Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

What is SPRS?

SPRS is the Supplier Performance Risk System—a Department of Defense database where defense contractors submit their cybersecurity assessment scores. If you want to win DoD contracts, your CMMC compliance status must be recorded in SPRS before contract award.

SPRS stands for Supplier Performance Risk System—the official DoD database for tracking contractor cybersecurity compliance and assessment scores.

Think of SPRS as your cybersecurity report card that the DoD checks before awarding contracts. No SPRS score means no contract eligibility.

Calculate Your SPRS Score With Our Calculator

Calculate your NIST SP 800-171 self-assessment score, identify your compliance gaps, and know exactly what to report in SPRS — before a contracting officer asks for it.

Why SPRS Matters for Defense Contractors

Starting with the CMMC program rollout, contracting officers verify your compliance status in SPRS before awarding contracts. This is not optional—it is a contractual requirement.

SPRS serves several purposes:

Contract Eligibility Verification

Contracting officers check SPRS to confirm you meet cybersecurity requirements before awarding contracts. Without a current, valid score in SPRS, you cannot receive contract awards requiring CMMC certification.

Standardized Reporting

SPRS provides a single, authoritative source for contractor compliance information. Instead of each contractor providing documentation separately to each contracting officer, SPRS centralizes this data.

Risk Assessment

The DoD uses SPRS data to assess supply chain risk. Your score helps the government understand the cybersecurity posture of its contractor base.

Compliance Tracking

SPRS maintains records of assessment dates, scores, and certification status, creating an audit trail of contractor compliance over time.

What Information SPRS Contains

Your SPRS record includes several key data elements:

Assessment Score

For NIST SP 800-171 self-assessments, this is a number from -203 to 110. A score of 110 means full implementation of all 110 security requirements. Lower scores indicate gaps, with each unimplemented requirement reducing your score based on its weighted value.

NIST SP 800-171 is the federal standard specifying 110 security requirements for protecting Controlled Unclassified Information (CUI).

Assessment Date

When your assessment was conducted. Assessments must be current—outdated assessments may not satisfy contract requirements.

Assessment Type

Whether the assessment was a self-assessment (conducted by your organization) or a third-party assessment (conducted by a Certified Third-Party Assessment Organization).

C3PAO stands for Certified Third-Party Assessment Organization—companies authorized to conduct official CMMC certification assessments.

CMMC Level and Status

Your certified CMMC level and whether certification is final or conditional.

Plan of Action and Milestones (POA&M)

If you have a POA&M documenting gaps and remediation plans, this is noted in SPRS along with the date gaps will be closed.

POA&M stands for Plan of Action and Milestones—a document listing security gaps and your plan to fix them.

Who Must Submit to SPRS

All defense contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) must have current information in SPRS:

CMMC Level 1 Contractors

Contractors handling only FCI must conduct annual self-assessments and submit scores to SPRS. Level 1 requires implementing 15 basic security practices from FAR 52.204-21.

FCI stands for Federal Contract Information—information provided by or generated for the government under contract, not intended for public release.

CMMC Level 2 Contractors (Self-Assessment)

Some Level 2 contractors may qualify for self-assessment rather than third-party certification. These contractors must submit their NIST 800-171 assessment scores to SPRS.

CMMC Level 2 Contractors (Certification)

Contractors requiring third-party certification will have their certification status recorded in SPRS by the CMMC ecosystem after successful C3PAO assessment.

Subcontractors

Subcontractors with flow-down requirements must also maintain current SPRS records. Prime contractors may verify subcontractor SPRS status before awarding subcontracts.

SPRS Score Range

For NIST SP 800-171 assessments, scores range from -203 to 110:

Score of 110

Full implementation of all 110 requirements. This is the target score indicating complete compliance.

Scores Between 0 and 109

Partial implementation with some gaps. Each unimplemented requirement reduces your score based on its assigned point value (1, 3, or 5 points).

Negative Scores

Significant gaps exist. Negative scores indicate many unimplemented requirements. Some contracts may have minimum score thresholds.

Scoring Example

If you have not implemented 5 requirements worth 3 points each and 2 requirements worth 5 points each:

  • Starting score: 110
  • Minus 15 points (5 × 3)
  • Minus 10 points (2 × 5)
  • Final score: 85

How to Access SPRS

SPRS is accessed through the Procurement Integrated Enterprise Environment (PIEE) portal:

Website: https://www.sprs.csd.disa.mil

Access Requirements

To submit information to SPRS, you need:

  • PIEE account with appropriate roles
  • Commercial and Government Entity (CAGE) code for your company
  • Designated representative authorized to submit on behalf of your organization

CAGE code is a five-character identifier assigned to companies doing business with the federal government.

User Roles

SPRS uses role-based access:

  • SPRS Cyber Vendor View: View your own company’s information
  • SPRS NIST Assessor: Submit assessment scores
  • Government users: View contractor information for acquisition decisions

SPRS and Contract Requirements

Several DFARS clauses connect to SPRS requirements:

DFARS 252.204-7019

Requires contractors to have a current NIST 800-171 DoD Assessment on record in SPRS. This clause made the SPRS submission mandatory for contracts involving CUI.

DFARS stands for Defense Federal Acquisition Regulation Supplement—contract clauses specific to DoD contracts.

DFARS 252.204-7020

Provides the government authority to assess contractor compliance and requires contractors to provide access for assessments.

DFARS 252.204-7021

The CMMC requirements clause will require appropriate CMMC certification status in SPRS.

Keeping SPRS Current

Your SPRS information must remain current:

Assessment Frequency

  • Level 1: Annual self-assessment and affirmation
  • Level 2 (self-assessment): Annual self-assessment and affirmation
  • Level 2 (certification): Triennial C3PAO assessment with annual affirmation

Updating After Changes

If your security posture changes significantly—either improving through remediation or degrading due to new gaps—update your SPRS record accordingly.

POA&M Updates

If you submitted a score with an associated POA&M, update SPRS when you complete remediation items and achieve a higher score.

Common SPRS Questions

Can competitors see my SPRS score?

No. SPRS data is protected. Only government users with appropriate access can view contractor scores for acquisition purposes. Competitors cannot access your information.

What if my score is low?

A low score does not necessarily disqualify you from all contracts, but some contracts may have minimum score requirements. Focus on remediation to improve your score over time.

How often must I update SPRS?

At a minimum, annually. Update sooner if your security posture changes significantly or when you complete POA&M items.

Is SPRS the same as CMMC certification?

No. SPRS is the database where compliance information is recorded. CMMC certification is the actual verification of your security practices. Your CMMC status is recorded in SPRS.

Key Takeaways

SPRS is the DoD’s official database for contractor cybersecurity compliance. Your assessment scores and CMMC certification status must be recorded in SPRS before you can receive contract awards.

Access SPRS through the PIEE portal at sprs.csd.disa.mil. Maintain current assessments and update your SPRS record at least annually or when your security posture changes.

Without a current SPRS record, you are ineligible for DoD contracts requiring CMMC certification.

Related Articles:

Official Sources: This article is based on DFARS clauses 252.204-7019, 7020, and 7021, the DoD CMMC Program Rule (32 CFR Part 170), and official SPRS documentation from the Defense Logistics Agency.

Need help with your SPRS submission and CMMC compliance? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.

Tags:
Table of Contents