Most small organizations do not fail a security review because they lied. They fail because nobody ever forced them to define what "we are fine" actually means, so the phrase drifted for years until it stopped describing anything real.
That gap matters more this month than last. Reporting in the trade press this week points again to defense suppliers who feel reasonably confident about their compliance posture while independent readouts of the same population look considerably weaker, and Federal News Network is tracking the Defense Department as it moves toward firmer decisions on contractor cybersecurity requirements. The direction of travel is clear even where the calendar is not. Sooner or later, someone else grades your homework. The question is whether you already know your grade.
Why does self assessment go wrong even when people are being honest?
Because honesty is not the hard part. Definition is.
Ask ten people in a small organization whether multifactor authentication is "in place" and you will get ten sincere yes answers describing four different realities. Yes on email but not the remote access gateway. Yes for staff but not the two contractors who have admin rights. Yes for everyone except the founder, who turned it off during a bad week in March and never turned it back on.
None of that is dishonesty. It is a question that was too vague to answer. The requirements in NIST SP 800-171 are written in the negative space around exactly this problem: each control asks about a specific class of user, system and data, not about a general vibe.
So here is the first real question for you. When you last said your organization was in decent shape, what specific evidence were you picturing, and could you show it to a stranger this afternoon?
What is the difference between a checklist answer and an evidence answer?
A checklist answer is a claim. An evidence answer is an artifact a third party could inspect without your narration.
The test is simple. For each thing you believe is true, name the artifact. Access reviews mean an actual list of accounts with a date and a reviewer name. Backups mean a restore that somebody performed and documented, not a service that reports green. Incident response means a written plan that names people who still work there, plus a record of the last time anyone walked through it.
If the artifact does not exist, the control is aspiration. That is not a moral failure, and plenty of organizations with genuinely good instincts live there. But it is important to write it down as aspiration, because the day a customer asks, the difference between claim and evidence becomes very sharp very fast.
Get an Outside Read Against the Framework Your Contracts Name
If you have never measured your organization against the framework your contracts or grantors actually reference, our in-kind gap assessment grant delivers that read. We perform the assessment for you and the report is yours.
Apply for the Gap Assessment Grant →How do you spot the places where you are quietly grading yourself generously?
Look for the four patterns below. In small organizations they show up almost every time.
The hero dependency. One person knows how everything works and has never written it down. Ask yourself honestly: if that person were unreachable for two weeks, what would break, and who would even know where to look?
The inherited environment. Systems set up by a departed employee, a former managed provider or a volunteer years ago, still running, never reviewed. Nobody is sure who has access.
The shadow perimeter. Personal devices, a home network doing real work, a file sharing account somebody opened for one project in 2023 that still holds sensitive material.
The unscoped scope. This one is the quiet killer for defense suppliers. If you have never drawn a boundary around where controlled unclassified information actually lives and travels in your environment, then every assessment you have done of yourself has been an assessment of an undefined thing.
What should a defense supplier be reading honestly right now?
If you handle controlled unclassified information, DFARS 252.204-7012 has required you to implement NIST SP 800-171 for years, and DFARS 252.204-7019 and 7020 have required a self assessment score posted in the Supplier Performance Risk System. The CMMC Program rule at 32 CFR Part 170 took effect on December 16, 2024, and the Defense Department has been working through the acquisition side that determines when requirements appear in solicitations. Phase in timing and the exact pace at which requirements land in new contracts continue to move, and anyone who tells you they know the precise date your specific contract vehicle will be affected is guessing. Treat that as unsettled.
What is not unsettled is the self reported score. If your SPRS entry was calculated quickly, by someone in a hurry, against a scope nobody had defined, then it is a number attached to your company name in a government system that you cannot currently defend. That is worth an honest afternoon.
A related signal for anyone selling into federal buyers: GSA maintains Highly Adaptive Cybersecurity Services on the Multiple Award Schedule for IT, which tells you something about how seriously federal customers treat assessment, penetration testing and incident response as procurable, expected capabilities. The bar the market is setting is visible in public documents. You can read it before it is read to you.
What does a good honest self read actually look like in practice?
Give it a fixed shape so it does not become a project with no ending.
Draw the boundary first. What data matters, where does it live, who touches it, what systems does it cross. One page. If you cannot draw it, that is your finding.
Then walk your top controls one at a time and mark each of them as evidenced, partial or aspirational. Three states, not two. The partial column is the most useful thing you will produce, because that is where surprise lives.
Then write down what you found in language a non technical board member or an owner could read. Include the uncomfortable items. A gap you documented yourself, with a date and an intended path, reads completely differently to an outside party than the same gap discovered on your behalf.
Then set a review date. A self read with no next date is a snapshot. A self read with a next date is a practice.
Who in your organization is allowed to say "actually, no, that one is not true" without it becoming a problem? If the answer is nobody, the assessment will be wrong no matter how good your controls are.
What if the honest answer is that you are further behind than you thought?
Then you have just done the single most valuable thing available to you this quarter.
Small organizations often assume that a bad self assessment is something to hide until it is fixed. In practice, most sophisticated buyers, insurers and prime contractors are far more comfortable with a supplier who says "here are our four open items, here is the sequence and here is who owns each one" than with a supplier who claims a clean sheet and cannot produce a single artifact.
Documented awareness is a posture. Undocumented confidence is a liability. If you have been sitting on a suspicion that things are not as solid as you have been saying, what would it take to turn that suspicion into a written page this month?
Frequently Asked Questions
Do I need an outside assessor to know where I stand?
No. A structured self read using NIST SP 800-171 as the frame will surface most of your real gaps, and it is required anyway for many defense suppliers under DFARS 252.204-7019 and 7020. An outside assessor validates and challenges your read, but they cannot substitute for you knowing your own environment. Do the internal work first so any external review starts from something real.
What is the most common mistake in a small organization self assessment?
Failing to define scope before scoring controls. If you have not established where sensitive or controlled information actually lives and moves, every control answer is measured against an undefined boundary. Draw the boundary on one page first, even roughly, then assess against it.
Is my SPRS self assessment score binding if I got it wrong?
Your posted score is a representation to the government and it can be revisited by contracting officers and updated by you. Scores calculated hastily against an undefined scope are common and correctable. If you believe your posted score does not reflect reality, reassess properly and update it rather than leaving an indefensible number in place.
When exactly will CMMC requirements appear in my contracts?
The CMMC Program rule at 32 CFR Part 170 became effective on December 16, 2024, and requirements are being introduced into acquisitions in phases. The precise timing for any given contract vehicle depends on the acquisition side and on program decisions that are still moving, so treat specific date claims with caution. Watch your solicitations and ask your contracting officer directly.
How often should we redo an honest self read?
At least annually, and immediately after any material change: a new system holding sensitive data, a departure of the person who ran your technology, a new customer contract with security terms, or an incident. A self read is a practice with a next date, not a one time document.
We are a nonprofit, not a defense contractor. Does any of this apply?
Yes, with a different driver. Nonprofits typically face donor data, grantor requirements, insurer questionnaires and partner due diligence rather than DFARS clauses. The same discipline applies: define scope, name your evidence, mark items as evidenced, partial or aspirational, and set a review date.
Sources: Federal News Network, Rules about funding and cybersecurity can shape the defense market as surely as contracts do; Cybersecurity Dive, Defense contractors still struggling with basic CMMC readiness; GSA Highly Adaptive Cybersecurity Services; 32 CFR Part 170, Cybersecurity Maturity Model Certification Program; DFARS 252.204-7012, 252.204-7019 and 252.204-7020; NIST SP 800-171; DoD CIO, CMMC program information.
