The NIST SP 800-171 DoD Assessment Methodology starts every organization at 110, one point of potential for each requirement, then subtracts a weighted deduction for every requirement not fully implemented. Deductions are 5 points for requirements whose absence exposes the network broadly (multifactor authentication, FIPS-validated cryptography, and similar), 3 points for requirements with specific and confined impact, and 1 point for the remainder. Miss everything and the floor is minus 203.
Exactly two requirements allow a reduced deduction. 3.5.3, multifactor authentication: 5 points if you have no MFA, but only 3 if MFA covers remote access and privileged accounts while general users still lack it. 3.13.11, FIPS-validated cryptography: 5 points if CUI is not encrypted at all, 3 if it is encrypted but the cryptography is not FIPS-validated. Every other requirement is all or nothing.
Requirement 3.12.4, the System Security Plan, carries no point value for a reason: without an SSP, the assessment cannot be conducted at all. No document, no score, no defensible SPRS entry.
Your score, its assessment date, and the scope it covers are submitted to SPRS, where contracting officers and primes can see it, and a senior official affirms it. An affirmed score that does not survive scrutiny is not just embarrassing: accuracy is enforceable, and False Claims Act cases in this space are no longer hypothetical. The score is also self-reported at the "basic" confidence level, which is exactly why primes increasingly ask what sits behind a suspiciously round 110.
Practical advice: score yourself honestly at the objective level, document the evidence behind every "met," and let the number be what it is while the plan of action closes the gap. A defensible 88 beats an indefensible 110 every time.
A short conversation usually settles it. No pitch, just answers.
Talk to CyberDeka