DFARS • NIST SP 800-171 • Understand
Low confidence does not mean low effort
A DFARS 252.204-7020 Basic Assessment is self-generated, but it still requires a methodology-based assessment, an adequate System Security Plan, a defined CUI environment, and a score the contractor can support if the Government looks behind it.
Direct answer
“Basic” identifies the assessment type—not permission to estimate the score.
DFARS 252.204-7020 defines a Basic Assessment as the contractor’s self-assessment of its NIST SP 800-171 implementation, based on the SSP and conducted under the DoD Assessment Methodology. The score receives a Low confidence level because it is self-generated.
That confidence label does not eliminate the 7012 obligation, the 7019 award gate, or the possibility of Government Medium or High verification. A supportable score must come from a supportable boundary, SSP, implementation record, and assessment process.
Read the clauses together
Three provisions create one operating obligation.
252.204-7012
Implement and operate. Provide adequate security, implement the applicable NIST SP 800-171 requirements, report covered cyber incidents, address cloud conditions, and flow the clause where required.
252.204-7019
Establish award eligibility. Verify that a current DoD Assessment score exists in SPRS for every covered contractor information system relevant to the offer—normally within the preceding three years unless less time is specified.
252.204-7020
Assess and permit verification. Follow the DoD methodology for the Basic Assessment, provide access for a Government Medium or High Assessment when required, address rebuttal and SPRS procedures, and impose applicable subcontractor assessment conditions.
The actual work
A defensible score begins before the scoring worksheet.
Confirm the governing record
Identify the solicitation, contract, order, modification, subcontract, incorporated clauses, information obligations, NIST version, assessment currency, CAGE codes, and relevant systems.
Trace CUI
Determine what CUI is received, generated, stored, processed, transmitted, backed up, supported, shared, archived, and destroyed—and by whom.
Define the assessment boundary
Categorize CUI assets, security protection assets, contractor risk managed assets, specialized assets, out-of-scope assets, external providers, administration paths, and relevant adjacency.
Establish the SSP
Document the boundary, operating environment, implementation, system relationships, connections, responsibilities, and exceptions. The DoD methodology states that an assessment cannot be completed without an SSP.
Evaluate implementation
Determine what is implemented and operating using relevant specifications, mechanisms, activities, people, records, observations, interviews, and tests.
Calculate and reconcile
Calculate the 110-requirement score using the DoD methodology; reconcile it to objective-level findings, POA&M items, evidence limitations, owners, and the date full implementation is expected.
110 requirements • 320 objectives
The score is reported by requirement; the conclusion is built from underlying facts.
NIST SP 800-171 Revision 2 contains 110 security requirements. NIST SP 800-171A decomposes those requirements into 320 assessment objectives that define what must be true for the corresponding requirement to be MET under the CMMC Level 2 assessment method.
The Basic Assessment definition does not transform a contractor’s self-assessment into a Government High Assessment or CMMC certification assessment. But an objective-level review is the defensible way for a qualified readiness provider to determine whether each scored requirement is actually implemented.
eTrepid’s professional rule
eTrepid will not recommend an SPRS score based only on a questionnaire, policy library, inherited platform claim, prior score, or unsupported control-owner statement.
We evaluate all 320 objectives, record the evidence and limitation supporting each determination, calculate the corresponding 110-requirement score, and require an accountable client official to review the factual basis before submission.
Assessment confidence
Basic, Medium, and High describe increasing Government confidence and verification depth.
| Assessment | Who performs it | Core activity | Confidence |
|---|---|---|---|
| Basic | Contractor | Self-assessment based on the SSP and DoD Assessment Methodology; summary score is posted to SPRS | Low because the score is self-generated |
| Medium | Government | Review of the Basic Assessment, thorough document review, and contractor discussions | Medium |
| High | Government | Basic Assessment review, thorough document review, and verification, examination, demonstration, and discussions using NIST SP 800-171A | High |
A contractor subject to 7020 must provide the facilities, systems, and personnel necessary for a Medium or High Assessment when the Government determines one is necessary. That possibility should shape the quality of the Basic Assessment from the beginning.
Representation and liability
A Low-confidence score can still be a material Government representation.
An unsupported or knowingly inaccurate score can affect award eligibility, Government risk decisions, subcontract awards, invoices, certifications, and continued performance. Depending on the facts, consequences may include contractual remedies, repayment, suspension or debarment concerns, reputational harm, and potential civil False Claims Act exposure.
The False Claims Act is fact-specific. A scoring error is not automatically fraud. Knowledge, falsity, materiality, the contract, the representation, correction efforts, and other facts matter. Contractors should obtain qualified legal advice for actual submissions and disclosures.
A documented enforcement example
In 2025, MORSECORP paid $4.6 million to resolve False Claims Act allegations concerning cybersecurity requirements. The company acknowledged that it had submitted a score of 104, lacked full implementation and an adequate consolidated SSP, and was later advised by a third party that its score was –142.
The lesson is not that every difference creates liability. It is that the organization should be able to reproduce the boundary, facts, methodology, evidence, and judgment behind the submitted score.
Submission decision record
Before an authorized official submits or relies on the score.
Scope attestation
Confirm which systems, SSPs, CAGE codes, locations, providers, and information flows the assessment covers—and what it excludes.
Assessment record
Retain the objective-level determinations, methods, evidence references, reviewer, dates, limitations, and approved corrections.
Score reconciliation
Verify that the requirement status, deduction, POA&M, expected completion date, and summary score agree.
Provider responsibility
Document inherited, shared, and customer-operated responsibilities rather than treating a product or provider claim as organizational compliance.
Executive review
Give the accountable official the actual condition, material limitations, open remediation, and escalation issues—not only the final number.
Correction path
Define how newly discovered errors, scope changes, incidents, provider changes, or implementation failures will be evaluated and corrected through authorized channels.
Contextual next step
Build a score you are prepared to defend.
eTrepid can help determine applicability, define the CUI boundary, evaluate all 320 objectives, reconcile the SSP and evidence, calculate the score, prioritize remediation, and prepare responsible personnel for Government verification.
Basic Assessment questions
Questions leadership should ask before relying on a score.
Does “Low confidence” mean DoD accepts an estimate?
No. The confidence label reflects that the score is self-generated. The Basic Assessment must still be based on the SSP and conducted under the DoD Assessment Methodology.
Does 7020 explicitly require a contractor to conduct a CMMC certification assessment?
No. A contractor Basic Assessment, a Government Medium or High Assessment, and a CMMC certification assessment are distinct activities. eTrepid uses the 320 objectives as its professional readiness and scoring standard; that does not convert the engagement into a Government or certification assessment.
Can we complete the assessment without an SSP?
No. The DoD Assessment Methodology states that absence of an SSP means the assessment could not be completed because of incomplete information and noncompliance with DFARS 252.204-7012.
Does a current SPRS score prove compliance?
No. A posted score records an assessment result for the identified systems and date. It does not prove that scope was correct, evidence was sufficient, implementation remains unchanged, or every representation was accurate.
Can DoD look behind the Basic Assessment?
Yes. Under 7020, the contractor must provide access necessary for a Government Medium or High NIST SP 800-171 DoD Assessment when required.
Can a prime rely on a subcontractor’s statement that it is compliant?
Not by itself. Applicable 7020 subcontracts require a current Basic Assessment for the relevant covered contractor systems, and the prime must address the correct contractual flow-down and information boundary.
Source and review record
Primary sources used for this draft.
- DFARS 252.204-7012 — Safeguarding and reporting
- DFARS 252.204-7019 — Current assessment award requirement
- DFARS 252.204-7020 — Assessment requirements
- DFARS 204.7302 — Policy
- DoD — NIST SP 800-171 Assessment Methodology, Version 1.2.1
- DoD CIO — CMMC Level 2 Assessment Guide, Version 2.13
- The Cyber AB — 2026 CMMC reform response
- Department of Justice — MORSECORP settlement
Prepare for the next assessment
For the readiness sequence, evidence preparation, interview rehearsal, and recurring operating cadence, read Preparing for a CMMC Level 2 Assessment.
Assessment preparation path
Start with the readiness check, then review eTrepid’s CMMC readiness approach for scoping, evidence, remediation, and sustained operations.
Review cadence
Recheck this guidance after material changes to DFARS, DoD implementation status, the assessment methodology, the NIST baseline, SPRS procedures, enforcement guidance, or eTrepid’s credentials and service method.