Skip to main content
Top Rated IT Provider · 5.0★ on Google · support answers in ~4 rings
ASG Information Technologies
Contact Us
NIST SP 800-171 · SPRS

NIST SP 800-171 Compliance

The 110 security requirements behind DFARS and CMMC Level 2: assessed, documented, remediated, and kept current by the same team that runs your IT.

203-440-4413
Where you'll stand with ASG
  • Gap assessment against all 110 requirements
  • Compliance paperwork done for you, SSP, POA&M, SPRS score
  • Remediation runs inside managed IT, not as a side project

What NIST SP 800-171 actually is

NIST Special Publication 800-171 defines how Controlled Unclassified Information (CUI) must be protected on non-federal systems: 110 security requirements across 14 families in Revision 2, covering access control, incident response, media protection, system integrity, and more. If your contracts carry DFARS 252.204-7012, you agreed to implement it the day you signed.

Revision 3 was published in 2024 with a consolidated control set, but DoD assessments (including CMMC) currently run against Revision 2. We build to Rev 2 today and track the Rev 3 transition so you're not rebuilding twice.

Who has to comply

Any contractor or subcontractor whose systems store, process, or transmit CUI. In Connecticut that means a large share of the precision-manufacturing supply chain feeding the primes. The requirement flows down: primes push it to their machine shops, fabricators, and engineering suppliers, and DFARS 252.204-7019/7020 require a current self-assessment score on file in SPRS before award.

800-171 is also the substance of CMMC Level 2: the 110 requirements are the same list.

Getting genuinely compliant with 800-171 is most of the road to certification.

The honest truth about first scores

The DoD scoring methodology runs from -203 to +110, and nearly every organization's first honest self-assessment lands negative. That's expected: some controls are worth 3 or 5 points each, and a handful of missing ones sink the number fast. We score you honestly, submit to SPRS, and then raise the number on a documented schedule.

A negative score with a credible System Security Plan and an active POA&M is a defensible position; a fabricated 110 is a False Claims Act problem.
What we do

From first gap assessment to a defensible score

Gap / Self-Assessment

All 110 requirements measured with the DoD scoring methodology. No wishful checkmarks.

SPRS Submission

Your score calculated, documented, and filed in the Supplier Performance Risk System correctly.

System Security Plan

The SSP assessors and primes actually accept, written for your real environment.

POA&M to Closure

Every open item tracked with an owner and a date, and actually closed.

Remediation, Managed

MFA, encryption, logging, access control, implemented as part of managed IT rather than a disruptive one-off project.

Continuous Compliance

Quarterly reviews keep the SSP current and the score real as your environment changes.

Credentials

Compliance help from people who hold the credentials

5
Cyber-AB Registered Practitioners (RP) on staff
CCP
Certified CMMC Professional
CISSP
Certified Information Systems Security Professional
Security+
CompTIA Security+

Credentials held across ASG's compliance and security team.

#1 Connecticut MSP · 2026 Channel Futures MSP 501 (#58 nationally) · 5.0 ★ · 104 Google reviews · Serving CT since 1997

Certification decisions belong to independent assessors. ASG's job is making sure you walk in ready: we prepare you for assessment, remediate gaps, and coordinate directly with an accredited C3PAO we regularly work with.

Questions, answered straight

Related: CMMC compliance servicesIT support for manufacturingCompliance & Risk services

Start with your NIST SP 800-171 gap assessment

Know exactly where you stand within a month: scope, score, and a prioritized roadmap. No deck, no pitch.

Call · engineer in ~4 rings