The NIST SP 800-171 DoD Basic Assessment often gets buried inside broader CMMC planning, but DFARS treats it as its own contracting requirement. For covered systems subject to DFARS 252.204-7012, DFARS 204.7302 says a current Basic Assessment is required at time of award, and 'current' normally means not more than three years old unless the solicitation sets a shorter period.
The three-year rule is therefore a bid-readiness date, not a filing-cabinet detail. A contractor should know which system the score describes, when the assessment was completed, what NIST revision was used, and whether that record still matches the environment being offered for contract performance.
What the three-year rule actually says
DFARS 204.7302 ties the Basic Assessment requirement to contractors that must implement NIST SP 800-171 under 252.204-7012. At award, the assessment must be current. The rule defines that as no more than three years old unless the solicitation specifies a shorter time. A procurement can therefore create a tighter window, so a blanket 'our score is good for three years' statement is incomplete.
Record the assessment completion date and the solicitation-specific validity requirement in the proposal file. If the procurement requires a shorter period, use that date for the readiness decision. Do not rely on the age displayed in an old internal spreadsheet without checking the current SPRS record and the actual solicitation language.
The score belongs to a system boundary
The Basic Assessment submission includes information about the system security plan and associated CAGE codes. That structure matters. A score is not a general cybersecurity grade for the legal entity; it represents an assessed implementation for a defined environment. If the company has several SSPs, proposal staff should know which score corresponds to the system that will perform the work.
Compare the current architecture with the architecture described when the score was calculated. A cloud migration, identity-provider change, acquisition, new enclave, or major remote-work redesign can make an unexpired score a poor description of the current system. Formal expiration is not the only reason to revisit the assessment.
SPRS is the government-facing record
DFARS procedures use SPRS so contracting officials can see summary-level assessment information. An internal score sheet is useful evidence, but it does not replace the government record when the procurement requires a current assessment posted in SPRS. Before award, verify that the expected record is present and that key fields match your current documentation.
Keep the supporting score calculation, SSP, POA&M information where relevant, submission record, and system description together. That package lets the security team explain how the score was produced if a question arises, while the proposal team can still work from a concise readiness register rather than opening the full technical assessment.
Do not confuse Basic Assessment currency with CMMC status
Both mechanisms can involve the same NIST SP 800-171 environment, which is why teams often assume one replaces the other. Current DFARS language treats them as related but distinct. A procurement can require CMMC information and a current NIST SP 800-171 DoD Assessment through separate clauses or provisions. Check both sets of requirements rather than collapsing them into one 'cyber score.'
This distinction should appear in your compliance register. Use separate rows for the Basic Assessment date and score, CMMC status and UID, annual affirmation, and any conditional closeout. The extra columns prevent a proposal manager from seeing one green date and assuming every cybersecurity prerequisite is current.
Reassess before the calendar forces you
Set reminders six to nine months before normal expiration, then again at a shorter interval appropriate to your bidding cycle. The early reminder gives the team time to update the SSP, resolve score-impacting gaps, validate architecture changes, and correct SPRS data without a proposal deadline dictating the schedule.
Also define event-based triggers. An acquisition, divestiture, major cloud move, replacement of the identity platform, new managed service, or significant boundary change should prompt an assessment review. You may conclude that the existing score still represents the system, but that conclusion should be deliberate and documented.
A five-minute pre-award check
Before final proposal release, confirm five items: the solicitation's assessment-age rule, the system that will perform the work, the date of the relevant Basic Assessment, the current SPRS entry, and whether material changes occurred after the assessment. If any item is unclear, stop treating the score as a simple administrative checkbox and resolve the mapping.
Keep a dated note of the verification and the name of the person who performed it. This small record is useful when options, extensions, or later task orders raise the same question. It also turns assessment currency into an ordinary contract-management control rather than a once-every-three-years scramble.
Suppose a contractor's Basic Assessment was completed on October 15, 2024. A simple three-year reminder on October 15, 2027 is too late for a company that routinely bids work six months before award. Set a planning milestone in early 2027, then compare the likely award dates of active opportunities with the assessment's formal currency window and any shorter solicitation requirement.
During that planning review, compare the 2024 boundary to today's system. If the company moved its CUI workload to a new tenant in 2026, the old score may no longer be a faithful operational record even though the calendar has not expired. That is a reason to re-examine the assessment before procurement pressure makes the decision for you.
Keep score recalculation separate from score improvement claims. If the environment changed, document how the score was recomputed and why. Do not simply replace a number in an internal spreadsheet because remediation tickets were marked complete. The supporting assessment logic should be reproducible.
When a new score is ready, verify the government record and then update every dependent internal register. Proposal templates, contract-readiness sheets, and leadership dashboards should not retain the old date after SPRS has changed. One controlled source of internal truth prevents inconsistent bid responses.
A three-year interval is a maximum currency window, not a recommendation to ignore the score until the final week. Tie the assessment register to architecture and contracting events as well as to the calendar. A merger, major cloud migration, new enclave, or materially different system used for an offer may justify an earlier review even when the date has not expired. The useful question is whether the posted score still describes the covered contractor information system relevant to the award.
A short working check
- ✓Find the existing SPRS Basic assessment record
- ✓Confirm its assessment date
- ✓Check the solicitation for a shorter validity period
- ✓Compare the scored boundary to today's environment
- ✓Plan reassessment before expiration
Common questions
How long is a Basic assessment normally current?
DFARS 204.7302 states not more than three years old unless the solicitation specifies a shorter period.
Does a CMMC Level 2 self-assessment replace the NIST SP 800-171 DoD Basic Assessment record?
Do not assume so. They are separate contracting mechanisms with separate DFARS provisions, records, and currency checks. Read the clauses in the solicitation and verify the specific SPRS record each requirement expects.
Can a solicitation require a shorter currency period?
Yes. DFARS uses the three-year window unless a lesser time is specified in the solicitation, so the solicitation must be checked.
Official sources used for this guide
Open the primary source before making a contract-specific decision. Regulations and program implementation can change.

