For small DoD contractors who need a rough NIST SP 800-171 DoD Assessment score before posting to SPRS: tick what you have actually implemented across the 110 controls and get a live score, the points you are losing by family, and the shortest path to 88.
How it scores: every control starts as not implemented (score −203). Ticking a control adds back its Annex A value: 5 significant exploitation risk · 3 specific, confined effect · 1 everything else. 3.5.3 (MFA) and 3.13.11 (FIPS crypto) have a partial state worth 3 back. A control that sits on a POA&M counts as not implemented — the methodology gives no credit for plans.
If remote access, wireless or mobile devices are prohibited outright in your environment, the methodology lets you treat 3.1.12/3.1.13, 3.1.16/3.1.17 and 3.1.18 as not applicable (no deduction) — tick them here and document the justification in your SSP.
Estimate below is out of date — it updates automatically in a moment.
Turn this estimate into a scored assessment, SSP draft and POA&M. SPRS Score Coach walks each of the 110 requirements with assessment objectives, builds the System Security Plan and the Plan of Action, and produces the exact entries for your SPRS posting.
Open SPRS Score Coach →