Skip to content
A Free Guide for Defense Contractors

What a Defensible NIST 800-171 Package Looks Like


For defense contractors who filed a SPRS score and want documentation that holds up when a prime or contracting officer asks. By Josef Kamara, CPA, CISSP, CISA.

Free Download

Get the 15-page guide

Sent to your inbox immediately. The complete documentation behind a defensible SPRS score.

Joins the AmerifusionGovCon updates list. Unsubscribe in one click.

Check your inbox.

The guide is on its way. If it does not arrive in 5 minutes, download it directly below.

Download the PDF →
Submission failed. Please try again or email amerifusionconsultants@gmail.com.
Written by

Josef Kamara, CPA, CISSP, CISA. 15+ years in audit and risk across KPMG, BDO, and Stryker. At BDO, led both the third-party attestation practice and the information assurance team. At Stryker, managed the IT audit function. Founder of AmerifusionGovCon, the federal contracting readiness practice.

What's Inside

What you will learn


01

The three documents required behind a defensible SPRS score

System Security Plan, dated DoD Assessment, and Plan of Action and Milestones. What each one contains and how they connect.

02

DFARS 252.204-7012 and 7020 documentation requirements

Including the post-CMMC-Phase-1 environment of November 2025 and the DCISE incident reporting transition that replaced DIBNet in June 2025.

03

SSP structure and content requirements

The seven elements every defensible System Security Plan describes: system boundary, environment, CUI marking, roles, control implementation, external connections, review cadence.

04

How to score each of the 110 NIST 800-171 practices

The DoD Assessment Methodology v1.2.1: starting score of +110, deductions of 1, 3, or 5 points, range of -203 to +110. What "Implemented" actually requires.

05

POA&M format with realistic remediation timelines

Defensible windows for the most common gap types, from policy gaps (30-60 days) to enclave migrations (12-24 months), with the math an assessor uses to read them.

06

Common failures when supporting documentation is requested

The three-step request pattern primes and contracting officers run, the controls that get sampled most often, and the SSP defects that turn a high score into a paused contract.

07

Two anonymized case studies

A high score that did not survive a prime's documentation request, and a low score that held under a DCMA DIBCAC Medium Assessment. The structural difference between them, and why a credible package is more defensible than an inflated one.

Why This Matters

The gap a SPRS score does not close


A SPRS score is a number. A defensible 800-171 package is the evidence that the number is real. Most contractors treat them as the same thing. Primes, contracting officers, and DCMA DIBCAC do not. They read the package, and they read it for consistency between what the SSP describes, what the assessment recorded, and what the POA&M is committing to fix.

When a prime asks for the supporting documentation behind a posted score and the contractor cannot produce a current SSP, a workbook with assessor names and dates, and a POA&M that traces to the closeout date in SPRS, the score stops being a credential. It becomes a question. That question, answered well on the first request, preserves the award. Answered badly, it pauses subcontract performance, escalates to the contracting officer, and shows up in the next solicitation cycle as elevated scrutiny. Defensibility is a one-time build that pays out every audit, every renewal, every flow-down request. This guide is what that build looks like.

Get the Guide

Send it to your inbox.

Joins the AmerifusionGovCon updates list. Unsubscribe in one click.

Check your inbox.

The guide is on its way. Direct download below if needed.

Download the PDF →
Submission failed. Please try again or email amerifusionconsultants@gmail.com.