NIST 800-171 Self-Assessment and SPRS: What Subcontractors Must Do

NIST 800-171 Self-Assessment and SPRS: What Subcontractors Must Do

NIST 800-171 Self-Assessment and SPRS: What Subcontractors Must Do

A lot of subcontractors assume cybersecurity compliance is the prime contractor’s problem. It is an understandable assumption, and it is wrong often enough to be worth correcting directly. If your work touches covered defense information anywhere in the supply chain, the assessment and scoring requirements can apply to you specifically, regardless of your size or how far removed you are from the government customer.

What the self-assessment actually covers

NIST Special Publication 800-171 lays out 110 security controls organized across 14 families, covering areas like access control, incident response, and system monitoring. A Basic Assessment is a self-conducted review of your environment against those controls. You are not hiring an outside assessor for this step. You are evaluating your own systems, documenting where you meet each requirement, and being honest about where you fall short.

The output of that review is a numeric score, calculated using a methodology set out in DFARS 252.204-7020, that reflects how completely your environment satisfies the 110 controls. A perfect score is possible. So is a negative one, if enough controls are unmet, and that number is not private.

Where the score goes, and who sees it

Your score gets submitted to the Supplier Performance Risk System, known as SPRS, along with the date of your assessment and the system security plan it was based on. This is the part subcontractors most often miss: a prime contractor evaluating you for teaming or a subcontract can see that score. It becomes part of how they assess whether to bring you into a program, alongside your technical capability and past performance. A subcontractor with no submitted score, or a poor one, can lose consideration before a technical conversation even happens.

On top of the initial submission, a senior company official must affirm the accuracy of the score annually, and after any significant change to your environment. This affirmation is a genuine compliance obligation with real consequences if it is inaccurate, not a formality to click through.

This obligation does not depend on where CMMC certification stands

Self-assessment, SPRS submission, and the annual affirmation exist under DFARS 252.204-7019 and 7020, independent of the CMMC certification program. Whatever happens with third-party CMMC assessments on any given timeline, these obligations do not move with it. A subcontractor waiting for certainty about CMMC before starting this work is waiting for the wrong signal. If your contract or your prime’s flow-down terms call for a current SPRS score, that requirement is live now.

Frequently asked questions

Do small subcontractors really need to do this?

If your work involves handling covered defense information, size does not exempt you. Whether the requirement applies to your specific contract depends on the clauses in it, so review your contract terms or ask your prime directly rather than assuming based on company size.

What happens if our score is low?

A low score does not automatically disqualify you, but it is visible information a prime can weigh, and it points to specific gaps you can address. A remediation plan, even one still in progress, is generally viewed more favorably than an absent or outdated submission.

Can a foreign subcontractor be asked for a SPRS score?

Yes, if the flow-down terms of the contract or teaming agreement require it. Being outside the United States does not remove the requirement if you are handling covered defense information as part of the program.

Where Nortrane fits

Compliance posture is something primes evaluate early, often before they evaluate your technical fit. Nortrane helps subcontractors and new entrants understand where this requirement sits inside their broader path to a first contract, alongside questions like teaming agreement structure and foreign ownership considerations where they apply. This is general information, not legal or cybersecurity advice. For guidance specific to your situation, start a conversation with us.

Tags
Share Article:

Nortrane Advisory Team

Nortrane's advisory team works daily with foreign and domestic manufacturers, subcontractors, and suppliers navigating FAR, DFARS, CMMC, and ITAR/EAR requirements to enter or expand within the U.S. defense and aerospace industrial base.

Leave a Comment