If you make parts for the defense supply chain and handle Controlled Unclassified Information, you already owe the government NIST SP 800-171, whatever happens with CMMC timelines. The good news is that the first steps take clear thinking and honest notes, not a consultant.
This post walks through those first steps the way a small shop would actually take them: with the people you already have, on a normal work week.
Does this week's CMMC news mean I can wait on NIST 800-171?
No. This week a legal industry roundup reported two things: another defense contractor settled False Claims Act allegations tied to not meeting its cybersecurity obligations, and CMMC Phase II has reportedly been suspended. We have not been able to confirm the details or how long any suspension would last, so treat the CMMC timeline as not settled until the Department of Defense says so officially.
What is settled is older than CMMC. The DFARS clause 252.204-7012 has required contractors handling covered defense information to implement NIST SP 800-171 for years. As of February 2026, that self-assessment obligation runs through DFARS 252.204-7021, the CMMC clause, after 252.204-7019 was deleted and 252.204-7020 was renumbered to 252.240-7997. CMMC is a way of checking that work. It did not create the obligation.
The settlement news shows where the real risk sits. Since 2021 the Justice Department's Civil Cyber-Fraud Initiative has used the False Claims Act against contractors who said they were compliant when they were not. A small shop's biggest exposure usually isn't being behind. It's posting a score it can't back up.
What is the very first thing a small manufacturer should do?
Find your CUI before you touch a single setting. Controlled Unclassified Information is usually easy to spot in a machine shop or fabrication business: technical drawings, specifications, and export-controlled data that come from a prime contractor or the government.
Walk the path one drawing takes through your business. Ask these questions out loud with your team:
- How does it arrive? Email, a customer portal, a USB drive, a paper packet?
- Where is it saved? A shared drive, someone's desktop, a CAM workstation on the floor?
- Who opens it? Estimating, engineering, programming, the machinist at the controller?
- Where does it go next? A subcontractor for plating or heat treat? A printer by the office door?
Sketch that path on a whiteboard. That sketch is the start of your scope, and scope decides how much work everything after it will be.
How do I keep the scope small enough to manage?
Every computer, account, and network segment that stores, processes, or sends CUI is in scope. So is anything that protects those systems. A small shop that lets drawings live everywhere ends up having to secure everything.
The practical move is to pull CUI into a smaller area. That might mean one set of workstations, one dedicated cloud environment, or one set of accounts that only certain people use, kept apart from the general office network and the guest Wi-Fi. People often call this an enclave. Many small manufacturers find it's the single decision that makes 800-171 feel possible.
Here's a question worth an hour of your leadership meeting: if you had to name the five people who truly need to open CUI to do their jobs, who would they be? Most shops find the real list is much shorter than the current one.
How do I assess myself against the requirements without outside help?
NIST SP 800-171 Revision 2, which the DFARS clause and CMMC Level 2 currently rely on, has 110 security requirements grouped into 14 families such as access control, awareness and training, and incident response. NIST has published Revision 3, but the Department of Defense has kept contractors on Revision 2 for now. If you see the two versions discussed side by side, that's why.
You don't have to guess what each requirement means. NIST SP 800-171A lays out assessment objectives for every requirement, which are the specific things an assessor would look for. The Department of Defense's NIST SP 800-171 Assessment Methodology explains how to score yourself: you start at 110 and subtract points for each requirement not yet met, with higher value requirements subtracting more. That result is the number that goes into SPRS.
CISA offers a free tool called the Cyber Security Evaluation Tool (CSET). It can walk you through the NIST 800-171 questions one at a time and keep your answers in one place. For a shop without a dedicated IT person, a guided questionnaire can be the difference between starting and staring at a PDF.
Be strict with yourself. If a requirement is half done, it isn't met yet. An honest low score with a clear plan is a much stronger position than a high score nobody can back up.
What documents do I actually need to write?
Two documents carry most of the weight at the beginning.
The System Security Plan (SSP) describes your in-scope environment and explains how you meet each requirement. It's written in plain language about your own shop: who has access, how accounts are set up, where backups live, what happens when someone leaves the company. The DFARS clause and the 800-171 requirements expect you to have one, and an assessment starts by reading it.
The Plan of Action and Milestones (POA&M) lists what isn't done yet, who owns each item, and when you expect to finish. It turns a list of gaps into a to-do list your team can work through. One caution: CMMC puts tighter limits on which items can sit on a POA&M and for how long, so don't treat it as a place to park hard requirements indefinitely.
Write both documents in your own words. Assessors can tell when a plan was copied from a template and doesn't match the building they're standing in.
Where can a small shop get help that isn't a consultant?
You don't have to do this alone, and you don't have to hire someone to get support.
- NIST's Manufacturing Extension Partnership (MEP) has centers in every state that work with small and mid-sized manufacturers, and many of them have cybersecurity specialists who know 800-171.
- CISA provides free resources to small organizations, including assessments, training, and the CSET tool mentioned above.
- NIST's Small Business Cybersecurity Corner collects plain-language guides written for organizations without security staff.
- Cyber Grants Alliance gives in-kind grants of hands-on cybersecurity and compliance support to small businesses, nonprofits, and small defense contractors that can't bring on a full-time security leader.
Need Hands-On Help Getting Started?
If your shop needs hands-on help getting started on NIST 800-171, apply for an in-kind grant at Cyber Grants Alliance.
What's one requirement your team could close before the end of this month? Start there. Progress on 800-171 comes from steady weekly work more than one big push.
Frequently Asked Questions
Do small manufacturers have to comply with NIST 800-171 if CMMC is delayed?
Yes, if your contracts include DFARS 252.204-7012 and you handle Controlled Unclassified Information. That clause has required NIST SP 800-171 for years, and CMMC is a way of verifying it rather than the source of the obligation. Any change to CMMC phase timing doesn't remove the existing contract requirement.
What is an SPRS score?
An SPRS score is the result of a self-assessment against NIST SP 800-171 using the Department of Defense Assessment Methodology, posted in the Supplier Performance Risk System. Scoring starts at 110 and subtracts points for each requirement not yet met. As of February 2026, DFARS 252.204-7021 (the CMMC clause) requires a current assessment on file for covered contracts, after 252.204-7019 was deleted.
Can a small manufacturer do a NIST 800-171 self-assessment without a consultant?
Yes. NIST SP 800-171A spells out assessment objectives for each requirement, and CISA's free Cyber Security Evaluation Tool can walk a team through the questions. The keys are an honest scope, strict scoring, and written evidence for each answer.
What is the first step in NIST 800-171 compliance?
The first step is finding where Controlled Unclassified Information enters, lives in, and leaves your business. That map sets your scope, which decides how many systems and people the requirements apply to. Shrinking that scope early makes every later step more manageable.
Which version of NIST 800-171 applies to defense contractors right now?
Defense contractors are currently assessed against NIST SP 800-171 Revision 2, which has 110 requirements across 14 families. NIST has published Revision 3, but the Department of Defense has kept Revision 2 in place for DFARS and CMMC purposes for now. Check official Department of Defense guidance before assuming that has changed.
Why does posting an inflated SPRS score create legal risk?
The Justice Department has used the False Claims Act against contractors who claimed cybersecurity compliance they didn't have. An honest score with a documented plan to close gaps is far safer than a high score you can't support with evidence.
Sources: NIST SP 800-171 Rev. 2; NIST SP 800-171 Rev. 3; NIST SP 800-171A; DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting; DoD NIST SP 800-171 Assessment Methodology, Version 1.2.1; 32 CFR Part 170, CMMC Program; DoD CIO, CMMC Program; CISA Cyber Security Evaluation Tool (CSET); NIST Manufacturing Extension Partnership; NIST Small Business Cybersecurity Corner. News peg (not a primary or government source, unconfirmed): JD Supra, "DOJ Cyber-FCA Settlements and DoW CMMC Phase II Suspension," September 2026: the described Phase II suspension has not been independently confirmed.
