★ ANNUAL REVIEW 2027 SPONSORSHIPS NOW OPEN   Learn more →

Log In  |  Become a Member  |  Sponsor  |  ⌕ Search

News/Cyber & Privacy/Parsing the Meaning of Performance Risk Scores
Free SampleYou’re reading a free sample of the Cyber & Privacy Brief. Members get every case digest like this, six days a week.See Membership Options
Expert Opinion·Cyber & Privacy Brief

Parsing the Meaning of Performance Risk Scores

Under a new interim rule, Defense Department contractors must have a current assessment on file of their compliance with the security controls in NIST SP 800-171, to be considered for an award. The department has recently taken two little-noticed actions that may provide some insight into how it plans to use these assessment scores.

  • First, DoD added to a FAQ list a note that such scores were intended to be used to support “basic,” “medium,” and “high” assessments and to provide “an objective assessment of a contractor’s NIST 800-171 implementation status.” The department also clarified that there will not be a score threshold for “passing.”
  • A proposed rule makes these summary scores a required evaluation factor for all solicitations for supplies and services, including those for commercial items, and amends DFARS by requiring contracting officers to use them as a factor in determining responsibility to “reduce supply chain risk.”
Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.