Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

The SPRS score explained

SPRS Score: A Clear Guide to the 2026 Scoring Rules

Your SPRS score is a single number between 110 and -203 that tells the Department of Defense how much of NIST SP 800-171 you have actually implemented. It is self-reported, it is a condition of award on covered contracts, and it is the figure a CMMC assessment starts from — which is why an honest one is worth more than a flattering one.

This guide covers how the score is calculated, the two requirements that earn partial credit, how long it stays current, and what a low score does and does not prevent.

SPRS score calculation: 110 points less weighted deductions
Start at 110, subtract the published weight of everything not implemented.

How the SPRS score is calculated

The method comes from the NIST SP 800-171 DoD Assessment Methodology, version 1.2.1, dated 24 June 2020. You begin at 110 — one point for each of the 110 security requirements in NIST SP 800-171 Revision 2 — and subtract a published weight for every requirement not fully implemented.

Weight What it means Effect if not implemented
5 points Absence has a significant effect on the security of the system and the CUI in it -5 each
3 points Specific and confined effect -3 each
1 point Limited or indirect effect -1 each

The weights are fixed in the methodology’s tables. An assessor looks them up; nobody chooses them. Implement everything and the SPRS score is 110. Implement none of it and the arithmetic bottoms out at -203, which is why a negative number is normal for an organization at the start of a programme rather than a sign that something has gone wrong.

The two requirements with partial credit

Almost every requirement is all or nothing. Two are not:

  • 3.5.3, multifactor authentication. Worth 5. If MFA is in place for remote and privileged access but not for all users, 3 points are deducted rather than 5.
  • 3.13.11, FIPS-validated cryptography. Worth 5. If encryption is employed but is not FIPS-validated, 3 points are deducted rather than 5.

Everywhere else, “mostly implemented” scores the same as “not implemented”. That is the single most common reason a self-assessed SPRS score comes back lower than the team expected.

Which revision the SPRS score is based on

Revision 2. NIST published Revision 3 of SP 800-171, but the DoD assessment methodology, the DFARS clauses and the CMMC programme still run on the 110 requirements of Revision 2, and scoring against Revision 3 produces a number nobody can use. Our guide to which revision your contract names covers how to check, and the template set covers how to tell Rev 2 content from Rev 3 without reading every page.

Submitting and maintaining the score

  1. Assess against the system security plan. The plan defines the boundary being scored. Without one, there is nothing to assess and the requirement covering it is itself unmet.
  2. Score at the system level. Each covered information system gets its own SPRS score, with its own boundary and its own plan.
  3. Post it in SPRS. Summary-level results for Basic (contractor self-assessment), Medium and High (government-conducted) assessments are posted in the Supplier Performance Risk System.
  4. Keep it current. An assessment older than three years is no longer current, and a contracting officer treats it as absent.
  5. Flow it down. DFARS 252.204-7020 requires the substance of the clause in subcontracts, so a subcontractor handling covered information needs its own current assessment.
  6. Re-score after real change. New systems, a moved boundary or a completed remediation project all change the number. Update it when the facts change, not only when a bid is due.

What a low SPRS score actually blocks

On its own, a low score does not disqualify you from a DFARS 7019/7020 award — having no current assessment posted does. Under CMMC the arithmetic bites harder: a Level 2 assessment needs at least 88 of 110 before unimplemented items may be carried on a plan of action and milestones at all, POA&M items are confined to the lower-weighted requirements so the 5-point ones must be fully implemented at assessment, and the plan has to be closed out within 180 days of the conditional status date or the status expires.

Where SPRS scores go wrong

Optimism about scope. A score calculated over a “CUI enclave” that the business routinely works outside of is measuring the wrong system.

Policy counted as implementation. A written procedure with no configuration behind it does not implement a technical requirement, and a High assessment will find that quickly.

A number nobody can reproduce. Keep the working: requirement, status, evidence, weight, deduction. A score you cannot rebuild on request is a liability, because the submission is a representation to the government and inaccurate cyber representations have been pursued under the False Claims Act.

Frequently asked questions

What is a good SPRS score?
110 is full implementation. For CMMC Level 2 the practical floor is 88, since below that no plan of action and milestones is permitted. Anything lower is a programme plan, not a bidding position.

How long does an SPRS score last?
Three years, unless the solicitation specifies something shorter or the environment changes materially in the meantime.

Can the score be negative?
Yes. The minimum is -203, reached when none of the 110 requirements is implemented.

Who can perform the assessment?
A Basic assessment is a self-assessment. Medium and High assessments are performed by the government, and a High assessment includes verification of the evidence rather than acceptance of the claim.

Does a CMMC certificate replace the SPRS score?
No. The scoring methodology underpins CMMC Level 2, and results are recorded in SPRS. The score remains the currency in which DoD reads your implementation status.

Where this leaves you

Calculate the SPRS score against a real system security plan, score honestly, and keep the working paper that produced the number. Fix the 5-point requirements first — they carry the most arithmetic and cannot be deferred under CMMC — take the partial credit on MFA and FIPS cryptography only where it genuinely applies, and refresh the assessment when the environment changes rather than waiting for the three-year clock. A defensible number you can rebuild beats a high one you cannot.

References

More on CUI and DoD compliance

Scoring worksheets, the system security plan and the CUI policy set are in the NIST SP 800-171 CUI Protection Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.