CMMC Self-Assessment & SPRS Score Guide

How Level 1 and Level 2 self-assessments work, how the SPRS score is calculated, and what it means for contracts

Status update · October 2026CMMC Phase 2 is paused. On July 13, 2026 the DoD suspended the November 10, 2026 move to mandatory third-party (C3PAO) certification while a reform task force reviews the program. Self-assessments, NIST SP 800-171, SPRS scores and DFARS 252.204-7012 still apply. No new date has been set. See the current timeline →

Why Self-Assessment and SPRS Matter Right Now

Here's the straight version: the pause hit third-party certification, not self-assessment. Since July 13, 2026, contracting officers have been told to use only Level 1 (Self) or Level 2 (Self) requirements, and C3PAO Level 2 requirements are coming out of solicitations and existing contracts. That makes the self-assessment and the score you post in SPRS the CMMC evidence that actually gets checked today.

Nothing else went away either. DFARS 252.204-7012 still requires you to safeguard CUI and report cyber incidents to DoD within 72 hours. DFARS 252.204-7019/-7020 still require a current SPRS score, and DoD can still run Medium or High assessments to check it. Where CMMC clauses are already in your contracts, annual affirmations still apply. And the False Claims Act still applies to anything you affirm: in September 2026 Honeywell Aerospace settled for about $2.04M over NIST 800-171 non-compliance. An honest, well-documented self-assessment is your best protection, and it's the foundation you'll need if third-party certification comes back in some form.

Level 1 vs. Level 2 Self-Assessment: Two Different Things

This is where a lot of contractors get tripped up. "CMMC self-assessment" can mean two very different jobs, and they're scored differently:

  • Level 1 (Self): For companies that handle only Federal Contract Information (FCI). You check the 15 basic safeguarding requirements from FAR 52.204-21 (presented as 17 practices in CMMC). Every requirement is either MET or NOT MET. There is no 110-point score and no POA&M. You redo it every year, and a senior company official affirms the result in SPRS.
  • Level 2 (Self): For companies that handle Controlled Unclassified Information (CUI). You assess all 110 security requirements in NIST SP 800-171 Rev 2 and calculate a score using the DoD Assessment Methodology (maximum 110). It's repeated every 3 years, with an annual affirmation in between.

Separately from CMMC, DFARS 252.204-7019/-7020 already require any contractor subject to DFARS 252.204-7012 to post a current NIST SP 800-171 (Basic) assessment score in SPRS. That's the "SPRS score" most people mean, and it uses the same 110-point method as Level 2.

Level 1 Self-Assessment

FCI only: 15 FAR requirements, each MET or NOT MET, affirmed annually in SPRS

Level 1 is a self-managed baseline. Level 2 can be a self-assessment or a C3PAO certification depending on what the contract calls for. With the Phase 2 rollout paused, self-assessments are what solicitations require, so this is where your effort pays off now.

Understanding SPRS (Supplier Performance Risk System)

SPRS is the DoD system where your assessment results live. You reach it through the PIEE portal. What you enter depends on the assessment:

  • NIST SP 800-171 Basic assessment / CMMC Level 2 (Self): a numeric score from 110 down to as low as -203, the date, the scope (CAGE codes covered), your system security plan, and if you're under 110, the date you expect to reach 110
  • CMMC Level 1 (Self): whether you've met all of the Level 1 requirements, plus the annual affirmation. No numeric score

How the 110-Point Score Works (NIST 800-171 and Level 2)

The score comes from the DoD Assessment Methodology (v1.2.1). The method is simple once you see it:

  • Start at 110: one point of headroom for each of the 110 NIST SP 800-171 requirements
  • Subtract for anything not implemented: each unimplemented requirement costs 5, 3, or 1 points depending on its weight. Requirements whose failure would let CUI be exploited or exfiltrated directly carry 5 points; lower-impact ones carry 3 or 1
  • No credit for "almost": a requirement is either implemented or it isn't. Having it on a POA&M doesn't earn points back until it's actually done
  • A few partial-credit rules: for example, 3.5.3 (multifactor authentication) costs 5 points if MFA isn't in place, but only 3 if you have it for remote and privileged access and not yet for general users. 3.13.11 (FIPS-validated cryptography) costs 5 points with no encryption, 3 if you encrypt but the module isn't FIPS-validated
  • Floor: if nothing is implemented, the score bottoms out at -203
  • Freshness: the score posted in SPRS must be no more than 3 years old

Real examples of 5-point requirements: 3.1.1 (limit system access to authorized users), 3.5.3 (MFA) and 3.13.11 (FIPS-validated encryption). A 1-point example: 3.1.9 (privacy and security notices, i.e. logon banners). You also need a system security plan (3.12.4); without one, DoD's position is that the assessment can't be completed at all.

What Level 1 Actually Covers

Level 1 is the 15 basic safeguarding requirements in FAR 52.204-21. CMMC lists them as 17 practices because the physical-access requirement is split into separate practices. Here's the plain-English version:

Family FAR 52.204-21 Requirement (CMMC ID) What It Requires Typical Evidence
Access Control b.1.i (AC.L1-b.1.i) Limit system access to authorized users, processes, and devices User account listing, access approval records
b.1.ii (AC.L1-b.1.ii) Limit users to the transactions and functions they're allowed to perform Role/group assignments, permission settings
b.1.iii (AC.L1-b.1.iii) Verify and control/limit connections to external systems Policy on personal devices and outside systems, firewall rules
b.1.iv (AC.L1-b.1.iv) Control information posted on publicly accessible systems Website/social posting approval process
Identification & Authentication b.1.v (IA.L1-b.1.v) Identify users, processes, and devices Unique user IDs, device inventory
b.1.vi (IA.L1-b.1.vi) Authenticate those identities before allowing access Password/authentication settings
Media Protection b.1.vii (MP.L1-b.1.vii) Sanitize or destroy media containing FCI before disposal or reuse Disposal procedure, destruction certificates
Physical Protection b.1.viii (PE.L1-b.1.viii) Limit physical access to systems and equipment to authorized people Badge/key control, locked server areas
b.1.ix (PE.L1-b.1.ix) Escort and monitor visitors, keep physical access logs, and manage physical access devices (keys, badges, codes) Visitor log, key/badge inventory
System & Communications Protection b.1.x (SC.L1-b.1.x) Monitor, control, and protect communications at external and key internal boundaries Firewall configuration, network diagram
b.1.xi (SC.L1-b.1.xi) Separate publicly accessible system components from internal networks Network diagram showing DMZ/segmentation or hosted public site
System & Information Integrity b.1.xii (SI.L1-b.1.xii) Identify, report, and correct system flaws in a timely manner Patch reports, update logs
b.1.xiii (SI.L1-b.1.xiii) Provide protection from malicious code Anti-malware deployment status
b.1.xiv (SI.L1-b.1.xiv) Update malicious code protection when new releases are available Definition/update status reports
b.1.xv (SI.L1-b.1.xv) Scan systems periodically and scan files from external sources in real time Scan schedules and results

Notice these are fundamentals: who gets in, how they log in, locking doors, patching, and anti-malware. For Level 1 you must meet every one of them. There's no partial credit and no POA&M for Level 1, so anything NOT MET has to be fixed before you can affirm.

Not sure where your controls stand?

Use our detailed checklist to audit your current compliance level before self-assessment.

Step-by-Step Self-Assessment Process

The steps are the same for Level 1 and Level 2. The difference is how many requirements you work through and how the result is recorded:

Step 1: Planning and Scoping (Week 1)

Assign a compliance coordinator (often an IT manager or security officer). Decide what's in scope: the systems, people, and facilities that handle FCI (Level 1) or CUI (Level 2). Create a responsibility matrix showing who owns evidence for each requirement, and schedule working sessions for the next few weeks.

Step 2: Evidence Gathering (Weeks 2-4)

For each requirement, collect proof that it's implemented:

  • For authentication: a screenshot or export of your password and login settings
  • For identification: a user account listing and device inventory from your directory or endpoint tool
  • For flaw remediation: patch deployment reports showing updates are applied in a timely manner
  • For malware protection: endpoint status showing protection is installed and current

Store evidence in a shared folder (Teams, SharePoint, Google Drive) organized by requirement. NIST SP 800-171A lists the assessment objectives for each requirement, which is the checklist an assessor would use.

Step 3: Evaluate Each Requirement (Week 5)

Mark each requirement MET or NOT MET (or not applicable, with a written justification). Don't invent a "partially implemented" category to soften things: if any assessment objective isn't satisfied, the requirement is NOT MET. For Level 2 and the NIST Basic assessment, document every NOT MET item in a Plan of Action and Milestones (POA&M).

Step 4: Record the Result (Week 6)

Level 1: if everything is MET, you're ready to affirm. If not, fix the gaps first. Level 2 / NIST Basic: start at 110 and subtract the weight (5, 3, or 1) of each NOT MET requirement, applying the partial-credit rules for 3.5.3 and 3.13.11. A spreadsheet works, or use our SPRS calculator.

Step 5: Submission (Week 7)

Post your results in SPRS through the PIEE portal. You'll need your CAGE code (from SAM.gov) and the right SPRS role. An authorized company official submits the result and the affirmation that it's accurate.

SPRS Score Calculation Example (Level 2 / NIST Basic)

Here's a worked example for a small CUI-handling company. Only the requirements that aren't fully implemented are shown; everything else is MET and costs nothing.

Requirement Status Points Deducted Notes
3.5.3 Multifactor authentication Partial (MFA for remote and privileged access only) -3 Partial-credit rule; would be -5 with no MFA at all
3.13.11 FIPS-validated cryptography Encryption in use, not FIPS-validated -3 Partial-credit rule; would be -5 with no encryption
3.1.9 Privacy and security notices NOT MET -1 No logon banner configured
Two other 3-point requirements NOT MET -6 Weights come from the DoD Assessment Methodology
Four other 1-point requirements NOT MET -4 Documented on the POA&M
TOTAL DEDUCTIONS: -17
SPRS SCORE (110 - 17): 93 Posted in SPRS with a target date to reach 110

This company posts 93 in SPRS. Note what that means under CMMC Level 2: a score of 88 or higher is necessary for Conditional status with a POA&M, but it isn't enough on its own. Only certain 1-point requirements can sit on a CMMC POA&M (with limited exceptions, such as 3.13.11 when encryption is used but isn't FIPS-validated). The open MFA item (a 5-point requirement) and the two 3-point items would have to be closed first. Any POA&M items must be closed within 180 days, and Final status means reaching 110.

Assessment Evidence Management

Organize and maintain proof of control implementation throughout the assessment

How to Submit Your Results in SPRS

Once you've finished the assessment, submitting takes these steps:

Get Access to SPRS

Register in the PIEE portal and request the SPRS role for your company. You'll need:

  • CAGE code (Commercial and Government Entity identifier from SAM.gov)
  • Business email address
  • Organization name as registered in federal systems

Enter the Assessment

Depending on the assessment type, SPRS asks for:

  • The assessment date and scope (which CAGE codes it covers)
  • For NIST/Level 2: your score, the system security plan it's based on, and the date you expect to reach 110 if you're below it
  • For Level 1: whether all requirements are met
  • The affirmation by an authorized senior official that the information is accurate

Submit and Receive Confirmation

Once submitted, your results are recorded in SPRS. Contracting officers can view them when you bid on contracts with DFARS 7019/7020 or CMMC clauses. Keep your evidence, SSP, and POA&M on file; you don't upload them, but you may be asked for them.

Important: Submission is not approval. Your score becomes part of your contracting record. DoD (DIBCAC) can follow up with a Medium or High assessment, and if third-party certification becomes required again (or you pursue it voluntarily), a C3PAO will test the same requirements you claimed.

What SPRS Score Do You Need?

There's no single published minimum score for DFARS 7019/7020. What you need depends on who's buying:

  • DoD solicitations: Since the July 2026 pause, contracting officers use Level 1 (Self) or Level 2 (Self) requirements. You need a current assessment posted in SPRS, and a higher score is a better look
  • CMMC Level 2 status: 110 for Final status; at least 88 (80%), with only allowable items on a POA&M, for Conditional status, which lasts 180 days
  • CMMC Level 1: no score. All requirements must be met
  • C3PAO certification: Removed from solicitations while Phase 2 is paused, and being removed from existing contracts at the next modification or option
  • Subcontractors to large primes: Some primes set their own score expectations, and some still ask suppliers for voluntary C3PAO certification

Check your specific contract vehicle (e.g., GSA schedule, IDIQ, task order) and your prime's flowdowns for the clauses that actually apply to you.

Common Mistakes in Self-Assessment

Organizations often make these errors, leading to inaccurate scores and trouble later in a DoD or C3PAO assessment:

Over-Reporting Compliance

Claiming a requirement is MET when it's only partly done. Example: a password policy exists on paper but isn't enforced on every system. That's NOT MET. Being honest upfront avoids assessment surprises and False Claims Act exposure.

Missing or Weak Evidence

Claiming a requirement is met without anything to show for it. If DoD or a C3PAO asks, you need proof. Document everything: screenshots, configuration exports, policy documents, training records.

Using a Score for Level 1

Applying the 110-point method to a Level 1 (FCI-only) assessment. Level 1 is all-or-nothing: every requirement must be met before you affirm.

Not Documenting a POA&M (Level 2 / NIST)

Identifying gaps but not documenting how and when you'll fix them. The POA&M shows DoD and your primes you have a remediation roadmap, and it's where the "date to reach 110" in SPRS comes from.

Forgetting People Outside IT

Scope includes non-IT personnel. If a requirement covers all users who handle CUI (security awareness training under Level 2, for example), training only the IT team doesn't meet it.

Not Tracking Control Decay

A control might be implemented today but decay over time if not maintained. Example: patching. If you patch for six months and then stop, the requirement is no longer met. Annual review (required for Level 1, and the affirmation cycle for Level 2) should catch this.

Self-Assessment vs. Third-Party Assessment Comparison

How a self-assessment differs from a C3PAO Level 2 certification assessment:

Aspect Level 1 or Level 2 Self-Assessment Level 2 C3PAO Assessment (currently voluntary)
Who Performs Your own company (consultants can help) Cyber AB-authorized third party (C3PAO)
Result Self-reported result and affirmation in SPRS CMMC Level 2 (C3PAO) status recorded by the assessor
Requirements Level 1: 15 FAR requirements (17 practices). Level 2: 110 NIST SP 800-171 requirements 110 NIST SP 800-171 requirements
Cost Minimal (staff time only) $8k-$250k+ depending on scope
Independence No independence requirement Strict independence from consulting work
How Often Level 1: every year. Level 2: every 3 years, with annual affirmations Every 3 years, with annual affirmations
Verification DoD can verify with a Medium or High assessment; false claims carry FCA risk Assessor examines evidence, interviews staff, and tests controls

Key distinction: a self-assessment is low-cost but self-reported. A C3PAO assessment costs more but gives you independent validation. Level 3 is a separate step above that: Level 2 (C3PAO) status plus 24 selected NIST SP 800-172 requirements, assessed by DoD's DIBCAC. While Phase 2 is paused, C3PAO Level 2 certification is voluntary unless a prime or contract asks for it, but a certificate is strong evidence if the requirement returns.

Deep dive into Level 2 and 3 assessments

Learn about formal CMMC assessments and what each level requires.

How to Improve Your SPRS Score

If your initial assessment reveals gaps, here's how to improve before you re-assess or bid:

Prioritize by Point Value and Effort

Close the 5-point items first; they move your score the most, and under CMMC they can't stay on a POA&M. MFA (3.5.3) and FIPS-validated encryption (3.13.11) are common ones. Then pick off 1-point items that are a settings change away, like logon banners (3.1.9).

Use Our Compliance Checklist

Our detailed CMMC checklist breaks requirements into actionable steps, tools, and templates you can use to accelerate remediation.

Leverage Tools and Automation

Deployment of scanning tools (vulnerability scanners, endpoint inventory tools, patch management systems) accelerates implementation and provides assessment-ready evidence.

Set Remediation Timeline and Track Progress

Create a POA&M specifying: requirement, current state, target completion date, responsible person, and required resources. Review monthly, and update your SPRS entry when your score changes.

SPRS Score and Contract Implications

Your SPRS results affect more than just current contract eligibility:

Contract Bid Eligibility

Solicitations with DFARS 7019/7020 or CMMC clauses require current results in SPRS, and since the pause they call for Level 1 (Self) or Level 2 (Self). Your SPRS record becomes part of your contractual standing, and a weak or missing entry can cost you the award.

Competitive Advantage

Contracting officers and primes can see your SPRS results, so a higher score can help you stand out.

Prime Contractor Supply Chain Pressure

Large primes flow down DFARS 7012 and SPRS requirements, and some still ask suppliers for voluntary C3PAO certification even with Phase 2 paused. If your score is below what they expect, you lose subcontracting opportunities.

Keeping It Current

A NIST SP 800-171 Basic score must be no more than 3 years old. CMMC Level 1 self-assessments are redone every year; Level 2 self-assessments every 3 years with annual affirmations. Updating your SPRS entry as you close gaps is smart even when it isn't required.

FAQ: CMMC Self-Assessment and SPRS Scoring

Do I still need a self-assessment now that CMMC Phase 2 is paused?

Yes. The July 13, 2026 pause stopped the move to mandatory C3PAO certification, not the self-assessment requirement. Contracting officers are using Level 1 (Self) and Level 2 (Self) requirements, and NIST SP 800-171, SPRS score posting under DFARS 252.204-7019/-7020, and DFARS 252.204-7012 all still apply. No new Phase 2 date has been set.

What is a SPRS score?

SPRS (Supplier Performance Risk System) is the DoD system, reached through PIEE, where assessment results are posted. The SPRS score is your NIST SP 800-171 score under the DoD Assessment Methodology: start at 110 and subtract 5, 3, or 1 points for each requirement not implemented, down to a floor of -203. The same method is used for CMMC Level 2 self-assessments. There is no single published minimum for DFARS 7019/7020; CMMC Level 2 Conditional status needs at least 88 and Final status needs 110.

Is there a SPRS score for CMMC Level 1?

No. Level 1 covers the 15 basic safeguarding requirements in FAR 52.204-21 (17 practices in CMMC). Each one is MET or NOT MET, all must be met, and no POA&M is allowed. You enter the result and a senior official's affirmation in SPRS every year, but there is no 110-point score.

Can I hire someone to help with my self-assessment?

Yes. A consultant can guide the process, but it's still your company's self-assessment: your people need to understand the results, and an authorized senior official of your company affirms them in SPRS and is accountable for their accuracy.

How do I submit my results in SPRS?

Results are posted in SPRS, which you reach through the PIEE portal. You complete the assessment, calculate your score (for NIST SP 800-171 or Level 2), keep your evidence, SSP and POA&M on file, and an authorized company official submits the result and affirmation.

What happens if I submit a false SPRS score?

Knowingly submitting false information can result in contract suspension, debarment from DoD contracting, False Claims Act liability, and criminal prosecution for fraud. The Phase 2 pause didn't change this: in September 2026 Honeywell Aerospace settled for about $2.04M over NIST 800-171 non-compliance. Always be honest about your compliance state.

Can I submit before fixing all gaps?

For the NIST SP 800-171 score and Level 2, yes. You post your honest score, document the gaps in a POA&M, and give the date you expect to reach 110. Unimplemented requirements still cost points until they're fixed. For CMMC Level 2 Conditional status you need at least 88 with only allowable items on the POA&M, closed within 180 days. For Level 1, no: every requirement must be met before you affirm.

What happens if my SPRS score is too low?

A low score doesn't automatically bar you from bidding, but contracting officers and primes can see it, and it can cost you awards and subcontracts. Document a POA&M, remediate, and update your score in SPRS.

How often do I need to reassess?

Level 1 self-assessments and affirmations are annual. Level 2 self-assessments are every 3 years with annual affirmations, and a NIST SP 800-171 Basic score in SPRS must be no more than 3 years old. C3PAO certification is currently voluntary while Phase 2 is paused; if you choose it (or a prime asks for it), it is valid for 3 years with annual affirmations.

Does Level 2 cover Level 1?

The 110 NIST SP 800-171 requirements in Level 2 include everything the 15 Level 1 requirements cover. If you handle CUI, Level 2 is your target. Either way, keep current in SPRS whichever assessment your contracts actually call for.

Ready to start your compliance roadmap?

Use our free readiness assessment to identify your current state and required controls.

Related CMMC Resources