NIST SP 800-171 and CMMC self-assessment for defense contractors, now in pilot
Defend your NIST SP 800-171 attestation.
Every defense contractor that handles Controlled Unclassified Information must implement the 110 security requirements of NIST SP 800-171, post a self-assessment score in the Supplier Performance Risk System (SPRS), and affirm compliance to stay eligible for award. Most small and mid-size contractors still manage that in spreadsheets that can't show what was true, and when.
ComplianceOS turns that spreadsheet into a living, evidenced record of your 800-171 posture, so the score you report and the affirmation you sign can be backed up.
- 1
Assess
Work through all 320 assessment objectives in NIST SP 800-171A, with status, notes, and an evidence reference for each.
- 2
Score
See a live SPRS score under the DoD Assessment Methodology, recalculated on every change.
- 3
Remediate
Tie a POA&M to every open requirement, with owners, milestones, and cost.
- 4
Affirm
Export the evidence package behind your signature.
Pilot release capabilities
Objective-level self-assessment
Built on the 320 assessment objectives of NIST SP 800-171A, not just the 110 headline requirements. A requirement is Met only when every applicable objective is Met.
Live SPRS score and history
Calculated under the DoD Assessment Methodology and updated with every change, so you can show what your score was on any given date.
POA&M management
Remediation plans, owners, milestones, and cost tied to each open requirement.
Immutable audit trail
Shows who changed what, and when each control became implemented.
Cost visibility
The Shared Data Layer links remediation work and IT spend to the controls they satisfy.
Ready for Rev. 3
The control catalog is data, so a move to NIST SP 800-171 Rev. 3 is an import, not a rebuild.
The affirmation evidence package
One export with your assessment scope and date, current SPRS score and score history, the status of all 110 requirements and their objectives, open POA&Ms with owners and target dates, and the preparer and supporting activity log.
Who it's for
Defense contractors and subcontractors
Small and mid-size companies in the defense industrial base handling FCI or CUI.
Prime contractors
Primes monitoring the NIST SP 800-171 posture of their suppliers.
MSPs and compliance consultants
Firms serving defense clients who need one consistent record across engagements.
Why ComplianceOS
Audit-minded design
Assessment objectives are treated the way an auditor treats assertions: each one tested, evidenced, and dated.
Built for what's next
If third-party assessment returns in a reformed program, the same evidence record carries forward.
Priced for small contractors
Not an enterprise GRC suite retrofitted downward.
Platform status
In pilot
ComplianceOS is architected for FIPS 140-3 validated encryption, multi-factor authentication, role-based access, tenant isolation, and immutable audit logging.
No CUI in the pilot
Pilot environments do not accept Controlled Unclassified Information. The pilot stores requirement status and a reference to where your evidence is kept, so sensitive evidence stays in your own systems.
Work with us
Most contractors don't need another tool. They need to know their real score, what it will cost to close the gaps, and what to fix first. Oakward Consulting does that work with you inside ComplianceOS, and the platform comes included.
Start here
Readiness and remediation budget
$7,500 fixed fee, up to 25 employees
$12,500 for 26 to 100 employees. Larger organizations quoted individually.
- Objective-level NIST SP 800-171 self-assessment, done with your team
- Your SPRS score, with the reasoning behind every deduction
- A POA&M with cost estimates for each gap and a cost-per-point priority order
- A remediation budget your leadership can approve
- Affirmation evidence package
- 12 months of ComplianceOS included
Managed compliance
$750 per month, up to 25 employees
$1,250 per month for 26 to 100 employees. Usually follows the readiness engagement.
- ComplianceOS included
- Quarterly score and POA&M review
- Remediation spend tracked against budget and points recovered
- Annual affirmation preparation
- Direct access to Oakward Consulting
Software only
Running your own program? Every plan includes NIST SP 800-171 and CMMC Level 2, unlimited users, objective-level assessment, the live SPRS score with history, POA&M management with cost visibility, the audit trail, and the affirmation package. Pay annually and get two months free.
Small
$149 per month
Up to 25 employees
- One company assessment
- Unlimited users
- Email support
- $1,490 per year billed annually
Standard
$349 per month
26 to 250 employees
- One company assessment
- Unlimited users
- Priority support and onboarding session
- $3,490 per year billed annually
Partner
$999 per month
MSPs, compliance consultants, and primes monitoring suppliers
- Up to 10 client or supplier assessments
- $79 per month for each additional assessment
- Unlimited users
- $9,990 per year billed annually
Start with a 30-day pilot.
Load your current self-assessment, see your score and gaps at the objective level, and decide with real data. No production use and no CUI during the pilot.
Request a pilot
NIST SP 800-171 Rev. 2 is the current CMMC Level 2 standard. ComplianceOS supports self-assessment; it does not certify compliance.