Regulatory & Privacy · NIST CSF 2.0 & SP 800-171

NIST assessments that protect the data and the contract.

We measure your program against the NIST Cybersecurity Framework and the 800-171 controls that guard Controlled Unclassified Information, then hand you an SPRS score and a roadmap you can act on.

NIST 800-171 is the control set federal contractors must meet to protect Controlled Unclassified Information, scored on a scale that runs to 110 in the SPRS system. The NIST Cybersecurity Framework is the broader risk model behind it. FinAudit CPA assesses both, documents your gaps, and points you toward CMMC.

Reviewed by Debraj Hazra, CPA (USA), ACA (ICAEW, ICAI)

Last updated July 2026

NIST CSF and 800-171: what each one actually is

People say "NIST" as if it names one thing. It does not. The National Institute of Standards and Technology publishes dozens of documents, and two of them dominate the conversation for companies that work with the US government. Knowing which one applies to you is the difference between a useful project and a wasted budget.

The NIST Cybersecurity Framework is a voluntary risk model. Any organization can adopt it to describe, in a common language, how it manages security risk. Version 2.0 organizes everything into 6 functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern is the newest of the 6, and it puts strategy, roles, and oversight at the center where they belong. The framework does not hand you a checklist of required controls. It gives you a structure for deciding what your risk actually is and whether your program answers it.

NIST SP 800-171 is a different animal. It is a specific catalog of 110 security requirements, grouped into 14 families, that protect Controlled Unclassified Information — CUI — when it lives on a system you own rather than a federal one. Where the framework is a way of thinking, 800-171 is a set of controls you either meet or do not. If a federal contract flows CUI down to you, 800-171 is usually the obligation attached to it, and you get scored against every one of those 110 requirements.

The Cybersecurity Framework tells you how to think about risk. 800-171 tells you exactly what to build. Contractors get in trouble when they treat the framework as the requirement and forget the 110 controls that actually hold the contract.
— FinAudit CPA

Who needs this, and when?

The clearest trigger is a contract clause. If you hold a federal contract with DFARS clause 252.204-7012, or you are a subcontractor to a prime who does, you are expected to protect CUI to the 800-171 standard and to report your posture. That obligation reaches deep into the defense supply chain — parts makers, software vendors, logistics firms, engineering shops, and the small businesses that feed all of them.

  • You are a defense or federal contractor. The CUI touches your systems, DFARS is in your contract, and a NIST 800-171 self-assessment with an SPRS score is already overdue or about to be.
  • You are a subcontractor in someone else's supply chain. The prime cannot certify their own compliance without evidence that you protect the data they pass you, so their flow-down becomes your requirement.
  • You want a framework before a mandate forces one. Security-mature companies often adopt the NIST Cybersecurity Framework voluntarily, because they would rather run a deliberate program than assemble one under deadline pressure.

If any of these fit, move sooner rather than later. NIST 800-171 compliance is not a weekend of paperwork. Some controls take months to stand up, and your SPRS score has to reflect reality on the day you claim it.

NIST CSF vs 800-171: which one applies to you?

The two documents answer different questions. The framework asks how mature and deliberate your whole program is. 800-171 asks whether you meet a fixed list of controls that protect government data. Most contractors end up needing both, but for different reasons.

NIST Cybersecurity Framework NIST SP 800-171
What it is A voluntary risk-management framework A mandatory control set for protecting CUI
Structure 6 functions: Govern, Identify, Protect, Detect, Respond, Recover 110 controls across 14 families
Who it fits Any organization building a security program Federal contractors and subcontractors handling CUI
How you are measured By maturity and risk coverage, not a fixed score By an SPRS score that starts at 110 and drops per gap
What it leads to A stronger, better-governed program DFARS compliance and the road to CMMC

How our NIST assessment runs

You always know which document we are measuring you against, where you stand, and what to fix first. No black box, no surprise invoices.

  1. 01

    Scoping

    We agree on what applies — the Cybersecurity Framework, 800-171, or both — and we draw the boundary around the systems that store, process, or transmit CUI. You get a fixed fee before we start.

  2. 02

    Assessment and scoring

    We test your environment against each of the 110 controls, or against the 6 framework functions, and we calculate an honest SPRS score rather than an optimistic one.

  3. 03

    Gap analysis

    We hand you a plain-language list of every gap, what it costs you in points, and which fixes move your score the most for the least effort.

  4. 04

    System Security Plan and POA&M

    We document how your controls work in a System Security Plan and lay out every open item, owner, and target date in a Plan of Action and Milestones.

  5. 05

    Remediation support

    You close the gaps. We answer questions as they come up so you are never guessing what a control really requires.

  6. 06

    Reporting and CMMC alignment

    We deliver a final report and map your work to CMMC levels, so the next certification builds on this instead of starting over.

What you get, and how long it takes

You receive the documents a contracting officer or a prime's security team actually asks for: a control-by-control assessment against NIST 800-171, a defensible SPRS score with the math behind it, a System Security Plan that describes how each control operates in your environment, and a Plan of Action and Milestones for anything not yet met. If we run a NIST CSF assessment instead, you get a maturity view across all 6 functions and a prioritized roadmap.

Timing depends on where you start. A focused assessment and scoring pass often lands within a few weeks. Remediation is the variable — some controls, like multifactor authentication or continuous monitoring, take longer to implement than a policy edit does. Companies that already run tidy controls reach a strong score quickly. Those starting from a bare environment should plan for several months of work between the first assessment and the score they want to post.

What actually drives the cost

We quote a fixed engagement fee, so you will not see a surprise hourly bill. The number depends on real factors, not guesswork:

Scope of the CUI boundary

A tightly enclaved environment where CUI lives in one segment costs far less to assess than one where it flows across every system you run.

Framework, 800-171, or both

A full 110-control assessment involves more testing and evidence than a framework maturity review, and running both together adds work.

Control maturity

If your controls already operate cleanly, the assessment moves fast. If most of the 110 are open, the effort shifts into remediation support.

CMMC ambition

Aiming only for a self-assessment is lighter than preparing the evidence a formal CMMC certification will demand later.

Why run your NIST assessment with FinAudit CPA

Plenty of shops will scan your network and email you a score. Fewer bring a licensed CPA firm's discipline to the evidence behind it. That discipline matters here, because an SPRS score is a claim the government can act on. A number you cannot defend is worse than no number, and a false one carries real legal exposure. We calculate your score the way an auditor would — conservatively, with documentation that stands up when someone checks it.

You also get senior attention that does not thin out as the work grows, a fixed scope you can budget around, and a global delivery model that keeps the project moving. Because 800-171 shares so much ground with CMMC, ISO 27001, and SOC 2, we map your controls once so the evidence carries into your next requirement instead of forcing you to build it twice.

Pair your NIST work with

  • CMMC readiness, when your contract path requires formal certification on top of a self-assessment
  • ISO 27001, when international customers want a recognized certification alongside your NIST posture
  • SOC 2, when commercial buyers ask for an attestation the government framework does not cover
  • VAPT, to prove the technical controls in your System Security Plan hold up under real testing

NIST CSF & 800-171 · questions buyers ask

Answers before you ever fill in a form.

More across our FAQs and glossary.

The NIST Cybersecurity Framework is a voluntary risk model built around 6 functions — Govern, Identify, Protect, Detect, Respond, and Recover — that any organization can use to structure its program. NIST 800-171 is a mandatory set of 110 controls that federal contractors must meet to protect Controlled Unclassified Information. The framework shapes how you think about risk; 800-171 tells you exactly which controls to build.

Any organization that stores, processes, or transmits Controlled Unclassified Information under a federal contract, usually through DFARS clause 252.204-7012. That reaches primes and subcontractors alike across the defense supply chain. If a prime passes you CUI, their flow-down obligation becomes your requirement, and you owe a self-assessment and an SPRS score whether or not you asked for the work.

SPRS is the Supplier Performance Risk System, where defense contractors post their NIST 800-171 self-assessment result. The score starts at 110, one point for each met control, and you subtract a weighted value for every control you have not met. Because some controls carry more weight, a handful of gaps can pull the number well below 110. We calculate it conservatively so it survives scrutiny.

CMMC, the Cybersecurity Maturity Model Certification, is built directly on NIST 800-171. Its main level requires the same 110 controls, but replaces self-attestation with a third-party assessment. So the 800-171 work you do now is not throwaway; it is the foundation CMMC certification sits on. We map your assessment to CMMC levels so the next step builds on this one instead of restarting.

Not necessarily. If your only driver is a federal contract, 800-171 is the obligation and the framework is optional. Many mature companies still run a NIST CSF assessment because it covers governance and risk strategy that 800-171 assumes rather than tests. If you want a program that manages risk deliberately across the whole business, the framework adds a layer the control list does not.

A System Security Plan documents how each of the NIST 800-171 controls actually operates in your environment — what you have, how it is configured, and who runs it. A Plan of Action and Milestones lists every control you have not yet met, with an owner and a target date. Together they are the core evidence a contracting officer or auditor expects, and we write both as part of the engagement.

The assessment and scoring pass often finishes within a few weeks. Reaching a strong score is the longer part, because some controls take months to implement. Multifactor authentication, logging, and continuous monitoring cannot be turned on with a policy edit. Companies with mature controls close the gap quickly; those starting from a bare environment should plan for several months between the first assessment and the score they post.

For NIST 800-171, the contractor formally submits its own self-assessment and SPRS score, so the accountability sits with your management. FinAudit CPA, a licensed US CPA firm, performs the independent assessment behind that submission and documents the evidence so your score is defensible. When your contract path later requires CMMC, that same evidence supports the third-party certification that replaces self-attestation.

FINAUDIT CPA · ASSURANCE · VERIFIED · INDEPENDENT ·

Ready when you are

Ready to make trust your competitive advantage?

One licensed CPA firm for your SOC, ISO, HIPAA, and VAPT programs — and the financial audits behind them. Talk to a senior auditor, not a sales rep.

Call Book a Consultation