What is my SPRS score?

If a prime contractor or contracting officer just asked for your "SPRS score" and you're not sure you have one — this page is for you. The short version: it's a number between 110 and −203 that summarizes how much of NIST SP 800-171 your company has implemented, and for most DoD contracts involving Controlled Unclassified Information (CUI), one must be on file before award.

What the score is

SPRS is the Supplier Performance Risk System — the DoD database where contractor risk information lives. Under DFARS clauses 252.204-7019 and -7020, contractors that handle CUI must have a current NIST SP 800-171 self-assessment score posted there. The score is computed with the DoD Assessment Methodology: start at 110 (one point per requirement in NIST SP 800-171 Rev 2) and subtract a fixed weight — 5, 3, or 1 — for each requirement not fully implemented. Nothing is "partially" implemented in the math: with two narrow exceptions (multifactor authentication and FIPS-validated encryption), an incomplete requirement deducts its full weight.

Under CMMC, the same number takes on more weight: a Level 2 self-assessment means posting your score in SPRS and affirming it annually, and a Level 2 certification assessment checks the same 110 requirements through a third-party assessor (C3PAO).

How to find the score you already have (if any)

  1. Log into the PIEE portal (piee.eb.mil) — the same portal used for WAWF/invoicing. You need the SPRS "Cyber Reports" role; your company's PIEE administrator can grant it.
  2. Open SPRS and go to the NIST SP 800-171 assessments view for your CAGE code.
  3. If nothing is listed, your company has never posted a self-assessment — which means one likely needs to be done before your next CUI-handling award.

If someone else (an IT provider or consultant) submitted it, the entry shows the score, the assessment date, the scope, and the projected date you'll reach 110.

What counts as a good score

A perfect score is 110, and a first honest self-assessment at a small shop commonly lands anywhere from −50 to 60 — the scoring is deliberately front-loaded with 5-point requirements that small businesses rarely have formalized (incident response, training, access control policy). Three things matter more than the raw number: that the score is current, that it's honest(a score you can't defend in an assessment is worse than a low one — the False Claims Act applies to cybersecurity self-attestations), and that you have a credible plan to reach 110, which is what the POA&M documents.

How to raise it fastest

Because deductions are weighted, the fastest path is fixing 5-point requirements that are cheap for a small business: enforcing MFA in Microsoft 365, writing the incident-response plan, turning on the built-in audit logging, running annual security awareness training. A gap assessment that sorts your unimplemented controls by weight and effort tells you exactly where the points are — that's what ClearPath's gap dashboard does, and our free SPRS score calculator gives you an estimated range in about three minutes.

Frequently asked questions

Do I need an SPRS score if I only handle FCI, not CUI?
The DFARS 7019/7020 self-assessment requirement applies to contractors subject to DFARS 252.204-7012, i.e. those handling CUI. If you only handle Federal Contract Information, CMMC Level 1 applies instead — 15 basic safeguarding practices with an annual self-assessment and affirmation, but no 110-point score.
How long is an SPRS score valid?
A Basic self-assessment score is valid for three years, but under CMMC Level 2 self-assessment you must also affirm your compliance annually in SPRS. Many primes ask for a score dated within the last year regardless.
Who in my company can submit the score?
Anyone your PIEE administrator grants the SPRS Cyber Reports role — typically an owner or office manager at a small shop. Under CMMC, the annual affirmation must come from a senior official of the company (the Affirming Official).
Can I just post 110?
Only if it's true at the assessment-objective level — all 320 objectives in NIST SP 800-171A. Posting an inflated score creates False Claims Act exposure, and DIBCAC audits have revised contractor scores downward dramatically. Post the honest number with a remediation plan instead.

Find out where you actually stand.

Twelve quick questions give you an estimated score range — free, no signup, nothing stored. The full questionnaire computes the exact number and drafts the SSP and POA&M that back it up.

Estimate my score now →

Informational only — not a compliance determination, an assessment, or legal advice. Requirements are defined by NIST SP 800-171 Rev 2, NIST SP 800-171A, the DoD Assessment Methodology, and 32 CFR Part 170; always verify against the official publications.