5 NIST 800-171 requirements to check before you trust a self-reported SPRS score.
⌘P (Mac) or Ctrl+P (Windows), choose “Save as PDF.” Print styles included.Why this exists
The SPRS score posted from a self-attested questionnaire and the score an assessor would compute today against the environment as it actually runs can differ. Each of the five requirements below is weighted at 5 points in the DoD Assessment Methodology, and each asks for more than its one-line summary suggests, so “we have this” is worth checking against what the requirement actually says.
Below: the five requirements, where a self-reported answer can fall short, the evidence to have ready, and a remediation path. The point-impact figures used in earlier drafts have been removed pending validated baseline data.
Multifactor Authentication on Privileged Accounts
The self-reported answer to test
"MFA enforced on all administrators."
Where that answer can fall short
- Microsoft 365 admin accounts: MFA enabled (good)
- On-prem Windows domain admin accounts: MFA not enforced
- Linux jump-server root accounts: MFA not enforced
- Network equipment privileged credentials (Cisco, Fortinet, Palo Alto): TACACS+/RADIUS without MFA
- Service accounts that someone occasionally uses interactively: MFA bypassed
NIST SP 800-171 Rev. 2 requirement 3.5.3 covers local and network access to privileged accounts, so every privileged account counts, not only the cloud ones.
Evidence to have ready
- Authoritative inventory of all privileged accounts (with role and last-used date)
- MFA policy configuration screenshots
- MFA enrollment logs for the past 90 days for each privileged account
- Documented procedure for adding/removing privileged accounts (and the MFA enforcement step)
The cleanest fix
Roll Duo, Microsoft Authenticator, or YubiKeys to every privileged account. Use a single MFA platform across cloud + on-prem + network equipment so there's one inventory to maintain. Document it in SSP Section 3.5.
Correlate Audit Review, Analysis and Reporting
The self-reported answer to test
"Logs are reviewed weekly by our IT lead."
Where that answer can fall short
- Logs are being collected, true. Microsoft 365, on-prem firewall, sometimes endpoint EDR.
- There's a phrase in the IT policy that says "reviewed weekly", true.
- No documented review cadence with sign-off
- No record of past reviews (no signed checklist, no Jira/ticket trail)
- No evidence of action taken on log findings, nothing showing the IT lead investigated an anomaly, escalated, and resolved
A policy that says "reviewed weekly" with no record behind it does not show the review, analysis and reporting processes working together, which is what 3.3.5 asks for.
Evidence to have ready
- Log review SOP (named procedure, named role, defined cadence)
- Signed weekly log review records for the past 90 days
- At least one log-driven action artifact (an investigation ticket, a Slack thread, an after-action note)
- The list of log sources covered by the review (and acknowledged gaps)
The cleanest fix
SIEM or log-aggregation tool (Wazuh, Microsoft Sentinel, Datadog, or Sumo Logic) with a documented weekly review cadence. Build a one-page review template with sign-off, and keep every completed review.
Monitor and Control Remote Access
The self-reported answer to test
"VPN required for all remote work."
Where that answer can fall short
- VPN is deployed and required, true
- No logging of remote sessions (or logs are being collected but not retained beyond 30 days)
- No session-timeout enforcement, workers can leave a VPN session open overnight
- No MFA on the VPN itself, username/password gets you in
- Remote sessions are not reviewed for anomalies (geo-impossible logins, off-hours access)
Evidence to have ready
- Remote-access policy
- VPN session logs for the past 90 days
- MFA enforcement evidence on VPN (configuration + enrollment)
- Session-termination configuration (idle timeout, max session length)
- Documented remote-access review cadence (folds into Killer #2's SIEM)
The cleanest fix
Enable VPN session logging. Add MFA to the VPN with the same provider used for Killer #1. Configure 30-minute idle timeout, 12-hour absolute max session. Review cadence folds into the SIEM weekly review from Killer #2.
Enforce Security Configuration Settings
The self-reported answer to test
"Standard build images deployed; group policy enforces baseline."
Where that answer can fall short
- Active Directory group policy is in place, true
- Windows endpoints are running multiple OS builds, for example legacy CAD workstations and machine controllers that cannot take the current baseline
- CIS benchmarks are not applied to endpoints
- Linux servers have no equivalent baseline (no CIS, no STIG)
- Deviation from policy is not detected or alerted, drift accumulates silently
Evidence to have ready
- Baseline configuration documentation (which CIS benchmark version, scope of systems covered)
- Evidence of regular configuration scanning (CIS-CAT, Nessus, Defender for Endpoint, Tenable)
- Deviation reports for the past 90 days
- Remediation evidence on flagged deviations
The cleanest fix
Adopt CIS Level 1 benchmarks for Windows + Linux. Deploy Microsoft Defender for Endpoint configuration drift detection (or Tenable, or Rapid7, your choice). Document baseline and scan cadence in SSP Section 3.4.
FIPS-Validated Cryptography
The self-reported answer to test
"AES-256 encryption used throughout."
Where that answer can fall short
- AES-256 is in use, true
- The cryptographic modules implementing AES-256 are not FIPS 140-2 (or 140-3) validated for the on-prem file shares, the OpenVPN deployment, or the database encryption
- Windows endpoints have FIPS mode disabled
- The product documentation says "AES-256" but the module's CMVP certificate number is missing or expired
NIST SP 800-171 Rev. 2 requirement 3.13.11 calls for FIPS-validated cryptography when it protects the confidentiality of CUI, not merely a strong algorithm.
Evidence to have ready
- Documented inventory of cryptographic modules in your environment
- Each module's FIPS validation certificate number from the NIST Cryptographic Module Validation Program (CMVP)
- Configuration evidence showing FIPS mode enabled where applicable (Windows group policy, OpenSSL provider settings, database FIPS mode)
The cleanest fix
Inventory cryptographic modules. Enable FIPS mode on Windows endpoints (group policy: "System cryptography: Use FIPS compliant algorithms..."). Check the VPN's cryptographic module against the CMVP list and confirm its certificate number; if it has no current certificate, change the module or the product. Switch file-share encryption to a FIPS-validated implementation. Replacing a module can take longer than a configuration change, so start the inventory early.
Putting it together
The five requirements above are technical, specific, and assessor-verifiable. Specific point impact for your environment depends on your starting posture across all 110 requirements. The CMMC Level 2 Readiness Snapshot gives a directional estimate from what your connected sources can observe, plus your intake answers.
What to do with this
- Compare it to your current SPRS posture. If you've recently submitted a self-reported score to DoD's SPRS system, work down this list and honestly check each of the five.
- If you want a quick read on where you stand, the free CMMC gap check asks 10 questions and shows your likely gaps on screen.
- If you want a directional estimate from your own environment, start the CMMC Level 2 Readiness Snapshot™. $999. The first PDF is in your inbox minutes after intake, built from your intake answers; connect a supported source and it is re-issued from that source’s read-only configuration data, mapped to the 110-control NIST 800-171 baseline. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2.
- If you'd rather start the full readiness work, Enclave AI™ Standard at $2,495/month (or $29,940/year) rebuilds your SSP, POA&M, CUI scoping package, Customer Responsibility Matrix and evidence index every 30 days. Month-to-month available.
- If you already bought, links, order status, downloads and refund requests are on the help page.
Get the checklist and next steps by email. No sales sequence follows, and the email carries a one-click unsubscribe link.
What this doesn't include
This is a reference on five requirements the DoD Assessment Methodology weights at 5 points. It's not:
- A complete CMMC L2 readiness checklist (that's 110 controls, 320 objectives, your real readiness work)
- A substitute for an actual SPRS scoring against your environment
- Legal advice on regulatory exposure or contract-specific obligations
- A replacement for a CMMC Level 2 certification assessment, which only an authorized C3PAO or DCMA DIBCAC can perform
Read it, use what's useful, ignore what isn't, and reach out if you want help with the rest.
About ElasticD3M, LLC
Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. Patent Pending. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. It is built for the OSAs preparing for assessment, the C3PAOs assessing them, the RPOs guiding them, and the MSPs, MSSPs and ESPs supporting them.
When you are ready to move from this five-control-area read into the full Level 2 readiness work, the free gap check at ai4cmmc.ai/gap-check is the 10-question first step. The CMMC Level 2 Readiness Snapshot at ai4cmmc.ai/cmmc-readiness-snapshot is $999, one-time. The first PDF is delivered to your inbox within minutes of intake, built from your intake answers, and is re-issued from your connected sources’ configuration data once you connect one.
Patent Pending
ElasticD3M, LLC · Texas
v2 · Last updated 2026-09-23