Sample deliverable

What an 800-171 gap assessment actually hands you.

Below is the structure of a NIST SP 800-171 gap assessment report, written for an illustrative defense contractor. It is not a client report and contains no client data — it exists so you can see the depth and tone of the deliverable before engaging, rather than after.

Report structure

Six sections, in this order.

1 · CUI boundary and scope

Where CUI enters, rests and leaves, drawn as an actual data flow rather than a network diagram. Every system is listed in-boundary or out, with the reasoning recorded — because an assessor reads the reasoning, not just the conclusion.

2 · Scoring by control family

All 14 families scored across the 110 practices, showing met, partially met, and not met. Partial is reported as partial rather than rounded in either direction; a practice half implemented is the most expensive kind to discover late.

3 · Findings with evidence

Each finding names the artifact that is missing or insufficient — the log, the ticket, the configuration export, the signed record — rather than restating the control text back at you. A finding you cannot act on is a sentence, not a finding.

4 · POA&M eligibility

Gaps separated into must-fix-before-assessment and POA&M-eligible, with the conditions and closeout clock stated for the latter. Not everything inconvenient is deferrable, and that is better learned here.

5 · SPRS score

The calculated score with the arithmetic shown — which practices cost which points, and what closing each gap would move it to. A score you cannot reconstruct is a number you cannot defend.

6 · Remediation roadmap

Ordered by what unblocks the most, not by control number. Boundary decisions first because they change what must be implemented at all, then implementation, then documentation, with evidence accumulating throughout.

What the sample deliberately shows

  • Partial scores, not flattering ones. The illustrative contractor does not pass; a sample where everything is met would demonstrate nothing.
  • Findings that name artifacts. "Quarterly access reviews are documented in policy but no review record exists for the last three quarters" — actionable, and checkable.
  • A scope section that excludes things. Exclusions with reasoning are the most valuable page in the report.
  • The honest sequencing. Implementation takes longer than documentation, and the roadmap says so.

What it is not

  • Not a certification, and not a substitute for a C3PAO assessment.
  • Not a client engagement — the organization in it does not exist.
  • Not a template you fill in. The value is in the boundary reasoning and the evidence review, neither of which generalizes.

C3PAO assessment preparation → · Sample SOC 2 gap assessment →

Want this run against your environment?

Tell us where CUI lives and what you have documented. You will get back a written view of your scope, the gaps that matter first, and a fixed fee before any work begins.