NIST SP 800-171 Compliance
The 110 security requirements behind DFARS and CMMC Level 2: assessed, documented, remediated, and kept current by the same team that runs your IT.
- ✓Gap assessment against all 110 requirements
- ✓Compliance paperwork done for you, SSP, POA&M, SPRS score
- ✓Remediation runs inside managed IT, not as a side project
What NIST SP 800-171 actually is
NIST Special Publication 800-171 defines how Controlled Unclassified Information (CUI) must be protected on non-federal systems: 110 security requirements across 14 families in Revision 2, covering access control, incident response, media protection, system integrity, and more. If your contracts carry DFARS 252.204-7012, you agreed to implement it the day you signed.
Revision 3 was published in 2024 with a consolidated control set, but DoD assessments (including CMMC) currently run against Revision 2. We build to Rev 2 today and track the Rev 3 transition so you're not rebuilding twice.
Who has to comply
Any contractor or subcontractor whose systems store, process, or transmit CUI. In Connecticut that means a large share of the precision-manufacturing supply chain feeding the primes. The requirement flows down: primes push it to their machine shops, fabricators, and engineering suppliers, and DFARS 252.204-7019/7020 require a current self-assessment score on file in SPRS before award.
800-171 is also the substance of CMMC Level 2: the 110 requirements are the same list.
Getting genuinely compliant with 800-171 is most of the road to certification.
The honest truth about first scores
The DoD scoring methodology runs from -203 to +110, and nearly every organization's first honest self-assessment lands negative. That's expected: some controls are worth 3 or 5 points each, and a handful of missing ones sink the number fast. We score you honestly, submit to SPRS, and then raise the number on a documented schedule.
A negative score with a credible System Security Plan and an active POA&M is a defensible position; a fabricated 110 is a False Claims Act problem.
From first gap assessment to a defensible score
Gap / Self-Assessment
All 110 requirements measured with the DoD scoring methodology. No wishful checkmarks.
SPRS Submission
Your score calculated, documented, and filed in the Supplier Performance Risk System correctly.
System Security Plan
The SSP assessors and primes actually accept, written for your real environment.
POA&M to Closure
Every open item tracked with an owner and a date, and actually closed.
Remediation, Managed
MFA, encryption, logging, access control, implemented as part of managed IT rather than a disruptive one-off project.
Continuous Compliance
Quarterly reviews keep the SSP current and the score real as your environment changes.
Compliance help from people who hold the credentials
Credentials held across ASG's compliance and security team.
#1 Connecticut MSP · 2026 Channel Futures MSP 501 (#58 nationally) · 5.0 ★ · 104 Google reviews · Serving CT since 1997
Certification decisions belong to independent assessors. ASG's job is making sure you walk in ready: we prepare you for assessment, remediate gaps, and coordinate directly with an accredited C3PAO we regularly work with.
Questions, answered straight
Related: CMMC compliance servicesIT support for manufacturingCompliance & Risk services
Start with your NIST SP 800-171 gap assessment
Know exactly where you stand within a month: scope, score, and a prioritized roadmap. No deck, no pitch.
