CaptureAgent uses strictly necessary cookies only — encrypted session cookies that keep you signed in. No advertising or cross-site tracking. See our Privacy Policy.

All resources
COMPLIANCE · CYBERSECURITY

CMMC & NIST SP 800-171: levels, POA&Ms, and your SPRS score

If a DoW contract touches Controlled Unclassified Information, CMMC is the gate. Here's the small-business path through it.

The timeline that matters

Since November 10, 2025, applicable new DoW contracts require at least a CMMC Level 2 self-assessment against NIST SP 800-171 Rev 2. Beginning November 10, 2026, third-party (C3PAO) assessments phase in for applicable contracts. Level 1 (FCI only) stays a 17-practice annual self-assessment.

Small-business path, step by step

  1. 1Scope your CUI environment — the smaller the enclave that touches CUI, the cheaper everything gets (many startups use a compliant cloud enclave)
  2. 2Write your System Security Plan (SSP) — control-by-control statement of how you meet the 110 requirements
  3. 3Self-assess with the DoW methodology — score range −203 to +110 Level 2 Assessment Guide (PDF)
  4. 4Post your score in SPRS — required by DFARS 252.204-7019/7020 — primes check it before teaming
  5. 5Open a POA&M for the gaps — only about one-third of controls are POA&M-eligible under 32 CFR 170, and every POA&M item must close within 180 days
  6. 6Prepare for certification — if your contracts will require C3PAO assessment, book early — assessor capacity is tight

Official references

CaptureAgent itself is designed to stay outside your CUI boundary: keep CUI out of the workspace, and it never needs to be in scope.
Put this to work in CaptureAgent

Track opportunities, design capabilities, and draft compliant proposal packages with your own AI keys.

Start Now