How is the SPRS score actually calculated, and what does a negative score mean?
The SPRS score quantifies an organisation's implementation of NIST SP 800-171 controls, starting from a perfect score of 110. Each unimplemented control incurs a deduction, weighted at -1, -3, or -5 points based on its criticality. A negative score signifies that certain controls are not yet fully implemented. This score reflects the current cybersecurity posture and is a mandatory input for Department of Defense contractors, indicating areas requiring remediation via a Plan of Action and Milestones.
The SPRS score is derived from a self-assessment or a higher-level assessment against the 110 security requirements outlined in NIST SP 800-171. The Department of Defense (DoD) assessment methodology assigns specific point values to each requirement, with more critical controls carrying higher negative weights (e.g., -5 points for multi-factor authentication or incident response, -3 points for access control, and -1 point for less critical controls). An organisation begins with a baseline score of 110, and points are subtracted for each unimplemented or partially implemented control. This calculation provides a standardised, quantitative measure of an organisation's compliance with the DFARS 252.204-7012 requirement to protect Controlled Unclassified Information (CUI).
Practitioners often misunderstand that a negative SPRS score is not inherently disqualifying for DoD contracts, provided there is a credible Plan of Action and Milestones (POA&M) in place to address the deficiencies. The critical aspect is demonstrating a clear path to full implementation and a commitment to continuous improvement. Organisations frequently err by either overstating their compliance or failing to develop a realistic POA&M with achievable timelines. Contracting officers consider the SPRS score, the POA&M, and the criticality of the unimplemented controls when making award decisions. A highly negative score with no clear remediation plan, especially for high-weighted controls, can significantly jeopardise contract eligibility.
Sources
- DFARS Clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS Clause 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements
- DoD, NIST SP 800-171 DoD Assessment Methodology