Your SPRS Calculator
is ready.
Click the download button in the next section to get your file. If the download doesn't start automatically, use the direct link provided below the button.
How to use your SPRS Score Calculator.
The workbook has three sheets. Here's the fastest path from download to knowing your score.
Open the 📋 Assessment sheet
This is your working sheet. All 110 NIST 800-171 controls are listed with their penalty point values and the full requirement text. Everything you need to complete your self-assessment is on this sheet.
Select a status for each control using column F
Click the dropdown in column F for each control and select
Met
,
Partially Met
,
Unmet
, or
Not Assessed
. The score impact in column H updates automatically. Work through all 110 controls before submitting your score to DoD.
Add notes in column I for any N/A or Partially Met controls
The Notes column is where you record your implementation evidence, not-applicable justifications, and remediation plans. This documentation is what a C3PAO assessor will look for. Don't skip it — especially for controls you've marked Met but with an N/A rationale.
Check your running score on the 📊 Dashboard
Your SPRS score updates in real time as you mark controls. The Dashboard shows your total score, a status count summary, and a family-level breakdown — so you can see which of the 14 control families is driving the most score risk.
Submit your score to SPRS
When your assessment is complete, self-report your score at sprs.csd.disa.mil. You'll need a CAC card or ECA certificate and your organization's CAGE code. The score you enter there should match the score in your completed calculator.
Not sure what to do with your score?
Understanding your SPRS score is step one. Here are two ways Greypike can help you figure out what it means and what to do about it — both free, no obligation.
CUI Scoping Session
If your score reveals gaps — or you're not sure whether your contracts even require CMMC — a scoping session gives you a definitive answer. We'll review your situation, define your CUI boundary, and give you a clear compliance path. Even if the answer is "you don't need CMMC," we'll tell you that.
Book a free scoping sessionManaged Enclave Feasibility Session
If you handle CUI and don't have internal IT staff to build and manage a GCC High environment, the Managed Enclave may be your fastest path to a CMMC-ready environment. $500/user/month, deployed in two weeks. Find out in 30 minutes whether it's right for your team — we'll tell you honestly if it isn't.
Book a feasibility sessionGreypike is a Cyber AB Registered Practitioner Advanced firm.