All news

Cybersecurity · · 5 min read

What it took to score 110 of 110 on NIST SP 800-171 as a two-month-old company

Artheus was formed in July 2026. By September we had posted a NIST SP 800-171 score of 110 of 110 in SPRS and affirmed CMMC Level 2 (Self). Here is what worked, written for other small suppliers facing the same requirement.

Any company that handles Controlled Unclassified Information (CUI) for the Department of Defense has to meet the 110 security requirements in NIST SP 800-171, score itself against them, and post that score in the Supplier Performance Risk System (SPRS). With CMMC requirements now appearing in contracts, the score and the status behind it increasingly decide who is eligible for award. Many small companies treat this as a year-long project. It does not have to be, if you are deliberate about a few things.

One note before the lessons. A score of 110 means we meet every requirement by our own assessment. It is a self-assessment, not a third-party certification, and we describe it that way everywhere.

1. Scope the boundary before anything else

The biggest decision is what sits inside the assessment boundary. Every device and cloud service that stores, processes or sends CUI is in scope, along with the people who use them and the tools that protect them, and all of it has to meet the requirements. Everything you leave out has to stay out, with a standing rule that controlled information never goes there.

Draw the boundary as tightly as the work allows: often a small set of devices and the cloud services they need. Machines used for everyday work can sit outside it, as long as they are kept separate from it and controlled information is never placed on them.

The payoff is large. A tight boundary means fewer machines to harden, fewer logs to review and a system security plan short enough that people actually read it. Decide the boundary before you buy anything, and treat any later change to it as a reason to re-assess before the change goes live.

2. Write the plan before you buy the tools

Vendors will offer a product for every control family. Hold off until you have a system security plan (SSP) that says, requirement by requirement, how you meet it today, who is responsible and where the proof lives.

Writing the plan first shows you which requirements you already meet with what you own, which ones only need a written procedure, and which ones need something new. For a small company, many of the 110 are about policy and practice: who gets access, how people are trained, how you respond to an incident, how you handle media. Tools come after the plan tells you what is missing.

Expect the plan to go through several versions in its first weeks. That is normal. Treat it as a working document that changes whenever the system changes.

3. Collect evidence as you go

A score is a claim. Evidence is what makes the claim hold up when the government or a prime contractor asks to see it. Save proof as you go: a dated record of the setting, the log entry, the training certificate, the signed procedure. Keep a change log that records every change to the system and to the plan.

Collecting evidence at the time costs minutes. Rebuilding it months later, for a review you did not expect, costs days, and some of it cannot be recovered at all.

4. Fix the five-point items first

The DoD Assessment Methodology does not weight requirements equally. Each gap subtracts one, three or five points from 110, and the weight matters for more than the score.

Under the CMMC rule, a company can hold a conditional Level 2 (Self) status with some gaps on a plan of action and milestones (POA&M), but only if its score is at least 88 and the open items are low-value ones. Items worth three or five points generally cannot sit on the plan at all, and everything that is on it must be closed within 180 days.

In practice, five-point items are a hard gate. A score in the high 90s with one open five-point item still does not qualify for any Level 2 (Self) status. Find your heaviest gaps on day one and close them before anything cosmetic.

5. Post the score, then affirm it

Two separate steps happen in SPRS. First, you post the NIST SP 800-171 score with the assessment date, the scope, and the name, version and date of your system security plan. Then, for CMMC, you enter the Level 2 (Self) assessment, and a senior official of the company affirms that the company meets the requirements and will keep meeting them.

That affirmation is a statement to the government by a named person, and it carries weight. It has to be renewed every year, and the self-assessment itself redone at least every three years. Put both dates on a calendar the day you post.

What this means for other small suppliers

Two months was possible because we were new and small, and because we treated compliance as engineering: define the boundary, write the plan, gather the evidence, fix the heaviest items first, then prove it. A larger or older company will take longer. The order of operations is the same.

It matters beyond defense, too. Commercial technology companies entering the government market meet this requirement early, and primes increasingly need their suppliers ready before a solicitation arrives. The work is easier with someone who has just been through it.