Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient - No AI Slop!
Secure Controls Framework

NIST 800-171 Basic Assessment Reporting To SPRS

CMMC,DFARS
ComplianceForge Support
November 12, 2020
NIST 800-171 Basic Assessment Reporting To SPRS

For those organizations in scope for NIST800-171, the self-imposed November 30, 2020 deadline is fast approaching for many subcontractors to submit the results oftheir “basic assessment” to Supplier Performance Risk System (SPRS). There is a good overview of the process at https://www.cmmcaudit.org/how-to-submit-a-nist-sp-800-171-self-assessment-to-sprs/.In summary, a contractor has to report the following self-assessment results toSPRS:

  1. The name(s)of the System Security Plan (SSP) (this might just be “[project name] SSP”);
  2. CAGE codeassociated with the contract;
  3. A briefdescription;
  4. Date ofthe self-assessment;
  5. The totalscore (out of 110); and
  6. The projecteddate that your organization will attain a score of 110.

The CMMC Centerof Awesomeness (CMMC-COA) has a free Excel-based tool to help you calculateyour “basic assessment” score. It is part of the CMMC-COA spreadsheet that isavailable at https://www.cmmc-coa.com/.