If you handle controlled unclassified information for the Department of Defense, or work as a subcontractor to someone who does, you will be asked how you measure up against NIST SP 800-171. The honest answer starts with a self-assessment. The temptation in that exercise is to round up. Anything you cannot prove feels like it should count as done because someone is probably handling it.
That habit is the single biggest risk in a self-assessment. A score that cannot be backed by evidence is a liability, with your customer and potentially under the contract. This post explains how to approach the work so the result holds up.
Start with scope
Before you score anything, decide where CUI lives and travels in your company. List the systems, people, locations and vendors that store, process or transmit it. Many small contractors discover that CUI arrives by email, lands on a few laptops and is shared with one or two outside parties.
A tight, well-documented scope is easier to protect and to defend. Leaving it vague makes every control harder to assess because the boundaries keep moving. Keep CUI in a defined environment rather than letting it spread across every device in the company.
Understand how scoring works
The Department of Defense assessment methodology for NIST SP 800-171 uses a scoring approach in which a perfect implementation of all 110 requirements yields a score of 110, and points are subtracted for requirements that are not implemented. Different requirements carry different weights, so a missing high-impact control costs more than a missing minor one. Use the official methodology document and the NIST SP 800-171 text as your source, not a summary from a vendor brochure.
The key principle is simple: a requirement is either fully implemented or it is not. Partially implemented does not earn credit unless the methodology specifically allows it.
Gather evidence, not impressions
For each requirement, write down three things.
- What the requirement asks for, in your own words.
- How you meet it, specifically: the tool, setting, policy or procedure.
- Proof: a screenshot, configuration export, policy document, training record or log that an assessor could review.
If you cannot produce proof, treat the control as not implemented until you can. This feels harsh, but it is the standard an assessor will apply.
Common places where optimism creeps in
- Multi-factor authentication: Enabled for most users is not enabled for everyone who touches CUI, including administrators and remote access.
- Access reviews: A policy that says reviews happen is not a record that they happened.
- Incident response: A written plan is not the same as having tested it.
- Media and device control: Policies mean little if personal phones and USB drives are used freely.
- Third parties: Cloud services and outside IT providers that handle CUI need to be part of your story.
Document gaps in a plan of action
Gaps are expected. What matters is that you know about them and have a credible plan. A plan of action and milestones, or POA&M, lists each unmet requirement, the work needed to close it, who is responsible, the resources required and a target date.
Keep dates realistic. A plan with every item due next month looks unserious. Prioritize the items that carry the most risk and the most scoring weight, and that close real exposure such as MFA, encryption and logging.
Build the system security plan alongside
The self-assessment and the system security plan feed each other. As you describe how each requirement is met, you are writing the plan. Keep both in one place, version them and assign an owner who updates them when systems change.
Avoid these mistakes
- Having an outside party fill out the assessment without involvement from your own staff.
- Scoring based on what the IT provider says without verifying.
- Treating the score as a one-time task rather than a living record.
- Submitting a score you would not be comfortable explaining line by line.
Never submit a number you cannot support. Misstating a security posture to a customer or the government carries consequences well beyond a lower score.
A realistic rhythm
For a small company, plan a few focused weeks for the first pass, then a quarterly review of changes and open items. Treat every new system, vendor or contract as a trigger to reassess scope.
How Ironfield Cyber can help
Ironfield Cyber works with defense subcontractors to define CUI scope, collect evidence and build a realistic POA&M. If you would like a candid read on where you stand before a prime contractor or an assessor asks, we can walk through the requirements with you and help you prioritize the work.