Field reference · v2 · 2026

5 NIST 800-171 requirements to check before you trust a self-reported SPRS score.

For Defense Industrial Base subcontractors preparing for CMMC Level 2 assessment. Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending

Why this exists

The SPRS score posted from a self-attested questionnaire and the score an assessor would compute today against the environment as it actually runs can differ. Each of the five requirements below is weighted at 5 points in the DoD Assessment Methodology, and each asks for more than its one-line summary suggests, so “we have this” is worth checking against what the requirement actually says.

Below: the five requirements, where a self-reported answer can fall short, the evidence to have ready, and a remediation path. The point-impact figures used in earlier drafts have been removed pending validated baseline data.

#1 · IA.L2-3.5.3

Multifactor Authentication on Privileged Accounts

The self-reported answer to test

"MFA enforced on all administrators."

Where that answer can fall short

NIST SP 800-171 Rev. 2 requirement 3.5.3 covers local and network access to privileged accounts, so every privileged account counts, not only the cloud ones.

Evidence to have ready

The cleanest fix

Roll Duo, Microsoft Authenticator, or YubiKeys to every privileged account. Use a single MFA platform across cloud + on-prem + network equipment so there's one inventory to maintain. Document it in SSP Section 3.5.

#2 · AU.L2-3.3.5

Correlate Audit Review, Analysis and Reporting

The self-reported answer to test

"Logs are reviewed weekly by our IT lead."

Where that answer can fall short

A policy that says "reviewed weekly" with no record behind it does not show the review, analysis and reporting processes working together, which is what 3.3.5 asks for.

Evidence to have ready

The cleanest fix

SIEM or log-aggregation tool (Wazuh, Microsoft Sentinel, Datadog, or Sumo Logic) with a documented weekly review cadence. Build a one-page review template with sign-off, and keep every completed review.

#3 · AC.L2-3.1.12

Monitor and Control Remote Access

The self-reported answer to test

"VPN required for all remote work."

Where that answer can fall short

Evidence to have ready

The cleanest fix

Enable VPN session logging. Add MFA to the VPN with the same provider used for Killer #1. Configure 30-minute idle timeout, 12-hour absolute max session. Review cadence folds into the SIEM weekly review from Killer #2.

Want to know which of these five apply to your environment? The free CMMC gap check asks 10 questions and shows your likely gaps on screen. Run the free gap check →
#4 · CM.L2-3.4.2

Enforce Security Configuration Settings

The self-reported answer to test

"Standard build images deployed; group policy enforces baseline."

Where that answer can fall short

Evidence to have ready

The cleanest fix

Adopt CIS Level 1 benchmarks for Windows + Linux. Deploy Microsoft Defender for Endpoint configuration drift detection (or Tenable, or Rapid7, your choice). Document baseline and scan cadence in SSP Section 3.4.

#5 · SC.L2-3.13.11

FIPS-Validated Cryptography

The self-reported answer to test

"AES-256 encryption used throughout."

Where that answer can fall short

NIST SP 800-171 Rev. 2 requirement 3.13.11 calls for FIPS-validated cryptography when it protects the confidentiality of CUI, not merely a strong algorithm.

Evidence to have ready

The cleanest fix

Inventory cryptographic modules. Enable FIPS mode on Windows endpoints (group policy: "System cryptography: Use FIPS compliant algorithms..."). Check the VPN's cryptographic module against the CMVP list and confirm its certificate number; if it has no current certificate, change the module or the product. Switch file-share encryption to a FIPS-validated implementation. Replacing a module can take longer than a configuration change, so start the inventory early.

Putting it together

The five requirements above are technical, specific, and assessor-verifiable. Specific point impact for your environment depends on your starting posture across all 110 requirements. The CMMC Level 2 Readiness Snapshot gives a directional estimate from what your connected sources can observe, plus your intake answers.

What to do with this

  1. Compare it to your current SPRS posture. If you've recently submitted a self-reported score to DoD's SPRS system, work down this list and honestly check each of the five.
  2. If you want a quick read on where you stand, the free CMMC gap check asks 10 questions and shows your likely gaps on screen.
  3. If you want a directional estimate from your own environment, start the CMMC Level 2 Readiness Snapshot™. $999. The first PDF is in your inbox minutes after intake, built from your intake answers; connect a supported source and it is re-issued from that source’s read-only configuration data, mapped to the 110-control NIST 800-171 baseline. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2.
  4. If you'd rather start the full readiness work, Enclave AI™ Standard at $2,495/month (or $29,940/year) rebuilds your SSP, POA&M, CUI scoping package, Customer Responsibility Matrix and evidence index every 30 days. Month-to-month available.
  5. If you already bought, links, order status, downloads and refund requests are on the help page.
Run the free 10-question gap check → Run my CMMC Level 2 Readiness Snapshot, $999

Get the checklist and next steps by email. No sales sequence follows, and the email carries a one-click unsubscribe link.

What this doesn't include

This is a reference on five requirements the DoD Assessment Methodology weights at 5 points. It's not:

Read it, use what's useful, ignore what isn't, and reach out if you want help with the rest.

About ElasticD3M, LLC

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. Patent Pending. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. It is built for the OSAs preparing for assessment, the C3PAOs assessing them, the RPOs guiding them, and the MSPs, MSSPs and ESPs supporting them.

When you are ready to move from this five-control-area read into the full Level 2 readiness work, the free gap check at ai4cmmc.ai/gap-check is the 10-question first step. The CMMC Level 2 Readiness Snapshot at ai4cmmc.ai/cmmc-readiness-snapshot is $999, one-time. The first PDF is delivered to your inbox within minutes of intake, built from your intake answers, and is re-issued from your connected sources’ configuration data once you connect one.

Patent Pending
ElasticD3M, LLC · Texas
v2 · Last updated 2026-09-23