The Complete Guide to NIST 800-171 Guide

All 110 requirements. All 14 families. The gaps that sink assessments, how SPRS scoring actually works, and how defense contractors implement compliance in Microsoft GCC High. Written for organizations handling CUI, not for beginners googling “what is cybersecurity.” 

23 pages. No fluff. Built on NIST SP 800-171 Rev 2, the standard your contracts requires today. 

If your organization holds DoD contracts involving CUI, DFARS 252.204-7012 makes all 110 NIST 800-171 requirements a contractual obligation. DFARS 252.204-7019 means no current SPRS score, no award consideration. This guide covers what the requirements demand, where organizations actually fail, and what implementation looks like in a Microsoft environment. 

What's Inside The Guide

Every requirement family explained. All 14 families of NIST SP 800-171 Rev 2, with the key requirements assessors weight most heavily and the exact requirement numbers to check against your SSP. 

The gaps that sink assessments. The recurring failures we see in real environments: MFA that skips privileged local access, logs nobody reviews, encryption that isn’t FIPS-validated, SSPs that describe an environment that doesn’t exist. 

SPRS scoring, demystified. How the DoD Assessment Methodology works: weighted deductions, the minus 203 floor, why there is no partial credit, and why an inflated score is a False Claims Act problem. 

Rev 2 vs. Rev 3, settled. Which revision your contracts actually require in 2026 and why (the DoD class deviation, explained). 

Where CMMC stands after the July 2026 suspension. What paused, what didn’t, and what it means for your compliance spend. 

GCC High implementation notes for every family. The specific Microsoft tools (Entra ID, Intune, Purview, Defender, Sentinel) that satisfy each family’s requirements. 

A six-phase implementation roadmap from scoping to annual affirmation, with realistic timelines. 

Built for Organizations Under Real Compliance Pressure

This guide is for defense contractors and subcontractors that handle CUI: manufacturers, engineering firms, research organizations, and service providers in the DoD supply chain. If a prime has asked for your SPRS score, if DFARS 7012 is in your contract, or if you’re staring down a self-assessment you’re not sure will hold up, this was written for you.  

It is not an intro to cybersecurity. Your team already knows what a firewall is. This is about the 110 requirements between you and your next contract. 

We’ll email you the guide and occasional CMMC and NIST 800-171 updates. No spam, unsubscribe anytime.

Why Agile IT

Agile IT implements NIST 800-171 in Microsoft environments. We migrate defense contractors to GCC High, configure and secure the environment, and validate it against all 110 requirements. We build compliance, we don’t just advise on it. The implementation notes in this guide come from doing this work in real contractor environments, not from reading the standard once. 

Start the Conversation

Tell us where you are and what you’re working toward. 

We will respond within one buisness day.

NSIT 800-171 Frequently Asked Questions

What is NIST 800-171?

NIST Special Publication 800-171 is the federal standard for protecting Controlled Unclassified Information (CUI) in nonfederal systems. Revision 2 contains 110 security requirements across 14 families. DFARS 252.204-7012 makes it contractually mandatory for DoD contractors handling covered defense information.

Does NIST 800-171 Rev 2 or Rev 3 apply to my DoD contracts?

Rev 2. NIST published Rev 3 in May 2024, but a DoD class deviation issued the same month requires contractors under DFARS 252.204-7012 to continue complying with Rev 2. The CMMC rule (32 CFR Part 170) is also built on Rev 2.

Is NIST 800-171 still required after the CMMC suspension?

Yes. The July 13, 2026 suspension paused CMMC Phase II third-party certification requirements. NIST 800-171 Rev 2, DFARS 252.204-7012, and Phase 1 self-assessment and SPRS requirements all remain in force, enforced through self-assessments and select government-led assessments.

What is a passing SPRS score?

There is no official passing score for the basic self-assessment; the scale runs from minus 203 to 110. But DFARS 7019 requires a current score for award consideration, primes screen scores when teaming, and under the CMMC rule a Level 2 conditional status requires at least 88 of 110 with remaining items on a POA&M closed within 180 days. 

How long does NIST 800-171 compliance take?

For a mid-sized contractor consolidating into a GCC High enclave, typically four to nine months from scoping to a defensible SPRS submission, depending on data sprawl and legacy systems. 

Do subcontractors have to comply?

Yes. DFARS 252.204-7012 flows down to every subcontractor whose work involves covered defense information, regardless of company size or tier. 

The 110 Requirements Are the Same for Everyone. Your Environment Isn’t.

The guide gives you the general picture: the families, the scoring, the gaps that sink assessments. A call with one of our experts gives you the specific one, for your contracts and your environment.