NIST 800-171 and DFARS 252.204-7012
The clause that requires contractors handling CUI to implement the 110 NIST 800-171 controls and report cyber incidents to the DoD within 72 hours.


CMMC helps decide which contractors can compete for Department of Defense (DoD) business. Contractors that handle Controlled Unclassified Information (CUI) must implement the NIST 800-171 controls, post a score to the Supplier Performance Risk System (SPRS), and, for most, pass a third-party assessment by a C3PAO. SideChannel is a CMMC Registered Provider Organization (RPO) that combines vCISO leadership with Enclave, our zero-trust platform, to take you from gap analysis to certification and keep you there. Building a defense or manufacturing program? See the DoD Contractors & the Defense Industrial Base page.
SideChannel combines vCISO leadership with Enclave to run the compliance program and provide the controls behind it. These are the three core elements of a CMMC engagement.
In CMMC and NIST 800-171, a segmented boundary around the systems that handle CUI is the standard way to reduce how much of your environment falls inside assessment scope, which lowers cost, complexity, and audit surface at once. Enclave's network segmentation builds that boundary, isolating CUI-handling systems from the rest of the network and protecting legacy shop-floor equipment that cannot be re-architected, with no network redesign.
An SPRS score and a Plan of Action and Milestones are only as credible as the asset inventory behind them, and a spreadsheet nobody trusts is what turns a self-attestation into risk. Enclave's asset intelligence keeps a live, accurate inventory of every system in scope, and automated certificate lifecycle management keeps CUI encrypted in transit without manual renewals that fall behind. So when the assessor asks for your inventory, the evidence behind your score is already current.
A vCISO drives the program end to end: gap analysis against NIST 800-171, System Security Plan development, POA&M management, SPRS scoring, through to a self-attestation you can defend. One team owns the program from assessment to attestation and keeps it current as the CMMC rules evolve, so you are ready if a third-party assessment is required.
When a vCISO identifies a gap against these requirements, Enclave closes the technical side of it.
The clause that requires contractors handling CUI to implement the 110 NIST 800-171 controls and report cyber incidents to the DoD within 72 hours.
A self-assessment score, from 110 down to negative values, that you post to the Supplier Performance Risk System and must have on file to be eligible for award. 7019 and 7020 require you to submit, maintain, and flow down that score.
Level 1 covers Federal Contract Information and requires a self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21. Level 2 covers CUI and rests on the NIST 800-171 controls, plus an additional set of requirements written into the FAR and DFARS. Contractors complete a gap assessment, align to the controls, and attest to their compliance.
The Cybersecurity Maturity Model Certification (CMMC) is a Department of Defense program that requires contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) to meet the security requirements appropriate to the information they handle and attest to that compliance. It applies across the Defense Industrial Base, from small subcontractors to large primes.
Level 1 applies to contractors handling only FCI and requires a self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21. Level 2 applies to contractors handling CUI and holds them to the 110 controls in NIST 800-171, a significantly higher bar. Contractors gap-assess, align to the controls, and attest to their compliance.
CMMC and NIST 800-171 allow contractors to limit assessment scope to the systems that actually handle CUI, provided those systems are properly isolated in a segmented enclave. Enclave's network segmentation builds that boundary, which means fewer systems fall under assessment, lowering both cost and audit complexity.
The Supplier Performance Risk System (SPRS) score is a self-reported score, from 110 down to negative values, reflecting how many of the 110 NIST 800-171 controls a contractor has implemented. DFARS 252.204-7019 and 7020 require an SPRS score on file for DoD contracts that involve CUI, and a Plan of Action and Milestones (POA&M) documents the path to closing whatever isn't yet implemented.
No, SideChannel builds and runs the program behind your CMMC compliance, but it does not grant certification. If an independent third-party assessment is required for your contract, SideChannel partners with assessors. SideChannel takes you through gap analysis, remediation, and readiness, then works alongside your chosen C3PAO through certification.
Whether you are starting a gap analysis or getting your SPRS score and attestation in order, SideChannel can get you there and keep it defensible. Tell us where you are on the path and we will start from there.