SPRS NIST SP 800-171 WORKFLOW.pdf

PDF 97 KB Posted

Attached to
Explosive Atmosphere Testing and Test Report Federal contract opportunity
Solicitation number
FA822224QB011
Issued by
Department of the Air Force Materiel Command Air Force Sustainment Center

About this file

This is a workflow document outlining the step-by-step process for contractors to complete and submit their NIST SP 800-171 cybersecurity assessment in the Supplier Performance Risk System (SPRS). The document details five key steps: obtaining SPRS access through PIEE registration, developing an IT System Security Plan (SSP), performing the NIST assessment, completing a Plan of Action if scoring below 110, and entering assessment details into SPRS.

The document also includes regulatory directives regarding DFARS provisions 252.204-7019 and 252.204-7020, which establish enforcement methodologies for NIST SP 800-171 compliance. Key requirements include maintaining a current assessment (not older than three years) in SPRS to be considered for contract awards, providing government access for higher-level assessments, and ensuring subcontractors have current assessments posted in SPRS. The provisions apply to all solicitations and contracts except those solely for COTS items, with mandatory flow-down to applicable subcontracts. Contact information for various help desks and relevant template links are provided throughout the document.

View the file

Other files for this federal contract opportunity

Other files attached to Explosive Atmosphere Testing and Test Report, newest first.
File Type Posted
Equipment List.xlsx XLSX spreadsheet
Statement of Work.docx DOCX document
FA822225QB004_Provisions and Clauses.pdf PDF
Combo Synopsis Solicitation_12.16.2024.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SPRS NIST SP 800-171 Workflow

Step 1. Obtain Access to SPRS; Register in PIEE and activate a “SPRS Cyber Vendor User” role:

Once your company registers with PIEE, your company will need to establish a Contractor Administrator (CAM). The CAM acts as your companies User Role approver. Your CAM will approve your request for a “SPRS Cyber Vendor User” role.

If there is only one CAM, and this person is applying for a SPRS User role, they must request User role activation from PIEE help desk.

PIEE HELPDESK

Email: disa.global.servicedesk.mbx.eb-ticket-requests@mail.mil

Phone: 1-866-618-5988

Step 2. In order to perform the NIST Assessment, your company needs to have an internal IT System Security Plan (SSP) in place. Hopefully, your IT department has already written one of these.

If not;

System Security Plan (SSP) Guide & Template: https://csrc.nist.gov/publications/detail/sp/800- 171/rev-2/final

The template is found on the right hand side under documentation. Titled CUI SSP Template.

Step 3. Once the SSP is in place, you are ready to ‘perform’ the NIST Assessment.

NIST SP 800-171

Methodology: https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171- Assessment-Methodology-Version-1.2.1-6.24.2020.pdf (scoring template begins on page 12)

For assistance with conducting your NIST SP 800-171 assessment, assessment interpretation, definitions, deadlines, regulations, requirements, scope, etc.; you will need to contact the DCMA Help Desk at: DCMA_7012_Assessment_Inquiry@mail.mil.

Step 4 If your score is less than 110 you will need to complete a Plan of Action

Plan of Action Template: https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final

The template is found on the right hand side under documentation.

Step 5. Entering score and other assessment details -- Walkthrough Guide:

NIST SP 800-171 Quick Entry Guide: https://www.sprs.csd.disa.mil/pdf/NISTSP800- 171QuickEntryGuide.pdf https://piee.eb.mil/piee-landing/ https://piee.eb.mil/piee-landing/ mailto:disa.global.servicedesk.mbx.eb-ticket-requests@mail.mil https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf mailto:DCMA_7012_Assessment_Inquiry@mail.mil https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final https://www.sprs.csd.disa.mil/pdf/NISTSP800-171QuickEntryGuide.pdf https://www.sprs.csd.disa.mil/pdf/NISTSP800-171QuickEntryGuide.pdf

Regulatory directives:

The new DFARS provision 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements, and new DFARS clause 252.204-7020, NIST SP 800-171 DoD Assessment Requirements, add additional cybersecurity measures to those already required under DFARS 252.204-7012 by establishing enforcement methodologies for ensuring contractors have implemented the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 DoD Assessment Methodology.

Contracting Officers are directed to include DFARS 252.204-7019 and 252.204-7020 in all solicitations and contracts including solicitations using FAR part 12 procedures for the acquisition of commercial items, except for solicitations solely for the acquisition of COTS items.

DFARS provision 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements, advises offerors required to implement the NIST SP 800-171 to have a current (not older than three years) NIST SP 800-171 DoD Assessment on record in order to be considered for award. The provision requires offerors to ensure the results of any applicable current Assessments are posted in Supplier Performance Risk System (SPRS) and provides offerors with additional information on conducting and submitting an Assessment when a current one is not posted in SPRS.

The new DFARS clause 252.204-7020, NIST SP 800-171 DoD Assessment Requirements, requires a contractor to provide the Government with access to its facilities, systems, and personnel when it is necessary for DoD to conduct or renew a higher-level (“MEDIUM “or “HIGH”) assessment. The clause also requires the contractor to ensure that applicable subcontractors have the results of a current Assessment posted in SPRS prior to awarding a subcontract or other contractual instruments. The clause also provides additional information on how a subcontractor can conduct and submit an Assessment when one is not posted in SPRS. Flow-down of this clause to applicable subcontracts is also mandated.

If you require a step-by-step guide for access to the SPRS system, please contact the contract specialist listed on the solicitation document.

File details come from the government source that posted it. Updated .