7-Phase NIST 800-171 Implementation Roadmap
For most contractors, getting to full NIST 800-171 compliance takes something like 24–32 weeks of steady work, sometimes less for small, tightly scoped shops and often longer for big or messy environments. This guide breaks it into seven phases. The week ranges are a typical sequence, not a rule.
Phase 1: Scope Definition and System Boundary (Weeks 1–2)
Objective: Define which systems, networks, and data flows are in scope for NIST 800-171 compliance.
Scope Definition Activities
- Identify systems handling CUI: Which systems store, process, or transmit Controlled Unclassified Information? Include the people, devices, and cloud services that touch it, plus any security tools that protect those systems
- Draw system boundary: Create architecture diagram showing:
- Systems in scope (CUI systems)
- Systems out of scope (public-facing, non-CUI)
- Network connections between them
- External integrations (cloud services, third-party APIs)
- Data flows and network interfaces
- Identify the CUI itself: What CUI do you receive or create? (Typically controlled technical information like drawings and specifications.) Go by contract requirements and markings, and check the DoD CUI Registry categories when in doubt
- Define users and providers: Who has access? (employees, contractors, managed service providers, subcontractors). Any cloud service that stores, processes, or transmits your CUI must meet the FedRAMP Moderate baseline or an equivalent under DFARS 7012; a December 2023 DoD CIO memo spells out what "equivalent" means
- Document assumptions and constraints: Legacy systems, cloud-only, distributed teams, etc.
Deliverable: System boundary diagram and data flow diagram (DFD) showing all CUI systems and connections. This becomes the foundation of your System Security Plan.
Phase 2: Gap Analysis Against 110 NIST Controls (Weeks 3–6)
Objective: Assess your current security controls and identify gaps against all 110 NIST 800-171 controls.
Gap Analysis Process
- Get the assessment objectives: NIST SP 800-171A lists what has to be true for each requirement to be met; the DoD Assessment Methodology gives each requirement its point weight
- For each of 110 requirements: Mark it MET or NOT MET (or not applicable, with a justification). A requirement is only MET if every assessment objective is satisfied
- Document evidence for each control:
- Policies and procedures (written documentation)
- Technical implementation (screenshots, system configs)
- Training records (employee acknowledgments)
- Test results (vulnerability scans, penetration tests)
- Logs and monitoring (system event logs, SIEM data)
- Calculate SPRS score: Start at 110 and subtract 5, 3, or 1 points for each requirement not met (partial credit applies only to a few, such as 3.5.3 MFA and 3.13.11 FIPS-validated encryption). The lowest possible score is -203. For CMMC Level 2, Conditional status needs at least 88/110 and Final status needs 110.
- Identify gaps: Which requirements are NOT MET, how many points each costs, and what's missing?
Expected outcome: An honest SPRS score baseline (a first assessment well below 110, even a negative score, is common and just means significant work ahead). Gap list prioritized by point value, risk, and difficulty.
Phase 3: System Security Plan (SSP) Creation (Weeks 7–12)
Objective: Write your System Security Plan (SSP), the document that explains how your environment meets each requirement. Requirement 3.12.4 requires one, and without it DoD treats an assessment as incomplete.
There is no mandated SSP format. NIST publishes an optional template, and plenty of contractors use their own layout. What 3.12.4 requires is that the plan describes your system boundary, the environment it operates in, how each security requirement is implemented, and how your system connects to or relies on other systems. You also don't need to do a FIPS 199 / NIST 800-60 security categorization of your system: NIST 800-171 already assumes CUI needs moderate confidentiality protection.
What Your SSP Needs to Cover
- System description and boundary
- System name, purpose, owner, location
- System boundary diagram (from Phase 1)
- Where CUI lives and how it flows
- Environment of operation
- Hardware, operating systems, and key applications in scope
- Physical locations, remote work, and cloud environments
- How each requirement is implemented
- All 110 requirements, each with a description of how it's met (or why it's not applicable)
- Status and responsible party for each, and where the supporting evidence lives
- Anything not yet met, cross-referenced to your POA&M
- Connections to other systems
- Interfaces with other internal systems outside the boundary
- External services: cloud providers, MSPs, partners, and who is responsible for which requirements
- Related documents (often kept separate)
- Plan of Action & Milestones for anything not yet met (3.12.2; see Phase 5)
- Risk assessment (3.11.1)
- How you monitor controls on an ongoing basis (3.12.3)
Document owner: Whoever owns security internally (a CISO, IT manager, or senior leader), even if an MSP or consultant writes it. NIST requires the SSP to be updated periodically without fixing a frequency; reviewing it at least annually and after major system changes is common practice.
Phase 4: Critical Control Implementation (Weeks 13–20)
Objective: Implement the highest-impact NIST 800-171 controls that address the greatest cyber risks.
Priority 1 Controls to Implement First
| Control | Family | Impact | Difficulty | Timeline |
|---|---|---|---|---|
| 3.13.1 (Boundary Protection) | SC | Critical | High | 6–8 weeks |
| 3.13.8 (Encryption in Transit) | SC | Critical | Medium | 3–4 weeks |
| 3.13.16 / 3.13.11 (Encryption at Rest, FIPS-Validated) | SC | Critical | Medium | 3–4 weeks |
| 3.5.3 (Multifactor Authentication) | IA | Critical | Medium | 4–6 weeks |
| 3.14.1 (Flaw Remediation / Patching) | SI | Critical | Low | 2–3 weeks |
| 3.14.6 (System Monitoring/SIEM) | SI | Critical | High | 6–8 weeks |
| 3.6.1 / 3.6.2 (Incident Handling and Reporting) | IR | Critical | Medium | 4–6 weeks |
Implementation Approach
- Assign control owners: Designate a person responsible for implementing each control family
- Create implementation plans: For each control, document:
- Current state vs. desired state
- Tools/systems needed
- People and roles involved
- Timeline and dependencies
- Testing approach
- Procure tools as needed: SIEM, encryption solutions, vulnerability scanning, etc.
- Configure and test: Implement controls, validate functionality, test edge cases
- Document implementation: Take screenshots, save configuration files, document the "how" for your SSP
- Operator training: Train staff on new tools and procedures
Phase 5: Plan of Action & Milestones (POA&M) for Remaining Gaps (Weeks 21–24)
Objective: Create a detailed remediation plan for all remaining control gaps with specific timelines and resource requirements.
POA&M Development
- List all remaining gaps: Every requirement still NOT MET
- For each gap, create an action item:
- Requirement identifier (e.g., 3.1.1)
- Gap description (what's missing)
- Remediation action (what needs to be done)
- Owner (person responsible)
- Target completion date
- Resource requirements (budget, tools, people)
- Status tracking
- Prioritize by:
- Risk impact (which controls prevent the biggest attacks)
- Effort required (quick wins vs. complex implementations)
- Dependencies (controls that must be done before others)
- Assign budget: Estimate costs for tools, consulting, staff time, training
- Schedule review cycles: Review the POA&M regularly (monthly is a good rhythm) and update it as actions complete
POA&M rules that matter: For your SPRS entry, the POA&M drives the date you report for reaching 110, and open items still cost points. For CMMC Level 2 Conditional status, you need a score of at least 88/110, only certain 1-point requirements may be on the POA&M (with limited exceptions), and every item must be closed within 180 days. Anything weighted 3 or 5 points generally has to be fixed before the assessment.
Phase 6: SPRS Scoring and Documentation (Weeks 25–26)
Objective: Recalculate your SPRS score using the DoD Assessment Methodology, documenting evidence for every requirement you mark as MET.
SPRS Scoring Process
- Reassess all 110 requirements: Update MET / NOT MET status based on Phase 4 implementations
- Document evidence for CMMC assessor: For each control, provide:
- Policy or procedure document
- Technical evidence (screenshots, configs, logs)
- Test results (vulnerability scans, code reviews)
- Training records and sign-offs
- Responsible person and contact info
- Tie evidence to the SSP: Each requirement's SSP entry should point to where its supporting evidence lives
- Calculate your SPRS score and post it: 110 minus the weights of anything not met. Post it in SPRS (through PIEE) along with your SSP's name and date and the date you expect to reach 110. For CMMC Level 2 you need 110 for Final status, or at least 88 with only allowable 1-point items on the POA&M for Conditional status
- Identify remaining gaps: Which requirements are still NOT MET? Update the POA&M.
Expected outcome: An accurate SPRS score posted in SPRS, ideally 110 (or at least 88 with only POA&M-eligible items open), with a comprehensive evidence package ready for a CMMC assessment.
Phase 7: CMMC Certification Assessment (Weeks 27–32)
Objective: Engage a C3PAO (Certified Third-Party Assessor Organization) for formal CMMC Level 2 assessment.
Where this stands now: With CMMC Phase 2 paused since July 13, 2026, C3PAO certification is currently voluntary. Most contractors can meet today's contract requirements with a Level 2 self-assessment posted in SPRS. A voluntary certificate is still worth considering if your primes ask for one, and it's strong evidence if the requirement returns, which is likely in some form. Here's how the process works.
CMMC Assessment Process
- Select a C3PAO: Pick an authorized assessor organization from the Cyber AB Marketplace and get it under contract
- Pre-assessment review: C3PAO reviews your SSP and POA&M (typically 2–3 weeks)
- Assessment: The assessment team spends several days on-site, remote, or both, depending on your size and scope:
- Documents review and verification
- Interviews with control owners and staff
- Testing that controls work as described
- System access review (account management, permissions)
- Assessment report: C3PAO issues detailed findings with:
- A MET / NOT MET finding for each of the 110 requirements
- Your resulting score
- Any items eligible for a POA&M
- Remediation (if needed): With a score of at least 88 and only allowable items open, you get Conditional status; close the POA&M items within 180 days and pass a POA&M close-out assessment to reach Final status
- Certification issued: CMMC Level 2 Final status is valid for 3 years, with an annual affirmation of continued compliance
Assessment cost and timing: C3PAO pricing varies a lot with your size, scope, and number of locations, so get quotes from more than one. See our CMMC cost breakdown for how the fee fits into a full budget. Assessor capacity is limited, so if you decide to certify, book early.
Control Family Implementation by Difficulty
A rough guide to where the heavy lifting usually is. Timelines are typical, and they overlap when different people own different families.
| Control Family | Requirements | Difficulty | Timeline |
|---|---|---|---|
| System & Communications Protection (SC) | 16 | High | 8–12 weeks |
| System & Information Integrity (SI) | 7 | High | 6–10 weeks |
| Access Control (AC) | 22 | Medium | 6–10 weeks |
| Incident Response (IR) | 3 | Medium | 4–8 weeks |
| Security Assessment (CA) | 4 | Medium | 4–6 weeks |
| Audit and Accountability (AU) | 9 | Low | 2–4 weeks |
| Awareness and Training (AT) | 3 | Low | 1–2 weeks |
How Consultants Can Accelerate Compliance
Plenty of contractors bring in outside help. Typical scopes and price ranges (estimates, and they vary a lot by scope):
- Gap analysis: Consultant assesses current controls and calculates SPRS baseline (typically 1–2 weeks, $5,000–$10,000)
- SSP development: Consultant writes comprehensive System Security Plan (typically 3–4 weeks, $15,000–$25,000)
- Control implementation guidance: Consultant designs and implements critical controls (typically 6–12 weeks, $40,000–$80,000)
- CMMC readiness review: Consultant conducts mock assessment and identifies remaining gaps (typically 2–3 weeks, $10,000–$20,000)
- Full managed service: Consultant manages entire compliance program (typically 6–9 months, $100,000–$200,000+)
Frequently Asked Questions
- How long does NIST 800-171 implementation take?
- Typically 24–32 weeks (6–8 months) from gap analysis to CMMC-ready. Small, tightly scoped organizations might finish in 16–20 weeks; larger or more complex ones can take 9–12 months or more.
- Do we need a consultant?
- Not mandatory, but many organizations benefit from outside expertise. A good consultant or MSP can speed things up and prevent false starts. Cost depends on how much you hand off; see the typical ranges above.
- What if we're migrating to Revision 3?
- Don't rush it. DFARS 252.204-7012, SPRS and CMMC Level 2 still assess against Rev 2 (110 requirements). A proposed FAR CUI rule (June 2026) would reference Rev 3, but it's not final. Build on Rev 2 now and plan for Rev 3 when it's actually required.
- Can we implement controls incrementally?
- Yes. Implement critical requirements first (3.13.1 boundary protection, 3.13.8 encryption in transit, 3.5.3 MFA, 3.14.1 patching, 3.14.6 monitoring), then medium-priority ones, then lower-priority. Complete a POA&M for gaps and track progress.
- What's a good SPRS target score for CMMC readiness?
- The goal is 110, which is what Final CMMC Level 2 status requires. The minimum for Conditional Level 2 status is 88/110 (80%), and only certain 1-point requirements may be on the POA&M (with limited exceptions), closed within 180 days. For DFARS 7019/7020 there is no published minimum, but an honest, improving score is what primes and contracting officers want to see.
- How often do we update our SSP?
- NIST requires periodic updates but doesn't set a frequency. At least annually is common practice, plus any time you make major system changes, have a security incident, or change how a requirement is met.
- What happens if we find a gap during CMMC assessment?
- The C3PAO marks the requirement NOT MET. If your score is still at least 88 and the open items are POA&M-eligible (certain 1-point requirements), you get Conditional status and have 180 days to close them. Otherwise you don't receive Level 2 status until the gaps are fixed and you are reassessed. (C3PAO certification is currently voluntary while CMMC Phase 2 is paused.)
Recommended Tools by Control Family
- SC (System & Communications): A next-generation firewall (Palo Alto, Fortinet, and similar) for boundary protection; encryption that uses FIPS-validated cryptographic modules (3.13.11). Check the module's validation status rather than taking "FIPS compliant" on faith
- SI and RA (Integrity and Vulnerability Management): EDR such as CrowdStrike Falcon or Microsoft Defender for Endpoint; a vulnerability scanner such as Tenable Nessus, Qualys, or Rapid7 InsightVM
- IA (Identification & Authentication): Microsoft Entra ID, Okta, or Duo for MFA
- AU (Audit & Accountability): A SIEM or log platform (Splunk, Microsoft Sentinel, Elastic) to collect, review, and protect logs
- Cloud services: Anything that stores, processes, or transmits CUI must be FedRAMP Moderate or meet the DoD equivalency standard; get the provider's documentation in writing
- CA and Documentation: NIST SP 800-171A assessment objectives, NIST's optional SSP template, and our free SPRS calculator; compliance platforms can help track evidence and POA&M items
Need a budget number? Use our cost calculator for a rough estimate of what a NIST 800-171 / CMMC Level 2 program costs at your size.
Disclosure: Defense Compliance.ai contains affiliate links to compliance software and consulting services. We recommend tools we've independently vetted; affiliate commissions help fund this resource.