Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient - No AI Slop!
ComplianceForge

How To Prepare for a NIST 800-171 Self-Assessment: An Internal Assessment Playbook

NIST 800-171
ComplianceForge Support
July 20, 2026
How To Prepare for a NIST 800-171 Self-Assessment: An Internal Assessment Playbook

Editorial note: This article is informational, not legal or compliance advice. CMMC requirements are in flux after the Department of War suspended Phase II on July 13, 2026, so confirm your specific contractual obligations before you rely on any assessment approach.

A NIST 800-171 self-assessment is a structured evaluation of how well your organization has implemented the security requirements in NIST SP 800-171, scored against the DoD Assessment Methodology and documented in a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M). With CMMC Phase II suspended and the interim path pointing to NIST 800-171 Rev 2 self-assessments and select government led assessments, this is the process most defense contractors need to get right in the near term.

This playbook walks through the self-assessment end to end, so you can produce a score you can stand behind rather than a number you hope no one checks.

Key Takeaways

• Scope first. You cannot assess controls until you know where Controlled Unclassified Information (CUI) lives.

• Assess every requirement against your real environment, not against your intentions.

• Score honestly using the DoD Assessment Methodology, where the maximum is 110 and specific requirements carry defined deductions.

• Record met requirements in your SSP and open items in your POA&M.

• Keep evidence, because a self-assessment is only as strong as what backs it up.

• Reassess on a cadence, since a self-assessment is a point in time snapshot.

Step 1: Define Your Scope and Find the CUI

Every NIST 800-171 self-assessment starts with scoping. NIST 800-171 exists to protect Controlled Unclassified Information, so the first job is to identify where CUI is received, processed, stored and transmitted across your people, processes and technology. That includes the obvious systems and the easy to miss ones, such as email, file shares, backups, and the endpoints of anyone who touches CUI.

Scoping decisions drive everything after them. A well designed enclave that concentrates CUI into a defined boundary usually makes the rest of the assessment smaller and cleaner. An undefined scope tends to pull your entire enterprise into the assessment and inflate both your work and your risk.

Step 2: Assess Each Requirement Against Reality

NIST 800-171 Rev 2 is organized into 14 control families and 110 security requirements. Work through each requirement and ask a direct question. Is this implemented, in my environment, today, in a way I can show someone?

The discipline here is to assess what is true rather than what is planned. A control that is written into a policy but not actually operating is not implemented. This is the single most common way self-assessments drift from reality, and it is the gap a government led assessment is most likely to find.

Step 3: Score Using the DoD Assessment Methodology

The DoD Assessment Methodology produces a score on a scale that tops out at 110, where you begin at 110 and subtract points for requirements that are not met. Not every requirement is weighted equally. Some carry a deduction of 5 points, some 3 points, and some 1 point, based on their impact. The result can be a negative number, which surprises people the first time they score honestly.

Record the score, the date, and the scope it applies to. That score, submitted where required, becomes part of your representation to the government, so it needs to match your SSP and your evidence.

Step 4: Document Your SSP and POA&M

Two artifacts turn an assessment into something defensible.

The System Security Plan (SSP) describes how each requirement is met in your specific environment. A strong SSP names systems, references the policies and procedures that govern each control, and describes the implementation clearly enough that an assessor could verify it. A weak SSP restates the requirement and adds nothing.

The Plan of Action and Milestones (POA&M) records every requirement that is not fully met, the plan to close it, the responsible owner, and the target date. A credible POA&M is a sign of a mature program. An empty POA&M attached to a low score is a red flag.

Step 5: Keep Your Evidence

A self-assessment claim is only as good as the evidence behind it. For each implemented requirement, keep the artifacts that would let an assessor confirm it, such as configuration screenshots, policy documents, procedure records, logs, and training records. Organizing evidence as you go is far easier than reconstructing it under the pressure of a government led assessment.

Step 6: Reassess on a Cadence

A self-assessment is a snapshot. Environments change, staff turn over, and controls drift. Set a cadence to reassess, and reassess after any significant change to your systems or your handling of CUI. The score you submitted last year does not describe the environment you run today.

How the NCP Turns This Playbook Into Documentation

Most of the effort in the steps above is documentation, and that is where the NIST 800-171 Compliance Program (NCP) does the heavy lifting. The NCP provides editable policies, standards and procedures, plus an SSP template and a POA&M template aligned to NIST 800-171 and CMMC 2.0. It covers the Assessment Objectives from NIST 800-171A, which are the criteria an assessor actually uses, so your documentation is written to the level a real assessment evaluates.

The NCP is designed to get you roughly 80 to 90 percent of the way to a complete set, leaving you the tailoring only you can do, such as describing your enclave, naming your systems, and assigning your procedures. Because it has been used to pass DIBCAC and C3PAO assessments, the documentation was built to withstand exactly the independent scrutiny a select government led assessment brings.

If you would rather spend your time assessing controls than writing policy from a blank page, begin with the NCP and tailor from there.

Frequently Asked Questions

What is a good NIST 800-171 self-assessment score? The methodology tops out at 110. A perfect score means every requirement is met. Many organizations start below that, sometimes well below, and use a POA&M to close the gap. Focus on an honest score with a credible plan rather than a flattering number.

How long does a NIST 800-171 self-assessment take? It depends on scope, environment complexity, and how much documentation already exists. Tight scoping and a ready made documentation set shorten it considerably.

Do I submit my self-assessment score to the government? In many DoD contracts, the score is submitted to the Supplier Performance Risk System. Confirm the current submission requirements for your specific contracts, since CMMC and DFARS requirements are changing.

Sources: NIST SP 800-171 and the DoD Assessment Methodology for the scoring structure. Department of War CMMC Phase II suspension release, July 13, 2026, at war.gov. Product details from the ComplianceForge NIST 800-171 Compliance Program (NCP) product page. Verify current scoring and submission requirements against primary sources.