Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

How to Calculate Your SPRS Score: NIST 800-171 Scoring Guide for DoD Contractors [Updated July 2026]

How to Calculate Your SPRS Score: NIST 800-171 Scoring Guide for DoD Contractors [Updated July 2026]


Updated July 14, 2026: On July 13, 2026, the Department of War suspended CMMC Phase 2 third-party assessments. Your SPRS score didn’t get less important — it became the government’s primary view into your compliance, and the annual affirmation your company signs over it is now where the legal risk concentrates. Full breakdown here: CMMC Phase 2 Is Suspended. Your Compliance Obligations Are Not.


Your SPRS score measures how well you have implemented the 110 security requirements in NIST SP 800-171 Revision 2. The score starts at 110 (full compliance) and decreases for each requirement you have not fully implemented, all the way down to a theoretical minimum of -203. Understanding how to calculate this score correctly is essential for accurate self-assessment, SPRS submission, and — after July 13, 2026 — for protecting whoever signs your annual affirmation.

SPRS stands for Supplier Performance Risk System — the government database where contractors submit cybersecurity assessment scores under DFARS 252.204-7019 and 252.204-7020.

NIST SP 800-171 is the federal standard specifying 110 security requirements for protecting Controlled Unclassified Information (CUI).

Why Your SPRS Score Matters More Since July 2026

Under the original CMMC rollout, a third-party assessor (C3PAO) would eventually verify your compliance — and catch any gap between your reported score and your actual environment before the government relied on it. That verification layer is suspended as of July 13, 2026.

What remains is your self-assessed score in SPRS and the annual affirmation: a named company official personally attesting to the federal government that the score is accurate. During the suspension, the Department is enforcing NIST SP 800-171 Rev 2 through exactly these self-assessments, plus select government-led assessments. The Department of Justice’s Civil Cyber-Fraud Initiative has already reached multimillion-dollar False Claims Act settlements with contractors whose SPRS scores didn’t match reality.

Translation: calculating your score accurately is no longer just good practice. It’s your primary legal protection.

The Scoring Methodology

The DoD Assessment Methodology (v1.2.1) assigns a “weighted subtractor” value to each NIST 800-171 requirement. When you have not implemented a requirement, you subtract its point value from 110.

Starting Point: 110

If you have fully implemented all requirements, your score is 110.

Point Values

Each scored requirement is worth 1, 3, or 5 points based on its security impact:

  • 5 points: Requirements whose absence could lead to significant exploitation of the network or exfiltration of CUI
  • 3 points: Requirements whose absence has a specific and confined effect on the security of the network and its data
  • 1 point: Requirements whose absence has a limited or indirect effect on security

Calculation Formula

SPRS Score = 110 − (sum of point values for unimplemented requirements)

The One Requirement With No Point Value: Your SSP

Before you score anything, know this: security requirement 3.12.4 — the System Security Plan — is not assigned a point value at all, and that’s not a break. Per the assessment methodology, the absence of an SSP results in a finding that an assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012.

In plain English: no SSP means no valid score. You can’t calculate around it, and you can’t POA&M your way past it. If you don’t have a current SSP describing your environment, that’s item zero on your list.

An SSP is a System Security Plan — the document describing how your environment implements each requirement. A POA&M is a Plan of Action and Milestones — the document tracking how and when you’ll close known gaps.

Point Values by Requirement

5-Point Requirements (Most Critical)

These are your highest-priority items. Examples include:

  • Limit system access to authorized users (3.1.1)
  • Multi-factor authentication (3.5.3)*
  • FIPS-validated cryptography (3.13.11)*
  • Boundary protection (3.13.1)
  • Malicious code protection (3.14.2)
  • Audit logging (3.3.1)
  • Baseline configurations (3.4.1)
  • Incident handling capability (3.6.1)
  • Media sanitization before disposal (3.8.3)

Failing to implement the 5-point requirements quickly drives your score negative.

*See the partial-scoring exceptions below — these two controls are the only ones in the methodology with built-in partial credit.

3-Point Requirements (Important)

These have a specific, confined security impact. Examples include:

  • Employ the principle of least privilege (3.1.5)
  • Protect (physically control and securely store) media containing CUI (3.8.1)
  • Periodically assess risk to organizational operations (3.11.1)
  • Develop and implement plans of action (POA&Ms) (3.12.2)

1-Point Requirements (Supporting)

These support overall security posture. Examples include:

  • Session lock with pattern-hiding displays (3.1.10)
  • Escort and monitor visitors (3.10.3)
  • Insider threat awareness training (3.2.3)
  • Protect the confidentiality of CUI at rest (3.13.16)

Notice that last one: CUI at rest (3.13.16) is a 1-point control, while FIPS-validated cryptography (3.13.11) is a 5-point control. Contractors frequently confuse the two. The methodology cares most about whether your cryptographic modules are FIPS-validated wherever encryption is required — that’s where the heavy deduction lives.

The Two Partial-Credit Exceptions

The methodology allows partial scoring on exactly two requirements. Everything else is all-or-nothing.

3.5.3 — Multi-Factor Authentication: If MFA is implemented for remote and privileged users but not yet for general network access, 3 points are deducted instead of 5. No MFA at all costs the full 5.

3.13.11 — FIPS-Validated Cryptography: If encryption is employed but is not FIPS-validated, 3 points are deducted. If encryption is not employed at all where required, 5 points are deducted.

Used correctly, these two rules can meaningfully change your score. Claimed incorrectly, they’re exactly the kind of overstatement that makes an affirmation indefensible.

Step-by-Step Scoring Process

Step 1: Confirm You Have a Current SSP

Without one, no valid assessment exists (see above). Your SSP defines the boundary you’re scoring.

Step 2: List the Requirements

Start with the complete list of NIST 800-171 Rev 2 requirements. The official DoD Assessment Methodology document (v1.2.1) lists each requirement with its point value in Annex A.

Step 3: Assess Each Requirement

For each requirement, determine your implementation status:

  • Implemented: Fully in place and operational — every assessment objective in NIST SP 800-171A satisfied
  • Partially Implemented: Some aspects in place, but gaps exist
  • Not Implemented: Not in place or not operational
  • Not Applicable: Does not apply to your environment (rare — must be justified, and formal N/A determinations require DoD CIO adjudication)

Step 4: Score Your Status

  • Implemented: No points deducted
  • Partially Implemented: Full points deducted — except for 3.5.3 and 3.13.11, the only two controls with built-in partial credit
  • Not Implemented: Full points deducted
  • Not Applicable: No points deducted, with documented justification

One more nuance the methodology allows: a temporary deficiency being actively worked in a plan of action — like a control that was implemented but broke due to a patch — can be assessed as implemented. A control you simply haven’t built yet is not a temporary deficiency.

Step 5: Calculate Total Deductions

Add up the point values for all requirements marked partially implemented (except the two exceptions at their reduced value) or not implemented.

Step 6: Subtract from 110

Your SPRS Score = 110 − Total Deductions

Scoring Examples

Example 1: Strong Compliance

A contractor has fully implemented all but 5 requirements:

  • One 5-point requirement (5)
  • Two 3-point requirements (6)
  • Two 1-point requirements (2)

Calculation: 110 − 5 − 6 − 2 = 97

Example 2: Moderate Gaps

Gaps in 15 requirements:

  • Three 5-point requirements (15)
  • Seven 3-point requirements (21)
  • Five 1-point requirements (5)

Calculation: 110 − 15 − 21 − 5 = 69

Example 3: The Partial-Credit Difference

A contractor has MFA deployed for remote and privileged accounts but not general users, and encrypts CUI with modules that aren’t FIPS-validated:

  • 3.5.3 partial: −3 (instead of −5)
  • 3.13.11 encryption-but-not-FIPS: −3 (instead of −5)
  • Plus four other 1-point gaps: −4

Calculation: 110 − 3 − 3 − 4 = 100

The same environment scored without knowing the partial-credit rules would report 96 — an unnecessary 4-point understatement. Accuracy cuts both ways.

Example 4: Major Deficiencies

Gaps in 50 requirements, including most critical controls:

  • Fifteen 5-point requirements (75)
  • Twenty-five 3-point requirements (75)
  • Ten 1-point requirements (10)

Calculation: 110 − 75 − 75 − 10 = −50

Understanding Negative Scores

Yes, your score can go negative. The theoretical minimum is −203 if you have implemented nothing.

Negative scores are common on a first honest assessment — the 5-point controls (enterprise MFA, FIPS cryptography, boundary protection, logging) are exactly the ones small contractors tend to leave for last. A negative score doesn’t automatically disqualify you from contracts, but it signals significant work ahead, and some solicitations set minimum score thresholds.

An honest −20 with a credible POA&M is a defensible position. An inflated 110 is not.

Common Scoring Mistakes

Mistake 1: Misapplying (or Missing) Partial Credit

Only 3.5.3 and 3.13.11 have partial scoring, under the specific conditions above. Claiming partial credit anywhere else overstates your score; failing to claim it where it legitimately applies understates it. Both are inaccuracies — and after July 2026, inaccuracy is the risk.

Mistake 2: Marking Requirements Not Applicable Without Justification

Very few requirements are truly not applicable, and formal N/A treatment runs through DoD CIO adjudication. Unjustified N/A designations are among the first things a government-led assessment will challenge.

Mistake 3: Confusing Policy with Implementation

Having a policy document does not mean a requirement is implemented. A policy saying you will encrypt CUI does not count — you must actually encrypt CUI, and NIST SP 800-171A’s assessment objectives are the yardstick.

Mistake 4: Not Assessing All Systems in the Boundary

Your assessment must cover every system in your CUI environment as defined in your SSP. Missing systems means missing requirements, which means an inaccurate score.

Mistake 5: Self-Scoring Too Generously

Overstating your compliance creates direct legal risk under the False Claims Act — the enforcement tool the DOJ’s Civil Cyber-Fraud Initiative uses against contractors who misrepresent cybersecurity compliance. With third-party audits suspended, there is no assessor left to catch the gap before the government relies on your number. Be honest and conservative.

Mistake 6: Scoring Without an SSP

See above — without a current SSP, the methodology says no assessment can be completed at all.

What Score Do You Need?

There is no universal minimum score, but consider these factors:

Contract Requirements

Some contracts specify minimum scores. Check solicitation requirements for specific thresholds.

The 88-Point CMMC Threshold

Under 32 CFR § 170.21, conditional CMMC Level 2 status requires a minimum score of 88 out of 110 (80% of 110 points is 88 — a common trap is assuming 80% means a score of 80), with remaining gaps documented in a POA&M and closed within 180 days. Certain critical requirements can’t be POA&M’d at all.

Note: C3PAO certification assessments are suspended as of July 13, 2026, so this threshold isn’t currently being tested by third parties — but it remains the benchmark in the CMMC rule, it’s the bar a reformed program would most likely inherit, and 88 is a sensible internal floor for any contractor handling CUI today.

Competitive Positioning

Contracting officers can see your SPRS score, and primes evaluate subcontractor posture regardless of what the certification program does. A higher — accurate — score is an advantage.

Target: 110

The goal is full compliance at 110. Anything less indicates gaps that need remediation, tracked in a POA&M.

After Calculating Your Score

Document Your Assessment

Create an assessment report documenting your methodology, findings, and score calculation, control by control. This evidence file is what makes your score defensible.

Create a POA&M

For every gap, document the remediation plan with milestones and timelines. Remember: a POA&M buys time and demonstrates good faith, but it does not restore deducted points.

Submit to SPRS

Enter your score in SPRS through the PIEE portal (you’ll need a PIEE account with the SPRS “Cyber Vendor” role). Your assessment date must be within the last three years to be considered current.

Affirm It — Carefully

Your company’s Affirming Official annually attests to the score’s accuracy in SPRS. That signature is a statement to the federal government in connection with contract awards — squarely inside the False Claims Act. It deserves the same rigor a third-party auditor would have brought.

Plan Remediation

Prioritize closing gaps on high-point-value requirements for maximum score improvement — they’re the highest security impact and the fastest way to move the number honestly.

Frequently Asked Questions

What is a good SPRS score?

110 is full implementation and the only score with zero gaps. 88 is the conditional CMMC Level 2 threshold under 32 CFR § 170.21 and a sensible internal floor for CUI handlers. There’s no universal contractual minimum, but an accurate score — even a low one paired with a credible POA&M — is always better positioned than an inflated one.

Can my SPRS score be negative?

Yes. The scale runs from 110 down to −203. Negative first-pass scores are common because the highest-weighted controls (MFA, FIPS cryptography, boundary protection, logging) are the ones most often unimplemented. A negative score is a starting point, not a disqualification.

Is there partial credit in SPRS scoring?

Only for two controls: 3.5.3 (multi-factor authentication) and 3.13.11 (FIPS-validated cryptography), each of which can deduct 3 points instead of 5 in defined partial-implementation cases. Every other requirement is all-or-nothing — a control that’s 80% done deducts its full value.

Do I still need to submit an SPRS score after the CMMC Phase 2 suspension?

Yes. The July 13, 2026 suspension paused third-party (C3PAO) assessments — it did not touch DFARS 252.204-7019/7020 SPRS scoring requirements, the annual affirmation, or your DFARS 252.204-7012 obligation to implement NIST SP 800-171. During the suspension, your self-assessed SPRS score is the government’s primary compliance signal.

How often do I need to update my SPRS score?

Your Basic self-assessment must be current within three years to be valid, and your Affirming Official affirms annually. Best practice: reassess and update after any material change to your environment — and immediately if you discover your current score doesn’t reflect reality.

Can I get in legal trouble for an inaccurate SPRS score?

Yes. Knowingly submitting an inflated score, or affirming compliance you aren’t maintaining, can violate the False Claims Act — with treble damages. The DOJ’s Civil Cyber-Fraud Initiative has already settled cases with defense contractors over misrepresented scores, and FCA cases are frequently initiated by whistleblowers.

Key Takeaways

Your SPRS score starts at 110 and decreases based on unimplemented NIST 800-171 Rev 2 requirements. Scored requirements are worth 1, 3, or 5 points, with partial credit available only for MFA (3.5.3) and FIPS cryptography (3.13.11) — and no valid score exists at all without a current SSP.

The conditional CMMC Level 2 benchmark is 88, not 80 — but with third-party assessments suspended since July 13, 2026, the score that matters most is the one your Affirming Official signs. Accuracy is now your primary legal protection.

Assess honestly against the NIST SP 800-171A objectives, document your evidence control by control, track gaps in a POA&M, and focus remediation on high-point requirements for the biggest honest score improvements.

Related Articles:

Official Sources:

The audit is suspended; the number you sign for isn’t. If you’re not certain your environment supports the score in SPRS next to your CAGE code, contact Greypike about SPRS Attestation Assurance — an independent NIST SP 800-171 Rev 2 assessment, control-by-control evidence collection, corrected scoring, and support for your Affirming Official.

Tags:
Table of Contents