NIST SP 800-171 Requirements for Orange County Defense Contractors
By Tom Hermstad · HD Tech

What is NIST SP 800-171, and does it apply to my Orange County defense subcontract?
NIST SP 800-171 is the federal cybersecurity standard that any non-government business must follow when handling Controlled Unclassified Information (CUI) — sensitive defense data like engineering drawings, specs, or manufacturing plans. Released in Revision 3 in February 2024, it defines 97 security requirements across 17 control families. If your Orange County machine shop or fabrication business touches CUI under a DoD contract, 800-171 applies — regardless of your company size.
The call I got from an Anaheim shop — and why it still bothers me
A few years back, I got a call from the owner of a precision machining shop in Anaheim. Good guy. Third-generation family business. They'd been a reliable defense subcontractor for many years.
His prime contractor had just sent an email asking for his SPRS score — the self-assessed compliance rating every defense contractor now has to submit to the Supplier Performance Risk System (SPRS). His nephew — sharp kid, handled their basic IT — had submitted a score on their behalf. The problem? The score looked great on paper. But there was no System Security Plan behind it. No Plan of Action. No documentation. Just a number.
When the prime contractor asked to see the supporting documentation, there was nothing to show. The shop nearly lost the contract. Not because they were doing anything wrong. Because they trusted someone who didn't know what they didn't know.
I've seen a version of that call end worse. A shop on the other side of OC lost a prime relationship — documentation request came in one day, the prime had a replacement subcontractor lined up just days later. That contract had taken them years to earn. It was gone before the owner fully understood what happened.
That's the call I never want you to have to make. And it's exactly why this guide exists.
The question your prime contractor is about to ask
It usually starts with an email. Or a clause buried in a new contract renewal. Or a purchasing agent who asks, "What's your SPRS score?"
If you're running a machine shop, metal fabrication house, or specialty manufacturer in Orange County that does work for the Department of Defense — directly or as a subcontractor — that question is coming. And if you don't have a real answer backed by real documentation, you're at risk of losing the contract.
NIST SP 800-171 is the standard sitting behind all of it. Most of the content you'll find online about this is written for IT directors at large defense primes. This guide isn't.
It's written for the owner of a shop in Anaheim who's great at precision machining and doesn't have time for cybersecurity jargon. That's the Plain-English Promise™ at work. Let's get into it.
First: Do you actually handle CUI?
Before anything else, answer this question honestly.
Controlled Unclassified Information (CUI) is government data that isn't classified secret or top secret — but still requires protection. In a defense manufacturing context, it includes:
- Engineering drawings marked CUI
- Technical specifications for defense components
- Manufacturing process data tied to a defense program
- Procurement information, test results, or program schedules marked as sensitive
NIST's own guidance says the first step for any small contractor is confirming whether you receive, store, process, or transmit CUI. If the answer is yes — even if the data only lives in your email or on a shared drive — 800-171 applies to you.
If you're not sure, read your contract carefully. Look for references to DFARS clause 252.204-7012. That clause is the legal trigger. If it's in your contract, you're obligated.
What NIST 800-171 actually is (in plain English)
NIST SP 800-171 Revision 3, published February 2024, defines 97 security requirements organized into 17 control families. Think of each family as a category of protection — a chapter in a security manual that covers everything from who can log in, to how you handle a printed drawing, to what happens when someone quits.
I'm not going to walk you through all 17 here line by line — that's what government PDFs are for, and you've got a shop to run. What I want to give you is the control families that consistently trip up Orange County manufacturers, because these are the gaps I see most often when we do a first assessment.
The control families that trip up OC shops most often
Here's what I actually get fired up about when I walk into a shop like yours — because fixing these areas is where real protection begins, and where I've seen shops go from exposed to rock-solid in a matter of months.
1. Access Control — Only the right people reach sensitive data. User accounts, role-based permissions, removing access the day someone leaves. Sounds simple. Rarely is. Most shops I walk into have former employees who still have active logins.
2. Identification and Authentication — Everyone who logs in proves they are who they say they are. Multi-factor authentication (MFA) — a password plus a phone code or hardware token — is the baseline. A surprising number of shops still aren't running it on email.
3. Incident Response — You have a documented plan for when something goes wrong. Not in your head. Written down, tested, and ready. The plan needs to exist before the incident — not get written the morning after.
4. System and Information Integrity — Threat detection running on your endpoints, patches applied promptly, vulnerabilities addressed before attackers find them. This is where the gap between "we have antivirus" and "we have a security program" becomes very visible.
5. Planning — You have a documented System Security Plan (SSP). A written description of what you protect, how you protect it, and what gaps remain. Without it, you're already non-compliant — full stop.
The other 12 families matter too. But if a shop is failing, it's almost always failing here first. Get these right and you've built the foundation the rest sits on.
If your shop has fallen behind on any of these — keep paddling. These gaps are fixable, and the shops that start now are the ones that walk into their next contract renewal with their heads up. The ones that wait are the ones I get the panicked call from.
The key documents you must have
The vast majority of small defense subcontractors in Orange County are missing most of these. That's the honest truth — and it's also the most fixable problem I know how to solve.
System Security Plan (SSP)
This is your written description of your IT environment — what systems exist, what CUI they handle, and how each of the 97 requirements is addressed. It's not a pass/fail test. It's documentation. If you don't have one, you're already non-compliant.
Plan of Action & Milestones (POA&M)
Most organizations do not meet all 97 requirements on day one. The POA&M documents which requirements you haven't met yet, what you're doing to fix them, and by when. An honest POA&M is not a liability — it demonstrates maturity.
SPRS Score
Once your SSP and POA&M are in place, you calculate your score using the DoD assessment methodology and submit it to the Supplier Performance Risk System (SPRS). Your prime contractor can see this score. So can DoD.
A missing or inaccurate score is a contract risk. If your purchasing agent asks for your SPRS score and you don't have one — or you submitted a score without the documentation to back it up — that's a serious problem. (See the Anaheim story above. That problem is more common than you'd think.)
Your SPRS score isn't just a compliance checkbox — it's a competitive weapon
Here's something most shops don't realize until it's too late: your SPRS score and your SSP aren't just documents you produce to satisfy a contracting requirement. They're a competitive differentiator.
When a prime contractor is evaluating subcontractors for a new program — especially a sensitive one — they look at SPRS scores. A strong, documented score backed by a complete SSP tells that prime you're a low-risk partner. It signals that your shop takes security seriously, that you know what you're protecting, and that you won't become the weak link in their supply chain.
Your competitors who haven't done this work can't show that. You can.
The shop that has a clean SSP, an honest POA&M, and a defensible SPRS score wins bids that other shops can't even compete for. Managed IT compliance support isn't a cost of doing business with the DoD — it's the edge that keeps prime relationships competitors can't touch. That's not theory. That's what I see playing out across Orange County, contract cycle after contract cycle.
Here's where most shops get tripped up — and it's completely fixable
This is the part I want you to pay close attention to.
A lot of small defense shops hand the SPRS submission to whoever manages their IT — sometimes an in-house IT coordinator, sometimes a nephew or a family friend who "knows computers." That person submits a score. The number gets entered into the system. And everyone assumes it's handled.
Here's the problem: submitting a score is the easy part. What the DoD and your prime contractor actually care about is whether the documentation behind that score is real.
A seasoned compliance partner doesn't just submit a number. They inventory every system that touches CUI. They write an accurate SSP that maps each of the 97 requirements to your actual environment. They build a defensible POA&M that documents your gaps honestly.
They calculate your score using the correct methodology — not a best guess. And they make sure the whole package holds up if a prime contractor or DoD auditor asks to see it.
That's the difference between a score and a posture. Your nephew may be great. But this isn't a task — it's a program.
"We let our in-house IT guy handle it" is one of the most common reasons shops lose prime relationships. Not because of malice. Because of a gap they didn't know existed until someone asked to see the paperwork.
How long does this actually take?
For most mid-size shops, full implementation is a substantial undertaking that takes meaningful time. That's not a worst-case scenario — that's typical for a contractor with meaningful gaps and a real IT environment to document.
Here's why it takes that long:
- Writing an accurate SSP requires inventorying every system that touches CUI. For shops running a mix of legacy CAD workstations, shared network drives, and personal devices, the discovery phase alone takes weeks.
- Closing technical gaps — MFA, encrypted backups, endpoint protection, network segmentation, log management — takes time to deploy and configure correctly.
- Writing policies and conducting employee training takes time most owners don't have on a Tuesday afternoon.
- Getting the POA&M right, calculating the SPRS score accurately, and submitting it correctly takes coordination.
If your contract renewal or a new defense bid is coming up in the near future, you may already be behind. Start now.
800-171 and CMMC: What's the connection?
If you've heard about CMMC — the Cybersecurity Maturity Model Certification — and wondered how it relates to NIST 800-171, here's the plain-English answer:
CMMC Level 2 maps directly to the requirements in NIST 800-171. If you achieve full compliance with 800-171, you are effectively CMMC Level 2 ready. The difference is that CMMC adds a verification requirement — instead of self-attesting, many contractors will need a third-party assessment organization (C3PAO) to audit and certify them.
I tell every client: working on 800-171 now isn't a detour — it IS the path. Every control family you address today brings you one step closer to CMMC readiness tomorrow. The work you do this quarter doesn't get thrown away when CMMC kicks in — it becomes the foundation your certification is built on.
I've walked Orange County shops through this journey enough times to know exactly where the wrong turns are. For more detail on the specific cybersecurity posture your defense contracts require, read our guide on cybersecurity for aerospace companies in Orange County — many of the same obligations apply.
Some common misconceptions we hear from OC defense shops
"We're too small for this to apply." Size doesn't determine applicability. If your contract includes CUI and references DFARS 252.204-7012, 800-171 applies to a small shop the same as a large prime. NIST's guidance is explicit on this point.
"We have a firewall and antivirus, so we're covered." Tools alone don't satisfy 800-171. The standard requires policies, training, incident response plans, documented risk assessments, and physical security controls — most of which have nothing to do with the firewall sitting in your server room. Our cybersecurity checklist for Orange County defense contractors breaks down exactly what "beyond the firewall" looks like in practice.
"This is only an IT problem." Four control families — Personnel Security, Physical Protection, Media Protection, and Supply Chain Risk Management — are operational and facility concerns, not IT concerns. HR owns termination procedures. The floor supervisor controls badge access. The shipping manager handles drawings. Every one of them has a role to play. 800-171 compliance is a company-wide commitment, full stop.
What's actually at stake — and why this is a leadership issue
You built this shop. Your employees' paychecks depend on these contracts. The reputation you've spent years building — with your primes, your customers, your team — rests on your ability to operate with integrity.
Losing a prime relationship over a missing SSP or an inaccurate SPRS score isn't an IT failure. It's a leadership risk.
NIST's supply chain risk guidance specifically highlights that a compromise in a small vendor's environment can disrupt development, manufacturing, or delivery for larger defense programs — and trigger contractual remedies against the subcontractor.
In plain English: if your systems get compromised and CUI is exposed, your prime contractor may remove you from their approved supplier list. DoD can audit your SPRS score submission. You may face contract termination for failure to meet DFARS obligations.
And if you submitted an inaccurate SPRS score — claiming compliance you didn't have — you could face False Claims Act exposure.
That's not fearmongering. That's the documented consequence of non-compliance in this space. The question isn't whether the risk is real. It's whether you're prepared — and whether you're leading your organization like someone who takes that seriously.
How HD Tech approaches 800-171 for Orange County defense manufacturers
We work with manufacturers, fabricators, and specialty defense subcontractors in Orange County who need to get compliant — and stay that way — without building an internal IT security department.
I'll be direct: over many years of doing this work in Orange County, I've seen the same compliance failures repeat themselves — at shops large and small, across Anaheim, Irvine, and everywhere in between. We've helped Anaheim defense subcontractors go from no documentation to a clean SPRS submission. The gaps aren't unique. What's unique is having a partner who's already seen them, already knows where to look, and already knows how to close them fast.
No out-of-state MSP flying in to learn your industry on your dime. No generalist IT person Googling DFARS requirements for the first time. We've been living this alongside Orange County manufacturers for a long time — and that's not something you can manufacture overnight.
Our approach follows the Lifeguard Loop™:
Listen & Learn: We start with a discovery session to understand your environment — what systems you run, what data you handle, where CUI lives, and what gaps exist. No assumptions.
Implement & Integrate: We help you close technical gaps — MFA, encrypted backups, endpoint protection, network segmentation, log management — and build the documentation your SSP requires.
Fortify & Future-Proof: We set up continuous monitoring so threats are caught before they become incidents. And we help you maintain the ongoing posture that keeps your SPRS score accurate over time.
Educate & Empower: We train your employees on CUI handling, phishing awareness, and your incident response procedures. Plain English, no jargon. So the person at the CAD station understands what they're protecting and why.
We don't hand you a thick report and walk away. We work alongside your team until compliance is real — documented, practiced, and auditable.
Here's what genuinely fires me up about this part of the work: the shops that go through this process don't just get compliant — they get confident. They know exactly what they have, what it's worth protecting, and what to do if something goes wrong.
I've watched owners who used to dread contract renewals walk into those conversations with their heads up, ready to show their documentation, ready to answer any question a prime throws at them. That transformation — from anxious to authoritative — is what this work is really about. And I never get tired of seeing it happen.
If your business handles both defense and commercial work, the same security discipline we apply for 800-171 carries over. We've helped construction-adjacent and specialty fabrication firms understand that cybersecurity for construction and defense manufacturing share more overlap than most owners expect — especially when CUI and proprietary project data live on the same network.
Frequently Asked Questions
A shop owner asked me this just last month — contract renewal was weeks away and he had no idea this applied to a business his size. I get fired up about this one because the answer is simpler than people make it: NIST SP 800-171 is a federal cybersecurity standard requiring any non-government organization to protect Controlled Unclassified Information (CUI). If your contract includes CUI and your business processes, stores, or transmits that data, you're covered — full stop. Revision 3, released in February 2024, defines 97 security requirements across 17 control families. Size doesn't determine applicability. The contract terms do. Failing to prepare here is preparing to fail — and I've watched it happen to good shops that just didn't know.
I hear this constantly from owners who've caught the word "CMMC" at a defense industry event and aren't sure whether to worry yet. Here's the truth — and it's actually great news: think of 800-171 as the rulebook and CMMC as the referee. CMMC Level 2 maps directly to the 800-171 requirements — same controls, same expectations. The difference is that 800-171 has historically relied on self-attestation, while CMMC brings in a third-party auditor to verify your work. Every requirement you satisfy now counts toward CMMC readiness. None of it gets thrown out when the auditor shows up. Keep paddling — the work you're doing today is exactly the right work.
A fabricator reached out after his prime mentioned SPRS in a sourcing meeting — he'd never heard the term. Here's what made me light up explaining it to him: your SPRS score is the number your prime uses to decide if you're a safe bet for their next program. It stands for Supplier Performance Risk System, and it's the DoD database where defense contractors submit a self-assessed compliance score for NIST 800-171. A missing score, a score with no documentation behind it, or an inflated score are all contract risks — and potentially False Claims Act exposure. Your score has to reflect your actual documented posture, backed by a real SSP and an honest POA&M. Prevention is preparedness — and a defensible score is exactly that.
The most common version of this question is: "Can we do this fast?" And I'll be straight with you — almost never. For most mid-size contractors with real gaps, full implementation is a substantial effort that takes considerable time. The timeline depends on your IT environment's complexity, how many gaps the initial assessment surfaces, and how quickly you can close technical controls and finalize required documentation. Shops that wait until a contract renewal is weeks away are at serious risk. Here's my bottom line: start now, keep paddling, and don't let the size of the task stop you from taking the first step. The shops that begin early walk into renewals with their heads up. The ones that don't make the panicked call.
Yes — and this one genuinely excites me to explain because it catches so many owners off guard. I've had shop owners tell me "I thought this was just an IT thing" — and watching that light bulb go on is one of my favorite moments. Physical Protection requires controlled access to any area where CUI is processed or stored. Personnel Security covers employee screening and termination procedures — including revoking access the day someone walks out the door. Media Protection governs how hard drives, USB drives, and printed drawings are handled and destroyed. Compliance is a company-wide commitment that pulls in HR, facility management, and operations leadership. Your IT team can't carry this one alone — and frankly, that's a good thing. More people invested means a stronger program.
Trust, yet verify — and that starts with knowing exactly where you stand today. If your contract renewal is coming up soon, you may already be behind — and a gap discovered by your prime is far more painful than one you find yourself. Book your Cyber Preparation Assessment now. HD Tech works with manufacturers and defense subcontractors across Orange County to close compliance gaps, build the documentation DoD expects, and establish the ongoing security posture that keeps your contracts safe. Failing to prepare is preparing to fail — find out exactly where you stand before your prime contractor does.

Tom Hermstad
President & CMO, HD Tech
Tom Hermstad has led HD Tech since 1995, building one of Southern California's most trusted managed IT and cybersecurity firms. He specializes in helping Orange County businesses eliminate IT headaches and stay ahead of evolving cyber threats — in plain English.
