What is an SPRS score and how do I improve it?
An SPRS score is the summary result of your NIST SP 800-171 Rev 2 assessment, posted in DoD's Supplier Performance Risk System. You start at 110 and subtract 1, 3 or 5 points for each requirement not met, so the score can go negative. You raise it by implementing the highest-weighted missing controls first, documenting them in your System Security Plan, and re-assessing.
What SPRS is and who sees it
The Supplier Performance Risk System is DoD's database of supplier performance information. For cybersecurity, it holds summary-level scores of NIST SP 800-171 assessments and, under CMMC, your CMMC status, assessment scope, CAGE codes and affirmations. Only the overall number is posted, not your result on each requirement.
Scores in SPRS are available to DoD personnel and protected under DoD policy. Your own authorized representatives can view your scores. Contracting officers use them to check whether you meet a solicitation's requirements.
For a CMMC Level 2 self-assessment, the SPRS entry must include at minimum the CMMC level, the status date, the assessment scope, every CAGE code covered by that scope, the overall score, such as 105 out of 110, and whether a POA&M is in use. SPRS assigns a CMMC unique identifier to each assessment, which you report to contracting officers.
How the score is calculated
Under 32 CFR 170.24, the maximum score equals the number of Level 2 requirements, 110. Each requirement not met subtracts its value:
- 5 points for requirements whose absence could lead to significant exploitation of the network or exfiltration of CUI, such as access control, audit logging, incident response, malware protection and boundary protection.
- 3 points for requirements with a specific and confined effect, such as tracing actions to individual users and protecting and sanitizing media.
- 1 point for the remaining requirements.
- Partial credit in two cases: MFA for remote and privileged users only costs 3 points instead of 5, and encryption that is not FIPS-validated costs 3 instead of 5.
- No System Security Plan means the assessment cannot be completed at all.
What score you need
To post Conditional Level 2 (Self), your score must be at least 88 of 110, with only allowed requirements on a POA&M, and you must close those within 180 days to reach Final status. A Level 2 self-assessment is renewed every three years, and a senior official must affirm continuing compliance at each assessment and annually. While Phase 2 is suspended, new DoD solicitations may only call for Level 1 or Level 2 self-assessments, so your SPRS entry is the main evidence DoD sees.
How to raise it, in order
- Confirm scope first: a smaller, well-defined CUI boundary means fewer assets to bring into compliance.
- Write or update the System Security Plan so every requirement has an implementation description and evidence location.
- Fix 5-point gaps first: MFA for all users, audit logging, malware protection, incident response, and limiting system access.
- Close 3-point gaps next, then 1-point items, which are the only ones generally allowed on a POA&M.
- Replace non-FIPS encryption for CUI with FIPS-validated modules.
- Re-assess with the NIST SP 800-171A objectives and post the new score.
Accuracy beats a high number
The affirming official attests that the posted score is accurate. DoD can conduct a Medium or High assessment, and the clause says those government results take precedence over your own. Score yourself strictly against the assessment objectives, since an inflated score is a contractual and legal liability, not an asset.
Common follow-up questions
What is the lowest possible SPRS score?
Because each unmet requirement subtracts 1, 3 or 5 points from 110, a company with few controls in place can have a negative score. The rule does not set a floor for posting, but Conditional Level 2 status requires at least 88 points.
How often must I update my SPRS score?
A Level 2 self-assessment must be repeated at least every three years, a POA&M closeout must be posted within 180 days, and a senior official must affirm continuing compliance every year. Update sooner if your environment or compliance status changes materially.
Can my MSP post my SPRS score for me?
An MSP or consultant can prepare the assessment and evidence, but your company owns the score and the affirmation. The affirming official must be a senior person at your company who is responsible for compliance and can attest the result is accurate.
LAN Service Group's certified ISSO runs NIST SP 800-171 self-assessments against the assessment objectives, prioritizes remediation by point value and prepares the SSP and evidence behind your SPRS score.
Talk to LAN Service Group (888) 281-7243Sources
- 32 CFR Part 170, CMMC Program (eCFR): sections 170.15, 170.16, 170.21, 170.24
- DFARS Class Deviation 2026-O0025, Revision 3 (DFARS Part 240, incl. 252.240-7997 and 252.204-7021)
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements
- Under Secretary of War memo: Implementing Suspension of CMMC Phase 2 Requirements (Jul 13, 2026)