Why NIST 800-171 Still Applies & How Teal Can Help

NIST 800 171

NIST 800-171 compliance hasn’t gone anywhere despite the September 3 class deviation memo that pulled CMMC requirements out of active defense contracts. While you might not be bound by an assessment, right now, you still owe the Department of War data protection. In this article, I’ll quickly cover the changes we’ve seen over the past couple of months and how managed IT services from an experienced provider can help you move forward.

Key Takeaways

  • A September 3 class deviation memo pulled CMMC third-party assessment requirements out of active contract awards.
  • While contracting officers can no longer require third-party CMMC verification, the underlying security controls and reporting obligations remain fully enforceable.
  • Managed IT services that treat NIST 800-171 compliance as ongoing work, not a one-time project, keep your self-assessed score defensible if/when the government asks you to prove it.

Table of Contents

What the September 3 Class Deviation Memo Changes

The memo, tracked under DARS number 2026-O0025 Revision 3, orders contracting officers to strip CMMC third-party assessment clauses out of active solicitations and existing contract awards.

It does not touch your underlying obligation to implement the 110 security requirements in NIST Special Publication 800-171. It also doesn’t change your duty to report that compliance honestly through the Supplier Performance Risk System.

Why Your NIST 800-171 Obligations Did Not Pause

Self-assessment against NIST 800-171 never went away. The class deviation changes who verifies your score. It does not impact whether you have to:

  • Score yourself honestly
  • Submit that score to SPRS
  • Hold your subcontractors to the same standard

Nobody knows what the CMMC reform will look like once the DoW CIO’s recommendations go public. But the deadline for the Task Force’s review came to an end on September 11. So now, we just have to wait for the results of the review from Kirsten Davies, DoW Chief Information Officer.

managed it

Why Leveraging Managed IT Services for NIST 800-171 Compliance Matters

Managed IT services matter significantly here because the Department of Justice is already treating an inflated NIST 800-171 self-assessment as a false claim under the False Claims Act (which is the federal law that lets the government recover money from contractors who knowingly submit false information to get paid).

In June 2026, Logzone Inc., a Huntsville, Alabama contractor, agreed to pay $507,144 to resolve False Claims Act allegations after the Defense Industrial Base Cybersecurity Assessment Center found the company had not implemented required NIST 800-171 controls on two Navy contracts.

And that is a significant penalty for a company that size.

The company submitted a nearly perfect score on its self-assessment. The government’s own assessment gave Logzone a score of negative 170 – on a scale that runs from negative 203 to positive 110 – nowhere near what the company had reported.

When you hire a managed IT service provider that has experience with compliance requirements like CMMC, a contractor won’t lose track of which controls it has in place. Because their provider will track, remediate, and document them all year. So the SPRS score you self-report reflects the environment the government would actually find if it came to look.

How Teal CMMC Supports Ongoing NIST 800-171 Compliance

We treat NIST 800-171 compliance as an ongoing piece of our managed IT services, not as a stand-alone consulting project.

That distinction carries more weight now that third-party assessments are off the table (for now, at least) and your self-assessments carry the full weight of your risk.

Because we’ve seen a pattern of contractors reporting an inflated SPRS score. For example, we had one tell us their SPRS score was around 80. When we actually got in there to take a look at their setup, they were nowhere close. They were in their mid-40s.

If you’re looking to reduce your risk when it comes to your NIST 800-171 obligations, our CMMC managed services will help you sleep at night. Not only are we experienced with NIST, but we are CMMC Level 2 certified and got 110/110.

Here’s how our CMMC managed services help you reduce risk so you can focus on keeping your contracts and earning new business.

Teal CMMC Level 2 Badge issued from KLCC in 2026

NIST 800-171 Gap Analysis & Consulting Projects

Many contractors want to start with a NIST 800-171 gap analysis or consulting project. We will tell you exactly where you stand against the 110 required controls, giving you a plan of action instead of a binder that you’re left to execute alone.

vCISO Support Services

We also offer ongoing vCISO services (which is a virtual chief information security officer who works with your team for a set number of hours). This ongoing cybersecurity leadership keeps your plan current as your contracts, your CUI scope, and the department’s own requirements shift.

Fully Managed IT Services

And, of course, our fully managed IT services do the actual day-to-day work behind the controls in your business, including: asset tracking, access management, dedicated cybersecurity monitoring, and Microsoft 365 environment management.

So, the score you report to SPRS is one your infrastructure can actually back up. Check out the full scope of that work on our CMMC managed services page.

Gar Whaley is a cofounder and Chief Revenue Officer of Teal, and has over 30 years of experience in the technology sector. He is an expert in cybersecurity, IT governance, and risk management, holding certifications including CISSP, CISM, CGEIT, CISA, and CMMC RP. He combines deep technical knowledge with a client-centric approach to guide businesses toward scalable, secure, and compliant IT practices.

Recent Articles

The Insider's Edge

The right IT strategies can transform your business. Subscribe now to access curated strategies, trends, and solutions for forward-thinking executives like you.

Categories
Don’t Stop Here

More To Explore