Skip to content
Industry update

CMMC Phase 2 C3PAO assessments are suspended. Your NIST 800-171 and SPRS obligations are not. Read the plain-English breakdown →

Greypike
  • About Us
  • Services
    Practices
    CybersecurityMonitoring, testing, and response — run for you. ComplianceOne control set, mapped to every framework you owe. AIGoverned, secured, and inside your boundary.
    How we deliver it
    Secure EnclaveThe hardened environment your regulated data lives in — built in your own cloud account. vCISOSecurity leadership without the hire, from a named practitioner.
    All services → Book a scoping session →
  • Pricing
  • Resources
    FrameworksCMMC, 800-171, export control, SOC 2, HIPAA and more — what each one is. KnowledgebasePlain-English answers to common compliance questions. BlogInsights on security, compliance, and government contracting. FAQStraight answers — including where our work stops and what we’re not. Readiness assessmentGauge where you stand before you commit to anything.
    Prefer to talk it through? Book a scoping session →
  • Contact Us
Free assessment Client portal

CMMC

/

September 19, 2025

Unlocking Your SPRS Score: Proven Method and Importance

SPRS Score

If you’re a Department of Defense (DoD) contractor, you’ve probably heard people talk about something called an SPRS Score. At first, it sounds like just another government acronym, but it’s actually a big deal. Your Supplier Performance Risk System (SPRS) score can make or break your ability to win contracts.

Let’s walk through what this score is, how to calculate it, and why it matters more than most people realize.

What is an SPRS Score?

The SPRS is like the DoD’s report card system for contractors. It collects data on how suppliers perform — not just whether they deliver on time or meet quality standards, but also how well they protect sensitive information. Your SPRS Score specifically refers to how well you’re doing on cybersecurity, based on how many of the 110 security requirements from NIST SP 800-171 you have fully implemented. These requirements are designed to protect Controlled Unclassified Information (CUI).

Every company that handles CUI has to submit a self-assessment, and the score from that self-assessment gets entered into the SPRS system. That’s the number people mean when they talk about your “SPRS Score.”

How the Score Works

Here’s how it breaks down: you start with 110 possible points — one for each NIST requirement. Every time you haven’t fully implemented a requirement, you subtract points.

But not all requirements are weighted the same. Some are more important, so they carry heavier point deductions. For example, missing something like multi-factor authentication might cost you 5 points, while not having a policy written down could cost 1 or 2 points. Your total can range from -203 (if nothing is implemented) up to +110 (if everything is fully done).

The DoD expects you to have a Plan of Action & Milestones (POA&M) for any gaps. That plan says what you’re missing, how you’ll fix it, and when you’ll be done. But keep in mind: your score only counts what’s done now, not what you plan to do later.

How to Calculate Your SPRS Score

Calculating your score might sound intimidating, but it’s actually straightforward if you take it step by step. Here’s what the process looks like in plain language.

First, you gather all the NIST 800-171 requirements. There are 110 of them, split across 14 families like Access Control, Incident Response, and System Integrity. Then, you check each one and ask: “Are we fully doing this?” If the answer is yes, you get the points. If the answer is no, you subtract the assigned point value.

The DoD provides a scoring sheet (called the NIST SP 800-171 DoD Assessment Methodology) that shows how many points each control is worth and how to score it. Some controls are worth -5, -3, or -1 if they’re not done.

When you’ve gone through all 110, you add up the points you earned. That’s your SPRS Score. For example, let’s say you have 90 controls fully done, 15 partially done, and 5 not started. If those 20 missing ones are mostly -1 and -3 controls, you might end up with something like +75. If you were missing bigger -5 controls like multi-factor authentication, your score might be closer to +60. The main thing is your score shows how much of the required security you’ve actually put in place today — not someday in the future.

Where to Submit Your Score

Once you’ve calculated it, you don’t just keep it in a spreadsheet. You have to enter your score into the SPRS website so the DoD can see it. To do that, you log in to the Supplier Performance Risk System using your Procurement Integrated Enterprise Environment (PIEE) account. You’ll go to the “NIST 800-171” section, click “Create New,” and fill in your score, the date, and when you expect to finish any remaining items on your POA&M.

That score stays active for three years — but if anything changes, you’re expected to update it. And any time you bid on a contract, the contracting officer will check your score in the system.

Why Your SPRS Score Matters So Much

Your SPRS Score isn’t just some random number on a government form. It’s part of how the DoD decides if they can trust your company with their data. If your score is low, it sends a signal that your security might be weak. That can make contracting officers nervous about awarding you work, especially if you’re handling CUI. A low score can even block you from bidding on certain contracts. Many solicitations require you to have an active SPRS score before they’ll consider your proposal. No score, no bid.

And if you claim a high score but don’t really have the controls in place, you could face False Claims Act penalties for misrepresenting your cybersecurity. That’s why it’s so important to be accurate and honest when you calculate it.

How to Improve Your Score

If your score isn’t where you want it to be, don’t panic. Improving it just means knocking out the missing requirements one by one. Start with the high-value controls (the ones worth -5 or -3) because fixing those will raise your score the fastest.

Create a clear POA&M that lists what you’re missing, who’s responsible for fixing it, and a deadline. Then actually work the plan — update policies, add technical controls, and train your staff.

As you close the gaps, you can submit an updated score in SPRS showing your progress. That shows the DoD you’re serious about cybersecurity and building toward full compliance.

If you need more help, Greypike helps government contractors get compliant with CMMC, NIST SP 800-171, and FedRAMP, among others. Contact us today if you get stuck!

Wrapping It Up

Your SPRS Score is more than just a number — it’s your company’s cybersecurity reputation with the Department of Defense. Understanding how to calculate it and why it matters can save you from lost contracts, compliance headaches, and even legal trouble.

By tackling your missing requirements and steadily raising your score, you’re not just checking boxes. You’re proving your company is trustworthy, reliable, and ready to protect the DoD’s data.

From the same category

DoW suspended CMMC Phase 2 on July 13, 2026 — but NIST 800-171, DFARS 7012, and SPRS affirmations still apply. A plain-English FAQ for defense contractors.
CMMC Phase 2 Suspended: What You Still Have to Do in 2026
CMMC, CMMC Level 2, Compliance, DoD ContractingJuly 14, 2026
Diagram showing data leaving a laptop and traveling to remote AI servers, illustrating AI data risk for CUI and CMMC compliance
Using AI in a CUI Environment: What Every Defense Contractor Needs to Understand First
AI, CMMC, ComplianceJune 30, 2026
MMC scope reduction cost comparison showing $545,000 whole-environment scope vs $352,200 enclave scope saving defense contractors $192,800
CMMC Scope Reduction: The 2026 Guide to Cutting Compliance Costs by 40%+
CMMC, CMMC Level 2, ComplianceMay 13, 2026
CMMC Level 2 assessment boundary step-by-step scoping process showing the 9 stages from contract review through mock assessment
How to Define Your CMMC Level 2 Assessment Boundary: A Step-by-Step Guide
CMMC, ComplianceMay 13, 2026
C3PAO vs RPO for CMMC Level 2
C3PAO vs RPO: Which Do You Need for CMMC Level 2?
CMMCMay 13, 2026
CMMC Level 2 small business cost comparison showing three paths with three-year totals from $90K self-assessment to $700K full environment
CMMC Level 2 for Small Defense Contractors: The Three Realistic Paths and What Each Actually Costs
AI, CMMC, CMMC Level 2, Compliance, DoD Contracting, Small Business ComplianceMay 1, 2026
Greypike — security, compliance, and AI for government contractors

Questions? Let’s talk.

(703) 214-9246
[email protected]

CAGE: 9WVS6
SAM UEI: N6CJNGDARFM5
DUNS: 132171639
SBA-certified Veteran-Owned Small Business

Request a quote

Company

  • About Us
  • Services
  • Pricing
  • Contact Us

Services

  • Cybersecurity
  • Compliance
  • AI
  • Secure Enclave
  • vCISO

Resources

  • Frameworks
  • Knowledge Base
  • Readiness Assessment
  • Blog
© 2026 Greypike Inc. All rights reserved. · Veteran-owned small business Privacy Policy · Terms
Go to Top
  • About Us
  • Services
    • Enclave
    • GreypikeAI
  • Pricing
  • Contact Us
  • Resources
    • CMMC Knowledge Base
    • CMMC Readiness
    • Blogs