SPRS NIST SP 800-171 WORKFLOW.pdf
PDF 97 KB Posted
- Attached to
- Explosive Atmosphere Testing and Test Report Federal contract opportunity
- Solicitation number
- FA822224QB011
About this file
This is a workflow document outlining the step-by-step process for contractors to complete and submit their NIST SP 800-171 cybersecurity assessment in the Supplier Performance Risk System (SPRS). The document details five key steps: obtaining SPRS access through PIEE registration, developing an IT System Security Plan (SSP), performing the NIST assessment, completing a Plan of Action if scoring below 110, and entering assessment details into SPRS.
The document also includes regulatory directives regarding DFARS provisions 252.204-7019 and 252.204-7020, which establish enforcement methodologies for NIST SP 800-171 compliance. Key requirements include maintaining a current assessment (not older than three years) in SPRS to be considered for contract awards, providing government access for higher-level assessments, and ensuring subcontractors have current assessments posted in SPRS. The provisions apply to all solicitations and contracts except those solely for COTS items, with mandatory flow-down to applicable subcontracts. Contact information for various help desks and relevant template links are provided throughout the document.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Equipment List.xlsx | XLSX spreadsheet | |
| Statement of Work.docx | DOCX document | |
| FA822225QB004_Provisions and Clauses.pdf | ||
| Combo Synopsis Solicitation_12.16.2024.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SPRS NIST SP 800-171 Workflow
Step 1. Obtain Access to SPRS; Register in PIEE and activate a “SPRS Cyber Vendor User” role:
Once your company registers with PIEE, your company will need to establish a Contractor Administrator (CAM). The CAM acts as your companies User Role approver. Your CAM will approve your request for a “SPRS Cyber Vendor User” role.
If there is only one CAM, and this person is applying for a SPRS User role, they must request User role activation from PIEE help desk.
PIEE HELPDESK
Email: disa.global.servicedesk.mbx.eb-ticket-requests@mail.mil
Phone: 1-866-618-5988
Step 2. In order to perform the NIST Assessment, your company needs to have an internal IT System Security Plan (SSP) in place. Hopefully, your IT department has already written one of these.
If not;
System Security Plan (SSP) Guide & Template: https://csrc.nist.gov/publications/detail/sp/800- 171/rev-2/final
The template is found on the right hand side under documentation. Titled CUI SSP Template.
Step 3. Once the SSP is in place, you are ready to ‘perform’ the NIST Assessment.
NIST SP 800-171
Methodology: https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171- Assessment-Methodology-Version-1.2.1-6.24.2020.pdf (scoring template begins on page 12)
For assistance with conducting your NIST SP 800-171 assessment, assessment interpretation, definitions, deadlines, regulations, requirements, scope, etc.; you will need to contact the DCMA Help Desk at: DCMA_7012_Assessment_Inquiry@mail.mil.
Step 4 If your score is less than 110 you will need to complete a Plan of Action
Plan of Action Template: https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
The template is found on the right hand side under documentation.
Step 5. Entering score and other assessment details -- Walkthrough Guide:
NIST SP 800-171 Quick Entry Guide: https://www.sprs.csd.disa.mil/pdf/NISTSP800- 171QuickEntryGuide.pdf https://piee.eb.mil/piee-landing/ https://piee.eb.mil/piee-landing/ mailto:disa.global.servicedesk.mbx.eb-ticket-requests@mail.mil https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf mailto:DCMA_7012_Assessment_Inquiry@mail.mil https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final https://www.sprs.csd.disa.mil/pdf/NISTSP800-171QuickEntryGuide.pdf https://www.sprs.csd.disa.mil/pdf/NISTSP800-171QuickEntryGuide.pdf
Regulatory directives:
The new DFARS provision 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements, and new DFARS clause 252.204-7020, NIST SP 800-171 DoD Assessment Requirements, add additional cybersecurity measures to those already required under DFARS 252.204-7012 by establishing enforcement methodologies for ensuring contractors have implemented the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 DoD Assessment Methodology.
Contracting Officers are directed to include DFARS 252.204-7019 and 252.204-7020 in all solicitations and contracts including solicitations using FAR part 12 procedures for the acquisition of commercial items, except for solicitations solely for the acquisition of COTS items.
DFARS provision 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements, advises offerors required to implement the NIST SP 800-171 to have a current (not older than three years) NIST SP 800-171 DoD Assessment on record in order to be considered for award. The provision requires offerors to ensure the results of any applicable current Assessments are posted in Supplier Performance Risk System (SPRS) and provides offerors with additional information on conducting and submitting an Assessment when a current one is not posted in SPRS.
The new DFARS clause 252.204-7020, NIST SP 800-171 DoD Assessment Requirements, requires a contractor to provide the Government with access to its facilities, systems, and personnel when it is necessary for DoD to conduct or renew a higher-level (“MEDIUM “or “HIGH”) assessment. The clause also requires the contractor to ensure that applicable subcontractors have the results of a current Assessment posted in SPRS prior to awarding a subcontract or other contractual instruments. The clause also provides additional information on how a subcontractor can conduct and submit an Assessment when one is not posted in SPRS. Flow-down of this clause to applicable subcontracts is also mandated.
If you require a step-by-step guide for access to the SPRS system, please contact the contract specialist listed on the solicitation document.
File details come from the government source that posted it. Updated .