---
title: "Defense Contractors: NIST 800-171 Evidence"
description: "Evidence behind the SPRS score you affirm: 110 NIST 800-171 requirements as hash-chained records in your tenant. Optional 30-day engagement, $15K flat."
url: https://policycortex.com/solutions/defense-contractors
sealed: 2026-09-02
amended: 2026-09-02
register: solutions/defense-contractors
records: 6
digest: sha3:fd4cfb584e736a99237c5eb6051fb053733897991752db10935f372421cd4c03
---

# The evidence behind the SPRS score you affirm.

DFARS 252.204-7012 / 7019 / 7020 / NIST SP 800-171 Rev. 2

CMMC Phase II is suspended, but Phase I self-assessments and DFARS 252.204-7012 safeguards remain, and the SPRS score you affirm is a claim about your environment. PolicyCortex records that environment against the 110 NIST 800-171 Rev. 2 requirements, hash chained inside your tenant, so the score rests on rows an assessor can recompute. A fixed-fee 30-day engagement is optional.

[Request verification](https://policycortex.com/contact) · [Book a call](https://policycortex.com/book)

Read only. Fourteen days. No sales call required.

## What a defense contractor must prove

Every prime and subcontractor handling covered defense information affirms a SPRS score under DFARS 252.204-7019, safeguards CUI under 7012, and can be assessed by the government under 7020. The Department suspended the CMMC Phase II transition on July 13, 2026 for a 60-day reform review and named NIST SP 800-171 Rev. 2 as the interim baseline; Phase I self-assessments remain in place. None of that pauses the obligation behind the score: for each of the 110 requirements, the state that satisfies it, the record of what changed it, and proof the package is the one that was assessed.

A score is a projection. If the rows behind it cannot be produced as of the date you affirmed it, the score is a memory.

- **dib.baseline**: NIST SP 800-171 Rev. 2, 110 requirements, 14 families. The interim CMMC baseline named by the Department.
- **dib.policy**: CMMC Phase II suspended 2026-07-13; Phase I self-assessments and DFARS 7012 safeguards remain active.
- **dib.boundary**: The CUI enclave is a declared scope on every record. Azure Government, AWS GovCloud, and GCC High are observed clouds; commercial cloud where CUI is out of scope.
- **dib.assessor**: Your C3PAO remains independent and controls the assessment package and eMASS submission. The output is C3PAO-agnostic.
- **dib.source**: Department of War release, July 13, 2026 (official release); the site's explainer: what changed and what to do.
- **dib.handoff**: The eMASS and C3PAO handoff package: what the assessor receives and how they verify it by hash.

## The evidence behind the score

One evidence base for the 110 requirements, handed to the assessor as generated evidence with the raw payload attached. Where each proof files:

- **AC · IA · SC**: Proof of state: access control, identification, and system protection settings as point-in-time records, content hashed, regenerable to the date the assessor names.
- **CM · AU**: Proof of change: who or what altered a CUI-scope resource, under what authority, with before and after hashes and a rollback identifier.
- **Machine actions**: Proof of agency: what any autonomous action was permitted to do before it ran, what it did, and what would have stopped it. Every remediation handler ships matched captureState and restoreState pairs; the runtime refuses actions without a defined rollback path.
- **SSP · POA&M · OSCAL**: Generated from the one implementation record and exported as OSCAL 1.1.2 with an eMASS and C3PAO handoff package.
- **SPRS**: SPRS-relevant evidence carried per requirement, so the score you affirm is a projection of rows, not a spreadsheet estimate.

![The PolicyCortex evidence package export: complete evidence inventory, validation results, POA&M, SSP, and SAR in ZIP, OSCAL, and eMASS shapes](https://policycortex.com/images/pcx-evidence-package-export-1600.webp)

Exhibit SB-5 · the assessor-ready package: inventory, validations, POA&M, SSP, SAR in ZIP, OSCAL, and eMASS shapes. Illustrative demo data; the interface is real.

## How an assessor verifies the score

For a SPRS score the recomputation proves the number is a projection: an assessor recomputes the rows behind each of the 110 requirements as of the date you affirmed it, and a score with no rows behind it cannot be recomputed at all.

Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.

A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.

**Stated limit.** PolicyCortex is not an assessor and does not certify anything. It produces the records a compliance decision rests on; the assessor, the authorizing official, or the accountable official makes the determination. What is not connected is not observed, and the record says so. Control identifiers cite NIST SP 800-53 Rev 5, NIST SP 800-171 Rev 2, PCI DSS 4.0, SOC 2 TSC, ISO/IEC 27001:2022 and 45 CFR 164 as published.

## How you evaluate it before affirming a score

The fourteen days run inside Azure Government, AWS GovCloud, or GCC High with the CUI enclave declared on every record, so the rows a score would be projected from exist before you next affirm one.

Connect read only for fourteen days, in SHADOW mode, inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. At the end of the fourteen days you hold the records and can recompute the chain yourself.

- **eval.mode**: SHADOW. Watch only; nothing executes.
- **eval.duration**: Fourteen days.
- **eval.location**: Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
- **eval.egress**: None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
- **eval.after**: You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.
- **eval.assessment**: Start with the self-serve CMMC Level 2 assessment: read only, fourteen days, inside your own tenant, no egress.

## The offer: a defensible SPRS baseline in 30 days, $15,000 flat

If you want the baseline stood up for you, the engagement is 30 days at $15,000 flat: connect one primary cloud environment (Azure Government, AWS GovCloud, or GCC High), validate the 110-requirement Rev. 2 baseline, coordinate approved technical remediation of cloud gaps, and walk away with the evidence behind your SPRS score as an SSP, POA&M, and OSCAL bundle your C3PAO can review, select from, and use for eMASS submission. The cleared founder runs the engagement. No hourly, no overages.

The independent assessor makes the certification decision. The engagement does not guarantee certification; it produces a package built to be verified.

- **offer.price**: $15,000 flat. No hourly, no overages, no surprises.
- **offer.duration**: 30 days from cloud connection to the evidence package.
- **offer.scope**: One primary cloud environment: Azure Government, AWS GovCloud, or GCC High. Multi-cloud or multi-tenant scope is priced separately.
- **offer.package**: SSP, POA&M, OSCAL 1.1.2 bundle, and the hashed evidence behind them, organized by control objective.
- **offer.review**: Support through assessor review for in-scope follow-up, at no additional cost.
- **offer.limit**: No certification guarantee. Your C3PAO remains independent.
- **offer.people**: Founder runs every engagement personally. DoD Secret and DoE Q clearances, both active. Four U.S. patent applications filed.

[Every term of the engagement, on its own page.](https://policycortex.com/engagement)

## Questions assessors and buyers ask

**Q: Did the Department of War cancel CMMC?**
A: No. It suspended the Phase II transition and future implementation milestones on July 13, 2026, while a reform task force conducts a 60-day review. Phase I self-assessment requirements remain in place.

**Q: Is GovCloud required for CMMC Level 2?**
A: Not strictly. Azure Government, AWS GovCloud, and GCC High are observed clouds, and commercial cloud is supported when CUI is out of scope. The boundary is declared on every record either way.

**Q: How long until we are assessment ready?**
A: The engagement is 30 days from cloud connection to the evidence package, $15,000 flat, no hourly, no overages. Assessment readiness is the assessor's judgment; the package is built so that judgment rests on rows they can recompute.

**Q: What if a remediation breaks production?**
A: Every action ships matched captureState and restoreState pairs. A hashed-delta mismatch after execution triggers automatic rollback, and the runtime refuses actions without a defined rollback path. The rollback is itself a row in proof of change.

**Q: Can we stay in advisory mode?**
A: Yes. SHADOW mode watches and executes nothing; the fourteen-day evaluation runs in it. GATED is the default beyond that: a named human approves each action and becomes part of its record. AUTONOMOUS is reserved for narrow, well-tested action classes, with every gate still run on every act.

**Q: Does PolicyCortex make us compliant?**
A: No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.

Affirm a score you can hand over as rows. [Request verification](https://policycortex.com/contact) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | OBLIGATION | 4a408aa56ed0 | 4bcec9f7238f |
| REC 0001 | EVIDENCE | 78266ff9d19f | 4a408aa56ed0 |
| REC 0002 | VERIFICATION | 7ab84e542fdb | 78266ff9d19f |
| REC 0003 | EVALUATION | a5e5694a1f79 | 7ab84e542fdb |
| REC 0004 | DELIVERY | 5a9812e1fb4d | a5e5694a1f79 |
| REC 0005 | QUESTIONS | fd4cfb584e73 | 5a9812e1fb4d |

Head sha3:fd4cfb584e736a99237c5eb6051fb053733897991752db10935f372421cd4c03. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
