On September 16, 2026, NIST published Special Publication 1352, Assessing Security Requirements for Controlled Unclassified Information (CUI): NIST SP 800-171A, Revision 3 Small Business Primer, a plain-language walkthrough of how a CUI security assessment actually works. The primer is aimed squarely at "business leaders or employees who are new to SP 800-171A and who are tasked with managing the implementation of SP 800-171, including conducting self-assessments or preparing to work with external assessors." It is a companion to the SP 800-171r3 implementation primer NIST released in August 2025 — that one covered what to build, this one covers how it gets graded.
The revision question, answered by NIST itself
The most consequential paragraph in the document is an FAQ. NIST states that at the time of publication, "the Department of War's Cybersecurity Maturity Model Certification (CMMC) Program leverages the requirements and assessment procedures in SP 800-171r2 (Revision 2) and SP 800-171Ar2." A second FAQ repeats the point: "CMMC is currently based on SP 800-171, Revision 2. Contractors should check for specific requirements in their contracts to understand which version they are required to use."
That matters because the primer itself is written against Revision 3. A contractor reading it for assessment mechanics is reading Revision 3 procedures while operating, in most DoD contracts, under a Revision 2 obligation. NIST points readers to its published change analysis between the two revisions to decide which fits their current and future needs — but the contract, not the newest publication, sets the requirement. We covered the practical mechanics of that gap in our guide to the SPRS score and DFARS 252.204-7019/-7020.
NIST is also unusually direct about the boundary of its own role: it develops the technical guidelines, but "NIST does not have a role in DOW's implementation of its programs," and it "is not involved in the design, development, or implementation of the CMMC model, accreditation body, or certification process." If you want to know what you owe, read the clause and ask the contracting officer. NIST writes the ruler; the contract decides what gets measured.
What an assessment procedure actually contains
The primer breaks the SP 800-171A structure into three parts that are worth memorizing before any assessor arrives:
Assessment objective — the security requirement decomposed into individual determination statements, each beginning with "A" and the requirement identifier (for example, A.03.01.10.a). Every determination statement within an objective must be satisfied for the requirement to be considered fully implemented. Partial credit is not a concept here.
Assessment methods — examine (reviewing policies, procedures, the system security plan), interview (discussions with personnel), and test (evaluating whether controls behave as expected). Not all three are required for every procedure.
Assessment objects — specifications (plans, policies, architectures), mechanisms (hardware, software, firmware), activities (backups, incident-response exercises, traffic monitoring), and individuals (the people doing the above).
Findings come back as one of two words: satisfied or other than satisfied. NIST notes that "other than satisfied" also covers the case where the assessor could not obtain enough information to make the determination — which means missing evidence is scored the same as a missing control. That is the single most expensive lesson in the document. For what your evidence file should look like, see what your contract requires you to log.
The four-phase process, and the two phases contractors skip
The primer maps assessment to four phases: prepare, develop the assessment plan, conduct the assessment, and document/analyze/report results. Most contractors show up for phase three.
Phase one is scoping. NIST is explicit that the SP 800-171 requirements apply "only to components of nonfederal systems that process, store, or transmit CUI or that provide protection for such components," and that scope can be limited by isolating those components into a separate security domain using subnetworks, firewalls, or other boundary protection — physical separation, logical separation, or both. Scoping is a protection-investment decision, not paperwork. Our CMMC Level 2 scoping and asset categories piece covers how that maps to the DoD asset framework.
Phase two is the assessment plan, and NIST includes a point primes and subs both under-read: review the contracts or agreements governing external systems that create, store, or transmit CUI, because the organization "does not always have direct control over the security requirements used in external systems," and tailor the procedures accordingly. That is a flowdown problem disguised as a planning step — see cybersecurity flowdown obligations.
Phase four turns findings into a Plan of Action and Milestones and, usually, revisions to the system security plan. NIST's framing is that gaps surface when "what is documented in the System Security Plan might not actually be what is happening in practice." That mismatch — plan versus practice — is precisely the theory behind the government's cyber False Claims Act cases collected on our enforcement page.
What this changes, and what it does not
Nothing. SP 1352 is an awareness document, not a requirement. It creates no new obligation, alters no clause, and does not shift any CMMC date. Its value is that it is a free, government-authored explanation of the assessment process written for someone who does not speak cybersecurity — which is most of the small-business defense industrial base. NIST also notes it does not endorse vendors, while pointing to the CyberAB Marketplace as one place to evaluate consultants.
Read against the current moment, the timing is useful. With CMMC Phase 2 suspended pending the Department of War's reform review, the self-assessment path is the one most contractors are on right now — and self-assessment is exactly what this primer is built to prepare you for. Start with Find My Requirements to confirm which obligations your contracts actually carry.
Key Takeaways
- NIST confirmed in writing that CMMC still runs on SP 800-171 Revision 2 and SP 800-171A Revision 2 — the new primer explains Revision 3 procedures, so check your clause before assuming the newest publication governs your contract.
- "Other than satisfied" includes evidence you could not produce. An assessor who cannot verify a control scores it the same as a control you never implemented; every determination statement in an objective must be satisfied for the requirement to count.
- Scoping and external-system contract review happen before the assessment, not during it. Isolating CUI components into a separate security domain limits scope legitimately, and reviewing agreements for external systems that touch CUI is a planning obligation NIST calls out directly.
---
This article is educational information about government contracting and cybersecurity requirements. It is not legal advice and does not create an attorney-client relationship. Contractors should review their specific contract terms and consult counsel on their particular obligations.
Primary source: NIST Special Publication 1352, Assessing Security Requirements for Controlled Unclassified Information (CUI): NIST SP 800-171A, Revision 3 Small Business Primer (September 2026), https://doi.org/10.6028/NIST.SP.1352 — publication page · full text (PDF) · NIST announcement, Sept. 16, 2026