compli.ai
From the blog

SPRS Scores: How to Calculate and Submit Yours

How to calculate your SPRS score with the weighted deduction method, a worked example, PIEE submission mechanics, affirmation, and CMMC status.

Your SPRS score is a single number, between -203 and 110, that tells the Department of War (DoW) how completely you have implemented NIST SP 800-171. You calculate it with the DoD Assessment Methodology: start at 110 and subtract weighted points for each of the 110 requirements you have not fully met. Then you submit it through the PIEE portal into the SPRS (Supplier Performance Risk System) module, where a senior company official affirms it is accurate. A current score and affirmation are required for DoW awards and option exercises, and submitting an inflated score carries False Claims Act exposure. This is not a number to guess at.

This guide shows exactly how the scoring works, walks a worked example from 110 downward, covers the PIEE submission and affirmation mechanics, and explains what score the Department actually expects and how your CMMC status shows up in SPRS.

What SPRS is and why the score matters

SPRS, the Supplier Performance Risk System, is the Department's system of record for supplier risk information, including your NIST SP 800-171 self-assessment score. The score is DoW's shorthand for "how secure is this contractor's handling of CUI." A contracting officer can look you up and see a number. That number gates award eligibility and, increasingly, feeds the broader CMMC picture.

The score reflects your implementation of NIST 800-171 Rev 2 — the operative DoW baseline (Rev 3 is finalized but not adopted for contracts; see our NIST 800-171 Rev 3 guide).

How the SPRS score is calculated

The methodology is deliberately strict: a requirement counts only when it is fully implemented, with two narrow exceptions for partial credit.

You start at a perfect 110 — the score you get if all 110 Rev 2 requirements are fully implemented. Then, for each requirement you have not fully met, you subtract its weighted value:

  • Subtract 5 points for the most impactful requirements not met.
  • Subtract 3 points for moderately impactful requirements not met.
  • Subtract 1 point for the least impactful requirements not met.

Weights reflect how much a given requirement matters to protecting CUI: the more fundamental the control, the bigger the deduction for missing it. For almost every requirement, "mostly implemented" scores the same as "not implemented," because you either meet the requirement in full or you take the full deduction. The two exceptions are multifactor authentication (3.5.3), which deducts 3 points instead of 5 when MFA covers remote and privileged users but not yet general users, and encryption (3.13.11), which deducts 3 points instead of 5 when encryption is employed but not FIPS-validated. The System Security Plan (3.12.4) carries no point weight, but an assessment cannot be completed without one.

Add up all your deductions, subtract from 110, and you have your score. The weights across all 110 requirements add up to 313 points, so the score can go deep into the negative: under the DoD Assessment Methodology (v1.2.1), the floor is -203. The CMMC rule codifies the same 5-, 3-, and 1-point deductions at 32 CFR 170.24.

Worked example: starting at 110 and subtracting

Say a contractor has most controls in place but is missing a handful. Here is how the math runs:

StepRequirement not metWeightRunning score
Start— (all implemented)—110
1MFA covers remote and privileged users but not general users (3.5.3, partial credit)−3107
2Encryption employed but not FIPS-validated (3.13.11, partial credit)−3104
3Security controls not monitored on an ongoing basis (3.12.3)−599
4Incident response capability not tested (3.6.3)−198
5Logged events not reviewed and updated (3.3.3)−197
6Connection of mobile devices not controlled (3.1.18)−592
7Session lock not configured everywhere (3.1.10)−191
Score7 requirements open—91

Illustrative example: the contractor is hypothetical, and the point values follow the DoD Assessment Methodology for each requirement listed. Confirm each point value against the methodology before you score your own environment. The pattern is what matters: a few high-weight misses drop you fast, which is why 5-point requirements such as ongoing monitoring and mobile device control, along with the partially credited MFA and encryption requirements, are the ones to close first. This example also scores above the 88-point threshold for CMMC Conditional status without qualifying for it, because 3.5.3, 3.12.3, and 3.1.18 are worth more than 1 point and 32 CFR 170.21 does not allow them on a POA&M.

What score does DoW expect?

There is no universal "passing" number in the way people hope, but here is the practical reality:

  • 110 is the goal — full implementation. It is what a mature program reports.
  • A negative score is a serious red flag to a contracting officer and signals a program with major gaps.
  • The score must be current. Self-assessment scores are generally valid for 3 years, and a current score and affirmation are required for awards and option exercises.
  • For CMMC Level 2, the score is not the whole story. Some requirements cannot be deferred to a POA&M, and there is a minimum score threshold for conditional status: at least 88 of 110 under 32 CFR 170.21. A middling number does not earn Conditional status on its own. See our POA&M guide for what can and cannot sit open.

The honest framing: aim for 110, report honestly if you are below it, and put every gap on a POA&M with a real closure date.

How to submit your SPRS score

Submission runs through the PIEE (Procurement Integrated Enterprise Environment) portal into the SPRS module. The mechanics:

  1. Register in PIEE and get SPRS access. You (or your affirming official) must be a registered PIEE user and approved for the SPRS role. This approval step catches people off guard — request it before you are up against a deadline.
  2. Open the NIST SP 800-171 Assessments module in SPRS.
  3. Enter the assessment details. SPRS stores: the assessment date, the score, the assessment scope, your POA&M completion date, your CAGE code(s), and your SSP name, version, and date.
  4. Record the assessment type. A contractor self-assessment is what the legacy DFARS 252.204-7020 clause called a Basic assessment; the replacement clause, DFARS 252.240-7997, defines only the government-performed Medium and High assessments.
  5. Affirm accuracy. A senior company official / affirming official attests that the score and details are accurate.

The affirmation is the legally loaded step. Submitting an inflated score, or a POA&M completion date you know you will not hit, is a false statement to the government and carries False Claims Act exposure. The whole system runs on the assumption that the number is honest — so make it honest.

How CMMC status appears in SPRS

SPRS is also where your CMMC standing surfaces:

  • CMMC self-assessment results and affirmations (Level 1 Self, Level 2 Self) are recorded in SPRS.
  • C3PAO and DIBCAC certification statuses flow into the CMMC eMASS/SPRS ecosystem and appear as your CMMC Status with a unique identifier (CMMC UID).
  • During the phase-in, primes provide their applicable CMMC UID(s) to the contracting officer.

So SPRS now carries both your raw NIST 800-171 score and your CMMC status. The clause numbers behind the submission changed in 2026. Since February 1, 2026, under the Revolutionary FAR Overhaul class deviation, DFARS 252.204-7019 (the provision that historically required score posting) no longer appears in new solicitations, and DFARS 252.204-7020 has been renumbered DFARS 252.240-7997. Older contracts may still carry the legacy clause numbers. SPRS remains the system of record, and a current score and affirmation are still required for awards and option exercises. The removal of -7019 from new solicitations does not end SPRS submissions.

FAQ

What is SPRS? SPRS, the Supplier Performance Risk System, is DoW's authoritative system for supplier risk data, including NIST SP 800-171 self-assessment scores and CMMC statuses. Contracting officers use it to check whether a contractor has a current, adequate score before award. You submit to it through the PIEE portal.

What is an SPRS score? It is a number from -203 to 110 representing how completely you have implemented the 110 requirements of NIST SP 800-171 Rev 2. You start at 110 and subtract weighted points (1, 3, or 5) for each requirement not fully met. 110 means full implementation; negative scores signal major gaps.

What is a good SPRS score? 110, which means full implementation, is the target and what a mature program reports. Any positive score is better than a negative one, but CMMC Level 2 Conditional status requires at least 88 and some requirements cannot be deferred, so a middling score is not a safe place to sit. Report honestly and close gaps via a POA&M rather than chasing a number.

How do I submit my SPRS score? Register in PIEE, get approved for SPRS access, open the NIST SP 800-171 Assessments module, and enter your assessment date, score, scope, POA&M completion date, CAGE code(s), and SSP details. A senior company official then affirms the entry is accurate. Budget time for the PIEE access approval — it is not instant.

When does a company need a CMMC certification versus an SPRS score? They are related but distinct. A NIST 800-171 self-assessment score in SPRS has long been required of contractors that handle CUI under DFARS 252.204-7012, and a current score and affirmation are still required for awards and option exercises. CMMC is the verification layer on top. The Department has suspended CMMC Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program. Phase 1 remains in effect, so contracts can still require CMMC Level 1 and Level 2 self-assessments with affirmations in SPRS. The contract tells you which applies, and both connect back to SPRS.

Can I submit an SPRS score if I'm below 110? Yes — you report your actual score, whatever it is, and pair it with a POA&M for the open items. What you cannot do is inflate the number or record a POA&M completion date you know is false; that carries False Claims Act liability. An honest below-110 score with a credible remediation plan is the correct submission.

Get your SPRS score right the first time

Your SPRS score is a legal attestation, not an estimate. The contractors who run into trouble are the ones who guess at weights, over-report to look competitive, or let the score go stale. The ones who do it right calculate honestly against the DoD methodology, back every "met" with evidence, and put every gap on a dated POA&M.

Book a demo and we will show you how Compli.ai computes your SPRS score live from your Controls Matrix using the DoD Assessment Methodology, shows which requirements are costing you points, and keeps the score, the SSP implementation statements, and the POA&M in one record inside your own Microsoft 365 tenant, so your affirmation rests on work you can show. It is built by practitioners who submit these for a living. Before you submit, start with our NIST 800-171 compliance guide and SSP walkthrough, or explore your options with CMMC compliance software.