+91 98804 42758

NIST SP 800-171 Gap Assessment

Find out exactly where you stand against all 110 controls before you book a C3PAO. A findings register, a real SPRS score, and a remediation roadmap with costs attached.

Updated August 2026 8 min read Compliance

What a NIST SP 800-171 Gap Assessment Is

A gap assessment measures your environment against all 110 NIST SP 800-171 controls and tells you, control by control, what is met, partially met, or missing. It produces three things: a findings register, an SPRS score calculated from those findings, and a remediation roadmap with effort and cost attached to every gap. It is the difference between knowing you have a CMMC problem and knowing what that problem costs.

It is preparation work, not certification. No consultant, ours included, can certify you — that is the C3PAO's job, and they are not permitted to assess a client they prepared.

Why It Comes First

Contractors who skip this stage make the same three mistakes, and all of them are expensive.

They buy tools before they scope. Security spend committed before the assessment boundary is drawn routinely pays for controls that were never in scope. Scoping first is what makes an enclave design possible, and enclave design is the single largest lever on your total CMMC cost.

They book a C3PAO too early. Assessor availability is the longest pole in most CMMC programmes right now. Booking before you know your gaps means either rescheduling, which wastes the slot, or walking into an assessment you fail.

They submit an SPRS score they cannot defend. Contracting officers can see that number before they see any certificate. A score assembled from optimism rather than evidence is a liability the moment someone asks how it was calculated.

The 14 Control Families We Assess

All 110 controls, grouped as NIST organizes them. Nothing is sampled out.

FamilyWhat it covers
Access ControlWho can reach CUI, from where, and under what conditions
Awareness & TrainingRole-based security training and insider-threat awareness
Audit & AccountabilityLogging, log review, and traceability to individual users
Configuration ManagementBaselines, change control, and least-functionality
Identification & AuthenticationMulti-factor authentication — a high-weighted family, and the most common failure
Incident ResponseDetection, handling, reporting, and testing your plan
MaintenanceSystem maintenance controls, including remote maintenance
Media ProtectionMarking, storage, transport and sanitization of CUI media
Personnel SecurityScreening, and protecting CUI during transfers and terminations
Physical ProtectionFacility access, visitor control, alternate work sites
Risk AssessmentVulnerability scanning and risk assessment cadence
Security AssessmentControl assessment, POA&M management, continuous monitoring
System & Communications ProtectionBoundary protection and FIPS-validated cryptography — the other common failure
System & Information IntegrityFlaw remediation, malicious code protection, monitoring

What You Get

A findings register. Every one of the 110 controls scored met, partially met, or not met, with the evidence we saw and the specific reason for anything short of met. No "needs improvement" hand-waving.

Your SPRS score, calculated properly. The number, the arithmetic behind it, and the specific controls dragging it down — see how the SPRS score works.

A costed remediation roadmap. Each gap with an owner, an effort estimate, and a cost, sequenced so the high-weighted controls close first. This is what turns a compliance problem into a budget line.

A scoping recommendation. Whether your current boundary is the cheapest defensible one, and what an enclave would save you if it is not.

Your SPRS Score, Before Anyone Else Sees It

The Supplier Performance Risk System score runs from −203 to 110 and is visible to contracting officers. Most contractors first calculate it under deadline pressure, which is the worst possible time to discover that multi-factor authentication has not actually been implemented everywhere it needs to be.

The assessment gives you the real number early, while there is still time to change it. How the SPRS score is calculated explains the weighting, including why a handful of controls cost five points each.

Cost and Timeline

A gap assessment is stage one of a NIST SP 800-171 programme, and it is priced separately from the remediation work that follows. For context, a full Avantcert NIST SP 800-171 / CSF engagement runs from $7,000 for a 5–50 employee contractor, around $18,000 at 51–200, and up to $30,000 at 201–500 or multi-site scope, within a 120-day maximum.

Most single-site assessments run two to four weeks, driven mainly by how fast your team can produce evidence.

Book Your Gap Assessment

Tell us your headcount and roughly where CUI sits. You get a scoped proposal within 24 hours.

Gap Assessment FAQs

What is a NIST SP 800-171 gap assessment?

It is a structured comparison of your current environment against all 110 NIST SP 800-171 controls across 14 families. The output is a findings register showing which controls are met, partially met, or not met, an SPRS score calculated from those findings, and a remediation roadmap with effort and cost attached to each gap.

Is a gap assessment the same as a CMMC assessment?

No. A gap assessment is preparation work performed by a consultant and carries no certification weight. A CMMC Level 2 assessment is performed by an independent C3PAO and results in certification. The same organization cannot do both for one client, which is why they are always separate engagements.

How long does a NIST 800-171 gap assessment take?

Typically two to four weeks for a single-site contractor, depending on how quickly your team can produce evidence and how many systems touch CUI. Scoping is the first activity and it usually determines the rest of the schedule.

Do I need a gap assessment before CMMC certification?

It is not formally required, but going into a C3PAO assessment without one is how contractors fail expensively. The assessment tells you your SPRS score, what remediation will cost, and whether your assessment boundary is the right shape, all before you have booked an assessor.

What are the 14 NIST SP 800-171 control families?

Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.

What Happens Next

The gap assessment is stage one of a CMMC engagement. See how the full engagement runs, what CMMC certification costs, or read the CMMC certification overview if you are still working out which level applies.

Official reference: NIST SP 800-171.

Find out where you actually stand

All 110 controls, a real SPRS score, and a costed roadmap. Two to four weeks.

Ready to get certified?

Join 3,000+ organizations that trust Avantcert. Get a free, scoped quote today.