NIST SP 800-171 Compliance & SPRS Scoring
DFARS 252.204-7012 requires every defense contractor handling CUI to implement all 110 NIST SP 800-171 controls and report a SPRS score. BLACKSAND implements the controls, documents your SSP, and raises your score — keeping you DFARS-eligible and contract-ready.
All 110 controls, implemented and documented
NIST SP 800-171 is the technical and operational foundation beneath CMMC Level 2. The 110 controls span access control, incident response, system integrity, and CUI boundary protection. DFARS 7012 also requires a current SPRS (Supplier Performance Risk System) score and a 72-hour cyber incident reporting workflow. A weak score or missing controls puts your DoD contracts at risk.
BLACKSAND implements the controls, builds your System Security Plan (SSP), manages your POA&M, and calculates an accurate SPRS score that reflects real maturity — not just a number. We also tie your 800-171 program directly to CMMC Level 2 readiness so you satisfy both requirements with one body of evidence.
Gap assessment against all 110 NIST SP 800-171 controls
System Security Plan (SSP) and POA&M development
CUI enclave scoping and access control implementation
Accurate SPRS score calculation and submission support
DFARS 7012 cyber incident reporting workflow
Evidence packaging aligned to CMMC Level 2 assessments
Related services
NIST SP 800-171 Compliance FAQ
What is a SPRS score and why does it matter? +
The SPRS (Supplier Performance Risk System) score is the score DoD contractors must submit to reflect their NIST SP 800-171 implementation maturity, ranging from -203 to +110. A low or unreported score flags your organization as higher risk to DoD buyers and can threaten contract eligibility. BLACKSAND implements controls and calculates an accurate, defensible score.
Is NIST SP 800-171 the same as CMMC Level 2? +
CMMC Level 2 aligns to the 110 controls of NIST SP 800-171. A strong 800-171 program is the technical foundation of CMMC Level 2 readiness. BLACKSAND builds one control set and body of evidence that satisfies both your DFARS 7012 obligations and a future CMMC assessment.
Do you support DFARS 7012 incident reporting? +
Yes. We build the 72-hour cyber incident reporting workflow, define roles and escalation paths, and run tabletop exercises so your team can meet DFARS 7012 reporting obligations when an incident occurs.
Ready to start your NIST SP 800-171 Compliance engagement?
Get a strategic security posture review with same-day response.
Request Your Assessment