Guides / October 02, 2026
How Do I Calculate My 800-171 Self-Assessment Score?
You have a DoD contract coming up, and someone asked for your 800-171 score.
NIST SP 800-171 is the National Institute of Standards and Technology checklist for protecting CUI. CUI is Controlled Unclassified Information. DoD is the Department of Defense. DoD scores your implementation with fixed arithmetic. You start at 110. You subtract points for each requirement not met. The number 110 matches the 110 security requirements in the checklist. (DoD Assessment Methodology)
Start at 110, subtract what is missing
The arithmetic is simple. Begin at 110. Subtract the assigned value for each requirement not met. All requirements met means a score of 110. Missing requirements pull the score down. The methodology says the score may go below zero. (DoD Assessment Methodology)
There is no partial credit. Two requirements are the exception. They have built-in partial scoring. A plan of action does not count as implemented. Without a system security plan, the assessment cannot be completed. (DoD Assessment Methodology)
The three weights and what they mean
DoD weights each requirement by the harm of leaving it undone. There are three weights.
Five points come off when a missing requirement could let attackers take over your network or steal CUI. Failing to limit system access to authorized users is one example. Failing to control removable media on your systems is another. (DoD Assessment Methodology)
Three points come off when the effect is narrow and local. Failing to limit access to CUI on system media is one example. Failing to encrypt CUI on a mobile device is another. The risk stays on the media, not on the whole network. (DoD Assessment Methodology)
One point comes off for the remaining requirements. These have a limited or indirect effect. Failing to prevent reuse of user identifiers for a set period is one example. (DoD Assessment Methodology)
Two requirements with built-in partial credit
MFA is multifactor authentication. FIPS means Federal Information Processing Standards.
For requirement 3.5.3, the deduction is 3 points if MFA covers only remote and privileged users. It is 5 points if you use no MFA at all. (DoD Assessment Methodology)
For requirement 3.13.11, the deduction is 3 points if you encrypt CUI without FIPS-validated cryptography. It is 5 points if you do not encrypt CUI at all. (DoD Assessment Methodology)
Everything else is all or nothing. A requirement is implemented or not implemented. There is no middle ground.
A worked example
Picture a 12-person machine shop. You review each requirement against your system security plan. You find five gaps.
- Requirement 3.1.1, limiting system access to authorized users: not met, minus 5.
- Requirement 3.1.2, limiting users to allowed functions: not met, minus 5.
- Requirement 3.8.2, limiting access to CUI on system media: not met, minus 3.
- Requirement 3.5.3, MFA for remote and privileged users only: minus 3.
- Requirement 3.5.5, preventing reuse of identifiers: not met, minus 1.
Add the deductions: 5 + 5 + 3 + 3 + 1 = 17. Subtract from 110. Your score is 93 out of 110.
One more missed 5-point requirement would drop the score to 88. Fixing all five gaps brings it back to 110.
What to record in SPRS
SPRS is the Supplier Performance Risk System. DFARS is the Defense Federal Acquisition Regulation Supplement. Your posted score is a summary, not a breakdown. DFARS 252.204-7020 calls it a summary level score, such as 95 out of 110. It is not the value of each requirement. (DFARS 252.204-7020)
DoD calls your self-assessment a Basic assessment. For each Basic assessment, you record the following.
- The standard you assessed against.
- The organization that ran the assessment.
- Each system security plan covered.
- The date the assessment was completed.
- The summary score, as 93 out of 110.
- The date you expect to reach 110.
You enter this in SPRS through PIEE. PIEE is the Procurement Integrated Enterprise Environment. You need a PIEE account with the SPRS Cyber Vendor role. You request the role through PIEE. (DoD Assessment Methodology)
Keep the score current
DFARS 252.204-7019 says your assessment must be current. Current means not more than 3 years old. A solicitation can set a shorter window. (DFARS 252.204-7019)
Check your SPRS entry date. Reassess before the 3-year mark. An expired score can block an award.
What to do this week
Open your system security plan. Walk through the 110 requirements one by one. Mark each one implemented or not implemented. For each gap, look up its weight in the scoring template. Total the deductions and subtract from 110. That number is your score.
Sources
- NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1, June 24, 2020 (scoring method, weights, Basic self-assessment, SPRS entry): https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf
- DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements (Basic assessment definition, summary score format, subcontractor flow-down): https://www.acquisition.gov/dfars/252.204-7020-nist-sp-800-171-dod-assessment-requirements.?searchTerms=DFARS+Clause+252.204-7020%3A+NIST+SP+800-171+DoD+Assessment+Requirements
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements (3-year currency, SPRS verification): https://www.acquisition.gov/dfars/252.204-7019-notice-nist-sp-800-171-dod-assessment-requirements.?searchTerms=DFARS+Provision+252.204-7019%3A+Notice+of+NIST+SP+800-171+DoD+Assessment+Requirements
Next step
Gather your evidence from the live system before you score it. PolicyCortex uses 33 collectors that read live Azure configuration. It builds SSP, SAR, and POA&M output from the evidence it collects. SSP is the System Security Plan. SAR is the Security Assessment Report. POA&M is the Plan of Action and Milestones. See how it works.