{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.compli.ai/"},{"@type":"ListItem","position":2,"name":"CMMC for SharePoint","item":"https://www.compli.ai/cmmc-for-sharepoint"},{"@type":"ListItem","position":3,"name":"SPRS Scoring & POA&M","item":"https://www.compli.ai/cmmc-sharepoint-sprs-scoring"}]}
Your CMMC self-assessment puts a current score in SPRS, and your affirmation of that score stands behind the safeguards protecting the CUI in your environment. That number is defined by the DoD Assessment Methodology (v1.2.1), and the CMMC rule codifies the same scoring arithmetic at 32 CFR 170.24. The GRC Hub computes it live from your Controls Matrix using that methodology, and it enforces the POA&M eligibility rules of 32 CFR 170.21 the same way. Scores are never rounded up, and the hub does not substitute an invented compliance percentage for the number an assessor would calculate.
You start at 110. Every requirement that is not Implemented (and not a justified Not Applicable) deducts its DoW-assigned weight — 1, 3, or 5 points. The scale runs from 110 down to −203.
A new deployment starts at −203 because nothing has been assessed yet. The score rises as you record the implementation status of each requirement, using the same arithmetic a government assessor would apply.
88 or above is the floor for Conditional Level 2 status. The dashboard shows your score in green at or above that threshold and in red below it, and it raises a standing warning for anything that would undermine an assessment, such as an unjustified N/A or a missing System Security Plan.
On July 13, 2026, the Department suspended CMMC Phase II, the third-party assessment mandates, and opened a 60-day program review. What is under review is the program that verifies CUI handling, not the obligation to handle CUI properly, and none of this math changed. Awards and option exercises still require a current, affirmed SPRS score computed this way, and the Phase 1 self-assessment requirements remain in force.
If MFA covers remote and privileged users but not yet general users, the methodology deducts 3 points instead of 5. You record that condition explicitly on the control, and the hub applies the partial credit only where the regulation allows it.
When encryption is employed but not yet FIPS-validated, the control deducts 3 points instead of 5, and under that condition alone it becomes POA&M-eligible.
The System Security Plan carries no point weight, but under the DoD Assessment Methodology an assessment cannot be completed without it. The dashboard shows a standing warning until it is in place.
A gap in the safeguards around your CUI can be deferred only where the regulation allows it. 32 CFR 170.21 strictly limits what may be deferred to a Plan of Action & Milestones, and the hub enforces those limits at the moment you create one:
When a control cannot be placed on a POA&M, the hub shows you why and cites the rule. That keeps an ineligible gap on the remediation path instead of parked where an assessor would find it.
Reaching Conditional status starts a new deadline of 180 days to close out the POA&M. You set the window start once in Settings, and the countdown then runs on the dashboard and the POA&M page, escalating inside the final 30 days. Closing an item records the actual completion date, with full version history behind it.
A demo takes about an hour and shows the scoring engine running against a live Controls Matrix.