If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
How to Calculate Your SPRS Score: NIST 800-171 Scoring Guide for DoD Contractors (Updated Aug 2026)
Updated Aug 28th, 2026: In July, the Department of War suspended CMMC Phase 2 third-party assessments. Your SPRS score didn’t get less important it became the government’s primary view into your compliance, and the annual affirmation your company signs over it is now where the legal risk concentrates. Full breakdown here: CMMC Phase 2 Is Suspended. Your Compliance Obligations Are Not.
Your SPRS score measures how well you have implemented the 110 security requirements in NIST SP 800-171 Revision 2. The score starts at 110 (full compliance) and decreases for each requirement you have not fully implemented, all the way down to a theoretical minimum of −203. Understanding how to calculate this score correctly is essential for accurate self-assessment, SPRS submission, and after July 13, 2026 for protecting whoever signs your annual affirmation.
SPRS stands for Supplier Performance Risk System the government database where contractors submit cybersecurity assessment scores under DFARS 252.204-7019 and 252.204-7020.
NIST SP 800-171 is the federal standard specifying 110 security requirements for protecting Controlled Unclassified Information (CUI).
Two Faster Ways to Get Your SPRS Score Number (Both Free)
The full manual method is below, and it’s worth walking at least once, scoring by hand is how you learn where your deductions actually live. But most people land on this page for one of two reasons: they need a score and don’t have one, or they have a score in SPRS and aren’t sure it’s real. There’s a free tool for each.
If you already have a score, use this:
Click here for the SPRS Score Reality Check
Nine quick questions about the highest-impact requirements, the ones that drive most of the deduction. You enter the score you’re currently reporting, answer the questions, and get back an indicative range plus the specific gaps and common scoring errors your answers flagged.
It’s a plausibility check, not an assessment. A perfect 110 sitting in SPRS next to an environment with no enterprise MFA and no FIPS-validated crypto is the single most common problem in the DIB right now, and this catches that in about two minutes. Free; results come to your email.
If you’re starting from zero, run this tool:
Click here for the SPRS Score Calculator
A free Excel/Google Sheets workbook with all 110 Rev 2 requirements across the 14 control families. Set each control to Met, Partially Met, Unmet, or Not Assessed from a dropdown, and the workbook applies the official DoD Assessment Methodology weights and updates your score live. It also breaks the score down by family, so you can see which family is costing you the most points, and includes a notes column per control.
Use that notes column. Control-by-control evidence notes are the thing that makes a score defensible later, and it’s far easier to capture them while you’re assessing than to reconstruct them a year from now.
Which one first? No score yet → the calculator. Score already in SPRS → the reality check, then the calculator to rebuild the number properly.
Neither tool replaces understanding the methodology the workbook automates exactly the process described below, and knowing what it’s doing is what lets you defend the output. So if you’re the person whose name goes on the affirmation, keep reading.
Why Your SPRS Score Matters More Since July 2026
Under the original CMMC rollout, a third-party assessor (C3PAO) would eventually verify your compliance and catch any gap between your reported score and your actual environment before the government relied on it. That verification layer is suspended as of July 13, 2026.
What remains is your self-assessed score in SPRS and the annual affirmation: a named company official personally attesting to the federal government that the score is accurate. During the suspension, the Department is enforcing NIST SP 800-171 Rev 2 through exactly these self-assessments, plus select government-led assessments. The Department of Justice’s Civil Cyber-Fraud Initiative has already reached multimillion-dollar False Claims Act settlements with contractors whose SPRS scores didn’t match reality.
Translation: calculating your score accurately is no longer just good practice. It’s your primary legal protection.
The Scoring Methodology
The DoD Assessment Methodology (v1.2.1) assigns a “weighted subtractor” value to each NIST 800-171 requirement. When you have not implemented a requirement, you subtract its point value from 110.
Starting Point: 110
If you have fully implemented all requirements, your score is 110.
Point Values
Each scored requirement is worth 1, 3, or 5 points based on its security impact:
- 5 points: Requirements whose absence could lead to significant exploitation of the network or exfiltration of CUI
- 3 points: Requirements whose absence has a specific and confined effect on the security of the network and its data
- 1 point: Requirements whose absence has a limited or indirect effect on security
Calculation Formula
SPRS Score = 110 − (sum of point values for unimplemented requirements)
The One Requirement With No Point Value: Your SSP
Before you score anything, know this: security requirement 3.12.4 the System Security Plan is not assigned a point value at all, and that’s not a break. Per the assessment methodology, the absence of an SSP results in a finding that an assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012.
In plain English: no SSP means no valid score. You can’t calculate around it, and you can’t POA&M your way past it. If you don’t have a current SSP describing your environment, that’s item zero on your list.
An SSP is a System Security Plan the document describing how your environment implements each requirement. A POA&M is a Plan of Action and Milestones the document tracking how and when you’ll close known gaps.
Point Values by Requirement
5-Point Requirements (Most Critical)
These are your highest-priority items. Examples include:
- Limit system access to authorized users (3.1.1)
- Multi-factor authentication (3.5.3)*
- FIPS-validated cryptography (3.13.11)*
- Boundary protection (3.13.1)
- Malicious code protection (3.14.2)
- Audit logging (3.3.1)
- Baseline configurations (3.4.1)
- Incident handling capability (3.6.1)
- Media sanitization before disposal (3.8.3)
Failing to implement the 5-point requirements quickly drives your score negative.
*See the partial-scoring exceptions below these two controls are the only ones in the methodology with built-in partial credit.
3-Point Requirements (Important)
These have a specific, confined security impact. Examples include:
- Employ the principle of least privilege (3.1.5)
- Protect (physically control and securely store) media containing CUI (3.8.1)
- Periodically assess risk to organizational operations (3.11.1)
- Develop and implement plans of action (POA&Ms) (3.12.2)
1-Point Requirements (Supporting)
These support overall security posture. Examples include:
- Session lock with pattern-hiding displays (3.1.10)
- Escort and monitor visitors (3.10.3)
- Insider threat awareness training (3.2.3)
- Protect the confidentiality of CUI at rest (3.13.16)
Notice that last one: CUI at rest (3.13.16) is a 1-point control, while FIPS-validated cryptography (3.13.11) is a 5-point control. Contractors frequently confuse the two. The methodology cares most about whether your cryptographic modules are FIPS-validated wherever encryption is required that’s where the heavy deduction lives.
The Two Partial-Credit Exceptions
The methodology allows partial scoring on exactly two requirements. Everything else is all-or-nothing.
3.5.3 Multi-Factor Authentication: If MFA is implemented for remote and privileged users but not yet for general network access, 3 points are deducted instead of 5. No MFA at all costs the full 5.
3.13.11 FIPS-Validated Cryptography: If encryption is employed but is not FIPS-validated, 3 points are deducted. If encryption is not employed at all where required, 5 points are deducted.
Used correctly, these two rules can meaningfully change your score. Claimed incorrectly, they’re exactly the kind of overstatement that makes an affirmation indefensible.
Step-by-Step Scoring Process
Step 1: Confirm You Have a Current SSP
Without one, no valid assessment exists (see above). Your SSP defines the boundary you’re scoring.
Step 2: List the Requirements
Start with the complete list of NIST 800-171 Rev 2 requirements. The official DoD Assessment Methodology document (v1.2.1) lists each requirement with its point value in Annex A. (The SPRS Score Calculator has this list pre-built with the weights already applied, if you’d rather not transcribe Annex A by hand.)
Step 3: Assess Each Requirement
For each requirement, determine your implementation status:
- Implemented: Fully in place and operational every assessment objective in NIST SP 800-171A satisfied
- Partially Implemented: Some aspects in place, but gaps exist
- Not Implemented: Not in place or not operational
- Not Applicable: Does not apply to your environment (rare must be justified, and formal N/A determinations require DoD CIO adjudication)
Step 4: Score Your Status
- Implemented: No points deducted
- Partially Implemented: Full points deducted except for 3.5.3 and 3.13.11, the only two controls with built-in partial credit
- Not Implemented: Full points deducted
- Not Applicable: No points deducted, with documented justification
One more nuance the methodology allows: a temporary deficiency being actively worked in a plan of action like a control that was implemented but broke due to a patch can be assessed as implemented. A control you simply haven’t built yet is not a temporary deficiency.
Step 5: Calculate Total Deductions
Add up the point values for all requirements marked partially implemented (except the two exceptions at their reduced value) or not implemented.
Step 6: Subtract from 110
Your SPRS Score = 110 − Total Deductions
Scoring Examples
Example 1: Strong Compliance
A contractor has fully implemented all but 5 requirements:
- One 5-point requirement (5)
- Two 3-point requirements (6)
- Two 1-point requirements (2)
Calculation: 110 − 5 − 6 − 2 = 97
Example 2: Moderate Gaps
Gaps in 15 requirements:
- Three 5-point requirements (15)
- Seven 3-point requirements (21)
- Five 1-point requirements (5)
Calculation: 110 − 15 − 21 − 5 = 69
Example 3: The Partial-Credit Difference
A contractor has MFA deployed for remote and privileged accounts but not general users, and encrypts CUI with modules that aren’t FIPS-validated:
- 3.5.3 partial: −3 (instead of −5)
- 3.13.11 encryption-but-not-FIPS: −3 (instead of −5)
- Plus four other 1-point gaps: −4
Calculation: 110 − 3 − 3 − 4 = 100
The same environment scored without knowing the partial-credit rules would report 96 an unnecessary 4-point understatement. Accuracy cuts both ways.
Example 4: Major Deficiencies
Gaps in 50 requirements, including most critical controls:
- Fifteen 5-point requirements (75)
- Twenty-five 3-point requirements (75)
- Ten 1-point requirements (10)
Calculation: 110 − 75 − 75 − 10 = −50
Understanding Negative Scores
Yes, your score can go negative. The theoretical minimum is −203 if you have implemented nothing.
Negative scores are common on a first honest assessment the 5-point controls (enterprise MFA, FIPS cryptography, boundary protection, logging) are exactly the ones small contractors tend to leave for last. A negative score doesn’t automatically disqualify you from contracts, but it signals significant work ahead, and some solicitations set minimum score thresholds.
An honest −20 with a credible POA&M is a defensible position. An inflated 110 is not.
Common Scoring Mistakes
Mistake 1: Misapplying (or Missing) Partial Credit
Only 3.5.3 and 3.13.11 have partial scoring, under the specific conditions above. Claiming partial credit anywhere else overstates your score; failing to claim it where it legitimately applies understates it. Both are inaccuracies and after July 2026, inaccuracy is the risk.
Mistake 2: Marking Requirements Not Applicable Without Justification
Very few requirements are truly not applicable, and formal N/A treatment runs through DoD CIO adjudication. Unjustified N/A designations are among the first things a government-led assessment will challenge.
Mistake 3: Confusing Policy with Implementation
Having a policy document does not mean a requirement is implemented. A policy saying you will encrypt CUI does not count you must actually encrypt CUI, and NIST SP 800-171A’s assessment objectives are the yardstick.
Mistake 4: Not Assessing All Systems in the Boundary
Your assessment must cover every system in your CUI environment as defined in your SSP. Missing systems means missing requirements, which means an inaccurate score.
Mistake 5: Self-Scoring Too Generously
Overstating your compliance creates direct legal risk under the False Claims Act the enforcement tool the DOJ’s Civil Cyber-Fraud Initiative uses against contractors who misrepresent cybersecurity compliance. With third-party audits suspended, there is no assessor left to catch the gap before the government relies on your number. Be honest and conservative.
Mistake 6: Scoring Without an SSP
See above without a current SSP, the methodology says no assessment can be completed at all.
What Score Do You Need?
There is no universal minimum score, but consider these factors:
Contract Requirements
Some contracts specify minimum scores. Check solicitation requirements for specific thresholds.
The 88-Point CMMC Threshold
Under 32 CFR § 170.21, conditional CMMC Level 2 status requires a minimum score of 88 out of 110 (80% of 110 points is 88 a common trap is assuming 80% means a score of 80), with remaining gaps documented in a POA&M and closed within 180 days. Certain critical requirements can’t be POA&M’d at all.
Note: C3PAO certification assessments are suspended as of July 13, 2026, so this threshold isn’t currently being tested by third parties but it remains the benchmark in the CMMC rule, it’s the bar a reformed program would most likely inherit, and 88 is a sensible internal floor for any contractor handling CUI today.
Competitive Positioning
Contracting officers can see your SPRS score, and primes evaluate subcontractor posture regardless of what the certification program does. A higher accurate score is an advantage.
Target: 110
The goal is full compliance at 110. Anything less indicates gaps that need remediation, tracked in a POA&M.
After Calculating Your Score
Document Your Assessment
Create an assessment report documenting your methodology, findings, and score calculation, control by control. This evidence file is what makes your score defensible.
Create a POA&M
For every gap, document the remediation plan with milestones and timelines. Remember: a POA&M buys time and demonstrates good faith, but it does not restore deducted points.
Submit to SPRS
Enter your score in SPRS through the PIEE portal (you’ll need a PIEE account with the SPRS “Cyber Vendor” role). Your assessment date must be within the last three years to be considered current.
Affirm It Carefully
Your company’s Affirming Official annually attests to the score’s accuracy in SPRS. That signature is a statement to the federal government in connection with contract awards squarely inside the False Claims Act. It deserves the same rigor a third-party auditor would have brought.
Plan Remediation
Prioritize closing gaps on high-point-value requirements for maximum score improvement they’re the highest security impact and the fastest way to move the number honestly.
Key Takeaways
Your SPRS score starts at 110 and decreases based on unimplemented NIST 800-171 Rev 2 requirements. Scored requirements are worth 1, 3, or 5 points, with partial credit available only for MFA (3.5.3) and FIPS cryptography (3.13.11) and no valid score exists at all without a current SSP.
The conditional CMMC Level 2 benchmark is 88, not 80 but with third-party assessments suspended since July 13, 2026, the score that matters most is the one your Affirming Official signs. Accuracy is now your primary legal protection.
Assess honestly against the NIST SP 800-171A objectives, document your evidence control by control, track gaps in a POA&M, and focus remediation on high-point requirements for the biggest honest score improvements.
Frequently asked
Questions about this topic
What is a good SPRS score?
Can my SPRS score be negative?
Is there partial credit in SPRS scoring?
Do I still need to submit an SPRS score after the CMMC Phase 2 suspension?
How often do I need to update my SPRS score?
Can I get in legal trouble for an inaccurate SPRS score?
Keep reading
More in SPRS & Self-Assessment
- CMMC Level 1 Self-Assessment Guide →
- CMMC Level 2 Self-Assessment Requirements →
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update] →
- What is SPRS? →
- How to Write a CMMC System Security Plan →
- POA&M Best Practices for CMMC →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5