
  • FIPS-validated encryption (SC family). Using encryption is not enough; NIST 800-171 requires FIPS-validated cryptography for protecting CUI. Plain TLS or unvalidated modules do not meet the requirement; they earn partial credit, a 3-point deduction instead of 5.
  • Audit log review (AU family). Logs are generated but nobody reviews them on a cadence. Generation without review does not meet the requirement.
  • Incident response testing (IR family). A plan exists but has never been exercised. Untested is treated as not operational.
  • Security assessment and POA&M discipline (CA family). No maintained SSP, or a POA&M that exists but is not managed.
  • Configuration baselines (CM family). No documented baseline, so "change control" has nothing to control against.
  • Vulnerability scanning and remediation (RA/SI). Scanning happens but findings are not tracked to closure.

Closing MFA, FIPS-validated encryption, configuration baselines, and vulnerability remediation often moves a score more than a dozen low-weight fixes, because those requirements carry 5-point weights. Incident response testing (3.6.3), by contrast, is a 1-point requirement.

What changes under Rev 3 (and why you still score Rev 2 today)

Rev 3, finalized in May 2024, restructures the requirements, but you do not assess against it yet. The Department assesses against Rev 2: Class Deviation 2024-O0013 ties DFARS 252.204-7012 to Rev 2 until it is rescinded, and the Department's September 3, 2026 class deviation keeps Rev 2. When Rev 3 eventually applies, expect:

  • 97 requirements instead of 110, reorganized into 17 families (Rev 3 adds Planning, System & Services Acquisition, and Supply Chain Risk Management).
  • Organization-Defined Parameters (ODPs), specific values such as frequencies and thresholds. DoW published its values for them in an April 2025 memo, which reduces "we interpreted it as X" ambiguity.
  • A non-trivial mapping — Rev 2 to Rev 3 is not a clean subtraction, so a crosswalk matters.

There is no official DoW transition date. An interim final rule to move from Rev 2 to Rev 3 (RIN 0790-AM01) was listed in the Unified Agenda with a July 2026 target, but it had not been published as of late September 2026. The practical move: self-assess against Rev 2 now, and keep an eye on the three new Rev 3 families (especially Supply Chain Risk Management) so you are not starting from zero later. Full detail in our NIST 800-171 Rev 3 guide.

FAQ

What is a NIST 800-171 self-assessment? It is the process of evaluating your own implementation of the 110 NIST 800-171 Rev 2 requirements, scoring each as met or not met, and calculating an SPRS score. The Department requires it before you can post a score to SPRS, and it is the foundation for a CMMC Level 2 self-assessment.

How many controls are in NIST 800-171? Rev 2, the version the Department assesses against, has 110 requirements across 14 families. Rev 3 (final May 2024, not yet adopted by DoW) has 97 requirements across 17 families. For any self-assessment tied to a contract or CMMC today, use the 110.

How do I become NIST 800-171 compliant? Self-assess against the 110 Rev 2 requirements, document how you meet each one in an SSP, put every gap on a POA&M with owners and dates, calculate your SPRS score, and post it to SPRS via PIEE. Then maintain it — close POA&M items with evidence and keep the SSP current. Our NIST 800-171 compliance guide walks the full path.

How do I perform a NIST 800-171 assessment? Go family by family through all 14 Rev 2 families, and for each requirement decide met or not met against its 800-171A assessment objectives — with evidence. Record gaps, calculate your weighted score from 110, and produce an SSP and POA&M. A structured checklist keeps you from skipping requirements or grading yourself too generously.

What is the difference between a self-assessment and a C3PAO assessment? A self-assessment is you scoring yourself and affirming the result in SPRS. A C3PAO assessment is an authorized third party independently verifying your implementation for CMMC Level 2 certification. Under the current CMMC phase-in, the Department has suspended Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program. Phase 1 remains in effect, so contracts can still require Level 1 and Level 2 self-assessments with affirmations in SPRS, and the contract specifies which applies. Either way, an honest self-assessment first is how you avoid surprises.

Turn the checklist into a real score

A self-assessment is only useful if it is honest, complete, and backed by evidence — which is exactly the part a spreadsheet checklist makes hard. Grading yourself straight across all 14 families, tying each requirement to an artifact, and keeping the resulting score, SSP, and POA&M in sync is real work.

Use the family-by-family checklist above to start working through every requirement. When you are ready to turn that checklist into a maintained score with evidence attached, book a demo. We will show you how Compli.ai runs the self-assessment objective by objective, computes your SPRS score with the DoD Assessment Methodology, and keeps the SSP implementation statements and POA&M on the same control set inside your own Microsoft 365 tenant. It is built by practitioners who run these assessments, so it scores with the same arithmetic an assessor applies. To compare doing it yourself versus with a platform or a practitioner, see CMMC compliance software.