Interactive Tool·CMMC Level 2

SPRS Score Calculator

Toggle each of the 110 NIST 800-171 Rev 2 practices between Met, Not Met, and POA&M. Score updates live. Practices ineligible for POA&M deferral are flagged.

3.1.1Limit system access to authorized users, processes acting on behalf of authorized users, and devices
3.1.2Limit system access to the types of transactions and functions authorized users are permitted to execute
3.1.3Control the flow of CUI in accordance with approved authorizations
3.1.4Separate the duties of individuals to reduce the risk of malevolent activity
3.1.5Employ the principle of least privilege, including for specific security functions and privileged accounts
3.1.6Use non-privileged accounts or roles when accessing non-security functions
3.1.7Prevent non-privileged users from executing privileged functions and capture execution in audit logs
3.1.8Limit unsuccessful logon attempts
3.1.9Provide privacy and security notices consistent with CUI rules
3.1.10Use session lock with pattern-hiding displays after a period of inactivity
3.1.11Terminate sessions after a defined condition
3.1.12Monitor and control remote access sessions
3.1.13Employ cryptographic mechanisms to protect confidentiality of remote access sessions
3.1.14Route remote access via managed access control points
3.1.15Authorize remote execution of privileged commands via remote access only for documented operational needs
3.1.16Authorize wireless access prior to allowing connections
3.1.17Protect wireless access using authentication and encryption
3.1.18Control connection of mobile devices
3.1.19Encrypt CUI on mobile devices and mobile computing platforms
3.1.20Verify and control/limit connections to external systems
3.1.21Limit use of portable storage devices on external systems
3.1.22Control CUI posted or processed on publicly accessible systems

Point values per DoD CMMC Assessment Methodology (DFARS 252.204-7019). SPRS is self-attested — verify all entries with a qualified C3PAO before submission to the Supplier Performance Risk System. ← Back to portal

TARGET

Strong CMMC posture — maintain and monitor

Met

110

practices

Not Met

0

practices

POA&M

0

deferred

Projected

110

after POA&M

Score Zones

Target
88 – 110
Conditional
60 – 87
High Risk
0 – 59
Critical
−203 – −1

Weight dots indicate risk tier: 5 = critical CUI protection practice, 3 = standard, 1 = administrative. NO POA&M = cannot be deferred under CMMC Level 2.

SPRS Score

110

0 not met
0 POA&M