The Supplier Performance Risk System (SPRS) score is how the DoD sees, at a glance, how far along you are on the 110 requirements of NIST SP 800-171. You start at a perfect 110 and subtract a weighted value — 5, 3, or 1 point — for every requirement you have not fully implemented. Because the weights add up to far more than 110, the floor is -203, not zero. There is no partial credit except for two 5-point controls: multifactor authentication (3.5.3) and FIPS-validated encryption (3.13.11), which drop to a -3 deduction when partially met. Your self-assessment carries Basic (Low) confidence; a government DIBCAC assessment carries Medium or High. The number is a legal representation — post an honest one.
What SPRS actually is
The Supplier Performance Risk System (SPRS) is a DoD system of record. Among other things, it holds your NIST SP 800-171 assessment score — a single number that a contracting officer can look at to judge how much of the required cybersecurity you have actually put in place before awarding you work involving Controlled Unclassified Information (CUI).
The score is produced by the NIST SP 800-171 DoD Assessment Methodology, a published, point-based procedure. It is not a maturity score you invent — it is a defined calculation against the 110 requirements of NIST SP 800-171 Rev 2. Most contractors compute it themselves (a self-assessment), then post it to SPRS to satisfy DFARS 252.204-7019 and -7020.
CMMC Level 2 uses the same 110 requirements and the same scoring math (now codified for CMMC at 32 CFR 170.24). Understanding the SPRS score is understanding the number underneath your CMMC readiness. For the framework-level picture, see CMMC vs. NIST 800-171.
Start at 110, subtract from there
The methodology is subtractive. You begin by assuming a perfect score of 110 — one point of headroom for each of the 110 requirements — and then remove points for everything you have *not* fully implemented.
- Implement all 110 requirements and you score 110.
- For each requirement you have not met, subtract its weighted value (5, 3, or 1).
- The lowest possible score is -203 — because the weights across all 110 requirements add up to 313 points, far more than the 110 you started with.
That negative floor surprises people. A score of -203 is not a bug; it reflects that the requirements protecting CUI are not equally important, and that missing enough of the heavy ones digs a deep hole. A brand-new program that has implemented almost nothing can genuinely sit well below zero.
The SPRS score is not a percentage. It is 110 minus the weighted cost of every gap — which is why it can run from +110 all the way down to -203.
Why 5, 3, and 1 points
Every requirement is assigned a weight of 5, 3, or 1 based on how much its absence exposes the system. Miss a foundational control and you lose more than you would for missing a narrow one.
| Weight | What it signals | You lose this much if it's not met |
|---|---|---|
| 5 points | A control whose absence undermines the whole environment — identity, encryption, monitoring, and similar keystones. | -5 |
| 3 points | A significant control with a narrower blast radius on its own. | -3 |
| 1 point | Important, but limited impact if it is the only thing missing. | -1 |
Two of the best-known 5-point requirements are 3.5.3 (multifactor authentication) and 3.13.11 (FIPS-validated cryptography) — and they are also the only two the methodology treats specially.
The only two partial-credit controls
For 108 of the 110 requirements, the methodology is binary: you either meet it (no deduction) or you do not (full deduction). Two 5-point requirements are the exception — the DoD built in a middle tier because a partial rollout still meaningfully reduces risk:
| Requirement | Full deduction (-5) | Partial credit (-3) |
|---|---|---|
| 3.5.3 — Multifactor authentication | No MFA, or MFA for general users only | MFA in place for remote and privileged access but not yet for general users |
| 3.13.11 — FIPS-validated encryption | No cryptography used to protect CUI at all | Cryptography is used, but it is not FIPS-validated |
If you can only do two things to move your number, get phishing-resistant MFA onto privileged and remote access (IT-01) and get FIPS-validated encryption turned on. Each converts a -5 into a -3 immediately, and finishing the job converts it to zero deduction.
Everywhere else: all or nothing
Outside those two controls, there is no credit for being close. A requirement that is 75% implemented scores exactly the same as one you have not started: the full weighted deduction applies. “Almost done” and “not done” are the same number to the methodology.
This is why an honest gap assessment matters more than a generous one. Rounding a half-finished control up to “implemented” does not just inflate your score — it misstates a control you may later have to demonstrate live to a government assessor. Score what is true and provable today, and put the rest on a POA&M.
Basic, Medium, and High confidence
The same score means different things depending on who produced it. The methodology defines three assessment levels, and SPRS records the confidence level alongside the number:
- Basic — Low confidence. Your own self-assessment. You run the methodology, you post the score. This is what most contractors submit, and it is a formal representation to the government.
- Medium — Medium confidence. A government review led by the DCMA Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) — a deeper look at your System Security Plan (SSP), POA&M, and supporting evidence, including interviews.
- High — High confidence. An on-site DIBCAC assessment with technical verification: documentation review, physical inspection, and live demonstration of controls.
A government-led (Medium or High) assessment can overwrite your self-reported Basic score in SPRS. A self-assessment that does not survive that scrutiny is a problem you created for yourself — another reason to score conservatively.
What you actually post to SPRS
Submitting a Basic Assessment is more than typing a number. The SPRS NIST SP 800-171 record captures the full context of the assessment:
- The assessment date and the score.
- The scope and the CAGE code(s) the assessment covers.
- The System Security Plan (SSP) name, version, and date — you must have an SSP to assess against.
- The plan-of-action completion date (when you expect open items closed).
- The confidence level (Basic, for a self-assessment).
Under DFARS 252.204-7019/-7020, the assessment must be current — within the last three years — to be eligible for award, and the government reserves the right to conduct its own Medium or High assessment. A missing or stale score can quietly make you ineligible before a proposal is ever evaluated.
What the number commits you to
The SPRS score is a representation to the federal government. Posting an inflated score is not a harmless optimism — under the civil False Claims Act, knowingly misstating your compliance can carry real liability, and DIBCAC assessments exist specifically to check the self-reported numbers.
None of that should discourage you from posting. A low but honest score is the correct starting point: it establishes a baseline, satisfies the clause, and gives you a measurable target. Under CMMC, limited POA&Ms let you carry certain open items for up to 180 days — but you cannot defer the highest-value controls indefinitely, and there is a minimum score you must clear. Raise the number by closing real gaps, in priority order.
Before you compute a formal score, a directional self-check helps you sequence the work. The IT Top 10 scorecard and the Top 10 → NIST 800-171 / CMMC crosswalk are free, browser-local ways to find your biggest gaps — then close them and let your SPRS score follow.
Key takeaways
- Start at 110, subtract weighted values. Every unmet requirement costs 5, 3, or 1 point; a perfect implementation scores 110.
- The floor is -203, not zero — the weights total 313 points, so missing the heavy controls goes deeply negative.
- No partial credit, with two exceptions: MFA (3.5.3) and FIPS-validated encryption (3.13.11) drop from -5 to -3 when partially met.
- Confidence level matters: a self-assessment is Basic/Low; DIBCAC produces Medium or High and can overwrite yours.
- The score is a legal representation. Post an honest one, keep it current (within three years), and raise it by closing real gaps — not by rounding up.
Sources
- NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 (OUSD A&S) ↗
- Acquisition.gov — DFARS 252.204-7019 (assessment reporting) ↗
- Acquisition.gov — DFARS 252.204-7020 (NIST SP 800-171 DoD assessment requirements) ↗
- SPRS — NIST SP 800-171 Quick Entry Guide (DISA) ↗
- eCFR — 32 CFR 170.24 (CMMC Scoring Methodology) ↗
- NIST SP 800-171 Rev 2 (Protecting CUI) ↗
Cloud consoles and federal guidance change; confirm control text and clause language against the official publication that applies to your contract. This article is independent education and does not by itself establish compliance or confer CMMC certification.