top of page

SPRS Score: Free CMMC Score Calculator and What Your Number Actually Means

Nav
7 hours ago
8 min read

Most defense contractors I talk to know their SPRS score the way I know my cholesterol: roughly, optimistically, and from a test a few years ago. That's fine right up until a contracting officer checks, or a prime asks for it in writing.


Here's the short answer. Your SPRS score is the number you post in the Supplier Performance Risk System after assessing yourself against the 110 security requirements in NIST SP 800-171. You start at 110 and subtract 1, 3 or 5 points for every requirement you haven't met, so the score runs from 110 all the way down to -203. For CMMC Level 2, the number that matters most is 88.


sprs score

TL;DR: Use the calculator below to get your SPRS score in about 20 minutes. It uses the DoD's exact point values. Anything below 88 needs work before your next bid, and a "we plan to" on a requirement still counts as not met.

I spent a decade doing IT inside the government contractor world before I started NSOCIT, and the SPRS score was always the number people were a little nervous to say out loud. So I built a calculator that does the math for you and tells you what to fix first.


Defense contractor calculating his SPRS score on a laptop

Calculate Your SPRS Score Right Here


Work through the 14 requirement families one at a time. Mark each requirement Met, Not met, or (for the few where it's allowed) partially met or not permitted in your environment. The score at the top updates as you go. At the end you get your estimated SPRS score, a CMMC Level 2 conditional check, and a fix list sorted by points.



Your answers are saved in your browser, so you can close the page and come back. Nothing is sent to us or anyone else. If you want a copy for your system security plan folder, the results screen has a CSV download.


Checklist on a clipboard representing how the SPRS score is calculated from 110 NIST SP 800-171 requirements

How the SPRS Score Is Calculated


The math comes from the DoD's NIST SP 800-171 Assessment Methodology. Its scoring template is blunt about it: "If all requirements are met, a score of 110 is awarded. For each requirement not met, the associated value is subtracted from 110."


Each of the 110 requirements carries a weight:


  • 5 points (42 requirements): the ones that, if missing, could lead to a real breach. Access control, audit logging, incident response, malware protection and boundary protection live here.

  • 3 points (14 requirements): a narrower effect, like least privilege (3.1.5) or encrypting CUI on mobile devices (3.1.19).

  • 1 point (51 requirements): limited or indirect effect, like session lock or privacy notices.


Two requirements get partial credit. Multi-factor authentication (3.5.3) costs 5 points if it's missing and 3 if you only have it for remote and privileged users. Encryption (3.13.11) costs 5 if you don't encrypt CUI at all and 3 if you encrypt it without FIPS-validated modules.


A few more rules trip people up:


  • No system security plan, no score. Requirement 3.12.4 has no point value. Without an SSP, the methodology says the assessment "could not be completed."

  • A plan to fix it doesn't count as fixed. An item on your plan of action is still Not met.

  • Remote, wireless and mobile get a pass if you don't allow them. Five requirements (3.1.12, 3.1.13, 3.1.16, 3.1.17 and 3.1.18) cost nothing if the capability isn't permitted, as long as you have a policy that keeps it that way.


That's why 42 five-point requirements can drag an honest first attempt well into negative numbers. Getting there isn't a disaster. Leaving it there is.


Score display representing what counts as a good SPRS score

What Is a Good SPRS Score?


The only truly good SPRS score is 110. Everything else is a work in progress with a deadline attached.


The practical line is 88. Under the CMMC rule at 32 CFR 170.21, you can only hold Conditional Level 2 status if your score divided by 110 "is greater than or equal to 0.8." That works out to 88.


Even at 88, the rule limits what you're allowed to leave open:


  • Only 1-point requirements can go on the plan of action, plus 3.13.11 at 3 points if you encrypt but aren't FIPS-validated

  • A handful can never be on it: 3.1.20, 3.1.22, 3.10.3, 3.10.4, 3.10.5 and your system security plan (3.12.4)

  • Everything on the plan has to be closed within 180 days, or the conditional status expires


So a score of 90 with an open 5-point item doesn't qualify. The calculator checks all three conditions for you.


Government building in Washington representing the CMMC Phase 2 suspension

Phase 2 Is Suspended. Your SPRS Score Just Got More Important.


If you've been following CMMC, you know the plan was for third-party certification to start being required on November 10, 2026. That's off, at least for now.


On July 13, 2026, DoD suspended Phase 2, and on September 3 a class deviation told contracting officers to strip third-party assessment requirements out of contracts, according to Washington Technology. A reform task force is reviewing the program.


Here's the part people are missing. Phase 1 stayed. DoD CIO Kirsten Davies said the department would keep relying on "self-assessments and select government-led assessments," as Washington Technology reported the day it was announced. Your self-assessed SPRS score is now the main number DoD sees.


And it still has to be current. DFARS 252.204-7019 requires a current assessment, "not more than 3 years old unless a lesser time is specified in the solicitation." If yours is from 2023, check the date.


Server room network equipment covered by five-point NIST SP 800-171 requirements

The Five-Point Requirements That Sink Most Scores


In my experience, the same handful of 5-point items show up on almost every first assessment. If you only fix five things this quarter, look here first:


  • 3.5.3 Multi-factor authentication. Up to 5 points. MFA for admins but not everyone else still costs you 3.

  • 3.3.1 Audit logs. You need logs detailed enough to investigate something. "The firewall probably keeps some" doesn't count.

  • 3.13.11 FIPS-validated encryption. Encryption that isn't FIPS-validated costs 3. No encryption costs 5.

  • 3.12.1 and 3.12.3 Assessing and monitoring your controls. Five points each for checking that your security actually works, on a schedule.

  • 3.14.1 to 3.14.3 Patching, malware protection and security alerts. Fifteen points between them, and the most fixable items on the list.

  • 3.6.1 and 3.6.2 Incident response. A real, tested process, and a way to report incidents. DFARS 7012 defines "rapidly report" as "within 72 hours of discovery of any cyber incident," so the process matters.


Fix these and a score in the negative numbers can move into the 60s or 70s quickly. The last stretch to 88 is usually the 1-point documentation items nobody enjoys.


Assessment report on a desk, the evidence behind an SPRS score you can defend

A Low Score You Can Defend Beats a High One You Can't


Here's my one strong opinion on this. A 110 posted in SPRS is a lot like a compliance badge on a website. It satisfies whoever glances at it. It doesn't mean the controls are running.


I watched this for years from the inside. Somebody fills out the assessment the week before a bid, rounds every "sort of" up to "met," and posts a number that looks great. Then a prime asks for the evidence, or DoD does a medium assessment, and the score drops by 60 points in an afternoon.


That's worse than just being low. The score is a representation to the government, and there are consequences for false or inadequate assessments. A contractor who posts 45 with a real plan of action is in a much better spot than one who posts 110 and can't show the SSP.


So be honest with the calculator. It's only useful if the number it gives you is one you'd be comfortable defending.


Laptop keyboard used to post an SPRS score through PIEE

How to Post Your Score in SPRS


Once you have a number you trust, posting it is mostly paperwork. Per the DoD methodology, you'll need:


  1. A PIEE account with the SPRS "Cyber Vendor" role

  2. The date of your assessment

  3. Your summary score (for example, 95 out of 110, not the individual requirement values)

  4. The scope of the assessment and which system security plan it covers

  5. The CAGE codes that plan applies to

  6. A plan of action completion date: when you expect to reach 110


SPRS usually updates within 24 hours. Keep the assessment and your evidence on file. If anyone asks, "how did you get this number?" should take five minutes to answer, not five weeks.


If you're still building the underlying program, our CMMC compliance checklist walks through it step by step.


Two businessmen in an office deciding whether they need help with CMMC

When You Don't Need Us for This


If you only handle Federal Contract Information, not CUI, you're dealing with the FAR 52.204-21 basic safeguarding requirements, not all 110. You probably don't need an MSP to get that right. They map to 17 of the 110, and the calculator marks those as "FAR basic" so you can see them.


And if you already have an internal IT person with the time, an SSP that's current, and a score in the 90s, keep going. Run the calculator every quarter and fix the list it gives you.


Where we're useful is the middle: a 10 to 150 person contractor, a score somewhere between -100 and 80, and nobody whose actual job is security. That's where managed cybersecurity and a flat monthly rate beat a consultant who writes a report and leaves.


Man thinking through common SPRS score questions

Straight Answers


What is an SPRS score?


It's a number from -203 to 110 that shows how many of the 110 NIST SP 800-171 security requirements a defense contractor has implemented. You calculate it with the DoD Assessment Methodology and post it in the Supplier Performance Risk System.


How is the SPRS score calculated?


Start at 110. For every requirement not met, subtract its value: 1, 3 or 5 points. Multi-factor authentication and FIPS encryption can cost 3 instead of 5 if partly in place. A missing system security plan means no valid score at all.


What is a good SPRS score?


110 is the goal. 88 is the minimum for CMMC Level 2 conditional status, and even then only 1-point items (and 3.13.11 at 3 points) can stay open, for up to 180 days.


Can an SPRS score be negative?


Yes. Because 42 requirements are worth 5 points, a first honest assessment often lands below zero. The lowest possible score is -203.


How often do I need to update my SPRS score?


DFARS 252.204-7019 requires an assessment that's not more than three years old, unless the solicitation asks for something more recent. In practice, update it whenever your environment changes or you close a batch of gaps.


Is CMMC still required after the Phase 2 suspension?


Phase 1 self-assessments are still in effect, and DFARS 7012, 7019 and 7020 still apply. What was suspended in July 2026 is the requirement for third-party certification. Your self-assessed SPRS score matters more, not less.


Does NIST SP 800-171 Revision 3 change the SPRS score?


Not yet for scoring purposes. The CMMC rule and the DoD methodology are both built on Revision 2 and its 110 requirements, which is what this calculator uses.


Businessman on a phone call getting help with his SPRS score

Still Stuck? Give Us a Call


If the calculator gave you a number you didn't love, you're in good company. Most first scores are rough. The fix list it produces is the start of your plan of action.


We're a flat-rate MSP in Baltimore covering Maryland, Virginia and Washington D.C., and we've spent a lot of time in the government contractor world. Give us a call on 410-703-3857 or book a free review, and we'll go through your results with you and tell you honestly how long it'll take to reach 88.


We'll even bring the coffee. Consider it the only thing in CMMC that doesn't need a plan of action.


Comments


bottom of page