How to calculate your SPRS score with the weighted deduction method, a worked example, PIEE submission mechanics, affirmation, and CMMC status.
Your SPRS score is a single number, between -203 and 110, that tells the Department of War (DoW) how completely you have implemented NIST SP 800-171. You calculate it with the DoD Assessment Methodology: start at 110 and subtract weighted points for each of the 110 requirements you have not fully met. Then you submit it through the PIEE portal into the SPRS (Supplier Performance Risk System) module, where a senior company official affirms it is accurate. A current score and affirmation are required for DoW awards and option exercises, and submitting an inflated score carries False Claims Act exposure. This is not a number to guess at.
This guide shows exactly how the scoring works, walks a worked example from 110 downward, covers the PIEE submission and affirmation mechanics, and explains what score the Department actually expects and how your CMMC status shows up in SPRS.
SPRS, the Supplier Performance Risk System, is the Department's system of record for supplier risk information, including your NIST SP 800-171 self-assessment score. The score is DoW's shorthand for "how secure is this contractor's handling of CUI." A contracting officer can look you up and see a number. That number gates award eligibility and, increasingly, feeds the broader CMMC picture.
The score reflects your implementation of NIST 800-171 Rev 2 — the operative DoW baseline (Rev 3 is finalized but not adopted for contracts; see our NIST 800-171 Rev 3 guide).
The methodology is deliberately strict: a requirement counts only when it is fully implemented, with two narrow exceptions for partial credit.
You start at a perfect 110 — the score you get if all 110 Rev 2 requirements are fully implemented. Then, for each requirement you have not fully met, you subtract its weighted value:
Weights reflect how much a given requirement matters to protecting CUI: the more fundamental the control, the bigger the deduction for missing it. For almost every requirement, "mostly implemented" scores the same as "not implemented," because you either meet the requirement in full or you take the full deduction. The two exceptions are multifactor authentication (3.5.3), which deducts 3 points instead of 5 when MFA covers remote and privileged users but not yet general users, and encryption (3.13.11), which deducts 3 points instead of 5 when encryption is employed but not FIPS-validated. The System Security Plan (3.12.4) carries no point weight, but an assessment cannot be completed without one.
Add up all your deductions, subtract from 110, and you have your score. The weights across all 110 requirements add up to 313 points, so the score can go deep into the negative: under the DoD Assessment Methodology (v1.2.1), the floor is -203. The CMMC rule codifies the same 5-, 3-, and 1-point deductions at 32 CFR 170.24.
Say a contractor has most controls in place but is missing a handful. Here is how the math runs:
| Step | Requirement not met | Weight | Running score |
|---|---|---|---|
| Start | — (all implemented) | — | 110 |
| 1 | MFA covers remote and privileged users but not general users (3.5.3, partial credit) | −3 | 107 |
| 2 | Encryption employed but not FIPS-validated (3.13.11, partial credit) | −3 | 104 |
| 3 | Security controls not monitored on an ongoing basis (3.12.3) | −5 | 99 |
| 4 | Incident response capability not tested (3.6.3) | −1 | 98 |
| 5 | Logged events not reviewed and updated (3.3.3) | −1 | 97 |
| 6 | Connection of mobile devices not controlled (3.1.18) | −5 | 92 |
| 7 | Session lock not configured everywhere (3.1.10) | −1 | 91 |
| Score | 7 requirements open | — | 91 |
Illustrative example: the contractor is hypothetical, and the point values follow the DoD Assessment Methodology for each requirement listed. Confirm each point value against the methodology before you score your own environment. The pattern is what matters: a few high-weight misses drop you fast, which is why 5-point requirements such as ongoing monitoring and mobile device control, along with the partially credited MFA and encryption requirements, are the ones to close first. This example also scores above the 88-point threshold for CMMC Conditional status without qualifying for it, because 3.5.3, 3.12.3, and 3.1.18 are worth more than 1 point and 32 CFR 170.21 does not allow them on a POA&M.
There is no universal "passing" number in the way people hope, but here is the practical reality:
The honest framing: aim for 110, report honestly if you are below it, and put every gap on a POA&M with a real closure date.
Submission runs through the PIEE (Procurement Integrated Enterprise Environment) portal into the SPRS module. The mechanics:
The affirmation is the legally loaded step. Submitting an inflated score, or a POA&M completion date you know you will not hit, is a false statement to the government and carries False Claims Act exposure. The whole system runs on the assumption that the number is honest — so make it honest.
SPRS is also where your CMMC standing surfaces:
So SPRS now carries both your raw NIST 800-171 score and your CMMC status. The clause numbers behind the submission changed in 2026. Since February 1, 2026, under the Revolutionary FAR Overhaul class deviation, DFARS 252.204-7019 (the provision that historically required score posting) no longer appears in new solicitations, and DFARS 252.204-7020 has been renumbered DFARS 252.240-7997. Older contracts may still carry the legacy clause numbers. SPRS remains the system of record, and a current score and affirmation are still required for awards and option exercises. The removal of -7019 from new solicitations does not end SPRS submissions.
What is SPRS? SPRS, the Supplier Performance Risk System, is DoW's authoritative system for supplier risk data, including NIST SP 800-171 self-assessment scores and CMMC statuses. Contracting officers use it to check whether a contractor has a current, adequate score before award. You submit to it through the PIEE portal.
What is an SPRS score? It is a number from -203 to 110 representing how completely you have implemented the 110 requirements of NIST SP 800-171 Rev 2. You start at 110 and subtract weighted points (1, 3, or 5) for each requirement not fully met. 110 means full implementation; negative scores signal major gaps.
What is a good SPRS score? 110, which means full implementation, is the target and what a mature program reports. Any positive score is better than a negative one, but CMMC Level 2 Conditional status requires at least 88 and some requirements cannot be deferred, so a middling score is not a safe place to sit. Report honestly and close gaps via a POA&M rather than chasing a number.
How do I submit my SPRS score? Register in PIEE, get approved for SPRS access, open the NIST SP 800-171 Assessments module, and enter your assessment date, score, scope, POA&M completion date, CAGE code(s), and SSP details. A senior company official then affirms the entry is accurate. Budget time for the PIEE access approval — it is not instant.
When does a company need a CMMC certification versus an SPRS score? They are related but distinct. A NIST 800-171 self-assessment score in SPRS has long been required of contractors that handle CUI under DFARS 252.204-7012, and a current score and affirmation are still required for awards and option exercises. CMMC is the verification layer on top. The Department has suspended CMMC Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program. Phase 1 remains in effect, so contracts can still require CMMC Level 1 and Level 2 self-assessments with affirmations in SPRS. The contract tells you which applies, and both connect back to SPRS.
Can I submit an SPRS score if I'm below 110? Yes — you report your actual score, whatever it is, and pair it with a POA&M for the open items. What you cannot do is inflate the number or record a POA&M completion date you know is false; that carries False Claims Act liability. An honest below-110 score with a credible remediation plan is the correct submission.
Your SPRS score is a legal attestation, not an estimate. The contractors who run into trouble are the ones who guess at weights, over-report to look competitive, or let the score go stale. The ones who do it right calculate honestly against the DoD methodology, back every "met" with evidence, and put every gap on a dated POA&M.
Book a demo and we will show you how Compli.ai computes your SPRS score live from your Controls Matrix using the DoD Assessment Methodology, shows which requirements are costing you points, and keeps the score, the SSP implementation statements, and the POA&M in one record inside your own Microsoft 365 tenant, so your affirmation rests on work you can show. It is built by practitioners who submit these for a living. Before you submit, start with our NIST 800-171 compliance guide and SSP walkthrough, or explore your options with CMMC compliance software.