SPRS Score

SPRS SCORE YOUR DOD COMPLIANCE SCORECARD

Your SPRS score is the number the Department of Defense uses to judge whether your company can be trusted with controlled unclassified information. The Supplier Performance Risk System records a self-assessed NIST SP 800-171 score on a scale from -203 to 110, and contracting officers read it before award. Petronella Technology Group, Inc. helps defense contractors calculate an honest sprs score, close the gaps that cost the most points, and keep the number current.

CMMC Registered Practitioner Org|BBB A+ Since 2003|23+ Years Experience
Definition

What Is SPRS? The Supplier Performance Risk System Explained

SPRS stands for the Supplier Performance Risk System. It is the Department of Defense authoritative source for supplier risk data, and it is where every defense contractor that handles covered defense information posts its NIST SP 800-171 self-assessment result. When a contracting officer asks "what is SPRS," the short answer is that it is the government-side database that turns your cybersecurity posture into a single number a buyer can act on.

SPRS predates the cybersecurity requirement. The system was built to consolidate supplier performance data such as delivery history, quality records, and price risk into one place so that source selection teams did not have to chase records across dozens of systems. The NIST SP 800-171 assessment score was added to that existing platform, which is why the supplier performance risk system SPRS module sits alongside quality and delivery indicators rather than in a standalone cybersecurity portal.

The cybersecurity piece became mandatory through DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements. That clause conditions eligibility for award on having a current assessment result posted in SPRS. Its companion, DFARS 252.204-7020, requires the contractor to give the government access to its facilities, systems, and personnel if DoD elects to conduct a higher-confidence assessment, and it requires the same obligation to flow down to subcontractors whose work involves covered defense information.

Both of those clauses attach to the older DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. DFARS 252.204-7012 is the clause that obligates contractors to implement NIST SP 800-171 in the first place and to report cyber incidents to DoD within 72 hours. The chain is straightforward: 7012 creates the security obligation, 7019 makes you score and publish it, and 7020 lets the government verify it.

Who needs a DoD SPRS score

If your contracts or subcontracts include DFARS 252.204-7012, you need a score. That covers prime contractors, subcontractors at any tier, and suppliers who never speak to a contracting officer directly but receive technical data packages, drawings, specifications, or other controlled unclassified information from a prime. Commercial off-the-shelf item suppliers are generally excluded, but the exclusion is narrower than most companies assume. Machine shops, engineering firms, testing labs, software vendors, and logistics providers routinely discover that a single flow-down clause pulled them into scope.

The practical trigger is data, not contract size. A one-person shop that receives a controlled drawing has the same obligation as a large integrator. If you are unsure whether the clause applies to you, read your prime contract flow-downs before assuming you are exempt, and confirm the scope of your covered environment with a CMMC gap assessment.

Where SPRS fits in the DoD compliance stack

Contractors often conflate three separate things: the security requirements themselves, the score that summarizes them, and the certification that verifies them. NIST SP 800-171 is the requirement set. SPRS is the reporting channel. CMMC is the verification regime established by 32 CFR Part 170. You can satisfy the reporting obligation with a self-assessment today and still fail a CMMC assessment later if the self-assessment was optimistic. That gap is the single most common source of contract risk we see in CMMC compliance engagements.

Understanding SPRS

How the SPRS Score Is Calculated

Each of the 110 NIST SP 800-171 requirements carries a weighted point value. Unimplemented requirements subtract from a starting value of 110.

The arithmetic comes from the NIST SP 800-171 DoD Assessment Methodology. You begin at 110, one point for every security requirement in the standard, and subtract the assigned weight of each requirement you have not fully implemented. The weights are not uniform. DoD assigned higher values to requirements whose absence would let an attacker into the environment or let data leave it undetected.

WeightWhat it signalsEffect of not implementing
5 pointsAbsence exposes the network and the data it holds to significant riskSubtract 5 from the score
3 pointsAbsence has a specific and confined effect on network securitySubtract 3 from the score
1 pointAbsence has a limited or indirect effect on network securitySubtract 1 from the score

Because the 5-point and 3-point requirements outnumber a naive one-point-each model, the total available deduction exceeds the starting value of 110. That is why the floor is negative. A company that has implemented nothing scores -203, and a company that has implemented all 110 requirements scores 110. There is no curve, no partial credit for effort, and no adjustment for company size.

The two partial-credit exceptions

The methodology carves out two requirements where a partially implemented control earns partial credit rather than a full deduction.

  • Multifactor authentication (3.5.3). If multifactor authentication is in place for remote and privileged accounts but not for general users on local access, the deduction is 3 points instead of 5. Implement it everywhere in scope and the deduction is zero. See CMMC 3.5.3 for the control detail.
  • Cryptographic protection (3.13.11). If you encrypt controlled unclassified information but the modules are not FIPS-validated, the deduction is 3 points instead of 5. Encryption that is merely "strong" does not satisfy the requirement. See CMMC 3.13.11.

Requirements that must be in place before you score at all

Three requirements function as prerequisites rather than line items. A System Security Plan is required by 3.12.4, and without one there is nothing to assess. Requirements 3.1.1 and 3.1.2, which limit system access to authorized users and to the transactions those users are permitted to execute, are foundational to nearly every other control family. If your access control model is undefined, the assessment result is not a low score, it is an assessment that cannot be completed honestly. Start there. CMMC 3.1.1 is the anchor control for the entire access control family.

Scope determines the score

Before you subtract a single point, you have to define what you are scoring. The assessment applies to the covered contractor information system, meaning the systems that process, store, or transmit covered defense information. Companies that score their entire corporate network usually produce a lower number than necessary, because they have dragged marketing laptops and guest wireless into scope. Companies that score only a narrow enclave without accounting for how data actually moves usually produce a number that will not survive review. Getting the boundary right is the highest-leverage decision in the whole exercise, and it is the first thing our assessors work on with a client.

Interpretation

SPRS Score Range: What Your Number Means

The sprs score range runs from -203 to 110. Here is how a contracting officer reads the number you post.

ScoreWhat it indicatesTypical read by a buyer
110All 110 requirements fully implementedNo open cybersecurity risk on the record
88 to 109Most requirements implemented, a small number of gapsCredible program with defined remaining work
1 to 87Substantial gaps, often in access control and cryptographyRemediation program expected, with dates
0 to -203More weighted requirements missing than implementedElevated risk, and a hard conversation at award time

There is no published passing threshold in DFARS 252.204-7019 itself. The clause requires a current score, not a specific score. In practice the number is used comparatively. When two suppliers are otherwise close, the one with the negative score is explaining itself and the one with the high score is not. Primes increasingly set their own floors for subcontractor flow-down, and those floors are contractual even though they are not regulatory.

A negative score is common and is not by itself a disqualification. Posting a score you cannot defend is the real hazard. Assessment results are subject to DoD review under DFARS 252.204-7020 and to third-party verification at CMMC Level 2, and an inflated self-assessment is a False Claims Act exposure.

Why the 88 threshold keeps coming up

Under the CMMC Program rule at 32 CFR Part 170, an organization can achieve a conditional status with a limited Plan of Action and Milestones if it meets a minimum score of 88 out of 110 and closes the remaining items within 180 days. That threshold applies to CMMC assessments, not to the DFARS 252.204-7019 posting obligation, but it has become the de facto planning target for contractors who intend to pursue Level 2. Certain requirements are never eligible for a Plan of Action and Milestones under that rule, which means a gap in one of them blocks conditional status no matter how high the rest of the score is.

How often the score has to be refreshed

DFARS 252.204-7019 requires a Basic self-assessment that is not more than three years old, unless the contract specifies otherwise. Three years is the outer limit, not the recommended cadence. Environments change faster than that. A cloud migration, a new manufacturing system, an acquisition, or a change of managed service provider can invalidate a score that was accurate when it was posted. We recommend reassessing annually and immediately after any material change to the covered environment.

Submission

How to Submit Your SPRS Score to DoD

Submission runs through PIEE. The mechanics are simple; the preparation is not.

Scores are entered through the Procurement Integrated Enterprise Environment, the DoD single sign-on portal that hosts the SPRS application. The steps below describe the standard path for a Basic self-assessment, which is the level the overwhelming majority of contractors use.

  1. Confirm your registration. Your entity must be registered in the System for Award Management with an active Unique Entity ID and a CAGE code. SPRS records are keyed to the CAGE code hierarchy, so a company with multiple CAGE codes must decide which ones the assessment covers.
  2. Get PIEE access with the right role. Someone at your company holds the Contractor Administrator role in PIEE. That person approves a user for the SPRS Cyber Vendor User role. Without that role the SPRS module will not display the assessment entry screen. Provisioning is the step that most often stalls a submission close to a proposal deadline.
  3. Complete the assessment against your System Security Plan. The score is derived from the System Security Plan, so the plan has to exist and has to describe the environment you actually run. Record the result for each of the 110 requirements as implemented or not implemented.
  4. Enter the assessment record. You submit the assessment date, the assessment scope description, the CAGE codes covered, the score, and the date by which you expect to reach a score of 110. That projected closure date is a commitment, not a formality.
  5. Verify what posted. Pull the record back up after submission and confirm the score, the scope, and the CAGE code list are what you intended. Errors here are common and are visible to every contracting officer who looks you up.

Basic, Medium, and High assessments

The DoD Assessment Methodology defines three confidence levels. A Basic assessment is the contractor self-assessment and carries low confidence. A Medium assessment is conducted by DoD personnel who review the System Security Plan and supporting documentation for consistency. A High assessment adds verification of the implementation itself, including demonstration and inspection of evidence. Medium and High assessments are performed at the government's discretion, and DFARS 252.204-7020 is the clause that obligates you to cooperate with them.

The reason this matters is that a Basic self-assessment is not a private document. It is a representation to the government that can be examined later. Build it as though a Medium assessment is coming, because for a growing number of suppliers it is.

Getting a defensible number before you submit

Most contractors we work with have submitted a score at some point, often produced quickly under deadline pressure by someone without a security background. Re-deriving the number honestly is the first phase of any engagement. Our SPRS calculator gives you a fast estimate, and a formal gap assessment produces the evidence trail behind it.

CMMC

SPRS and CMMC: How the Two Systems Connect

CMMC SPRS reporting is the same channel with a higher evidentiary bar behind it.

The CMMC Program rule at 32 CFR Part 170 establishes three levels. Level 1 covers 15 basic safeguarding requirements drawn from FAR 52.204-21 and is satisfied by annual self-assessment and affirmation. Level 2 covers the 110 requirements of NIST SP 800-171 and is satisfied either by self-assessment or by a certification assessment performed by an authorized C3PAO, depending on what the contract requires. Level 3 adds a further set of requirements drawn from NIST SP 800-172 and is assessed by the government.

SPRS is the system of record for all of it. Level 1 self-assessment results, Level 2 self-assessment results, and Level 2 certification results are recorded in SPRS along with the affirmation from a senior official. That is why cmmc sprs shows up as a search term: for practical purposes the two are the same reporting pipeline. What changes between the DFARS 7019 posting and a CMMC Level 2 certification is not the number or the destination, it is who checks the work.

Your current score predicts your CMMC outcome

Because CMMC Level 2 assesses the same 110 requirements, your honest SPRS score is a direct preview of a certification assessment. If your defensible score is 62, a C3PAO assessment scheduled for next quarter will not go well. If it is 104 with documented evidence behind every implemented requirement, the assessment is a verification exercise rather than a discovery exercise. Detailed scoping and readiness guidance lives on our CMMC Level 2 page.

One structural difference deserves attention. Under DFARS 252.204-7019 scoring, a requirement listed in a Plan of Action and Milestones still counts as not implemented and still subtracts its full weight. Under the CMMC rule, a limited Plan of Action and Milestones can support a conditional certification status subject to the 88-point minimum and the 180-day closeout window, with specific requirements excluded from eligibility. Do not read the CMMC allowance backward into your SPRS score. They are different instruments with different arithmetic.

NIST published Revision 3 of SP 800-171 in 2024. The CMMC Program rule is built on Revision 2, and organizations should score and assess against the revision their contract clauses invoke rather than against the newest publication. If your contracts are silent, ask the contracting officer instead of guessing. Background on the underlying standard is on our NIST compliance page.

Remediation

How to Raise a Low SPRS Score

Sequence the work by point value and by dependency, not by whichever gap is easiest to close.

A remediation plan that works through the requirements in numerical order wastes months. The weighting is the roadmap. A single 5-point requirement is worth five 1-point requirements, and the 5-point items cluster in access control, identification and authentication, system and communications protection, and system and information integrity. Close those families and the score moves in large steps.

  1. Fix the scope first. Re-derive the boundary of the covered environment. Pulling out-of-scope systems out of the assessment often recovers points immediately and legitimately, and it shrinks every downstream remediation task.
  2. Close the 5-point gaps. Multifactor authentication across the covered environment, FIPS-validated cryptography for data at rest and in transit, boundary protection, and timely flaw remediation. These are the requirements that move a score from negative to positive.
  3. Stand up audit and monitoring. Centralized logging, review of audit records, and the ability to produce evidence on demand. This family is expensive to retrofit and is the most common source of findings during a verification assessment. See CMMC 3.14.1 for the flaw remediation requirement.
  4. Rewrite the System Security Plan against reality. Most plans we inherit describe an environment nobody runs. The plan is the assessment artifact. If it is wrong, the score derived from it is wrong.
  5. Work the 3-point and 1-point items in batches. Policy, training, media protection, physical protection, and personnel security requirements are often closed in groups because they share the same documentation and the same approval path.
  6. Reassess and repost. Update the SPRS record with the new score, the new assessment date, and a revised projected closure date.

Documentation versus technical work

Roughly speaking, requirements split into two categories. Policy and documentation gaps close in weeks because the fix is writing, approving, and adopting a control. Technical gaps such as FIPS-validated encryption, network segmentation, centralized logging, and identity federation change infrastructure and take longer. Sequencing both tracks in parallel is what compresses a remediation program. Trying to finish all documentation before touching infrastructure is what stretches it across a year.

What not to do

Do not post a score you cannot support with evidence. Do not treat a Plan of Action and Milestones as a substitute for implementation when calculating your DFARS 7019 score. Do not let a managed service provider tell you that using their platform makes you compliant; the obligation sits with your company, and the shared responsibility boundary has to be documented. Do not scope so narrowly that controlled unclassified information demonstrably flows outside the assessed boundary.

If you need senior security leadership to own this program without hiring a full-time executive, our virtual CISO service carries the plan, the evidence, and the reassessment cadence. If you want an outside read on where you stand before committing to a timeline, start with a CMMC readiness assessment.

Understanding SPRS

How SPRS Scoring Works

Each of the 110 NIST 800-171 controls carries a weighted point value. Unimplemented controls reduce your score from the maximum of 110.

Score Range: -203 to 110

A perfect score of 110 means all controls are implemented. Missing controls reduce your score based on their security weight.

Submission Required

DFARS 252.204-7019 requires contractors to submit their SPRS score before contract award. Scores are visible to DoD contracting officers.

POA&M Impact

Controls documented in your Plan of Action and Milestones still reduce your score. Only fully implemented controls receive full credit.

Annual Reassessment

Scores must be updated annually or when significant changes occur. Petronella manages ongoing assessment and submission.

Our Services

How Petronella Improves Your SPRS Score

01

Assess current NIST 800-171 implementation

02

Calculate accurate SPRS score

03

Prioritize high-value control gaps

04

Implement controls to close gaps

05

Submit updated score to SPRS

06

Maintain score through continuous compliance

FAQ

SPRS Score FAQ

What is a good SPRS score?

110 is the maximum. Most organizations aim for the highest score possible since contracting officers use SPRS scores to evaluate suppliers. Any negative score indicates significant compliance gaps.

Is submitting an SPRS score required?

Yes. DFARS 252.204-7019 requires contractors to have a current SPRS score on file before contract award for contracts involving NIST 800-171 requirements.

How often must SPRS scores be updated?

Scores must be reassessed annually at minimum, or whenever significant changes occur in your security environment.

What is the relationship between SPRS and CMMC?

SPRS measures your self-assessed NIST 800-171 compliance. CMMC adds third-party verification. A high SPRS score is a strong foundation for CMMC Level 2 certification.

How do I improve my SPRS score for DFARS 252.204-7012 compliance?

Reassess honestly, then close the highest-weight gaps first. The SPRS score comes from the NIST SP 800-171 DoD Assessment Methodology: you start at 110 and subtract points for each unimplemented requirement, with the most critical weighted at 5 points, so a handful of items such as multifactor authentication and FIPS-validated encryption move the score far more than dozens of 1-point items. Document every implemented control in your System Security Plan, put realistic dates on remaining gaps in a Plan of Action and Milestones, remediate the 5-point and 3-point items, then submit the updated score in SPRS. Petronella Technology Group scored its own environment 110 out of 110 using this approach and runs the same process for defense contractors.

How fast can a defense contractor raise a low SPRS score?

It depends on which requirements are missing. Policy and documentation gaps can often be closed in weeks because the fix is writing and adopting the control, while technical gaps such as FIPS-validated encryption, centralized logging, or network segmentation take longer because they change infrastructure. The fastest legitimate path is a gap assessment that sequences remediation by point value. Inflating a self-assessment instead is a False Claims Act risk, since scores are subject to DoD review and to verification at CMMC Level 2.

What is SPRS and who can see my score?

SPRS is the Supplier Performance Risk System, the Department of Defense authoritative source for supplier risk data. Your NIST SP 800-171 assessment score is stored there against your CAGE code hierarchy. Government acquisition personnel can view it when evaluating you for award. Primes cannot pull your record directly, but they routinely require you to disclose the score during subcontract flow-down, so treat it as a number your customers will see.

What is the SPRS score range?

The sprs score range runs from -203 to 110. You start at 110 and subtract the assigned weight of every requirement you have not fully implemented: 5 points for the highest-impact requirements, 3 points for those with a specific and confined effect on security, and 1 point for the rest. Because the weighted deductions total more than 110, an organization that has implemented nothing scores -203.

How do I submit a DoD SPRS score?

Submissions run through the Procurement Integrated Enterprise Environment. Your company needs an active System for Award Management registration, a CAGE code, and a user provisioned with the SPRS Cyber Vendor User role by your PIEE Contractor Administrator. You then enter the assessment date, the scope description, the CAGE codes covered, the score, and the date you expect to reach 110. Provisioning the PIEE role is the step that most often delays a submission.

Does a subcontractor have to post an SPRS score?

Yes, if the subcontract includes DFARS 252.204-7012 and the work involves covered defense information. DFARS 252.204-7020 requires the obligation to flow down to subcontractors at all tiers for work of that type. Company size does not change the requirement. The trigger is whether controlled unclassified information reaches your systems.

Does a Plan of Action and Milestones raise my SPRS score?

No. Under the NIST SP 800-171 DoD Assessment Methodology used for DFARS 252.204-7019 reporting, a requirement listed in a Plan of Action and Milestones is still scored as not implemented and still subtracts its full weight. The CMMC Program rule at 32 CFR Part 170 separately allows a limited plan to support a conditional status when the score is at least 88 and the items close within 180 days, but that allowance does not change the DFARS score.

High-Impact Controls

Controls That Impact Your SPRS Score Most

These CMMC controls carry the highest weighted values in SPRS scoring. Implementing them first yields the largest score improvements.

Get Started

Improve Your SPRS Score

Get an accurate assessment and a clear plan to maximize your NIST 800-171 compliance score.