NIST 800-171 is a live contract obligation under DFARS 252.204-7012. The pause on CMMC Phase 2 assessments did not change it. Read our analysis →
DFARS 252.204-7012 flows down now, your SPRS score is the number a prime's supply chain office asks for, and someone at your company signs an annual affirmation that it is accurate. Stehrling builds the 800-171 program behind that signature, at the control level, to the standard an assessor applies. CMMC certification guided where a contract requires it.
Talk to a practitioner
compliance@stehrling.comYou will reach a credentialed practitioner directly. We respond within 24 hours.
Most compliance consultants operate above the technical layer. They hand your IT team a gap report and move on. Stehrling's practitioners work directly with your technical staff on the actual controls that assessors evaluate: configurations, policies, procedures, and the organizational behaviors that hold them together.
NIST SP 800-171 has 110 controls. Roughly half are technical: system configurations, access controls, encryption. The rest are organizational, covering policies, training, incident response, and change control. We build both.
We meet weekly, build alongside your people, and make sure your organization understands the reasoning behind every control. When we are done, you maintain compliance independently. You are not dependent on us forever.
Every member of our delivery team holds a CCA or CCP credential. Because they have sat on the assessor's side of the table, the people preparing you know exactly what gets evaluated and what evidence holds up, and a full mock assessment confirms it before anyone else checks.
One program, run in phases. We meet weekly until it is done, and we stay after.
Define CUI boundaries, map your systems, establish your assessment perimeter.
Gap analysis against all 110 controls, and the SPRS score that falls out of it: 110 minus weighted deductions, not a count of what is in place.
Policies, procedures, training, and technical controls. Built for your organization, validated weekly.
Full mock assessment by our CCAs and CCPs, so you know exactly what an assessor will find before the assessor does.
SPRS score supported by evidence, affirmation your leadership can sign, and the C3PAO path guided where a contract still requires it.
Practitioner insights on 800-171 implementation, SPRS scoring, and the questions primes are putting to their suppliers right now.
Enclaves are a legitimate tool for narrowing your CMMC scope. But an enclave is infrastructure, not a compliance program. Here is what is still missing after the enclave is deployed.
Assessors evaluate policies, procedures, training programs, and whether your organization actually follows them. That is an organizational discipline, not a system configuration. Most firms figure this out too late.
The most common source of assessment failure starts with scope. If you cannot trace where CUI enters, moves through, and exits your environment, everything downstream is built on assumptions.
Talk to a practitioner. We will tell you where you stand against the 110 controls, what your SPRS score should actually be, and what it takes to support the affirmation someone has to sign.
Reach us directly
compliance@stehrling.comYou will reach a practitioner, not a sales team.
We respond within 24 hours.

Registered Practitioner Organization
The Cyber AB
An independent firm focused exclusively on NIST 800-171 compliance for defense contractors and the DIB.