[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-169230-en":3,"doc-seo-169230-105":30,"detail-sidebar-cat-1-en-105":93},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":11,"category_id":12,"category_name":13,"doc_title":14,"doc_description":15,"doc_content":16,"file_id":17,"file_url":18,"file_type":19,"file_size":20,"view_count":4,"is_deleted":4,"is_public":11,"is_downloadable":11,"audit_status":11,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":15,"update_tm":28,"read_time":29},169230,2336474466412,"\tJames","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",1,11,"Presentations","NIST SP 800-171 DoD Assessment Methodology - Version 1.2.1 - Strategy and Scoring","NIST SP 800-171 DoD Assessment Methodology, Version 1.2 defines a standard approach for conducting strategic assessments of contractors’ implementation of NIST SP 800-171 security requirements for covered defense information. It supports compliance with DFARS clauses on safeguarding CUI and cyber incident reporting, enabling DoD to assess prime contractors and providing a basis for subcontractor status reviews. The methodology covers assessment levels, scoring and confidence rationale, documentation of results, and supporting templates for scoring and formatted outcomes.","NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1\nTable of Contents\nBackground\nPurpose\nStrategically Assessing a Contractor’s Implementation of NIST SP 800-171\nLevels of Assessment\nNIST SP 800-171 DoD Assessment Scoring Methodology\nDocumenting NIST SP 800-171 DoD Assessment Results\nGlossary of Terms\nAnnex A - NIST SP 800-171 DoD Assessment Scoring Template\nAnnex B - Basic (Contractor Self-Assessment) NIST SP 800-171 DoD Assessment Results Format\n\u000f\nBackground\nDefense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, requires contractors and subcontractors to provide ‘adequate security’ to safeguard covered defense information, hereto referred to, for the purposes of this methodology, as Department of Defense (DoD) controlled unclassified information (CUI),  when residing on or transiting through a contractor’s/subcontractor’s internal information system or network, and to report cyber incidents that affect that system or network to DoD.  DFARS clause 252.204-7012 further states that to provide adequate security, the Contractor shall implement, at a minimum, the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations.  Contractors are also required to flow down DFARS Clause 252.204-7012 to all subcontracts for operationally critical support, or for which subcontract performance will involve DoD CUI.  Contractors must mark or otherwise identify, in accordance with direction contained within the specific contract, DoD CUI that is collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of performance of the contract.\nDFARS provision 252.204-7008, Compliance with Safeguarding Covered Defense Information Controls, requires, among other things, offerors to represent they will implement the security requirements in NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer.  To document implementation of NIST SP 800-171, the contractor must develop, document, and periodically update a system security plan that describes system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.  If implementation of the security requirements is not complete, companies must develop and implement plans of action to describe when and how any unimplemented security requirements will be met.\nUnder Secretary of Defense (Acquisition and Sustainment) (USD(A&S)) memorandum, “Strategically Implementing Cybersecurity Contract Clauses,” dated February 5, 2019, directed the Defense Contract Management Agency (DCMA) to pursue, with companies for which they administer contracts, the application of a standard methodology and approach to assess a contractor’s implementation of NIST SP 800-171 at a strategic (corporate-wide) level as an alternative to the requirement for contractors to document implementation of NIST SP 800-171 on a contract-by-contract basis.\nPurpose\nThe NIST SP 800-171 DoD Assessment Methodology, Version 1.2 documents a standard methodology that enables a strategic assessment of a contractor’s implementation of NIST SP 800-171, a requirement for compliance with DFARS clause 252.204-7012.\nThis methodology is used for assessment purposes only and does not, and is not intended to, add any substantive requirements to either NIST SP 800-171 or DFARS clause 252.204-7012.\nDoD will use this methodology to assess the implementation of NIST SP 800-171 by its prime contractors.  Prime contractors may use this methodology to assess the implementation status of NIST SP 800-171 by subcontractors.\nThis methodology informed the conduct of pilot NIST SP 800-171 DoD Assessments performed by DCMA, in partnership with the Defense Co","cbCaifDQyVp5w4Vy","https://ap.wps.com/l/cbCaifDQyVp5w4Vy","docx",55746,24,"English","en",105,"# Background\n## Purpose\n## Strategically Assessing a Contractor’s Implementation of NIST SP 800-171\n# Levels of Assessment\n## Basic (Contractor Self-Assessment) NIST SP 800-171 DoD Assessment\n## Medium NIST SP 800-171 DoD Assessment\n## NIST SP 800-171 DoD Assessment Scoring Methodology\n## Documenting NIST SP 800-171 DoD Assessment Results\n# Glossary of Terms\n# Annex A - NIST SP 800-171 DoD Assessment Scoring Template\n# Annex B - Basic (Contractor Self-Assessment) NIST SP 800-171 DoD Assessment Results Format","[{\"question\":\"What requirement does the methodology support for protecting CUI?\",\"answer\":\"It supports DFARS clause 252.204-7012, requiring contractors and subcontractors to implement the minimum security requirements in NIST SP 800-171 to safeguard DoD controlled unclassified information (CUI) and to report relevant cyber incidents.\"},{\"question\":\"What is the purpose of the NIST SP 800-171 DoD Assessment Methodology?\",\"answer\":\"It provides a standard methodology for DoD to conduct strategic assessments of contractors’ NIST SP 800-171 implementation, offering visibility to summary level scores and serving as an alternative to assessing each contract individually.\"},{\"question\":\"What are the levels of assessment and how do they differ?\",\"answer\":\"The methodology describes three assessment levels reflecting assessment depth and associated confidence. The Basic assessment is contractor self-assessment and results in a low confidence level, while higher levels are conducted by trained DoD personnel.\"}]","NIST SP 800-171 DoD Assessment Methodology - Version 1.2.1 - Strategy and Scoring | DOCX",1788248753,8,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":14,"keywords":34,"description":15,"schema_data":35,"social_meta":88,"head_meta":90,"extra_data":92,"updated_unix":28},"nist-sp-800-171-dod-assessment-methodology-version-121-strategy-and-scoring","",{"@graph":36,"@context":87},[37,54,70],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":11},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/template/","Template",2,{"item":49,"name":13,"@type":43,"position":50},"https://docshare.wps.com/template/presentations/",3,{"item":52,"name":14,"@type":43,"position":53},"https://docshare.wps.com/template/nist-sp-800-171-dod-assessment-methodology-version-121-strategy-and-scoring/169230/",4,{"url":52,"name":14,"@type":55,"author":56,"headline":14,"publisher":58,"fileFormat":61,"inLanguage":23,"description":15,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-05","2026-09-01",true,{"@type":66,"interactionType":67,"userInteractionCount":69},"InteractionCounter",{"@type":68},"ViewAction",5,{"@type":71,"mainEntity":72},"FAQPage",[73,79,83],{"name":74,"@type":75,"acceptedAnswer":76},"What requirement does the methodology support for protecting CUI?","Question",{"text":77,"@type":78},"It supports DFARS clause 252.204-7012, requiring contractors and subcontractors to implement the minimum security requirements in NIST SP 800-171 to safeguard DoD controlled unclassified information (CUI) and to report relevant cyber incidents.","Answer",{"name":80,"@type":75,"acceptedAnswer":81},"What is the purpose of the NIST SP 800-171 DoD Assessment Methodology?",{"text":82,"@type":78},"It provides a standard methodology for DoD to conduct strategic assessments of contractors’ NIST SP 800-171 implementation, offering visibility to summary level scores and serving as an alternative to assessing each contract individually.",{"name":84,"@type":75,"acceptedAnswer":85},"What are the levels of assessment and how do they differ?",{"text":86,"@type":78},"The methodology describes three assessment levels reflecting assessment depth and associated confidence. The Basic assessment is contractor self-assessment and results in a low confidence level, while higher levels are conducted by trained DoD personnel.","https://schema.org",{"og:url":52,"og:type":89,"og:title":14,"og:site_name":59,"og:description":15},"article",{"robots":91,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":94},[95,98,103,108,113,118,123,128,132],{"id":12,"doc_module":11,"doc_module_name":46,"category_name":13,"show_sort_weight":96,"slug":97},90,"presentations",{"id":99,"doc_module":11,"doc_module_name":46,"category_name":100,"show_sort_weight":101,"slug":102},12,"Resumes",80,"resumes",{"id":104,"doc_module":11,"doc_module_name":46,"category_name":105,"show_sort_weight":106,"slug":107},14,"Invoices",70,"invoices",{"id":109,"doc_module":11,"doc_module_name":46,"category_name":110,"show_sort_weight":111,"slug":112},15,"Posters",60,"posters",{"id":114,"doc_module":11,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},16,"Social Media",50,"social-media",{"id":119,"doc_module":11,"doc_module_name":46,"category_name":120,"show_sort_weight":121,"slug":122},17,"Forms",40,"forms",{"id":124,"doc_module":11,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},18,"Letters",30,"letters",{"id":129,"doc_module":11,"doc_module_name":46,"category_name":130,"show_sort_weight":69,"slug":131},21,"Paper Templates","papers-templates",{"id":133,"doc_module":11,"doc_module_name":46,"category_name":134,"show_sort_weight":4,"slug":135},158,"General","general-158"]