BLACKSAND®
CUI PROTECTION & DFARS 7012

NIST SP 800-171 Compliance & SPRS Scoring

DFARS 252.204-7012 requires every defense contractor handling CUI to implement all 110 NIST SP 800-171 controls and report a SPRS score. BLACKSAND implements the controls, documents your SSP, and raises your score — keeping you DFARS-eligible and contract-ready.

All 110 controls, implemented and documented

NIST SP 800-171 is the technical and operational foundation beneath CMMC Level 2. The 110 controls span access control, incident response, system integrity, and CUI boundary protection. DFARS 7012 also requires a current SPRS (Supplier Performance Risk System) score and a 72-hour cyber incident reporting workflow. A weak score or missing controls puts your DoD contracts at risk.

BLACKSAND implements the controls, builds your System Security Plan (SSP), manages your POA&M, and calculates an accurate SPRS score that reflects real maturity — not just a number. We also tie your 800-171 program directly to CMMC Level 2 readiness so you satisfy both requirements with one body of evidence.

Gap assessment against all 110 NIST SP 800-171 controls

System Security Plan (SSP) and POA&M development

CUI enclave scoping and access control implementation

Accurate SPRS score calculation and submission support

DFARS 7012 cyber incident reporting workflow

Evidence packaging aligned to CMMC Level 2 assessments

FAQ

NIST SP 800-171 Compliance FAQ

What is a SPRS score and why does it matter? +

The SPRS (Supplier Performance Risk System) score is the score DoD contractors must submit to reflect their NIST SP 800-171 implementation maturity, ranging from -203 to +110. A low or unreported score flags your organization as higher risk to DoD buyers and can threaten contract eligibility. BLACKSAND implements controls and calculates an accurate, defensible score.

Is NIST SP 800-171 the same as CMMC Level 2? +

CMMC Level 2 aligns to the 110 controls of NIST SP 800-171. A strong 800-171 program is the technical foundation of CMMC Level 2 readiness. BLACKSAND builds one control set and body of evidence that satisfies both your DFARS 7012 obligations and a future CMMC assessment.

Do you support DFARS 7012 incident reporting? +

Yes. We build the 72-hour cyber incident reporting workflow, define roles and escalation paths, and run tabletop exercises so your team can meet DFARS 7012 reporting obligations when an incident occurs.

Ready to start your NIST SP 800-171 Compliance engagement?

Get a strategic security posture review with same-day response.

Request Your Assessment