Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
GOVERNMENT ASSESSMENT

DFARS 252.204-7020 Medium and High Assessments: What Contractors Must Be Ready to Show

A practical guide to DFARS 252.204-7020 Medium and High NIST SP 800-171 DoD Assessments, contractor access duties, rebuttal timing, SPRS records, and subcontract implications.

A Basic NIST SP 800-171 DoD Assessment is a contractor self-assessment. A Medium or High Assessment is different: government personnel review the contractor's implementation with progressively more verification. DFARS 252.204-7020 is the clause that gives the Government access to facilities, systems, and personnel when a Medium or High Assessment is necessary. For a small defense contractor, that means readiness cannot stop at having a number in SPRS.

A Medium or High Assessment is not a second self-assessment with a different name. DFARS 252.204-7020 gives Government personnel access to the facilities, systems, and personnel needed for the review, and the clause defines a High Assessment as including verification, examination, and demonstration of the SSP implementation. Preparation therefore has to connect what the SSP says to what the environment can actually show.

Start with the three assessment levels in the clause

DFARS 252.204-7020 defines Basic, Medium, and High assessments rather than treating every NIST SP 800-171 review as the same event. The Basic Assessment is based on the contractor's review of the SSP and the DoD Assessment Methodology, and the clause describes its confidence level as Low because the score is self-generated. Medium and High assessments are conducted by Government personnel and increase the amount of independent examination.

For planning, translate those labels into evidence expectations. Basic readiness asks whether the organization can accurately score the requirements and support the score internally. Medium readiness adds the need to present documents coherently and answer questions from reviewers. High readiness adds the need to show the system operating as the SSP says it operates. The evidence repository should therefore be built for traceability, not merely for submission of a summary score.

Know exactly what access the clause can require

Paragraph (c) requires the contractor to provide access to facilities, systems, and personnel necessary for the Government to conduct a Medium or High Assessment if one is necessary. That does not mean an assessment team should receive unrestricted access to unrelated corporate systems. It means the contractor needs a controlled way to provide the access reasonably necessary to evaluate the covered contractor information system and the security requirements being assessed.

Prepare an assessment access plan before anyone asks for one. Identify the facility contact, system owner, security lead, identity administrator, endpoint or network administrator, and contract representative who can support the review. Decide how demonstrations will be performed, how screenshots or exports containing sensitive security information will be handled, and how an assessor will be shown configuration without exposing credentials or unrelated customer data.

Prepare named escorts and system owners in advance. The person who knows the enclave architecture may not be the person who can explain contract scope, and the person who administers an identity platform may not know why a compensating workflow exists. A short responsibility map prevents a review from stalling while the company searches for the only employee who can answer a basic implementation question.

  • Facilities relevant to the covered contractor information system
  • Systems and configurations needed to validate implementation
  • Personnel who can explain the SSP, operation, and evidence
  • Documents that support the Basic Assessment and claimed score

Build evidence around the SSP, not around screenshots

The clause's High Assessment definition specifically refers to verification, examination, and demonstration of the contractor's SSP. Treat the SSP as the map that connects a requirement to the actual implementation. For each requirement, the SSP should identify the responsible system component or service, the implementation approach, and enough boundary context that a reviewer can find the control in the real environment.

Then link evidence to that implementation. An access-control statement might point to the identity provider, privileged-role design, and access review process; the evidence index can then point to a current role export, access review record, and a demonstration script. For vulnerability management, the SSP can identify the scanner, coverage, and remediation workflow, while evidence shows recent scans and tickets. This prevents the evidence set from becoming a folder of disconnected screenshots with no explanation of what each item proves.

Avoid evidence that only exists because an assessment is approaching. A screenshot of a policy portal does not prove the control operated during the preceding months. Prefer artifacts produced by normal operations: configuration exports, system-generated logs, tickets, review records, inventories, scan results, and approved change records. A reviewer can then test the control against records that were not staged for the visit.

Prepare for the score discussion before the clock starts

DFARS 252.204-7020 says DoD will provide Medium and High Assessment summary scores to the contractor and allow an opportunity for rebuttal and adjudication before posting the summary score to SPRS. The clause also states that, upon completion of each assessment, the contractor has 14 business days to provide additional information demonstrating that it meets requirements not observed by the assessment team or to rebut findings that may be in question.

That window is much easier to use when evidence ownership is already defined. Keep a finding-response template with the requirement number, assessor observation, contractor position, existing evidence, evidence owner, and approval path. The purpose is not to create a missing control after the assessment. It is to rapidly locate and present information that supports the contractor's position about the implementation that was actually in place.

Treat the 14-business-day period as a rebuttal and clarification window, not as a normal remediation period. If the team failed to present evidence that already existed, organize and submit it quickly. If the control was genuinely not implemented when assessed, a new screenshot created afterward does not rewrite the historical observation.

Separate evidence gaps from implementation gaps

A missing artifact and a missing safeguard are not the same problem. An evidence gap means the control may have been operating but the organization cannot substantiate it cleanly. An implementation gap means the safeguard itself is absent, incomplete, or not operating as described. Labeling the two correctly helps leadership decide whether the response is document retrieval, technical correction, or a challenge to the assessment team's interpretation.

For disputed observations, preserve the exact configuration state, logs, tickets, policy version, SSP language, and responsible-person explanation that existed at the time of assessment. Do not replace a precise factual record with a broad narrative saying the organization has 'always done this.'

Do not miss the subcontract requirements

The subcontract paragraph of DFARS 252.204-7020 is operationally important. The clause requires its substance to be inserted in covered subcontracts and other contractual instruments, except for the stated COTS exclusion. It also says the contractor shall not award a subcontract that is subject to NIST SP 800-171 implementation under DFARS 252.204-7012 unless the subcontractor has completed, within the required currency window, at least a Basic Assessment for the covered systems relevant to the offer.

For a prime contractor, this creates a pre-award supplier check rather than a paperwork exercise after the subcontract is signed. The supplier record should identify which system will receive or process covered defense information, whether the relevant Basic Assessment is current, which CAGE codes and SSP it maps to, and who verified the information. If the supplier plans to use a different system from the one associated with its assessment, the presence of any score in SPRS is not enough.

Keep this check tied to the information flow. A subcontractor receiving no covered defense information may have a different clause analysis from a supplier that will receive CUI and perform engineering work inside its own environment. Contracts and security should make the determination together so the company does not either over-collect security records or miss a real flowdown dependency.

Run a mock review that behaves like a Government review

A useful mock review is narrower than a full consulting exercise. Select a sample of requirements from different families, ask an internal reviewer who did not implement them to follow the SSP, retrieve the evidence, interview the control owner, and observe a demonstration. If the reviewer cannot understand the implementation without the original administrator translating every sentence, the documentation is too dependent on tribal knowledge.

Include boundary tests. Ask which systems are covered by the SSP, how CUI enters and leaves, which external providers support the environment, and how the asset inventory reconciles to the network diagram. A technically strong control can still create assessment trouble when the evidence is tied to an asset or tenant that is not clearly inside the assessed system.

Finish with an access drill: can the team produce the current SSP version, the correct assessment history, the requested configuration, and the named control owner without searching through personal drives? That is the practical standard a small contractor should aim for. Medium and High Assessment readiness is less about creating more documents and more about being able to show, explain, and verify what already exists.

End the mock review with a short exceptions register: claimed requirement, observed evidence, unresolved question, evidence owner, and whether the issue is implementation, documentation, or scope. That register is more useful than a generic readiness score because it points to the exact conversations likely to fail under review.

WORKING CHECKLIST

A short working check

  • Confirm the SSP and Basic Assessment refer to the same system boundary
  • Assign system, security, contracts, and facility points of contact
  • Prepare evidence that can be demonstrated, not only described
  • Separate documentation gaps from implementation gaps
  • Preserve contemporaneous evidence for any disputed observation
  • Know the 14-business-day rebuttal/additional-information window
  • Verify subcontractor cooperation obligations before assessment week

Common questions

What is the main difference between Medium and High Assessments?

A Medium Assessment includes government review of the Basic Assessment, documentation, and discussions. A High Assessment adds verification, examination, and demonstration of the SSP implementation.

How long does a contractor have to provide additional information after a Medium or High Assessment?

The current clause provides 14 business days after completion of the assessment to submit additional information supporting requirements not observed or to rebut findings in question.

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.