A new small-business assessment resource
On September 16, 2026, NIST published Special Publication 1352, a small-business primer for assessing security requirements for Controlled Unclassified Information under NIST SP 800-171A Revision 3. NIST says the guide is intended for owners and employees managing SP 800-171 implementation, self-assessment, or preparation for external assessors.
For Central Florida defense manufacturers, engineering firms, technology providers, and subcontractors, the publication is a timely prompt to organize evidence before treating assessment as a last-minute questionnaire.
Confirm whether CUI is actually in scope
Begin with contracts, flow-down clauses, customer instructions, and systems that create, receive, process, store, or transmit CUI. Do not label every company system in scope without analysis, but do not omit connected services or administrative paths that can affect protected environments. Coordinate scope with the contracting and legal teams.
Map requirements to evidence
For each applicable requirement, identify the implementation owner, system component, policy or procedure, technical configuration, and evidence that shows the control operates. Evidence may include configuration exports, access reviews, training records, tickets, logs, test results, and approved plans. A policy statement alone may not demonstrate implementation.
Separate gaps from explanations
If a requirement is not fully implemented, record the gap, affected assets, interim protection, owner, target date, and dependency. Avoid creating evidence after the fact or describing an intended future state as current. Accurate preparation helps leadership prioritize resources and reduces confusion during assessment.
Prepare people as well as documents
Identify who can explain identity, configuration, incident response, media protection, vendor services, and system boundaries. Rehearse concise answers grounded in evidence. Preserve versions of documents and exports so the assessment record reflects the environment at the relevant time.
Use the primer as orientation, not a certification shortcut
SP 1352 provides a high-level overview; it does not replace contractual direction, SP 800-171, SP 800-171A, or assessor requirements. Use it to build assessment literacy, then obtain qualified guidance for the organization's actual obligations.
Human-reviewed draft; verify contract clauses, current NIST publications, CMMC requirements, and assessor expectations before publication.

