All 110 requirements. All 14 families. The gaps that sink assessments, how SPRS scoring actually works, and how defense contractors implement compliance in Microsoft GCC High. Written for organizations handling CUI, not for beginners googling “what is cybersecurity.”
23 pages. No fluff. Built on NIST SP 800-171 Rev 2, the standard your contracts requires today.
If your organization holds DoD contracts involving CUI, DFARS 252.204-7012 makes all 110 NIST 800-171 requirements a contractual obligation. DFARS 252.204-7019 means no current SPRS score, no award consideration. This guide covers what the requirements demand, where organizations actually fail, and what implementation looks like in a Microsoft environment.
Every requirement family explained. All 14 families of NIST SP 800-171 Rev 2, with the key requirements assessors weight most heavily and the exact requirement numbers to check against your SSP.
The gaps that sink assessments. The recurring failures we see in real environments: MFA that skips privileged local access, logs nobody reviews, encryption that isn’t FIPS-validated, SSPs that describe an environment that doesn’t exist.
SPRS scoring, demystified. How the DoD Assessment Methodology works: weighted deductions, the minus 203 floor, why there is no partial credit, and why an inflated score is a False Claims Act problem.
Rev 2 vs. Rev 3, settled. Which revision your contracts actually require in 2026 and why (the DoD class deviation, explained).
Where CMMC stands after the July 2026 suspension. What paused, what didn’t, and what it means for your compliance spend.
GCC High implementation notes for every family. The specific Microsoft tools (Entra ID, Intune, Purview, Defender, Sentinel) that satisfy each family’s requirements.
A six-phase implementation roadmap from scoping to annual affirmation, with realistic timelines.
This guide is for defense contractors and subcontractors that handle CUI: manufacturers, engineering firms, research organizations, and service providers in the DoD supply chain. If a prime has asked for your SPRS score, if DFARS 7012 is in your contract, or if you’re staring down a self-assessment you’re not sure will hold up, this was written for you.
It is not an intro to cybersecurity. Your team already knows what a firewall is. This is about the 110 requirements between you and your next contract.
We’ll email you the guide and occasional CMMC and NIST 800-171 updates. No spam, unsubscribe anytime.
Agile IT implements NIST 800-171 in Microsoft environments. We migrate defense contractors to GCC High, configure and secure the environment, and validate it against all 110 requirements. We build compliance, we don’t just advise on it. The implementation notes in this guide come from doing this work in real contractor environments, not from reading the standard once.
Tell us where you are and what you’re working toward.
We will respond within one buisness day.
NIST Special Publication 800-171 is the federal standard for protecting Controlled Unclassified Information (CUI) in nonfederal systems. Revision 2 contains 110 security requirements across 14 families. DFARS 252.204-7012 makes it contractually mandatory for DoD contractors handling covered defense information.
Rev 2. NIST published Rev 3 in May 2024, but a DoD class deviation issued the same month requires contractors under DFARS 252.204-7012 to continue complying with Rev 2. The CMMC rule (32 CFR Part 170) is also built on Rev 2.
Yes. The July 13, 2026 suspension paused CMMC Phase II third-party certification requirements. NIST 800-171 Rev 2, DFARS 252.204-7012, and Phase 1 self-assessment and SPRS requirements all remain in force, enforced through self-assessments and select government-led assessments.
There is no official passing score for the basic self-assessment; the scale runs from minus 203 to 110. But DFARS 7019 requires a current score for award consideration, primes screen scores when teaming, and under the CMMC rule a Level 2 conditional status requires at least 88 of 110 with remaining items on a POA&M closed within 180 days.
For a mid-sized contractor consolidating into a GCC High enclave, typically four to nine months from scoping to a defensible SPRS submission, depending on data sprawl and legacy systems.
Yes. DFARS 252.204-7012 flows down to every subcontractor whose work involves covered defense information, regardless of company size or tier.
The 110 Requirements Are the Same for Everyone. Your Environment Isn’t.
The guide gives you the general picture: the families, the scoring, the gaps that sink assessments. A call with one of our experts gives you the specific one, for your contracts and your environment.