SPRS Score Reality Check

Is your SPRS score actually right?

Many contractors report a score of 110 — a perfect score — when their real posture is deeply negative. SPRS scoring subtracts weighted points for every unmet requirement, and a few common gaps can drop you below zero fast. Answer a few questions and we’ll tell you whether your reported score holds up.

Step 1 of 3 · Your details

Where should we send your results?

Please enter your name.

Please enter a valid email.

Please enter your company.

Question 1 of 9

You reported

 

Indicative range from your answers

A rough estimate, not a certified score

What your answers flagged

    Get a real number from a Cyber AB Registered Practitioner.

    A short scoping session gives you an accurate read on your SPRS posture and a clear path to a defensible score — before an inaccurate self-report becomes a problem.

    Book a scoping session

    This tool provides an indicative estimate based on a sample of high-weight NIST SP 800-171 requirements and common scoring errors. It is not a certified SPRS score or a substitute for a full assessment. Your actual score depends on all 110 requirements and their implementation. An official CMMC assessment is conducted by an independent C3PAO.

    Why this matters

    An inaccurate SPRS score isn’t a paperwork problem. It’s a legal one.

    The SPRS portal accepts whatever number you enter — it doesn’t verify it. But the moment that score supports a DoD contract, an overstated number stops being a compliance gap and starts looking like a false claim. And the gap usually gets discovered by someone else first: an assessor, a prime, or a whistleblower.

    Reported

    104

    Actual

    −142

    A 246-point gap cost one contractor $4.6 million.

    In March 2025, a Massachusetts defense contractor settled False Claims Act allegations for $4.6 million after submitting an SPRS score of 104 when a later third-party assessment put its real score at −142. The case was started by a former employee — a whistleblower — who received roughly $851,000 of the settlement.

    The company eventually remediated and reached a perfect score. It didn’t matter: under the law, fixing the gap later does not erase the earlier false claim.

    False Claims Act exposure

    When an overstated score supports a contract, it can be treated as a false claim. The FCA doesn’t require intent to defraud — “reckless disregard” for whether your score is accurate is enough, and penalties include treble damages.

    A recurring annual affirmation

    Since CMMC went live on November 10, 2025, a senior official must affirm compliance in SPRS each year. Every affirmation is a fresh point of exposure — the risk doesn’t end once you’ve submitted a number.

    Whistleblowers are watching

    Your IT staff, compliance team, and departing employees all know your real posture. Whistleblowers can collect 15–30% of any recovery — and most recent cybersecurity cases started exactly that way.

    Greypike is not a law firm and this isn’t legal advice. These are real, publicly reported DOJ settlements from 2024–2025. The point is simple: an accurate, defensible score protects you — and you can’t fix a gap you don’t know you have.

    The 110 problem

    Why a “110” is usually wrong.

    A perfect score means all 110 NIST 800-171 requirements are fully met and documented. In practice, that’s rare — the median DIB self-score sits around 60. Here’s where the inflation almost always comes from.

    1

    There’s no SSP behind the number

    A real score requires a System Security Plan documenting how each requirement is met. Many “110s” are submitted with no SSP at all — which means the number can’t be substantiated if anyone asks.

    2

    Controls are assumed, not validated

    “We have MFA” and “it’s encrypted” often don’t hold up. MFA has to cover every path to CUI; encryption has to be FIPS-validated. Close-but-not-quite still scores as not met.

    3

    The scope is wrong

    If your CUI boundary isn’t clearly defined, the score is measuring the wrong thing. Scoping errors are one of the most common reasons a self-assessment looks far better than reality.

    4

    The score was guessed

    Plenty of scores are a round number someone entered without running the DoD Assessment Methodology. A score that wasn’t actually calculated is the single biggest red flag of all.

    The pattern is always the same: the score reflects what a team hopes is true, not what an assessor would find. The fix isn’t a better guess — it’s an honest, documented assessment.

    Why Greypike

    Straight answers from people who do this every day.

    Cyber AB Registered Practitioners

    Your check and your guidance come from credentialed practitioners who work in CMMC and NIST 800-171 day in, day out — not a generic IT vendor.

    We prepare you — we don’t grade you

    Greypike gets you ready for assessment. The official assessment is always conducted by an independent C3PAO, so there’s no conflict of interest in your result.

    No lock-in, no pressure

    The reality check is genuinely useful on its own. If you work with us, you own your environment and documentation — and can walk away with them anytime.

    What you get

    From a rough self-check to a number you can defend.

    The reality check tells you whether to worry. A scoping session with a Registered Practitioner tells you exactly where you stand — and what it takes to fix it.

    It’s a focused working conversation, not a sales pitch. You leave with a clearer picture than most contractors ever get from a self-assessment.

    • An honest read on your posture

      Where your real score likely sits — and why — against the requirements that actually matter.

    • Your biggest gaps, prioritized

      The high-weight items dragging your score down, ordered by impact so you fix what counts first.

    • A clear path to a defensible score

      What it takes to close the gaps and stand behind your number — whether you do it yourself or with us.

    Questions

    Before you check.

    Is this my official SPRS score?
    No. This is an indicative reality check, not a certified score. It looks at a sample of the highest-weight NIST 800-171 requirements and common scoring errors to flag whether your reported number is likely accurate. Your official score depends on all 110 requirements, and an official CMMC assessment is conducted by an independent C3PAO.
    What is SPRS, and who has to report a score?
    The Supplier Performance Risk System is the DoD database where defense contractors submit a self-assessed NIST 800-171 score. If you handle Controlled Unclassified Information (CUI) under a DoD contract, you’re generally expected to have a current score on file — and increasingly, you can’t win awards without one.
    What happens if my score turns out to be wrong?
    The sooner you know, the better your options. An inaccurate score that supports a contract can create real legal and contract exposure — but a score you correct and can defend protects you. The worst position is not knowing. A scoping session gives you an accurate read and a path forward. We’re not a law firm; for legal questions, talk to counsel.
    How fast can you help?
    A scoping session can usually be booked within days, and you’ll get a clearer picture of your posture from that single conversation. If you decide to move forward, we’ll scope the work and timeline to your environment.

    Find out if your score holds up.

    Take the reality check, or skip straight to a scoping session with a Cyber AB Registered Practitioner for an accurate read on where you really stand.

    Book a scoping session

    Free, no obligation — and genuinely useful even if we never work together.