SPRS Score Calculator

Calculate your supplier performance risk score based on NIST 800-171 compliance

What is SPRS (Supplier Performance Risk System)?

SPRS is the Department of Defense's supplier performance risk evaluation system. It measures how well defense contractors implement cybersecurity controls, specifically the NIST 800-171 protection of controlled technical information (CTI). Your SPRS score is a quantitative measure of your organization's cybersecurity posture and risk to the DoD.

Unlike CMMC, which is a certification you pursue, SPRS is a risk score the DoD calculates on you. However, your SPRS score and CMMC certification are closely related: contractors with poor SPRS scores are flagged for closer scrutiny, while strong CMMC certification supports a higher SPRS score.

Key facts about SPRS:

How SPRS Scoring Works: The 110-Point System

SPRS uses a 110-point scale based on the 14 control families in NIST SP 800-171. Each control family can result in point deductions if not properly implemented. Your score starts at 110 and decreases based on gaps in your compliance.

The 14 Control Families and Deduction Points:

Control Family NIST 800-171 Area Deduction if Non-Compliant Risk If Missing
System & Communications Protection SC (Boundary protection, cryptography) -8 points Unencrypted data in transit; no network segmentation
Access Control AC (User access, privilege management) -8 points Shared accounts, weak password controls, over-privileged users
Identification & Authentication IA (MFA, strong authentication) -8 points No multi-factor authentication; weak password enforcement
Audit & Accountability AU (Logging, monitoring) -8 points No system logs; can't detect intrusions or unauthorized access
Configuration Management CM (System baselines, change control) -7 points Unauthorized system changes; no baseline documentation
Incident Response IR (Detection, response procedures) -7 points No incident response plan; delayed breach response
System & Information Integrity SI (Malware protection, patching) -8 points Unpatched systems; no endpoint detection tools
Media Protection MP (Data handling, disposal) -7 points USB drives not controlled; insecure data disposal
Physical & Environmental Protection PE (Physical security, environmental) -7 points Unsecured server rooms; no access controls
Planning PL (Security planning, risk assessment) -6 points No security plan; no risk assessments conducted
Personnel Security PS (Background checks, training) -6 points No background checks; inadequate security training
Risk Assessment RA (Ongoing risk evaluation) -6 points No regular risk assessments; unidentified vulnerabilities
Security Awareness & Training AT (Staff training, phishing) -6 points Staff not trained on security; high phishing risk
Supplier Risk Management SR (Third-party security) -6 points No vendor security assessments; sub-contractor risks unknown
Security scoring dashboard

Interactive Calculator Below

Use the calculator to check each control family and see your real-time SPRS score. Start with where you are today and identify which controls will have the most impact.

Interactive SPRS Calculator

Check the boxes below for each control family your organization has fully implemented. Your score will calculate in real-time. This calculator gives you a quick snapshot—a formal SPRS assessment by the DoD may result in a different score.

SPRS Score Calculator

Select the NIST 800-171 control families your organization has implemented

Network encryption, boundary protection, cryptography, wireless security
User account management, privilege levels, session control, access restrictions
Multi-factor authentication, password strength, biometric controls
System logging, event tracking, audit log protection, accountability
Malware protection, patch management, system monitoring, flaw remediation
System baselines, change control, configuration tracking
Incident detection, response procedures, testing, post-incident analysis
Data handling procedures, disposal controls, portable media security
Server room security, facility access control, environmental monitoring
Security plans, architecture documentation, security objectives
Background checks, security screening, personnel termination procedures
Regular risk assessments, vulnerability scanning, threat evaluation
Security training, phishing awareness, role-based training
Vendor security assessments, third-party controls, sub-contractor risk

110

Out of 110 Points

Excellent: Your organization has strong cybersecurity controls. You're well-positioned for CMMC certification and will receive favorable SPRS evaluation.
Implemented
0
Gap Areas
14
Compliance %
0%
Points at Risk
110

What Your SPRS Score Means

Your SPRS score tells contracting officers and the DoD how much cybersecurity risk you represent. Here's what different score ranges indicate:

Score Range Risk Level What It Means Contractor Impact
100-110 Low Risk Strong CMMC certification (L2 or L3); all major controls implemented Preferred supplier; favorable bid evaluation; contract priority
80-99 Moderate Risk Partial CMMC implementation; most controls in place but some gaps Competitive bidder; may need risk mitigation in contracts
60-79 Elevated Risk Basic CMMC compliance (L1); significant gaps in advanced controls Higher scrutiny in evaluations; may be passed over for higher-scored competitors
Below 60 High Risk Minimal compliance; critical control gaps; no CMMC cert or failed assessment Unfavorable evaluation; may be ineligible for some contracts; at risk of bid exclusion

SPRS Score Thresholds for Different Contract Types

Different contracts require different SPRS thresholds. While SPRS is not a hard pass/fail system, the DoD uses it to evaluate contractor risk. Meeting or exceeding these thresholds strengthens your position:

Ready to improve your SPRS score?

Identify your biggest compliance gaps with a full gap analysis, then prioritize the controls that will have the most impact on your score.

Start a Gap Analysis

How to Submit Your SPRS Score to the DoD SPRS Portal

After you obtain CMMC certification or complete a self-assessment, you can register your score in the DoD SPRS portal (SPRS.csd.disa.mil). This ensures contracting officers can access your official SPRS score.

Steps to register:

  1. Log in to SPRS portal with your company's DoD credentials (Common Access Card or user ID)
  2. Navigate to "Register CMMC Assessment" or "Submit Self-Assessment"
  3. Enter your C3PAO assessment details, certificate number, and expiration date (if applicable)
  4. The system automatically calculates your SPRS score based on CMMC data
  5. Confirm the score and submit
  6. Your SPRS score is now visible to all contracting officers in real-time

If you're pursuing CMMC, the C3PAO automatically registers your certificate in the CMMC portal, and the DoD pulls that data to update your SPRS score. You don't need to manually register CMMC assessments—it happens automatically.

SPRS Score Improvement Strategies

Your score improves when you implement controls. Here's how to prioritize for maximum impact:

Phase 1 Priority (Highest Impact, 8-Point Deductions Each):

Implementing these five controls alone jumps your score from 110 to 60 points and removes your most critical vulnerabilities.

Phase 2 Priority (Mid-Impact, 7-Point Deductions Each):

Phase 3 Priority (Foundational, 6-Point Deductions Each):

Common SPRS Scoring Mistakes

Many contractors misunderstand SPRS and leave points on the table. Avoid these mistakes:

Frequently Asked Questions

Is SPRS the same as CMMC?

No. CMMC is a certification you pursue through a C3PAO assessment. SPRS is a score the DoD calculates on you. However, they're related: your CMMC certification drives your SPRS score. A strong CMMC cert results in a high SPRS score.

Can I improve my SPRS score without CMMC certification?

Yes. The DoD accepts self-assessments of NIST 800-171 compliance. You can submit a self-assessment and receive an SPRS score without formal CMMC certification. However, CMMC certification results in a higher, more credible score that gives you a competitive advantage.

How often is my SPRS score updated?

Your SPRS score updates when you submit new assessment data (CMMC cert, self-assessment update, etc.) to the SPRS portal. The DoD checks the CMMC registry daily for new certifications, so CMMC certs are reflected in SPRS within 24 hours of registration.

What if I disagree with my calculated SPRS score?

You can dispute your SPRS score by submitting evidence of control compliance to the SPRS portal. If the DoD disagrees with your initial score, the official CMMC assessment by a C3PAO is the most authoritative way to correct it. A formal CMMC cert will override self-assessment data.

Do all contractors need an SPRS score?

Only contractors with controlled technical information (CTI) or federal contract information (FCI) are automatically scored in SPRS. If you don't handle CTI/FCI, you may not have an active SPRS score. Check with your contracting officer if CMMC/SPRS applies to you.

Can my SPRS score hurt me in contract bids?

Yes. Many contracting officers now use SPRS scores as an evaluation criterion. A low SPRS score can result in a downgrade in technical evaluation, loss of contract awards, or requirement to implement risk mitigation measures. A strong SPRS score is a competitive advantage.