DFARS Cyber Safeguarding · 3 of 3

NIST SP 800-171 DoD assessments

← All Insights

In short

  • A current assessment is not more than 3 years old.
  • Contractors have 14 business days to rebut Medium or High findings.
  • Subcontractors need at least a Basic Assessment before award.
Published10 October 2026
Last reviewed10 October 2026
Sources current as of10 October 2026

1. A current assessment before award

Contractors required to implement National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 under the Defense Federal Acquisition Regulation Supplement (DFARS) face an assessment duty at award. Those implementing it under the clause at 252.204-7012 must hold a current assessment at that point (DFARS 204.7302(a)(2)). It must be at least a Basic NIST SP 800-171 Department of Defense (DoD) Assessment. Current means not more than 3 years old, unless the solicitation specifies a shorter time.

The solicitation provision at 252.204-7019 makes this a condition of being considered for award (DFARS 252.204-7019(b)). An offeror required to implement NIST SP 800-171 must have a current assessment for each covered contractor information system relevant to the offer, contract, task order or delivery order. The provision goes in all solicitations, including those for commercial products and commercial services, except those solely for commercially available off-the-shelf (COTS) items (DFARS 204.7304(d)).

2. Three levels of assessment

A Basic Assessment is the contractor’s self-assessment of its implementation of NIST SP 800-171, based on its review of its system security plans (DFARS 252.204-7020(a)). It is conducted under the NIST SP 800-171 DoD Assessment Methodology. It results in a confidence level of “Low” in the score, because the score is self-generated.

A Medium Assessment is conducted by the Government and consists of a review of the contractor’s Basic Assessment, a thorough document review and discussions with the contractor as needed (DFARS 252.204-7020(a)). It results in a confidence level of “Medium”. A High Assessment is conducted by Government personnel using NIST SP 800-171A. It adds verification, examination and demonstration of the system security plan, to validate that the requirements have been implemented as described. It results in a confidence level of “High”.

Under the DFARS policy, High assessments are conducted by Government personnel (DFARS 204.7302(a)(4)). A NIST SP 800-171 DoD Assessment does not duplicate any other Defense Department assessment or the Cybersecurity Maturity Model Certification (CMMC), except in rare circumstances (DFARS 204.7302(a)(5)). One example is a change in cybersecurity risks, threats or awareness that requires a re-assessment to ensure current compliance.

3. Posting scores

The offeror must verify that summary level scores of a current assessment are posted in the Supplier Performance Risk System (SPRS) for all covered contractor information systems relevant to the offer (DFARS 252.204-7019(c)(1)). If no current scores are posted, the offeror may conduct and submit a Basic Assessment for posting to SPRS (DFARS 252.204-7019(c)(2)). Summary level scores for all assessments will be posted in SPRS 30 days after the assessment (DFARS 252.204-7019(d)).

A Basic Assessment submission is sent by encrypted email and covers the version of NIST SP 800-171 assessed and the organization conducting the assessment (DFARS 252.204-7020(d)(1)(i)). For each system security plan supporting a Defense contract, it lists all associated Commercial and Government Entity (CAGE) codes, with a brief architecture description if there is more than one plan. It also gives the completion date and the summary level score, such as 95 out of 110, not the value for each requirement. The last item is the date by which all requirements are expected to be implemented, meaning a score of 110, based on the plans of action.

4. Medium and High results and rebuttal

For Medium and High Assessments, the Department posts the standard assessed, the assessing organization and the CAGE codes. It also posts the date and level, the summary score and the expected date of full implementation (DFARS 252.204-7020(d)(2)). It gives the contractor those scores and an opportunity for rebuttal and adjudication before posting them to SPRS (DFARS 252.204-7020(e)(1)). After each assessment, the contractor has 14 business days to provide added information showing it meets requirements not observed by the team, or to rebut findings in question (DFARS 252.204-7020(e)(2)).

The clause applies to covered contractor information systems that must comply with NIST SP 800-171 under the clause at 252.204-7012 (DFARS 252.204-7020(b)). The contractor must give access to the facilities, systems and personnel the Government needs to conduct a Medium or High Assessment, if necessary (DFARS 252.204-7020(c)).

5. Who sees the scores

Scores posted in SPRS are available to Defense personnel and protected under DoD Instruction 5000.79 (DFARS 252.204-7020(f)(1)). Authorized representatives of the assessed contractor may view their own summary level scores in SPRS (DFARS 252.204-7020(f)(2)). Any added documentation resulting from a High Assessment is retained and protected as Controlled Unclassified Information for internal Department use only (DFARS 252.204-7020(f)(3)). It is protected against unauthorized use and release, including through applicable Freedom of Information Act exemptions. Exemption 4, for example, covers trade secrets and commercial or financial information obtained from a contractor that is privileged or confidential.

6. The contracting officer’s check and subcontracts

The check applies to offerors required to implement NIST SP 800-171 under the clause at 252.204-7012. Before award to such an offeror, the contracting officer verifies that the summary level score of a current assessment for each relevant covered system is posted in SPRS (DFARS 204.7303(b)). The same check applies before exercising an option period or extending the period of performance with a contractor that must implement NIST SP 800-171. The clause at 252.204-7020 goes in all solicitations, contracts, task orders and delivery orders except those solely for COTS items (DFARS 204.7304(e)).

The contractor must insert the substance of the clause in all subcontracts, including those for commercial products or commercial services, but excluding COTS items (DFARS 252.204-7020(g)(1)). It must not award a subcontract subject to NIST SP 800-171 unless the subcontractor has completed, within the last 3 years, at least a Basic Assessment (DFARS 252.204-7020(g)(2)). That covers all covered systems relevant to its offer that are not part of a system operated on behalf of the Government. A subcontractor without current scores may conduct and submit a Basic Assessment for posting (DFARS 252.204-7020(g)(3)). The safeguarding clause itself is covered in covered defense information and adequate security.

Key terms

Basic AssessmentA contractor self-assessment with a low confidence level.
Medium AssessmentA Government review of the Basic Assessment and documents.
High AssessmentA Government assessment under NIST SP 800-171A with demonstration.
Summary level scoreThe overall score out of 110 posted in SPRS.
Rebuttal windowFourteen business days after an assessment to respond to findings.

Every statement above links to the document behind it. The full source list for this piece is on the sources page.

This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.

How Sentfore supports this

Assessment scores follow a contractor across awards. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.