SPRS score: how to calculate it, post it, and keep it current
The Supplier Performance Risk System (SPRS) is the United States government database where a defense contractor posts its National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 assessment score. If your contract carries Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, and your systems hold Controlled Unclassified Information (CUI), you need a current score in SPRS before you can be considered for award.
This page explains how the score is calculated, what you post with it, which clauses make it required, and how to keep the number matched to the systems you actually run.
Who has to post a score
If DFARS clause 252.204-7012 is in your contract and you have a covered contractor information system, you need a current assessment on record. Current means not more than three years old, unless the solicitation says less.
This reaches further than most companies expect. A prime contractor must confirm that its subcontractors also have a current assessment posted before it awards a subcontract. So a small supplier with no direct government contract can still be asked for a score by the company above it.
The three assessment confidence levels
DFARS clause 252.204-7020 defines three levels. They differ by who performs the assessment and how much the government verifies.
| Level | Who performs it | What it involves |
|---|---|---|
| Basic | You | Your own self-assessment, run against the NIST SP 800-171 DoD Assessment Methodology. This is what most companies post. |
| Medium | The government | A government review of your system security plan and your described implementation. |
| High | The government | A government assessment that verifies, examines, and asks you to demonstrate implementation, using NIST SP 800-171A. |
A Basic Assessment is a self-assessment. It is still a statement the government relies on when it awards work.
How the score is calculated
The method is subtraction, not addition.
- The score starts at 110, one point for each of the 110 requirements in NIST SP 800-171.
- For each requirement you have not met, you subtract 1, 3, or 5 points, depending on how much that requirement matters.
- The lowest possible score is -203.
- A partly met requirement is not met. There is no partial credit for most requirements, and rounding up is how a score drifts away from reality.
Only the summary level score goes into SPRS. You post one number for each assessed system, not a value for each requirement. The government's own guidance gives the example of posting 105 out of 110 rather than the individual value assigned to each requirement.
What you post alongside the score
A score on its own is not a complete submission. Each entry carries the context that makes it meaningful.
| Field | What it means |
|---|---|
| Commercial and Government Entity (CAGE) code | The code or codes the assessed system covers. |
| Assessment date | The date the assessment was completed. |
| Confidence level | Basic for a self-assessment. The government posts Medium and High itself. |
| Assessment scope | Enterprise for your primary network, Enclave for a subsystem. |
| System security plan (SSP) name, version, and date | Which plan was assessed, and when it was last updated. |
| Plan of Action and Milestones (POA&M) completion date | When open items will all be closed. Required when the score is below 110. |
| Summary level score | The single number. |
Scope matters more than any other field. A score that describes a well-run enclave is a different statement than a score that describes your whole company, and the field you select is how the government knows which one you meant.
The clauses behind the requirement
| Clause | What it does |
|---|---|
| DFARS 252.204-7012 | Requires NIST SP 800-171 safeguarding on covered contractor information systems, and requires rapid reporting of cyber incidents. See DFARS 252.204-7012. |
| DFARS 252.204-7019 | Says you must have a current assessment posted in SPRS to be considered for award. |
| DFARS 252.204-7020 | Requires you to give the government access for a Medium or High assessment, to confirm your subcontractors have current assessments posted, and to flow the requirement down. |
The annual affirmation
A senior official at your company affirms that the organization meets the requirements and keeps meeting them, and that affirmation is renewed every year.
That signature is the part companies underestimate. It converts a number in a database into a statement the government can act on. Three Department of Justice settlements under the False Claims Act turned on a posted score that did not describe the real environment, including one company that posted a perfect 110 against a government assessment of -170.
The detail on those cases, and six habits that keep a score true, are in Your SPRS score is a sworn statement.
How to raise a score, in order
- Fix the scope first. Name the systems that actually hold CUI. A smaller, well-defined enclave is easier to score accurately and easier to defend than a sprawling environment. See Secure enclaves.
- Take the 5-point requirements first. They move the number the most, and they tend to be the access control, authentication, and audit requirements that a privileged access product addresses directly.
- Collect the evidence as you go. A requirement you cannot show is a requirement you cannot count.
- Re-score when the environment changes. New systems, new vendors, and staff changes all move the number.
- Update the posted score when you learn it is wrong. Waiting makes the gap worse, not smaller.
How the AIC CMMC Complete kit supports the work
Analog Informatics Corporation (AIC) builds AIC CMMC Completeâ„¢ for Level 1, Level 2, and Level 3. The kit does not calculate or submit your SPRS score. It gives you working controls and the records behind them, so the number you do post is one you can support.
| What it does | Where |
|---|---|
| Checks controls against the selected framework and level, and rescans so you see what changed | Current State Compliance |
| Shows which requirements have live evidence and which do not | Control coverage |
| Records drift over time, so a slipping requirement shows up before the score goes stale | Control state history |
| Holds the evidence behind each requirement, for the senior official before signing and for an assessor later | Assessment Binder |
| Carries open items as POA&M entries | Assessment Binder |
| Calculates the summary level score and submits it to SPRS | Not a kit function |
How to read availability:
An assessment organization, certification body, or regulator decides whether a requirement is satisfied. These pages describe product availability. They are not an assessment result, a certification, or legal advice.
Common questions
Is a score required if I have no direct government contract?
Often yes. A prime contractor must confirm its subcontractors have a current assessment posted before awarding a subcontract, so the requirement flows down to suppliers who never deal with the government directly.
How old can a score be?
Not more than three years, unless the solicitation specifies less.
Does a low score block an award?
The clause requires a current assessment on record. It does not set a minimum number. A low score with an accurate POA&M completion date is a different thing than no score, and it is a very different thing than a high score you cannot support.
Can I score only part of my company?
Yes. That is what the Enterprise and Enclave scope selection is for. Score the systems that hold CUI, and say clearly which ones those are.
Does the July 2026 CMMC pause remove this?
No. The pause changed who verifies compliance and when. Level 1 (Self) and Level 2 (Self) assessments continue, DFARS 252.204-7012 still requires the 110 requirements of NIST SP 800-171, and the SPRS affirmation still stands. See CMMC Phase 2 and Why CMMC was paused, and what actually fixes it.
What if I do not have a SPRS account?
The government's guidance allows a company to send its summary level score by email for posting on its behalf, with the organization name, CAGE code, system name, score, confidence level, and the relevant dates.
Who signs the affirmation?
A senior official at your company. That person should see the evidence before signing.
Related pages
- CMMC Level 2: all 110 requirements, row by row
- DFARS 252.204-7012: the clause that starts the obligation
- C3PAO: who performs a Level 2 certification assessment
- NIST SP 800-171
- Continuous compliance
- Secure enclaves
- AIC CMMC Completeâ„¢ and pricing
- CMMC solutions
- Product screenshots
- Glossary
Sources
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1
- Supplier Performance Risk System
- NIST SP 800-171 Rev. 2
- 32 CFR Part 170, CMMC Program