Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
What is SPRS?
SPRS is the Supplier Performance Risk System—a Department of Defense database where defense contractors submit their cybersecurity assessment scores. If you want to win DoD contracts, your CMMC compliance status must be recorded in SPRS before contract award.
SPRS stands for Supplier Performance Risk System—the official DoD database for tracking contractor cybersecurity compliance and assessment scores.
Think of SPRS as your cybersecurity report card that the DoD checks before awarding contracts. No SPRS score means no contract eligibility.
Calculate Your SPRS Score With Our Calculator
Calculate your NIST SP 800-171 self-assessment score, identify your compliance gaps, and know exactly what to report in SPRS — before a contracting officer asks for it.
Why SPRS Matters for Defense Contractors
Starting with the CMMC program rollout, contracting officers verify your compliance status in SPRS before awarding contracts. This is not optional—it is a contractual requirement.
SPRS serves several purposes:
Contract Eligibility Verification
Contracting officers check SPRS to confirm you meet cybersecurity requirements before awarding contracts. Without a current, valid score in SPRS, you cannot receive contract awards requiring CMMC certification.
Standardized Reporting
SPRS provides a single, authoritative source for contractor compliance information. Instead of each contractor providing documentation separately to each contracting officer, SPRS centralizes this data.
Risk Assessment
The DoD uses SPRS data to assess supply chain risk. Your score helps the government understand the cybersecurity posture of its contractor base.
Compliance Tracking
SPRS maintains records of assessment dates, scores, and certification status, creating an audit trail of contractor compliance over time.
What Information SPRS Contains
Your SPRS record includes several key data elements:
Assessment Score
For NIST SP 800-171 self-assessments, this is a number from -203 to 110. A score of 110 means full implementation of all 110 security requirements. Lower scores indicate gaps, with each unimplemented requirement reducing your score based on its weighted value.
NIST SP 800-171 is the federal standard specifying 110 security requirements for protecting Controlled Unclassified Information (CUI).
Assessment Date
When your assessment was conducted. Assessments must be current—outdated assessments may not satisfy contract requirements.
Assessment Type
Whether the assessment was a self-assessment (conducted by your organization) or a third-party assessment (conducted by a Certified Third-Party Assessment Organization).
C3PAO stands for Certified Third-Party Assessment Organization—companies authorized to conduct official CMMC certification assessments.
CMMC Level and Status
Your certified CMMC level and whether certification is final or conditional.
Plan of Action and Milestones (POA&M)
If you have a POA&M documenting gaps and remediation plans, this is noted in SPRS along with the date gaps will be closed.
POA&M stands for Plan of Action and Milestones—a document listing security gaps and your plan to fix them.
Who Must Submit to SPRS
All defense contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) must have current information in SPRS:
CMMC Level 1 Contractors
Contractors handling only FCI must conduct annual self-assessments and submit scores to SPRS. Level 1 requires implementing 15 basic security practices from FAR 52.204-21.
FCI stands for Federal Contract Information—information provided by or generated for the government under contract, not intended for public release.
CMMC Level 2 Contractors (Self-Assessment)
Some Level 2 contractors may qualify for self-assessment rather than third-party certification. These contractors must submit their NIST 800-171 assessment scores to SPRS.
CMMC Level 2 Contractors (Certification)
Contractors requiring third-party certification will have their certification status recorded in SPRS by the CMMC ecosystem after successful C3PAO assessment.
Subcontractors
Subcontractors with flow-down requirements must also maintain current SPRS records. Prime contractors may verify subcontractor SPRS status before awarding subcontracts.
SPRS Score Range
For NIST SP 800-171 assessments, scores range from -203 to 110:
Score of 110
Full implementation of all 110 requirements. This is the target score indicating complete compliance.
Scores Between 0 and 109
Partial implementation with some gaps. Each unimplemented requirement reduces your score based on its assigned point value (1, 3, or 5 points).
Negative Scores
Significant gaps exist. Negative scores indicate many unimplemented requirements. Some contracts may have minimum score thresholds.
Scoring Example
If you have not implemented 5 requirements worth 3 points each and 2 requirements worth 5 points each:
- Starting score: 110
- Minus 15 points (5 × 3)
- Minus 10 points (2 × 5)
- Final score: 85
How to Access SPRS
SPRS is accessed through the Procurement Integrated Enterprise Environment (PIEE) portal:
Website: https://www.sprs.csd.disa.mil
Access Requirements
To submit information to SPRS, you need:
- PIEE account with appropriate roles
- Commercial and Government Entity (CAGE) code for your company
- Designated representative authorized to submit on behalf of your organization
CAGE code is a five-character identifier assigned to companies doing business with the federal government.
User Roles
SPRS uses role-based access:
- SPRS Cyber Vendor View: View your own company’s information
- SPRS NIST Assessor: Submit assessment scores
- Government users: View contractor information for acquisition decisions
SPRS and Contract Requirements
Several DFARS clauses connect to SPRS requirements:
DFARS 252.204-7019
Requires contractors to have a current NIST 800-171 DoD Assessment on record in SPRS. This clause made the SPRS submission mandatory for contracts involving CUI.
DFARS stands for Defense Federal Acquisition Regulation Supplement—contract clauses specific to DoD contracts.
DFARS 252.204-7020
Provides the government authority to assess contractor compliance and requires contractors to provide access for assessments.
DFARS 252.204-7021
The CMMC requirements clause will require appropriate CMMC certification status in SPRS.
Keeping SPRS Current
Your SPRS information must remain current:
Assessment Frequency
- Level 1: Annual self-assessment and affirmation
- Level 2 (self-assessment): Annual self-assessment and affirmation
- Level 2 (certification): Triennial C3PAO assessment with annual affirmation
Updating After Changes
If your security posture changes significantly—either improving through remediation or degrading due to new gaps—update your SPRS record accordingly.
POA&M Updates
If you submitted a score with an associated POA&M, update SPRS when you complete remediation items and achieve a higher score.
Common SPRS Questions
Can competitors see my SPRS score?
No. SPRS data is protected. Only government users with appropriate access can view contractor scores for acquisition purposes. Competitors cannot access your information.
What if my score is low?
A low score does not necessarily disqualify you from all contracts, but some contracts may have minimum score requirements. Focus on remediation to improve your score over time.
How often must I update SPRS?
At a minimum, annually. Update sooner if your security posture changes significantly or when you complete POA&M items.
Is SPRS the same as CMMC certification?
No. SPRS is the database where compliance information is recorded. CMMC certification is the actual verification of your security practices. Your CMMC status is recorded in SPRS.
Key Takeaways
SPRS is the DoD’s official database for contractor cybersecurity compliance. Your assessment scores and CMMC certification status must be recorded in SPRS before you can receive contract awards.
Access SPRS through the PIEE portal at sprs.csd.disa.mil. Maintain current assessments and update your SPRS record at least annually or when your security posture changes.
Without a current SPRS record, you are ineligible for DoD contracts requiring CMMC certification.
Related Articles:
- What is CMMC Level 2?
- CMMC Access Control Requirements for Level 2
- How to Calculate Your SPRS Score
- SPRS Portal
- DFARS 252.204-7019
- 32 CFR Part 170 – CMMC Program Rule
Official Sources: This article is based on DFARS clauses 252.204-7019, 7020, and 7021, the DoD CMMC Program Rule (32 CFR Part 170), and official SPRS documentation from the Defense Logistics Agency.
Need help with your SPRS submission and CMMC compliance? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.