Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

Expired SPRS Score and a Bid Due? Fix It This Week

An expired SPRS score is the most fixable emergency in this whole category, and it never announces itself in advance. A proposal is due Thursday, somebody finally opened the SPRS record, and the assessment date on it is from 2022. The question that follows is always the same: does this disqualify us, and can it be fixed before the deadline. The short answer is that it is fixable, usually within a day or two, and the thing that will hurt you is not the expired date but a rushed replacement score you cannot support. This article sits inside Something Just Happened and You Need CMMC: A Triage Guide.

What an expired SPRS score actually means under the clause

DFARS 252.204-7019 says that to be considered for award, an offeror required to implement NIST SP 800-171 must have a current assessment on record in SPRS, and it defines current as not more than three years old unless the solicitation specifies a shorter period. That last clause matters. Some solicitations ask for an assessment inside twelve months, and a score that is perfectly valid under the three year rule can still fail the specific solicitation in front of you.

Two consequences follow. First, the relevant date is the assessment date, not the date you last logged into PIEE or the date you last edited anything. Second, nothing automatically removes an old score. It stays visible with its original date, which means a contracting officer can see exactly how stale it is.

What the clause does not require is a good score. It requires a current one. That distinction is the difference between a problem you can solve this week and a problem you cannot.

Four fields to check before you do anything else

  1. Assessment date. The single field that determines whether you are eligible. Compare it to today and to any shorter window the solicitation names.
  2. Assessment scope. SPRS records the boundary the score covers. If the scope description is vague or describes a system you no longer run, the score has a second problem beyond its age.
  3. Confidence level. Basic, Medium or High. A Basic self-assessment is what most small contractors have and is acceptable under the clause.
  4. Affirming official. Whoever is named there attested to the number. If that person has left the company, you have an administrative task waiting regardless of the deadline.

If the solicitation in front of you also asks for a certification rather than a score, read an RFP requires a Level 2 certification you don’t have before you respond, because those are different asks.

You need a PIEE account with the SPRS Cyber Vendor role to see and edit any of this. If nobody at your company currently holds that role, provisioning it is the long pole in the tent, not the assessment itself. Start that request today even if you plan to do the scoring next week.

The realistic timeline

TaskTimeNotes
Obtain or confirm the PIEE Cyber Vendor role1 to 10 business daysDepends entirely on your company’s PIEE administrator. This is the step that misses deadlines.
Confirm your System Security Plan exists and describes the current environmentHours to weeksWithout an SSP the methodology says no valid assessment can be completed at all.
Score all 110 requirements honestly4 to 16 hoursLonger the first time. Faster if you have prior evidence to work from.
Enter and submit the score in SPRSUnder an hourThe mechanical part is short.
Senior official affirmationSame day, if they are availableGet this on their calendar early. It is a signature with legal weight, not a formality.

Read that table as a warning about sequence rather than duration. An expired SPRS score is not what costs companies the bid. The scoring work is not what runs out of time. Access provisioning and a missing SSP are what run out of time.

The SSP problem, which is the one people discover late

The DoD Assessment Methodology treats requirement 3.12.4, the System Security Plan, differently from every other requirement. It carries no point value. Instead, its absence produces a finding that the assessment could not be completed because of incomplete information, together with a finding of noncompliance with DFARS 252.204-7012.

If you do not have one, How to Write a CMMC System Security Plan covers the structure, and 90 days to get compliant covers where it sits in a compressed timeline.

In practice that means you cannot produce a defensible score without a current SSP that describes the environment you are actually running today. If your SSP is a template with your logo on the front page, or it describes a network you replaced in 2023, that is the work item standing between you and a valid submission. It is also the work item most likely to be discovered on the Tuesday before a Thursday deadline.

If the proposal is already submitted

Post the corrected score anyway, and do it promptly. The clause conditions award eligibility, and awards happen after submission. A score that becomes current before award is materially better than one that does not.

Then tell the contracting officer, in writing, that you have updated your assessment and give the new date. If the same question arrives from a prime as a spreadsheet rather than from a contracting officer, your prime just sent you a cybersecurity questionnaire covers that response. This is unglamorous and it works. Contracting officers deal with stale SPRS records constantly, and a supplier who identifies the problem and fixes it reads very differently from one who waits to be asked.

Do not amend a submitted proposal to reference the new score unless the solicitation provides a mechanism for it. Send the notification through the channel the solicitation specifies for questions and correspondence.

Posting a number you can defend

The pressure of a deadline creates a specific temptation, which is to enter a number that looks respectable rather than the number your environment supports. Understand what that costs you.

The annual affirmation attached to your SPRS record is a statement made to the federal government in connection with contract awards. The Department of Justice Civil Cyber-Fraud Initiative has settled multiple cases against contractors whose reported cybersecurity posture did not match reality, and those cases are frequently initiated by employees. Since July 13, 2026, when CMMC Phase 2 certification assessments were suspended, there is no longer a third party assessor who would eventually surface the gap between your reported score and your actual environment. Your self assessment is what the government relies on.

An honest score of 42 with a credible Plan of Action and Milestones is a normal supplier position and rarely costs an award on its own. A 110 you cannot evidence is a different category of problem entirely, and it does not expire in three years.

For the mechanics of scoring, including the weighted values and the two controls that allow partial credit, see How to Calculate Your SPRS Score.

Preventing the next expired SPRS score

Set a calendar reminder for two years and nine months from your new assessment date. The three year window is generous enough that most companies forget about it entirely and rediscover the problem the same way you just did.

Better than a reminder is a trigger. Reassess whenever you materially change the environment: a new cloud tenant, a new location handling controlled information, a change of managed service provider, a merger. Those events change your score whether or not you update the record, and the record is what the government reads.

Frequently asked

Questions about this topic

How old can an assessment be before you have an expired SPRS score?
DFARS 252.204-7019 defines a current assessment as one not more than three years old, unless the solicitation specifies a shorter period. Always check the solicitation, because a shorter window overrides the general rule and a score that is valid elsewhere may not be valid for that particular bid.
Can I update my SPRS score the same week a proposal is due?
The submission itself takes under an hour once you have PIEE access with the Cyber Vendor role and a completed assessment. The parts that take real time are obtaining that role if nobody holds it, and producing or updating the System Security Plan the assessment depends on. Start with the access request.
Does an expired SPRS score automatically disqualify our bid?
The clause conditions eligibility for award on having a current assessment on record. An expired score is a genuine eligibility problem, but it is one you can usually correct before award rather than a permanent bar. Correct it and notify the contracting officer in writing.
What happens if we post a low score?
Nothing automatic. The clause requires currency, not a threshold. Some solicitations set minimum scores, so read yours, but in the general case a low score paired with a documented Plan of Action and Milestones is a survivable and very common position.
Do we need a System Security Plan before we can submit a score?
Yes. The DoD Assessment Methodology assigns no point value to requirement 3.12.4 and instead treats a missing System Security Plan as a finding that the assessment could not be completed, along with noncompliance with DFARS 252.204-7012. There is no valid score without one.
Is the annual affirmation the same thing as the assessment?
No. The assessment produces the score and is valid for up to three years. The affirmation is a separate annual statement by a named senior official confirming that the posted score remains accurate. Both obligations continue during the CMMC Phase 2 suspension.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Table of Contents