If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
Expired SPRS Score and a Bid Due? Fix It This Week
An expired SPRS score is the most fixable emergency in this whole category, and it never announces itself in advance. A proposal is due Thursday, somebody finally opened the SPRS record, and the assessment date on it is from 2022. The question that follows is always the same: does this disqualify us, and can it be fixed before the deadline. The short answer is that it is fixable, usually within a day or two, and the thing that will hurt you is not the expired date but a rushed replacement score you cannot support. This article sits inside Something Just Happened and You Need CMMC: A Triage Guide.
What an expired SPRS score actually means under the clause
DFARS 252.204-7019 says that to be considered for award, an offeror required to implement NIST SP 800-171 must have a current assessment on record in SPRS, and it defines current as not more than three years old unless the solicitation specifies a shorter period. That last clause matters. Some solicitations ask for an assessment inside twelve months, and a score that is perfectly valid under the three year rule can still fail the specific solicitation in front of you.
Two consequences follow. First, the relevant date is the assessment date, not the date you last logged into PIEE or the date you last edited anything. Second, nothing automatically removes an old score. It stays visible with its original date, which means a contracting officer can see exactly how stale it is.
What the clause does not require is a good score. It requires a current one. That distinction is the difference between a problem you can solve this week and a problem you cannot.
Four fields to check before you do anything else
- Assessment date. The single field that determines whether you are eligible. Compare it to today and to any shorter window the solicitation names.
- Assessment scope. SPRS records the boundary the score covers. If the scope description is vague or describes a system you no longer run, the score has a second problem beyond its age.
- Confidence level. Basic, Medium or High. A Basic self-assessment is what most small contractors have and is acceptable under the clause.
- Affirming official. Whoever is named there attested to the number. If that person has left the company, you have an administrative task waiting regardless of the deadline.
If the solicitation in front of you also asks for a certification rather than a score, read an RFP requires a Level 2 certification you don’t have before you respond, because those are different asks.
You need a PIEE account with the SPRS Cyber Vendor role to see and edit any of this. If nobody at your company currently holds that role, provisioning it is the long pole in the tent, not the assessment itself. Start that request today even if you plan to do the scoring next week.
The realistic timeline
| Task | Time | Notes |
|---|---|---|
| Obtain or confirm the PIEE Cyber Vendor role | 1 to 10 business days | Depends entirely on your company’s PIEE administrator. This is the step that misses deadlines. |
| Confirm your System Security Plan exists and describes the current environment | Hours to weeks | Without an SSP the methodology says no valid assessment can be completed at all. |
| Score all 110 requirements honestly | 4 to 16 hours | Longer the first time. Faster if you have prior evidence to work from. |
| Enter and submit the score in SPRS | Under an hour | The mechanical part is short. |
| Senior official affirmation | Same day, if they are available | Get this on their calendar early. It is a signature with legal weight, not a formality. |
Read that table as a warning about sequence rather than duration. An expired SPRS score is not what costs companies the bid. The scoring work is not what runs out of time. Access provisioning and a missing SSP are what run out of time.
The SSP problem, which is the one people discover late
The DoD Assessment Methodology treats requirement 3.12.4, the System Security Plan, differently from every other requirement. It carries no point value. Instead, its absence produces a finding that the assessment could not be completed because of incomplete information, together with a finding of noncompliance with DFARS 252.204-7012.
If you do not have one, How to Write a CMMC System Security Plan covers the structure, and 90 days to get compliant covers where it sits in a compressed timeline.
In practice that means you cannot produce a defensible score without a current SSP that describes the environment you are actually running today. If your SSP is a template with your logo on the front page, or it describes a network you replaced in 2023, that is the work item standing between you and a valid submission. It is also the work item most likely to be discovered on the Tuesday before a Thursday deadline.
If the proposal is already submitted
Post the corrected score anyway, and do it promptly. The clause conditions award eligibility, and awards happen after submission. A score that becomes current before award is materially better than one that does not.
Then tell the contracting officer, in writing, that you have updated your assessment and give the new date. If the same question arrives from a prime as a spreadsheet rather than from a contracting officer, your prime just sent you a cybersecurity questionnaire covers that response. This is unglamorous and it works. Contracting officers deal with stale SPRS records constantly, and a supplier who identifies the problem and fixes it reads very differently from one who waits to be asked.
Do not amend a submitted proposal to reference the new score unless the solicitation provides a mechanism for it. Send the notification through the channel the solicitation specifies for questions and correspondence.
Posting a number you can defend
The pressure of a deadline creates a specific temptation, which is to enter a number that looks respectable rather than the number your environment supports. Understand what that costs you.
The annual affirmation attached to your SPRS record is a statement made to the federal government in connection with contract awards. The Department of Justice Civil Cyber-Fraud Initiative has settled multiple cases against contractors whose reported cybersecurity posture did not match reality, and those cases are frequently initiated by employees. Since July 13, 2026, when CMMC Phase 2 certification assessments were suspended, there is no longer a third party assessor who would eventually surface the gap between your reported score and your actual environment. Your self assessment is what the government relies on.
An honest score of 42 with a credible Plan of Action and Milestones is a normal supplier position and rarely costs an award on its own. A 110 you cannot evidence is a different category of problem entirely, and it does not expire in three years.
For the mechanics of scoring, including the weighted values and the two controls that allow partial credit, see How to Calculate Your SPRS Score.
Preventing the next expired SPRS score
Set a calendar reminder for two years and nine months from your new assessment date. The three year window is generous enough that most companies forget about it entirely and rediscover the problem the same way you just did.
Better than a reminder is a trigger. Reassess whenever you materially change the environment: a new cloud tenant, a new location handling controlled information, a change of managed service provider, a merger. Those events change your score whether or not you update the record, and the record is what the government reads.
Frequently asked
Questions about this topic
How old can an assessment be before you have an expired SPRS score?
Can I update my SPRS score the same week a proposal is due?
Does an expired SPRS score automatically disqualify our bid?
What happens if we post a low score?
Do we need a System Security Plan before we can submit a score?
Is the annual affirmation the same thing as the assessment?
Keep reading
More in Trigger Events & Urgent Situations
- 90 Days to CMMC Compliance: What Is Really Possible →
- CMMC Compliant MSP? How to Verify What Yours Claims →
- CMMC Level 2 Certification an RFP Wants? Bid Anyway →
- CMMC Trigger Events: A Triage Guide for Contractors →
- CUI in Commercial Microsoft 365: What to Do Now →
- CUI Marked Drawings You Were Not Expecting? Do This →
- Cybersecurity Questionnaire From Your Prime? Do This →
- DFARS 7021 Clause Found After Award? Read This First →
- Dropped Without CMMC? What a Prime Can Actually Do →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5