Skip to content
July 13 Update

CMMC Phase 2 audits are suspended. Your NIST 800-171 and SPRS obligations are not. Read the plain-English breakdown →

Greypike
  • About Us
  • Services
    CMMC Readiness RoadmapWhere every engagement starts — gap analysis and a prioritized path. Managed Compliant EnclaveA compliant cloud environment, built in your account and managed by us. Managed ComplianceOngoing SSP, POA&M, evidence and audit-readiness for your existing IT. Compliant AI EnablementCopilot and Gemini deployed compliantly, plus custom AI agents.
    Not sure where to start? Book a scoping session →
  • Solutions
    CMMC Level 1Handle FCI? Meet the 15 safeguards via annual self-assessment. CMMC Level 2Handle CUI? All 110 NIST 800-171 controls, with a score you can defend. Solopreneurs & Small TeamsRight-sized compliance for the smallest shops — our Starter enclave. Incorporate AI SecurelyRun Copilot or Gemini inside your accredited environment.
    Not sure which fits? Book a scoping session →
  • Pricing
  • Resources
    KnowledgebasePlain-English answers to common CMMC and NIST 800-171 questions. BlogInsights and updates on compliance, security, and the DIB. CMMC ReadinessGauge where you stand against the controls before you commit. PricingTransparent pricing across every Greypike offer.
    Prefer to talk it through? Book a scoping session →
  • Contact Us
Take a Free CMMC Assessment

CMMC

/

September 19, 2025

Unlocking Your SPRS Score: Proven Method and Importance

SPRS Score

If you’re a Department of Defense (DoD) contractor, you’ve probably heard people talk about something called an SPRS Score. At first, it sounds like just another government acronym, but it’s actually a big deal. Your Supplier Performance Risk System (SPRS) score can make or break your ability to win contracts.

Let’s walk through what this score is, how to calculate it, and why it matters more than most people realize.

What is an SPRS Score?

The SPRS is like the DoD’s report card system for contractors. It collects data on how suppliers perform — not just whether they deliver on time or meet quality standards, but also how well they protect sensitive information. Your SPRS Score specifically refers to how well you’re doing on cybersecurity, based on how many of the 110 security requirements from NIST SP 800-171 you have fully implemented. These requirements are designed to protect Controlled Unclassified Information (CUI).

Every company that handles CUI has to submit a self-assessment, and the score from that self-assessment gets entered into the SPRS system. That’s the number people mean when they talk about your “SPRS Score.”

How the Score Works

Here’s how it breaks down: you start with 110 possible points — one for each NIST requirement. Every time you haven’t fully implemented a requirement, you subtract points.

But not all requirements are weighted the same. Some are more important, so they carry heavier point deductions. For example, missing something like multi-factor authentication might cost you 5 points, while not having a policy written down could cost 1 or 2 points. Your total can range from -203 (if nothing is implemented) up to +110 (if everything is fully done).

The DoD expects you to have a Plan of Action & Milestones (POA&M) for any gaps. That plan says what you’re missing, how you’ll fix it, and when you’ll be done. But keep in mind: your score only counts what’s done now, not what you plan to do later.

How to Calculate Your SPRS Score

Calculating your score might sound intimidating, but it’s actually straightforward if you take it step by step. Here’s what the process looks like in plain language.

First, you gather all the NIST 800-171 requirements. There are 110 of them, split across 14 families like Access Control, Incident Response, and System Integrity. Then, you check each one and ask: “Are we fully doing this?” If the answer is yes, you get the points. If the answer is no, you subtract the assigned point value.

The DoD provides a scoring sheet (called the NIST SP 800-171 DoD Assessment Methodology) that shows how many points each control is worth and how to score it. Some controls are worth -5, -3, or -1 if they’re not done.

When you’ve gone through all 110, you add up the points you earned. That’s your SPRS Score. For example, let’s say you have 90 controls fully done, 15 partially done, and 5 not started. If those 20 missing ones are mostly -1 and -3 controls, you might end up with something like +75. If you were missing bigger -5 controls like multi-factor authentication, your score might be closer to +60. The main thing is your score shows how much of the required security you’ve actually put in place today — not someday in the future.

Where to Submit Your Score

Once you’ve calculated it, you don’t just keep it in a spreadsheet. You have to enter your score into the SPRS website so the DoD can see it. To do that, you log in to the Supplier Performance Risk System using your Procurement Integrated Enterprise Environment (PIEE) account. You’ll go to the “NIST 800-171” section, click “Create New,” and fill in your score, the date, and when you expect to finish any remaining items on your POA&M.

That score stays active for three years — but if anything changes, you’re expected to update it. And any time you bid on a contract, the contracting officer will check your score in the system.

Why Your SPRS Score Matters So Much

Your SPRS Score isn’t just some random number on a government form. It’s part of how the DoD decides if they can trust your company with their data. If your score is low, it sends a signal that your security might be weak. That can make contracting officers nervous about awarding you work, especially if you’re handling CUI. A low score can even block you from bidding on certain contracts. Many solicitations require you to have an active SPRS score before they’ll consider your proposal. No score, no bid.

And if you claim a high score but don’t really have the controls in place, you could face False Claims Act penalties for misrepresenting your cybersecurity. That’s why it’s so important to be accurate and honest when you calculate it.

How to Improve Your Score

If your score isn’t where you want it to be, don’t panic. Improving it just means knocking out the missing requirements one by one. Start with the high-value controls (the ones worth -5 or -3) because fixing those will raise your score the fastest.

Create a clear POA&M that lists what you’re missing, who’s responsible for fixing it, and a deadline. Then actually work the plan — update policies, add technical controls, and train your staff.

As you close the gaps, you can submit an updated score in SPRS showing your progress. That shows the DoD you’re serious about cybersecurity and building toward full compliance.

If you need more help, Greypike helps government contractors get compliant with CMMC, NIST SP 800-171, and FedRAMP, among others. Contact us today if you get stuck!

Wrapping It Up

Your SPRS Score is more than just a number — it’s your company’s cybersecurity reputation with the Department of Defense. Understanding how to calculate it and why it matters can save you from lost contracts, compliance headaches, and even legal trouble.

By tackling your missing requirements and steadily raising your score, you’re not just checking boxes. You’re proving your company is trustworthy, reliable, and ready to protect the DoD’s data.

From the same category

DoW suspended CMMC Phase 2 on July 13, 2026 — but NIST 800-171, DFARS 7012, and SPRS affirmations still apply. A plain-English FAQ for defense contractors.
CMMC Phase 2 Suspended: The Plain-English FAQ for Small Defense Contractors Who Just Want a Straight Answer
CMMC, CMMC Level 2, Compliance, DoD ContractingJuly 14, 2026
Diagram showing data leaving a laptop and traveling to remote AI servers, illustrating AI data risk for CUI and CMMC compliance
Using AI in a CUI Environment: What Every Defense Contractor Needs to Understand First
AI, CMMC, ComplianceJune 30, 2026
MMC scope reduction cost comparison showing $545,000 whole-environment scope vs $352,200 enclave scope saving defense contractors $192,800
CMMC Scope Reduction: The 2026 Guide to Cutting Compliance Costs by 40%+
CMMC, CMMC Level 2, ComplianceMay 13, 2026
CMMC Level 2 assessment boundary step-by-step scoping process showing the 9 stages from contract review through mock assessment
How to Define Your CMMC Level 2 Assessment Boundary: A Step-by-Step Guide
CMMC, ComplianceMay 13, 2026
C3PAO vs RPO for CMMC Level 2
C3PAO vs RPO: Which Do You Need for CMMC Level 2?
CMMCMay 13, 2026
CMMC Level 2 small business cost comparison showing three paths with three-year totals from $90K self-assessment to $700K full environment
CMMC Level 2 for Small Defense Contractors: The Three Realistic Paths and What Each Actually Costs
AI, CMMC, CMMC Level 2, Compliance, DoD Contracting, Small Business ComplianceMay 1, 2026
Greypike — Compliance, Cybersecurity, Managed Services

Questions? Let's Talk!

(703) 214-9246
[email protected]

CAGE: 9WVS6
SAM-UEI: N6CJNGDARFM5
DUNS: 132171639
SBA: Certified VOSB

Request A Quote

Company

  • About Us
  • Services
  • Pricing
  • Contact Us

Solutions

  • CMMC Level 1
  • CMMC Level 2
  • Solopreneurs & Micro Teams
  • AI for CUI

Resources

  • CMMC Knowledge Base
  • CMMC Readiness
  • Blogs
© 2026 Greypike Inc. All rights reserved. · Veteran-Owned Small Business Privacy Policy · Terms
Go to Top
  • About Us
  • Services
    • Enclave
    • GreypikeAI
  • Pricing
  • Contact Us
  • Resources
    • CMMC Knowledge Base
    • CMMC Readiness
    • Blogs