SPRS Score Calculator

Estimate your NIST 800-171 SPRS score and learn how the real 110-point scoring works

Status update · October 2026CMMC Phase 2 is paused. On July 13, 2026 the DoD suspended the November 10, 2026 move to mandatory third-party (C3PAO) certification while a reform task force reviews the program. Self-assessments, NIST SP 800-171, SPRS scores and DFARS 252.204-7012 still apply. No new date has been set. How to post your SPRS self-assessment →

What is SPRS (Supplier Performance Risk System)?

SPRS is the Department of Defense's Supplier Performance Risk System, reached through the PIEE portal. For cybersecurity, it's where your NIST SP 800-171 assessment score is recorded. When people say "SPRS score," they mean that number: how many of the 110 NIST SP 800-171 requirements protecting Controlled Unclassified Information (CUI) you've implemented, scored with the DoD Assessment Methodology.

Unlike CMMC, which is an assessment program written into contracts, SPRS is the system where the results are stored. The score in SPRS comes from you: you run a Basic (self) assessment and post it, as DFARS 252.204-7019/-7020 require. DoD (DIBCAC) can also run Medium or High assessments, and those results are recorded too. CMMC results (Level 1 and Level 2 self-assessments, and C3PAO assessments) show up in SPRS as well.

Key facts about SPRS scores:

How SPRS Scoring Works: The 110-Point System

The DoD Assessment Methodology scores each of the 110 NIST SP 800-171 requirements individually, not by family. Your score starts at 110, and every requirement that isn't implemented subtracts its weight:

If nothing were implemented, the deductions would total 313, which is why the floor is -203.

The 14 NIST SP 800-171 Rev 2 Control Families:

Control Family Requirements What It Covers Risk If Missing
Access Control (AC)22User access, least privilege, remote accessShared accounts, over-privileged users
Awareness & Training (AT)3Security awareness, role-based and insider threat trainingStaff not trained on security; high phishing risk
Audit & Accountability (AU)9Logging, log review, log protectionCan't detect intrusions or trace actions to users
Configuration Management (CM)9Baselines, change control, least functionalityUnauthorized system changes; no baseline documentation
Identification & Authentication (IA)11Unique IDs, MFA, password rulesNo multi-factor authentication; weak password enforcement
Incident Response (IR)3Incident handling, reporting, testingNo incident response plan; delayed breach response
Maintenance (MA)6Controlled maintenance, remote maintenance, toolsUnsupervised or unsecured maintenance access
Media Protection (MP)9Media handling, encryption, sanitizationUSB drives not controlled; insecure data disposal
Personnel Security (PS)2Screening; protecting CUI at termination/transferFormer employees keep access
Physical Protection (PE)6Facility access, visitors, access logsUnsecured server rooms; no access controls
Risk Assessment (RA)3Risk assessments, vulnerability scanning and remediationUnidentified vulnerabilities
Security Assessment (CA)4Control assessment, POA&M, monitoring, SSPNo security plan; no idea whether controls work
System & Communications Protection (SC)16Boundary protection, encryption, FIPS cryptoUnencrypted CUI; no network segmentation
System & Information Integrity (SI)7Patching, malware protection, monitoringUnpatched systems; no endpoint protection
Security scoring dashboard

Interactive Calculator Below

Use the calculator for a rough, family-level snapshot of where you stand. Your real score comes from assessing all 110 requirements individually.

Interactive SPRS Calculator

Check the boxes below for each control family your organization has fully implemented. This is a simplified, family-level estimate: each family's "up to" value is its share of the 313 points you can lose, spread evenly across its requirements, not the official per-requirement weights. Your actual SPRS score comes from scoring each of the 110 requirements at 5, 3, or 1 points as described above, and can be much lower (down to -203).

SPRS Score Calculator

Select the NIST 800-171 control families your organization has implemented

Network encryption, boundary protection, cryptography, wireless security
User account management, privilege levels, session control, access restrictions
Multi-factor authentication, unique identifiers, password rules
System logging, event tracking, audit log protection, accountability
Malware protection, patch management, system monitoring, flaw remediation
System baselines, change control, configuration tracking
Incident detection, response procedures, testing, post-incident analysis
Data handling procedures, disposal controls, portable media security
Server room security, facility access control, visitor escorts and logs
System security plan, control assessments, POA&M, ongoing monitoring
Personnel screening, protecting CUI when people leave or transfer
Regular risk assessments, vulnerability scanning, threat evaluation
Security training, phishing awareness, role-based training
Controlled maintenance, maintenance tools, remote maintenance with MFA

-203

Out of 110 Points

Excellent: Your organization has strong cybersecurity controls. You're well-positioned for CMMC certification and will receive favorable SPRS evaluation.
Implemented
0
Gap Areas
14
Compliance %
0%
Points at Risk
313

What Your SPRS Score Means

Your SPRS score tells contracting officers, primes, and the DoD how much of NIST SP 800-171 you've actually implemented. The numbers that matter most come from the CMMC rule:

Score Range Risk Level What It Means Contractor Impact
110 Low Risk All 110 requirements implemented Meets the bar for Final CMMC Level 2 status; strongest position with primes
88-109 Moderate Risk Most requirements in place, some gaps Conditional CMMC Level 2 status is possible only if every open item is POA&M-eligible (certain 1-point requirements, with limited exceptions), closed within 180 days
0-87 Elevated Risk Significant gaps Below the 88 needed for Conditional Level 2 status; can still be posted for DFARS 7019/7020, but expect scrutiny
Below 0 High Risk Many high-weight requirements missing Common on a first honest assessment; post it accurately and build a remediation plan

SPRS Score Thresholds for Different Contract Types

There's no official SPRS cutoff by contract type, and DFARS 252.204-7019/-7020 don't set a minimum score. What is defined:

Whatever your target, the score you post must be accurate. While CMMC Phase 2 is paused, your self-assessed SPRS score is the main evidence of your NIST 800-171 status, and overstating it creates False Claims Act exposure.

Ready to improve your SPRS score?

Identify your biggest compliance gaps with a full gap analysis, then prioritize the controls that will have the most impact on your score.

Start a Gap Analysis

How to Submit Your SPRS Score to the DoD SPRS Portal

SPRS is accessed through the PIEE portal. Once you've completed a self-assessment, you post the results there so contracting officers can see them.

Steps to post a NIST SP 800-171 Basic assessment:

  1. Register in PIEE and request the SPRS role for your company (you'll need your CAGE code)
  2. Open SPRS and go to the NIST SP 800-171 assessment entry
  3. Enter the assessment date, your score, the scope (CAGE codes covered), the system security plan it's based on, and, if you're below 110, the date you expect to reach 110
  4. Submit; your score is then visible to authorized government users
  5. Keep your SSP, POA&M, and evidence on file. You don't upload them, but DoD can ask

CMMC self-assessments (Level 1 and Level 2) are also entered in SPRS, along with the affirmation by a senior company official. If you pursue a voluntary C3PAO assessment, the C3PAO submits the results, and you still affirm in SPRS.

SPRS Score Improvement Strategies

Your score improves when you implement requirements. Here's how to prioritize for maximum impact:

Priority 1: Your SSP and the 5-point requirements

Each 5-point requirement you close adds 5 points to your score, so a handful of them can move you a long way, often across the 88-point line.

Priority 2: The 3-point requirements

Priority 3: The 1-point requirements

Common SPRS Scoring Mistakes

Many contractors misunderstand SPRS and leave points on the table. Avoid these mistakes:

Frequently Asked Questions

Is SPRS the same as CMMC?

No. CMMC is a certification program; Level 2 can be met by self-assessment or a C3PAO assessment (third-party certification is currently voluntary while Phase 2 is paused). SPRS is where your score is recorded and seen by the DoD. They're related: your assessment results drive your SPRS score.

Can I improve my SPRS score without CMMC certification?

Yes. Your SPRS score is normally a self-assessment of NIST 800-171 compliance that you post yourself, so you improve it by implementing requirements and posting an updated assessment. No CMMC certification is needed. Self-assessment is what most contractors use today while CMMC Phase 2 is paused. A voluntary C3PAO certification is more credible evidence and can give you a competitive advantage with primes.

How often is my SPRS score updated?

Your SPRS score changes when new assessment results are entered: when you post an updated self-assessment, or when DoD records a Medium or High assessment. It must be no more than 3 years old, but you can post an update whenever you close gaps.

What if DoD assesses me and gets a different score?

A Basic assessment is your own score, so if it's wrong, you correct it by posting an updated assessment. If DoD (DIBCAC) performs a Medium or High assessment, its result is recorded in SPRS alongside yours. The best protection is a self-assessment you can back up with evidence.

Do all contractors need an SPRS score?

Contractors subject to DFARS 252.204-7012 (those handling CUI) need a current NIST SP 800-171 assessment score in SPRS to be considered for awards that include DFARS 252.204-7019. Companies that handle only Federal Contract Information (FCI) don't get a 110-point score, but where a CMMC Level 1 requirement applies they post an annual self-assessment and affirmation in SPRS. Check your contracts and your prime's flowdowns.

Can my SPRS score hurt me in contract bids?

Yes. Contracting officers and primes can see your SPRS score. A low SPRS score can result in a downgrade in technical evaluation, loss of contract awards, or requirement to implement risk mitigation measures. A strong SPRS score is a competitive advantage.