Updated August 26, 2026

DFARS • NIST SP 800-171 • Understand

Low confidence does not mean low effort

A DFARS 252.204-7020 Basic Assessment is self-generated, but it still requires a methodology-based assessment, an adequate System Security Plan, a defined CUI environment, and a score the contractor can support if the Government looks behind it.

Direct answer

“Basic” identifies the assessment type—not permission to estimate the score.

DFARS 252.204-7020 defines a Basic Assessment as the contractor’s self-assessment of its NIST SP 800-171 implementation, based on the SSP and conducted under the DoD Assessment Methodology. The score receives a Low confidence level because it is self-generated.

That confidence label does not eliminate the 7012 obligation, the 7019 award gate, or the possibility of Government Medium or High verification. A supportable score must come from a supportable boundary, SSP, implementation record, and assessment process.

Read the clauses together

Three provisions create one operating obligation.

252.204-7012

Implement and operate. Provide adequate security, implement the applicable NIST SP 800-171 requirements, report covered cyber incidents, address cloud conditions, and flow the clause where required.

252.204-7019

Establish award eligibility. Verify that a current DoD Assessment score exists in SPRS for every covered contractor information system relevant to the offer—normally within the preceding three years unless less time is specified.

252.204-7020

Assess and permit verification. Follow the DoD methodology for the Basic Assessment, provide access for a Government Medium or High Assessment when required, address rebuttal and SPRS procedures, and impose applicable subcontractor assessment conditions.

The actual work

A defensible score begins before the scoring worksheet.

Confirm the governing record

Identify the solicitation, contract, order, modification, subcontract, incorporated clauses, information obligations, NIST version, assessment currency, CAGE codes, and relevant systems.

Trace CUI

Determine what CUI is received, generated, stored, processed, transmitted, backed up, supported, shared, archived, and destroyed—and by whom.

Define the assessment boundary

Categorize CUI assets, security protection assets, contractor risk managed assets, specialized assets, out-of-scope assets, external providers, administration paths, and relevant adjacency.

Establish the SSP

Document the boundary, operating environment, implementation, system relationships, connections, responsibilities, and exceptions. The DoD methodology states that an assessment cannot be completed without an SSP.

Evaluate implementation

Determine what is implemented and operating using relevant specifications, mechanisms, activities, people, records, observations, interviews, and tests.

Calculate and reconcile

Calculate the 110-requirement score using the DoD methodology; reconcile it to objective-level findings, POA&M items, evidence limitations, owners, and the date full implementation is expected.

110 requirements • 320 objectives

The score is reported by requirement; the conclusion is built from underlying facts.

NIST SP 800-171 Revision 2 contains 110 security requirements. NIST SP 800-171A decomposes those requirements into 320 assessment objectives that define what must be true for the corresponding requirement to be MET under the CMMC Level 2 assessment method.

The Basic Assessment definition does not transform a contractor’s self-assessment into a Government High Assessment or CMMC certification assessment. But an objective-level review is the defensible way for a qualified readiness provider to determine whether each scored requirement is actually implemented.

eTrepid’s professional rule

eTrepid will not recommend an SPRS score based only on a questionnaire, policy library, inherited platform claim, prior score, or unsupported control-owner statement.

We evaluate all 320 objectives, record the evidence and limitation supporting each determination, calculate the corresponding 110-requirement score, and require an accountable client official to review the factual basis before submission.

Assessment confidence

Basic, Medium, and High describe increasing Government confidence and verification depth.

Operational summary. The current DFARS text and DoD Assessment Methodology control.
Assessment Who performs it Core activity Confidence
Basic Contractor Self-assessment based on the SSP and DoD Assessment Methodology; summary score is posted to SPRS Low because the score is self-generated
Medium Government Review of the Basic Assessment, thorough document review, and contractor discussions Medium
High Government Basic Assessment review, thorough document review, and verification, examination, demonstration, and discussions using NIST SP 800-171A High

A contractor subject to 7020 must provide the facilities, systems, and personnel necessary for a Medium or High Assessment when the Government determines one is necessary. That possibility should shape the quality of the Basic Assessment from the beginning.

Representation and liability

A Low-confidence score can still be a material Government representation.

An unsupported or knowingly inaccurate score can affect award eligibility, Government risk decisions, subcontract awards, invoices, certifications, and continued performance. Depending on the facts, consequences may include contractual remedies, repayment, suspension or debarment concerns, reputational harm, and potential civil False Claims Act exposure.

The False Claims Act is fact-specific. A scoring error is not automatically fraud. Knowledge, falsity, materiality, the contract, the representation, correction efforts, and other facts matter. Contractors should obtain qualified legal advice for actual submissions and disclosures.

A documented enforcement example

In 2025, MORSECORP paid $4.6 million to resolve False Claims Act allegations concerning cybersecurity requirements. The company acknowledged that it had submitted a score of 104, lacked full implementation and an adequate consolidated SSP, and was later advised by a third party that its score was –142.

The lesson is not that every difference creates liability. It is that the organization should be able to reproduce the boundary, facts, methodology, evidence, and judgment behind the submitted score.

Submission decision record

Before an authorized official submits or relies on the score.

Scope attestation

Confirm which systems, SSPs, CAGE codes, locations, providers, and information flows the assessment covers—and what it excludes.

Assessment record

Retain the objective-level determinations, methods, evidence references, reviewer, dates, limitations, and approved corrections.

Score reconciliation

Verify that the requirement status, deduction, POA&M, expected completion date, and summary score agree.

Provider responsibility

Document inherited, shared, and customer-operated responsibilities rather than treating a product or provider claim as organizational compliance.

Executive review

Give the accountable official the actual condition, material limitations, open remediation, and escalation issues—not only the final number.

Correction path

Define how newly discovered errors, scope changes, incidents, provider changes, or implementation failures will be evaluated and corrected through authorized channels.

Contextual next step

Build a score you are prepared to defend.

eTrepid can help determine applicability, define the CUI boundary, evaluate all 320 objectives, reconcile the SSP and evidence, calculate the score, prioritize remediation, and prepare responsible personnel for Government verification.

Do not submit CUI, credentials, vulnerability information, SSPs, diagrams, contracts, assessment evidence, or SPRS records through a public website form or chat.

Basic Assessment questions

Questions leadership should ask before relying on a score.

Does “Low confidence” mean DoD accepts an estimate?

No. The confidence label reflects that the score is self-generated. The Basic Assessment must still be based on the SSP and conducted under the DoD Assessment Methodology.

Does 7020 explicitly require a contractor to conduct a CMMC certification assessment?

No. A contractor Basic Assessment, a Government Medium or High Assessment, and a CMMC certification assessment are distinct activities. eTrepid uses the 320 objectives as its professional readiness and scoring standard; that does not convert the engagement into a Government or certification assessment.

Can we complete the assessment without an SSP?

No. The DoD Assessment Methodology states that absence of an SSP means the assessment could not be completed because of incomplete information and noncompliance with DFARS 252.204-7012.

Does a current SPRS score prove compliance?

No. A posted score records an assessment result for the identified systems and date. It does not prove that scope was correct, evidence was sufficient, implementation remains unchanged, or every representation was accurate.

Can DoD look behind the Basic Assessment?

Yes. Under 7020, the contractor must provide access necessary for a Government Medium or High NIST SP 800-171 DoD Assessment when required.

Can a prime rely on a subcontractor’s statement that it is compliant?

Not by itself. Applicable 7020 subcontracts require a current Basic Assessment for the relevant covered contractor systems, and the prime must address the correct contractual flow-down and information boundary.

Source and review record

Primary sources used for this draft.

Reviewed August 26, 2026. Recheck DFARS, DoD implementation status, the assessment methodology, the NIST baseline, SPRS procedures, and credential claims before publication and after material change.

Review cadence

Recheck this guidance after material changes to DFARS, DoD implementation status, the assessment methodology, the NIST baseline, SPRS procedures, enforcement guidance, or eTrepid’s credentials and service method.