What is SPRS (Supplier Performance Risk System)?
SPRS is the Department of Defense's Supplier Performance Risk System, reached through the PIEE portal. For cybersecurity, it's where your NIST SP 800-171 assessment score is recorded. When people say "SPRS score," they mean that number: how many of the 110 NIST SP 800-171 requirements protecting Controlled Unclassified Information (CUI) you've implemented, scored with the DoD Assessment Methodology.
Unlike CMMC, which is an assessment program written into contracts, SPRS is the system where the results are stored. The score in SPRS comes from you: you run a Basic (self) assessment and post it, as DFARS 252.204-7019/-7020 require. DoD (DIBCAC) can also run Medium or High assessments, and those results are recorded too. CMMC results (Level 1 and Level 2 self-assessments, and C3PAO assessments) show up in SPRS as well.
Key facts about SPRS scores:
- SPRS scores top out at 110 points (higher is better); because deductions are weighted, a score can go as low as -203
- Contractors subject to DFARS 252.204-7012 (handling CUI) need a current NIST SP 800-171 assessment posted in SPRS, no more than 3 years old
- Your score is visible to contracting officers and can influence bid evaluations and prime contractors' decisions
- CMMC Level 2 uses the same 110-point scoring: 110 for Final status, at least 88 for Conditional status with a POA&M
- CMMC Level 1 (FCI only) has no score: you affirm in SPRS that all Level 1 requirements are met (see our self-assessment guide)
How SPRS Scoring Works: The 110-Point System
The DoD Assessment Methodology scores each of the 110 NIST SP 800-171 requirements individually, not by family. Your score starts at 110, and every requirement that isn't implemented subtracts its weight:
- 5 points: requirements whose absence could lead to significant exploitation of the network or exfiltration of CUI. Examples: 3.1.1 (limit access to authorized users), 3.5.3 (multifactor authentication), 3.13.11 (FIPS-validated cryptography)
- 3 points: requirements with a meaningful but more limited effect
- 1 point: lower-impact requirements. Example: 3.1.9 (privacy and security notices / logon banners)
- Partial credit: only a few requirements have it. 3.5.3 costs 3 instead of 5 if MFA covers remote and privileged access but not general users; 3.13.11 costs 3 instead of 5 if you encrypt but the cryptography isn't FIPS-validated
- No credit for plans: a requirement on your POA&M still costs its full weight until it's done. You also need a system security plan (3.12.4); without one, DoD considers the assessment incomplete
If nothing were implemented, the deductions would total 313, which is why the floor is -203.
The 14 NIST SP 800-171 Rev 2 Control Families:
| Control Family | Requirements | What It Covers | Risk If Missing |
|---|---|---|---|
| Access Control (AC) | 22 | User access, least privilege, remote access | Shared accounts, over-privileged users |
| Awareness & Training (AT) | 3 | Security awareness, role-based and insider threat training | Staff not trained on security; high phishing risk |
| Audit & Accountability (AU) | 9 | Logging, log review, log protection | Can't detect intrusions or trace actions to users |
| Configuration Management (CM) | 9 | Baselines, change control, least functionality | Unauthorized system changes; no baseline documentation |
| Identification & Authentication (IA) | 11 | Unique IDs, MFA, password rules | No multi-factor authentication; weak password enforcement |
| Incident Response (IR) | 3 | Incident handling, reporting, testing | No incident response plan; delayed breach response |
| Maintenance (MA) | 6 | Controlled maintenance, remote maintenance, tools | Unsupervised or unsecured maintenance access |
| Media Protection (MP) | 9 | Media handling, encryption, sanitization | USB drives not controlled; insecure data disposal |
| Personnel Security (PS) | 2 | Screening; protecting CUI at termination/transfer | Former employees keep access |
| Physical Protection (PE) | 6 | Facility access, visitors, access logs | Unsecured server rooms; no access controls |
| Risk Assessment (RA) | 3 | Risk assessments, vulnerability scanning and remediation | Unidentified vulnerabilities |
| Security Assessment (CA) | 4 | Control assessment, POA&M, monitoring, SSP | No security plan; no idea whether controls work |
| System & Communications Protection (SC) | 16 | Boundary protection, encryption, FIPS crypto | Unencrypted CUI; no network segmentation |
| System & Information Integrity (SI) | 7 | Patching, malware protection, monitoring | Unpatched systems; no endpoint protection |
Interactive Calculator Below
Use the calculator for a rough, family-level snapshot of where you stand. Your real score comes from assessing all 110 requirements individually.
Interactive SPRS Calculator
Check the boxes below for each control family your organization has fully implemented. This is a simplified, family-level estimate: each family's "up to" value is its share of the 313 points you can lose, spread evenly across its requirements, not the official per-requirement weights. Your actual SPRS score comes from scoring each of the 110 requirements at 5, 3, or 1 points as described above, and can be much lower (down to -203).
What Your SPRS Score Means
Your SPRS score tells contracting officers, primes, and the DoD how much of NIST SP 800-171 you've actually implemented. The numbers that matter most come from the CMMC rule:
| Score Range | Risk Level | What It Means | Contractor Impact |
|---|---|---|---|
| 110 | Low Risk | All 110 requirements implemented | Meets the bar for Final CMMC Level 2 status; strongest position with primes |
| 88-109 | Moderate Risk | Most requirements in place, some gaps | Conditional CMMC Level 2 status is possible only if every open item is POA&M-eligible (certain 1-point requirements, with limited exceptions), closed within 180 days |
| 0-87 | Elevated Risk | Significant gaps | Below the 88 needed for Conditional Level 2 status; can still be posted for DFARS 7019/7020, but expect scrutiny |
| Below 0 | High Risk | Many high-weight requirements missing | Common on a first honest assessment; post it accurately and build a remediation plan |
SPRS Score Thresholds for Different Contract Types
There's no official SPRS cutoff by contract type, and DFARS 252.204-7019/-7020 don't set a minimum score. What is defined:
- CMMC Level 2 Final status: 110
- CMMC Level 2 Conditional status: at least 88 out of 110 (80%), with only allowable 1-point items on the POA&M (limited exceptions), closed within 180 days
- DFARS 7019/7020: a current score (no more than 3 years old) must be posted; contracting officers and primes decide what they're comfortable with
- Primes: some set their own expectations for suppliers, so ask
Whatever your target, the score you post must be accurate. While CMMC Phase 2 is paused, your self-assessed SPRS score is the main evidence of your NIST 800-171 status, and overstating it creates False Claims Act exposure.
Ready to improve your SPRS score?
Identify your biggest compliance gaps with a full gap analysis, then prioritize the controls that will have the most impact on your score.
Start a Gap AnalysisHow to Submit Your SPRS Score to the DoD SPRS Portal
SPRS is accessed through the PIEE portal. Once you've completed a self-assessment, you post the results there so contracting officers can see them.
Steps to post a NIST SP 800-171 Basic assessment:
- Register in PIEE and request the SPRS role for your company (you'll need your CAGE code)
- Open SPRS and go to the NIST SP 800-171 assessment entry
- Enter the assessment date, your score, the scope (CAGE codes covered), the system security plan it's based on, and, if you're below 110, the date you expect to reach 110
- Submit; your score is then visible to authorized government users
- Keep your SSP, POA&M, and evidence on file. You don't upload them, but DoD can ask
CMMC self-assessments (Level 1 and Level 2) are also entered in SPRS, along with the affirmation by a senior company official. If you pursue a voluntary C3PAO assessment, the C3PAO submits the results, and you still affirm in SPRS.
SPRS Score Improvement Strategies
Your score improves when you implement requirements. Here's how to prioritize for maximum impact:
Priority 1: Your SSP and the 5-point requirements
- Write or update your system security plan (3.12.4); without it the assessment isn't complete
- Close any open 5-point requirements, such as 3.1.1 (authorized access), 3.5.3 (multifactor authentication) and 3.13.11 (FIPS-validated encryption)
- Under CMMC, requirements weighted more than 1 point generally can't sit on a POA&M, so these have to be done before an assessment
Each 5-point requirement you close adds 5 points to your score, so a handful of them can move you a long way, often across the 88-point line.
Priority 2: The 3-point requirements
- Work through the remaining 3-point items next; they're also generally not POA&M-eligible under CMMC
Priority 3: The 1-point requirements
- Many are quick wins, like configuring logon banners (3.1.9)
- These are the items that can go on a CMMC POA&M if needed, but they still cost a point each until they're done
Common SPRS Scoring Mistakes
Many contractors misunderstand SPRS and leave points on the table. Avoid these mistakes:
- Confusing SPRS with CMMC: SPRS is a score; CMMC is a certification program. With CMMC Phase 2 paused, most contractors need an accurate self-assessment score posted in SPRS rather than a C3PAO certificate (for now).
- Using the wrong method: Scoring by family, or giving fractional credit for "mostly done," produces a number that won't hold up. Score each of the 110 requirements at its official weight.
- Partial control implementation: SPRS is binary per control—you either meet it or you don't. Implementing 90% of a control still counts as a gap. Complete controls fully.
- Forgetting subcontractors: Your score covers your own systems, but you must flow DFARS 7012 down to subs that handle CUI, and under 7019/7020 primes are expected to make sure those subs have current scores in SPRS.
- Letting it go stale: A NIST SP 800-171 score in SPRS must be no more than 3 years old, CMMC Level 2 status lasts 3 years with annual affirmations, and Level 1 is redone every year. Plan your re-assessment well in advance.
- Only pursuing Level 1: CMMC Level 1 is not enough if you handle CUI. Target Level 2 to stay competitive.
Frequently Asked Questions
Is SPRS the same as CMMC?
No. CMMC is a certification program; Level 2 can be met by self-assessment or a C3PAO assessment (third-party certification is currently voluntary while Phase 2 is paused). SPRS is where your score is recorded and seen by the DoD. They're related: your assessment results drive your SPRS score.
Can I improve my SPRS score without CMMC certification?
Yes. Your SPRS score is normally a self-assessment of NIST 800-171 compliance that you post yourself, so you improve it by implementing requirements and posting an updated assessment. No CMMC certification is needed. Self-assessment is what most contractors use today while CMMC Phase 2 is paused. A voluntary C3PAO certification is more credible evidence and can give you a competitive advantage with primes.
How often is my SPRS score updated?
Your SPRS score changes when new assessment results are entered: when you post an updated self-assessment, or when DoD records a Medium or High assessment. It must be no more than 3 years old, but you can post an update whenever you close gaps.
What if DoD assesses me and gets a different score?
A Basic assessment is your own score, so if it's wrong, you correct it by posting an updated assessment. If DoD (DIBCAC) performs a Medium or High assessment, its result is recorded in SPRS alongside yours. The best protection is a self-assessment you can back up with evidence.
Do all contractors need an SPRS score?
Contractors subject to DFARS 252.204-7012 (those handling CUI) need a current NIST SP 800-171 assessment score in SPRS to be considered for awards that include DFARS 252.204-7019. Companies that handle only Federal Contract Information (FCI) don't get a 110-point score, but where a CMMC Level 1 requirement applies they post an annual self-assessment and affirmation in SPRS. Check your contracts and your prime's flowdowns.
Can my SPRS score hurt me in contract bids?
Yes. Contracting officers and primes can see your SPRS score. A low SPRS score can result in a downgrade in technical evaluation, loss of contract awards, or requirement to implement risk mitigation measures. A strong SPRS score is a competitive advantage.