SPRS score calculator

This calculator scores you the way the DoD Assessment Methodology does — start at 110, subtract 1, 3, or 5 points for every NIST SP 800-171 requirement you haven't fully implemented. Answer the 12 highest-signal questions below for an estimated range. No signup, and nothing about your systems is stored.

1. Does every person sign in to company computers and systems with their own individual account — no shared logins?

2. Where is multi-factor authentication (MFA) turned on?

3. Are operating systems and software patched promptly, with automatic updates on and critical fixes prioritized?

4. Is reputable antivirus running on all computers, updating itself automatically, with real-time protection plus scheduled scans?

5. Is there a properly configured firewall at your internet connection, with your network designed so sensitive systems are separated from the rest?

6. Is CUI encrypted where it's stored — full-disk encryption on computers, encrypted shares or cloud storage?

7. Is activity logging turned on for your key systems — computers, email/cloud accounts, firewall — and kept for at least 90 days?

8. Do you run vulnerability scans on a schedule (for example monthly) and after major changes?

9. Do you have a written incident response plan — how you'd detect, contain, and recover from a security incident, and who to call?

10. Are standard users prevented from installing software or changing system settings — only admins can?

11. What's your policy on USB drives and other removable media?

12. When you encrypt CUI, is the encryption FIPS-validated?

0 of 12 answered

Estimated SPRS range: -203 to 28 (perfect is 110)

The range tightens as you answer.

How the SPRS score is actually calculated

The score comes from the DoD's published "NIST SP 800-171 Assessment Methodology." The math is simple but unforgiving:

  • Start at 110 — one point for each of the 110 security requirements in NIST SP 800-171 Rev 2.
  • Subtract that control's weight for every requirement not fully implemented:5 points for the requirements whose absence exposes the network broadly, 3 for most others, 1 for a small set. The weights are fixed in Annex A of the methodology — you don't get to choose them.
  • There is no partial credit.A requirement is implemented only when every one of its assessment objectives (from NIST SP 800-171A) is met. "Mostly done" deducts the full weight, with exactly two exceptions below.
  • The floor is −203, not zero. Implementing nothing scores 110 − 313 = −203.

The two partial-credit exceptions: multifactor authentication (3.5.3) deducts 3 instead of 5 if MFA covers remote and privileged users but not yet everyone, and FIPS-validated cryptography (3.13.11) deducts 3 instead of 5 if you encrypt but the cryptography isn't FIPS-validated. One requirement — 3.12.4, the System Security Plan itself — carries no point value, because without an SSP a DoD assessment can't be conducted at all.

A worked example

A 12-person machine shop has done the basics but has no incident-response plan (3.6.1, a 5-point control), no security-awareness training (3.2.1 and 3.2.2, 5 points each), and hasn't set up log review (3.3.3, a 1-point control). Their score is 110 − 5 − 5 − 5 − 1 = 94. Most small shops that have never run a gap assessment land far lower — scores between −50 and 60 are common on a first honest pass, because the 5-point controls concentrate in areas small businesses rarely formalize.

Frequently asked questions

What is a good SPRS score?
110 is a perfect score, and under CMMC Level 2 the practical target, since certification requires meeting all 110 requirements (with limited, time-boxed POA&M allowances). For the older DFARS 252.204-7019/7020 self-assessment obligation, any current score on file satisfies the posting requirement — but primes increasingly screen subcontractors on the number itself.
Where do I submit my SPRS score?
Scores are posted to the Supplier Performance Risk System (SPRS) through the PIEE portal (piee.eb.mil). You submit the score, the scope of the assessment, the date, and the date you expect to reach 110.
Can my SPRS score really be negative?
Yes. The methodology subtracts up to 313 points from 110, so the floor is −203. A negative score simply means many high-weight requirements are not yet implemented — it is common for first assessments and it improves quickly with the 5-point fixes.
Is this calculator the same as an official assessment?
No. This is an informational estimate using the official scoring math on 12 questions. A Basic self-assessment covers all 110 requirements against the 320 assessment objectives in NIST SP 800-171A — the full ClearPath questionnaire walks you through that in plain English.

Get your full self-assessment score — and the documents that go with it.

The full plain-English questionnaire assesses all 110 requirements, computes your SPRS self-assessment score, and drafts your System Security Plan and POA&M for you to review.

Start your full assessment →

Informational only — not a compliance determination, an assessment, or legal advice. Requirements are defined by NIST SP 800-171 Rev 2, NIST SP 800-171A, the DoD Assessment Methodology, and 32 CFR Part 170; always verify against the official publications.