What's my SPRS score?

12 quick questions, scored with the official DoD Assessment Methodology (110 down to −203). No signup, nothing stored about your systems.

1. Does every person sign in to company computers and systems with their own individual account — no shared logins?

2. Where is multi-factor authentication (MFA) turned on?

3. Are operating systems and software patched promptly, with automatic updates on and critical fixes prioritized?

4. Is reputable antivirus running on all computers, updating itself automatically, with real-time protection plus scheduled scans?

5. Is there a properly configured firewall at your internet connection, with your network designed so sensitive systems are separated from the rest?

6. Is CUI encrypted where it's stored — full-disk encryption on computers, encrypted shares or cloud storage?

7. Is activity logging turned on for your key systems — computers, email/cloud accounts, firewall — and kept for at least 90 days?

8. Do you run vulnerability scans on a schedule (for example monthly) and after major changes?

9. Do you have a written incident response plan — how you'd detect, contain, and recover from a security incident, and who to call?

10. Are standard users prevented from installing software or changing system settings — only admins can?

11. What's your policy on USB drives and other removable media?

12. When you encrypt CUI, is the encryption FIPS-validated?

0 of 12 answered

Estimated SPRS range: -203 to 28 (perfect is 110)

The range tightens as you answer.

Informational estimate only — not a compliance determination, an assessment, or legal advice.