A family-by-family NIST 800-171 self-assessment checklist for the 14 Rev 2 families, how to score honestly, common failures, and Rev 3 changes.
A NIST 800-171 self-assessment is you scoring your own implementation of the 110 requirements — the same exercise the Department of War (DoW) requires before you can post a score to SPRS and pursue CMMC Level 2. Done honestly, it tells you your real SPRS score and exactly which gaps to close. Done as a box-ticking exercise, it produces a number you cannot defend when an assessor reviews it. This post gives you a family-by-family checklist for all 14 Rev 2 families, shows how to score without fooling yourself, flags the requirements that fail most often, and notes what shifts under Rev 3.
Two things up front. First, you assess against Revision 2, the version the Department assesses against for contracts and CMMC today (Rev 3 is final but not adopted; more below). Second, a requirement counts only when it is fully met. The scoring methodology allows partial credit in just two places: multifactor authentication (3.5.3) and encryption that is not FIPS-validated (3.13.11).
You are running the DoD Assessment Methodology on yourself. For each of the 110 requirements, you decide: is this fully implemented, yes or no? Then you calculate your SPRS score by starting at 110 and subtracting the weighted value (1, 3, or 5) of every requirement not met, and you document the gaps on a POA&M. The output of a good self-assessment is three things: a score, a POA&M, and an SSP that matches both.
The trap is grading on a curve. "We kind of do that" is a no. "We have a policy but don't enforce it" is a no. The methodology rewards implementation, not intention.
Rev 2 organizes its 110 requirements into 14 families. Use this as your top-level map, and record a met or not-met status for each requirement as you go.
| # | Family | Focus | What "met" looks like |
|---|---|---|---|
| 1 | Access Control (AC) | Who can access what | Least-privilege access, enforced authorizations, controlled remote access and session management |
| 2 | Awareness & Training (AT) | People know their role | Security awareness training delivered and tracked; role-based training for privileged users |
| 3 | Audit & Accountability (AU) | Logging and review | Audit logs generated, protected, and actually reviewed on a cadence; actions traceable to individuals |
| 4 | Configuration Management (CM) | Systems built to a known baseline | Baseline configurations, change control, restriction of unnecessary software and ports |
| 5 | Identification & Authentication (IA) | Proving who you are | Unique user IDs, MFA, strong authenticator management |
| 6 | Incident Response (IR) | When something goes wrong | An incident response capability that is documented, tested, and tied to 72-hour DoW reporting |
| 7 | Maintenance (MA) | Servicing systems safely | Controlled maintenance, sanitization of equipment, oversight of maintenance personnel |
| 8 | Media Protection (MP) | Protecting CUI on media | Marking, access control, sanitization, and controlled transport of media holding CUI |
| 9 | Personnel Security (PS) | Trustworthy people | Screening before CUI access; protecting CUI during personnel transfers and terminations |
| 10 | Physical Protection (PE) | Doors and facilities | Limited physical access, escorting visitors, protecting physical devices and facilities |
| 11 | Risk Assessment (RA) | Knowing your exposure | Periodic risk assessments and vulnerability scanning with remediation |
| 12 | Security Assessment (CA) | Checking your own controls | Assessing controls, building POA&Ms, and maintaining the SSP — the self-assessment lives here |
| 13 | System & Communications Protection (SC) | Protecting data in transit and boundaries | Boundary protection, FIPS-validated encryption, network segmentation |
| 14 | System & Information Integrity (SI) | Catching and fixing flaws | Flaw remediation, malicious-code protection, monitoring and alerting |
The value of a self-assessment is entirely in its honesty. A dishonest one just moves the failure to a more expensive moment: a government-led or third-party assessment, or worse, a False Claims Act problem after you attest to it. Rules for scoring straight:
Then do the math: 110 minus your weighted deductions equals your score. That number is what you post to SPRS. If you would be embarrassed to defend it to an assessor, fix the gaps before you submit.
Across self-assessments, the same requirements come up short. If you are triaging, look here first, because most of them carry high weights and hurt your score the most:
Closing MFA, FIPS-validated encryption, configuration baselines, and vulnerability remediation often moves a score more than a dozen low-weight fixes, because those requirements carry 5-point weights. Incident response testing (3.6.3), by contrast, is a 1-point requirement.
Rev 3, finalized in May 2024, restructures the requirements, but you do not assess against it yet. The Department assesses against Rev 2: Class Deviation 2024-O0013 ties DFARS 252.204-7012 to Rev 2 until it is rescinded, and the Department's September 3, 2026 class deviation keeps Rev 2. When Rev 3 eventually applies, expect:
There is no official DoW transition date. An interim final rule to move from Rev 2 to Rev 3 (RIN 0790-AM01) was listed in the Unified Agenda with a July 2026 target, but it had not been published as of late September 2026. The practical move: self-assess against Rev 2 now, and keep an eye on the three new Rev 3 families (especially Supply Chain Risk Management) so you are not starting from zero later. Full detail in our NIST 800-171 Rev 3 guide.
What is a NIST 800-171 self-assessment? It is the process of evaluating your own implementation of the 110 NIST 800-171 Rev 2 requirements, scoring each as met or not met, and calculating an SPRS score. The Department requires it before you can post a score to SPRS, and it is the foundation for a CMMC Level 2 self-assessment.
How many controls are in NIST 800-171? Rev 2, the version the Department assesses against, has 110 requirements across 14 families. Rev 3 (final May 2024, not yet adopted by DoW) has 97 requirements across 17 families. For any self-assessment tied to a contract or CMMC today, use the 110.
How do I become NIST 800-171 compliant? Self-assess against the 110 Rev 2 requirements, document how you meet each one in an SSP, put every gap on a POA&M with owners and dates, calculate your SPRS score, and post it to SPRS via PIEE. Then maintain it — close POA&M items with evidence and keep the SSP current. Our NIST 800-171 compliance guide walks the full path.
How do I perform a NIST 800-171 assessment? Go family by family through all 14 Rev 2 families, and for each requirement decide met or not met against its 800-171A assessment objectives — with evidence. Record gaps, calculate your weighted score from 110, and produce an SSP and POA&M. A structured checklist keeps you from skipping requirements or grading yourself too generously.
What is the difference between a self-assessment and a C3PAO assessment? A self-assessment is you scoring yourself and affirming the result in SPRS. A C3PAO assessment is an authorized third party independently verifying your implementation for CMMC Level 2 certification. Under the current CMMC phase-in, the Department has suspended Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program. Phase 1 remains in effect, so contracts can still require Level 1 and Level 2 self-assessments with affirmations in SPRS, and the contract specifies which applies. Either way, an honest self-assessment first is how you avoid surprises.
A self-assessment is only useful if it is honest, complete, and backed by evidence — which is exactly the part a spreadsheet checklist makes hard. Grading yourself straight across all 14 families, tying each requirement to an artifact, and keeping the resulting score, SSP, and POA&M in sync is real work.
Use the family-by-family checklist above to start working through every requirement. When you are ready to turn that checklist into a maintained score with evidence attached, book a demo. We will show you how Compli.ai runs the self-assessment objective by objective, computes your SPRS score with the DoD Assessment Methodology, and keeps the SSP implementation statements and POA&M on the same control set inside your own Microsoft 365 tenant. It is built by practitioners who run these assessments, so it scores with the same arithmetic an assessor applies. To compare doing it yourself versus with a platform or a practitioner, see CMMC compliance software.