If you’re a Department of Defense (DoD) contractor, you’ve probably heard people talk about something called an SPRS Score. At first, it sounds like just another government acronym, but it’s actually a big deal. Your Supplier Performance Risk System (SPRS) score can make or break your ability to win contracts.
Let’s walk through what this score is, how to calculate it, and why it matters more than most people realize.
What is an SPRS Score?
The SPRS is like the DoD’s report card system for contractors. It collects data on how suppliers perform — not just whether they deliver on time or meet quality standards, but also how well they protect sensitive information. Your SPRS Score specifically refers to how well you’re doing on cybersecurity, based on how many of the 110 security requirements from NIST SP 800-171 you have fully implemented. These requirements are designed to protect Controlled Unclassified Information (CUI).
Every company that handles CUI has to submit a self-assessment, and the score from that self-assessment gets entered into the SPRS system. That’s the number people mean when they talk about your “SPRS Score.”
How the Score Works
Here’s how it breaks down: you start with 110 possible points — one for each NIST requirement. Every time you haven’t fully implemented a requirement, you subtract points.
But not all requirements are weighted the same. Some are more important, so they carry heavier point deductions. For example, missing something like multi-factor authentication might cost you 5 points, while not having a policy written down could cost 1 or 2 points. Your total can range from -203 (if nothing is implemented) up to +110 (if everything is fully done).
The DoD expects you to have a Plan of Action & Milestones (POA&M) for any gaps. That plan says what you’re missing, how you’ll fix it, and when you’ll be done. But keep in mind: your score only counts what’s done now, not what you plan to do later.
How to Calculate Your SPRS Score
Calculating your score might sound intimidating, but it’s actually straightforward if you take it step by step. Here’s what the process looks like in plain language.
First, you gather all the NIST 800-171 requirements. There are 110 of them, split across 14 families like Access Control, Incident Response, and System Integrity. Then, you check each one and ask: “Are we fully doing this?” If the answer is yes, you get the points. If the answer is no, you subtract the assigned point value.
The DoD provides a scoring sheet (called the NIST SP 800-171 DoD Assessment Methodology) that shows how many points each control is worth and how to score it. Some controls are worth -5, -3, or -1 if they’re not done.
When you’ve gone through all 110, you add up the points you earned. That’s your SPRS Score. For example, let’s say you have 90 controls fully done, 15 partially done, and 5 not started. If those 20 missing ones are mostly -1 and -3 controls, you might end up with something like +75. If you were missing bigger -5 controls like multi-factor authentication, your score might be closer to +60. The main thing is your score shows how much of the required security you’ve actually put in place today — not someday in the future.
Where to Submit Your Score
Once you’ve calculated it, you don’t just keep it in a spreadsheet. You have to enter your score into the SPRS website so the DoD can see it. To do that, you log in to the Supplier Performance Risk System using your Procurement Integrated Enterprise Environment (PIEE) account. You’ll go to the “NIST 800-171” section, click “Create New,” and fill in your score, the date, and when you expect to finish any remaining items on your POA&M.
That score stays active for three years — but if anything changes, you’re expected to update it. And any time you bid on a contract, the contracting officer will check your score in the system.
Why Your SPRS Score Matters So Much
Your SPRS Score isn’t just some random number on a government form. It’s part of how the DoD decides if they can trust your company with their data. If your score is low, it sends a signal that your security might be weak. That can make contracting officers nervous about awarding you work, especially if you’re handling CUI. A low score can even block you from bidding on certain contracts. Many solicitations require you to have an active SPRS score before they’ll consider your proposal. No score, no bid.
And if you claim a high score but don’t really have the controls in place, you could face False Claims Act penalties for misrepresenting your cybersecurity. That’s why it’s so important to be accurate and honest when you calculate it.
How to Improve Your Score
If your score isn’t where you want it to be, don’t panic. Improving it just means knocking out the missing requirements one by one. Start with the high-value controls (the ones worth -5 or -3) because fixing those will raise your score the fastest.
Create a clear POA&M that lists what you’re missing, who’s responsible for fixing it, and a deadline. Then actually work the plan — update policies, add technical controls, and train your staff.
As you close the gaps, you can submit an updated score in SPRS showing your progress. That shows the DoD you’re serious about cybersecurity and building toward full compliance.
If you need more help, Greypike helps government contractors get compliant with CMMC, NIST SP 800-171, and FedRAMP, among others. Contact us today if you get stuck!
Wrapping It Up
Your SPRS Score is more than just a number — it’s your company’s cybersecurity reputation with the Department of Defense. Understanding how to calculate it and why it matters can save you from lost contracts, compliance headaches, and even legal trouble.
By tackling your missing requirements and steadily raising your score, you’re not just checking boxes. You’re proving your company is trustworthy, reliable, and ready to protect the DoD’s data.





