Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

How to Calculate Your SPRS Score: NIST 800-171 Scoring Guide for DoD Contractors (Updated Aug 2026)

Updated Aug 28th, 2026: In July, the Department of War suspended CMMC Phase 2 third-party assessments. Your SPRS score didn’t get less important it became the government’s primary view into your compliance, and the annual affirmation your company signs over it is now where the legal risk concentrates. Full breakdown here: CMMC Phase 2 Is Suspended. Your Compliance Obligations Are Not.

Your SPRS score measures how well you have implemented the 110 security requirements in NIST SP 800-171 Revision 2. The score starts at 110 (full compliance) and decreases for each requirement you have not fully implemented, all the way down to a theoretical minimum of −203. Understanding how to calculate this score correctly is essential for accurate self-assessment, SPRS submission, and after July 13, 2026 for protecting whoever signs your annual affirmation.

SPRS stands for Supplier Performance Risk System the government database where contractors submit cybersecurity assessment scores under DFARS 252.204-7019 and 252.204-7020.

NIST SP 800-171 is the federal standard specifying 110 security requirements for protecting Controlled Unclassified Information (CUI).

Two Faster Ways to Get Your SPRS Score Number (Both Free)

The full manual method is below, and it’s worth walking at least once, scoring by hand is how you learn where your deductions actually live. But most people land on this page for one of two reasons: they need a score and don’t have one, or they have a score in SPRS and aren’t sure it’s real. There’s a free tool for each.

Nine quick questions about the highest-impact requirements, the ones that drive most of the deduction. You enter the score you’re currently reporting, answer the questions, and get back an indicative range plus the specific gaps and common scoring errors your answers flagged.

It’s a plausibility check, not an assessment. A perfect 110 sitting in SPRS next to an environment with no enterprise MFA and no FIPS-validated crypto is the single most common problem in the DIB right now, and this catches that in about two minutes. Free; results come to your email.

A free Excel/Google Sheets workbook with all 110 Rev 2 requirements across the 14 control families. Set each control to Met, Partially Met, Unmet, or Not Assessed from a dropdown, and the workbook applies the official DoD Assessment Methodology weights and updates your score live. It also breaks the score down by family, so you can see which family is costing you the most points, and includes a notes column per control.

Use that notes column. Control-by-control evidence notes are the thing that makes a score defensible later, and it’s far easier to capture them while you’re assessing than to reconstruct them a year from now.

Which one first? No score yet → the calculator. Score already in SPRS → the reality check, then the calculator to rebuild the number properly.

Neither tool replaces understanding the methodology the workbook automates exactly the process described below, and knowing what it’s doing is what lets you defend the output. So if you’re the person whose name goes on the affirmation, keep reading.

Why Your SPRS Score Matters More Since July 2026

Under the original CMMC rollout, a third-party assessor (C3PAO) would eventually verify your compliance and catch any gap between your reported score and your actual environment before the government relied on it. That verification layer is suspended as of July 13, 2026.

What remains is your self-assessed score in SPRS and the annual affirmation: a named company official personally attesting to the federal government that the score is accurate. During the suspension, the Department is enforcing NIST SP 800-171 Rev 2 through exactly these self-assessments, plus select government-led assessments. The Department of Justice’s Civil Cyber-Fraud Initiative has already reached multimillion-dollar False Claims Act settlements with contractors whose SPRS scores didn’t match reality.

Translation: calculating your score accurately is no longer just good practice. It’s your primary legal protection.

The Scoring Methodology

The DoD Assessment Methodology (v1.2.1) assigns a “weighted subtractor” value to each NIST 800-171 requirement. When you have not implemented a requirement, you subtract its point value from 110.

Starting Point: 110

If you have fully implemented all requirements, your score is 110.

Point Values

Each scored requirement is worth 1, 3, or 5 points based on its security impact:

  • 5 points: Requirements whose absence could lead to significant exploitation of the network or exfiltration of CUI
  • 3 points: Requirements whose absence has a specific and confined effect on the security of the network and its data
  • 1 point: Requirements whose absence has a limited or indirect effect on security

Calculation Formula

SPRS Score = 110 − (sum of point values for unimplemented requirements)

The One Requirement With No Point Value: Your SSP

Before you score anything, know this: security requirement 3.12.4 the System Security Plan is not assigned a point value at all, and that’s not a break. Per the assessment methodology, the absence of an SSP results in a finding that an assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012.

In plain English: no SSP means no valid score. You can’t calculate around it, and you can’t POA&M your way past it. If you don’t have a current SSP describing your environment, that’s item zero on your list.

An SSP is a System Security Plan the document describing how your environment implements each requirement. A POA&M is a Plan of Action and Milestones the document tracking how and when you’ll close known gaps.

Point Values by Requirement

5-Point Requirements (Most Critical)

These are your highest-priority items. Examples include:

  • Limit system access to authorized users (3.1.1)
  • Multi-factor authentication (3.5.3)*
  • FIPS-validated cryptography (3.13.11)*
  • Boundary protection (3.13.1)
  • Malicious code protection (3.14.2)
  • Audit logging (3.3.1)
  • Baseline configurations (3.4.1)
  • Incident handling capability (3.6.1)
  • Media sanitization before disposal (3.8.3)

Failing to implement the 5-point requirements quickly drives your score negative.

*See the partial-scoring exceptions below these two controls are the only ones in the methodology with built-in partial credit.

3-Point Requirements (Important)

These have a specific, confined security impact. Examples include:

  • Employ the principle of least privilege (3.1.5)
  • Protect (physically control and securely store) media containing CUI (3.8.1)
  • Periodically assess risk to organizational operations (3.11.1)
  • Develop and implement plans of action (POA&Ms) (3.12.2)

1-Point Requirements (Supporting)

These support overall security posture. Examples include:

  • Session lock with pattern-hiding displays (3.1.10)
  • Escort and monitor visitors (3.10.3)
  • Insider threat awareness training (3.2.3)
  • Protect the confidentiality of CUI at rest (3.13.16)

Notice that last one: CUI at rest (3.13.16) is a 1-point control, while FIPS-validated cryptography (3.13.11) is a 5-point control. Contractors frequently confuse the two. The methodology cares most about whether your cryptographic modules are FIPS-validated wherever encryption is required that’s where the heavy deduction lives.

The Two Partial-Credit Exceptions

The methodology allows partial scoring on exactly two requirements. Everything else is all-or-nothing.

3.5.3 Multi-Factor Authentication: If MFA is implemented for remote and privileged users but not yet for general network access, 3 points are deducted instead of 5. No MFA at all costs the full 5.

3.13.11 FIPS-Validated Cryptography: If encryption is employed but is not FIPS-validated, 3 points are deducted. If encryption is not employed at all where required, 5 points are deducted.

Used correctly, these two rules can meaningfully change your score. Claimed incorrectly, they’re exactly the kind of overstatement that makes an affirmation indefensible.

Step-by-Step Scoring Process

Step 1: Confirm You Have a Current SSP

Without one, no valid assessment exists (see above). Your SSP defines the boundary you’re scoring.

Step 2: List the Requirements

Start with the complete list of NIST 800-171 Rev 2 requirements. The official DoD Assessment Methodology document (v1.2.1) lists each requirement with its point value in Annex A. (The SPRS Score Calculator has this list pre-built with the weights already applied, if you’d rather not transcribe Annex A by hand.)

Step 3: Assess Each Requirement

For each requirement, determine your implementation status:

  • Implemented: Fully in place and operational every assessment objective in NIST SP 800-171A satisfied
  • Partially Implemented: Some aspects in place, but gaps exist
  • Not Implemented: Not in place or not operational
  • Not Applicable: Does not apply to your environment (rare must be justified, and formal N/A determinations require DoD CIO adjudication)

Step 4: Score Your Status

  • Implemented: No points deducted
  • Partially Implemented: Full points deducted except for 3.5.3 and 3.13.11, the only two controls with built-in partial credit
  • Not Implemented: Full points deducted
  • Not Applicable: No points deducted, with documented justification

One more nuance the methodology allows: a temporary deficiency being actively worked in a plan of action like a control that was implemented but broke due to a patch can be assessed as implemented. A control you simply haven’t built yet is not a temporary deficiency.

Step 5: Calculate Total Deductions

Add up the point values for all requirements marked partially implemented (except the two exceptions at their reduced value) or not implemented.

Step 6: Subtract from 110

Your SPRS Score = 110 − Total Deductions

Scoring Examples

Example 1: Strong Compliance

A contractor has fully implemented all but 5 requirements:

  • One 5-point requirement (5)
  • Two 3-point requirements (6)
  • Two 1-point requirements (2)

Calculation: 110 − 5 − 6 − 2 = 97

Example 2: Moderate Gaps

Gaps in 15 requirements:

  • Three 5-point requirements (15)
  • Seven 3-point requirements (21)
  • Five 1-point requirements (5)

Calculation: 110 − 15 − 21 − 5 = 69

Example 3: The Partial-Credit Difference

A contractor has MFA deployed for remote and privileged accounts but not general users, and encrypts CUI with modules that aren’t FIPS-validated:

  • 3.5.3 partial: −3 (instead of −5)
  • 3.13.11 encryption-but-not-FIPS: −3 (instead of −5)
  • Plus four other 1-point gaps: −4

Calculation: 110 − 3 − 3 − 4 = 100

The same environment scored without knowing the partial-credit rules would report 96 an unnecessary 4-point understatement. Accuracy cuts both ways.

Example 4: Major Deficiencies

Gaps in 50 requirements, including most critical controls:

  • Fifteen 5-point requirements (75)
  • Twenty-five 3-point requirements (75)
  • Ten 1-point requirements (10)

Calculation: 110 − 75 − 75 − 10 = −50

Understanding Negative Scores

Yes, your score can go negative. The theoretical minimum is −203 if you have implemented nothing.

Negative scores are common on a first honest assessment the 5-point controls (enterprise MFA, FIPS cryptography, boundary protection, logging) are exactly the ones small contractors tend to leave for last. A negative score doesn’t automatically disqualify you from contracts, but it signals significant work ahead, and some solicitations set minimum score thresholds.

An honest −20 with a credible POA&M is a defensible position. An inflated 110 is not.

Common Scoring Mistakes

Mistake 1: Misapplying (or Missing) Partial Credit

Only 3.5.3 and 3.13.11 have partial scoring, under the specific conditions above. Claiming partial credit anywhere else overstates your score; failing to claim it where it legitimately applies understates it. Both are inaccuracies and after July 2026, inaccuracy is the risk.

Mistake 2: Marking Requirements Not Applicable Without Justification

Very few requirements are truly not applicable, and formal N/A treatment runs through DoD CIO adjudication. Unjustified N/A designations are among the first things a government-led assessment will challenge.

Mistake 3: Confusing Policy with Implementation

Having a policy document does not mean a requirement is implemented. A policy saying you will encrypt CUI does not count you must actually encrypt CUI, and NIST SP 800-171A’s assessment objectives are the yardstick.

Mistake 4: Not Assessing All Systems in the Boundary

Your assessment must cover every system in your CUI environment as defined in your SSP. Missing systems means missing requirements, which means an inaccurate score.

Mistake 5: Self-Scoring Too Generously

Overstating your compliance creates direct legal risk under the False Claims Act the enforcement tool the DOJ’s Civil Cyber-Fraud Initiative uses against contractors who misrepresent cybersecurity compliance. With third-party audits suspended, there is no assessor left to catch the gap before the government relies on your number. Be honest and conservative.

Mistake 6: Scoring Without an SSP

See above without a current SSP, the methodology says no assessment can be completed at all.

What Score Do You Need?

There is no universal minimum score, but consider these factors:

Contract Requirements

Some contracts specify minimum scores. Check solicitation requirements for specific thresholds.

The 88-Point CMMC Threshold

Under 32 CFR § 170.21, conditional CMMC Level 2 status requires a minimum score of 88 out of 110 (80% of 110 points is 88 a common trap is assuming 80% means a score of 80), with remaining gaps documented in a POA&M and closed within 180 days. Certain critical requirements can’t be POA&M’d at all.

Note: C3PAO certification assessments are suspended as of July 13, 2026, so this threshold isn’t currently being tested by third parties but it remains the benchmark in the CMMC rule, it’s the bar a reformed program would most likely inherit, and 88 is a sensible internal floor for any contractor handling CUI today.

Competitive Positioning

Contracting officers can see your SPRS score, and primes evaluate subcontractor posture regardless of what the certification program does. A higher accurate score is an advantage.

Target: 110

The goal is full compliance at 110. Anything less indicates gaps that need remediation, tracked in a POA&M.

After Calculating Your Score

Document Your Assessment

Create an assessment report documenting your methodology, findings, and score calculation, control by control. This evidence file is what makes your score defensible.

Create a POA&M

For every gap, document the remediation plan with milestones and timelines. Remember: a POA&M buys time and demonstrates good faith, but it does not restore deducted points.

Submit to SPRS

Enter your score in SPRS through the PIEE portal (you’ll need a PIEE account with the SPRS “Cyber Vendor” role). Your assessment date must be within the last three years to be considered current.

Affirm It Carefully

Your company’s Affirming Official annually attests to the score’s accuracy in SPRS. That signature is a statement to the federal government in connection with contract awards squarely inside the False Claims Act. It deserves the same rigor a third-party auditor would have brought.

Plan Remediation

Prioritize closing gaps on high-point-value requirements for maximum score improvement they’re the highest security impact and the fastest way to move the number honestly.

Key Takeaways

Your SPRS score starts at 110 and decreases based on unimplemented NIST 800-171 Rev 2 requirements. Scored requirements are worth 1, 3, or 5 points, with partial credit available only for MFA (3.5.3) and FIPS cryptography (3.13.11) and no valid score exists at all without a current SSP.

The conditional CMMC Level 2 benchmark is 88, not 80 but with third-party assessments suspended since July 13, 2026, the score that matters most is the one your Affirming Official signs. Accuracy is now your primary legal protection.

Assess honestly against the NIST SP 800-171A objectives, document your evidence control by control, track gaps in a POA&M, and focus remediation on high-point requirements for the biggest honest score improvements.

Frequently asked

Questions about this topic

What is a good SPRS score?
110 is full implementation and the only score with zero gaps. 88 is the conditional CMMC Level 2 threshold under 32 CFR § 170.21 and a sensible internal floor for CUI handlers. There’s no universal contractual minimum, but an accurate score even a low one paired with a credible POA&M is always better positioned than an inflated one.
Can my SPRS score be negative?
Yes. The scale runs from 110 down to −203. Negative first-pass scores are common because the highest-weighted controls (MFA, FIPS cryptography, boundary protection, logging) are the ones most often unimplemented. A negative score is a starting point, not a disqualification.
Is there partial credit in SPRS scoring?
Only for two controls: 3.5.3 (multi-factor authentication) and 3.13.11 (FIPS-validated cryptography), each of which can deduct 3 points instead of 5 in defined partial-implementation cases. Every other requirement is all-or-nothing a control that’s 80% done deducts its full value.
Do I still need to submit an SPRS score after the CMMC Phase 2 suspension?
Yes. The July 13, 2026 suspension paused third-party (C3PAO) assessments it did not touch DFARS 252.204-7019/7020 SPRS scoring requirements, the annual affirmation, or your DFARS 252.204-7012 obligation to implement NIST SP 800-171. During the suspension, your self-assessed SPRS score is the government’s primary compliance signal.
How often do I need to update my SPRS score?
Your Basic self-assessment must be current within three years to be valid, and your Affirming Official affirms annually. Best practice: reassess and update after any material change to your environment and immediately if you discover your current score doesn’t reflect reality.
Can I get in legal trouble for an inaccurate SPRS score?
Yes. Knowingly submitting an inflated score, or affirming compliance you aren’t maintaining, can violate the False Claims Act with treble damages. The DOJ’s Civil Cyber-Fraud Initiative has already settled cases with defense contractors over misrepresented scores, and FCA cases are frequently initiated by whistleblowers.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Tags:
Table of Contents