How to Calculate Your SPRS Score
The SPRS score starts at 110 and deducts weighted points for every practice you have not implemented. Here is how to calculate it correctly and what counts as fully implemented.
What the SPRS Score Measures
The Supplier Performance Risk System (SPRS) score is a single number between -203 and 110 that represents your implementation status against the 110 NIST 800-171 practices. The DoD uses it to assess contractor risk before awarding contracts that involve CUI.
The score is mandatory under DFARS 252.204-7019. You must calculate and submit it to SPRS before responding to any solicitation that requires NIST 800-171 compliance. The score is recalculated when your environment changes materially or when you remediate practices.
Use the interactive SPRS calculator to compute your score practice-by-practice. The calculator handles the math automatically and shows you which practices are dragging your score down.
The Scoring Formula
Start at 110. For each of the 110 practices, deduct the practice weight if it is not fully implemented. The weights are not equal. Some practices weigh 5 points, some 3, and some 1. The DoD assigned higher weights to practices that protect CUI most directly.
The 5-point practices include items like:
- 3.1.1: Limit system access to authorized users
- 3.1.2: Limit system access to authorized transactions
- 3.5.3: Multi-factor authentication for privileged accounts
- 3.13.11: FIPS-validated cryptography for CUI
Miss any 5-point practice and your score immediately drops by 5. Miss several and you can land in negative territory fast. The minimum possible score is -203 if you fail every practice with maximum weight loss.
The good news: a Plan of Action and Milestones (POA&M) does not reduce your projected score for practices listed there, as long as those practices are POA&M-eligible.
How to Calculate Your Current Score
Walk through each of the 110 practices and assign one of three states:
- Met: The practice is fully implemented across your CUI boundary. You have evidence to prove it.
- Not Met: The practice is missing or only partially implemented. Deduct the full weight.
- POA&M: The practice is on your remediation plan with a realistic completion date. For POA&M-eligible practices, this counts as met for projected scoring but not for current scoring.
Some practices cannot be put on a POA&M and must be fully met. These include the four 5-point practices listed above. If those are not met, you cannot certify.
For each practice, look at the assessment objectives in NIST 800-171A. The practice is only "met" if you can answer yes to every objective. Half-met means not met.
Run the SPRS calculator to walk through this systematically.
Improving Your SPRS Score
The fastest way to lift your score is to focus on the 5-point practices first. Each one you close gives you 5 points back. Common 5-point closures that move the needle:
- Deploy MFA on all privileged accounts (3.5.3): closes immediately once MFA is enabled and verified across admin accounts.
- Migrate to FIPS-validated cryptography (3.13.11): use FIPS-validated modules in cloud services and confirm with certificate numbers.
- Restrict system access (3.1.1, 3.1.2): formalize role-based access control and document the access matrix.
After 5-point practices, target the 3-point ones. Audit logging, configuration baselines, and incident response plans are common 3-point gaps that close with reasonable effort.
Track your score over time. A SPRS score climbing from 65 to 95 over six months tells DoD you are actively maturing. A flat score for two years signals neglect.
Submitting Your Score to SPRS
Submission happens in the SPRS portal at sprs.csd.disa.mil. You need a CAGE code, an active System for Award Management (SAM) registration, and a Procurement Integrated Enterprise Environment (PIEE) account.
The submission requires:
- Your calculated score (110 to -203)
- The date of the assessment
- The CAGE code(s) covered by the score
- The plan completion date (when you expect to reach 110)
- The level of confidence (basic, medium, or high)
Most companies submit at the "basic" confidence level for self-assessments. "Medium" requires DCMA review. "High" requires C3PAO assessment. The score expires every three years, so re-submission cadence is built in.
Keep your CMMC documentation aligned with what you submit. The score and the SSP must tell the same story.
Frequently Asked Questions
Related Articles
CMMC Level 2 Requirements
CMMC Level 2 covers 110 practices across 14 families, all aligned to NIST 800-171. Here is what your environment needs to satisfy and what assessors actually verify.
NIST 800-171 Controls Explained
NIST 800-171 has 110 practices across 14 families. This walks through each family, what the practices require, and what implementation looks like in real environments.
CMMC Plan of Action and Milestones
A CMMC POA&M is the document that lets you certify with open gaps, but only if those gaps are POA&M-eligible and the milestones are credible. Here is how to build one that holds up.