SPRS Score Explained: How to Calculate and Improve
First developed as part of our LinkedIn content series, June 2026. Expanded and updated for this site.
A defense subcontractor self-assessed their SPRS score at 97. When a DIBCAC assessor arrived for a Medium confidence assessment, the verified score came back at -14. The contractor had counted "we have a policy document" as implementation for 23 controls that were not operationally enforced. That 111-point gap is now a False Claims Act liability under the Department of Justice's Civil Cyber-Fraud Initiative -- because the inflated score was submitted to a federal system and used in source selection decisions.
This is not hypothetical. The Aerojet Rocketdyne settlement ($9 million, 2022) and multiple ongoing DOJ investigations demonstrate that SPRS accuracy is a legal obligation, not just a compliance exercise.
Why Your SPRS Score Matters Right Now
Three forces are converging to make SPRS accuracy existential for defense contractors:
CMMC Phase 2 enforcement begins with solicitations in November 2026. Your SPRS score is the quantitative prerequisite for C3PAO assessment scheduling. A score that does not survive scrutiny means failed assessment, wasted fees, and lost contract eligibility.
DOJ Civil Cyber-Fraud Initiative is accelerating. The initiative uses the False Claims Act (31 U.S.C. 3729) to pursue contractors who misrepresent cybersecurity compliance. An inflated SPRS score submitted to the SPRS portal is a false claim to the federal government.
Contracting officers are comparing scores to assessment findings. When your self-assessed score of 95 produces a DIBCAC-verified score of 40, the contracting officer's confidence in your organization collapses -- not just for that contract, but for every future evaluation.
What Is the SPRS Score?
The Supplier Performance Risk System (SPRS) score is a numerical representation of how well your organization implements the 110 security requirements in NIST SP 800-171 Rev 2. It ranges from -203 (no practices implemented) to 110 (full compliance). The score is stored in the SPRS portal and is visible to DoD contracting officers evaluating your organization for contract awards.
SPRS is not optional. DFARS clause 252.204-7019 requires contractors to have a current NIST SP 800-171 assessment on file. DFARS 252.204-7020 requires contractors to provide access for higher-level assessments when requested.
How the Score Is Calculated
The calculation starts at 110 and subtracts weighted values for each security requirement that is not fully implemented.
Point Value Weights
Each of the 110 requirements carries a point value of 1, 3, or 5:
| Weight | Impact |
|---|---|
| 5 points | Critical practices -- missing six drops your score by 30 |
| 3 points | Important practices with moderate individual impact |
| 1 point | Supporting practices with lowest individual impact |
Scoring States
For each requirement, there are three possible states:
- Implemented -- The practice is fully operational and evidenced. No points subtracted.
- Not Implemented (with POA&M) -- Not yet implemented, but a POA&M documents the plan and timeline. Points are subtracted.
- Not Implemented (without POA&M) -- Neither implemented nor tracked for remediation. Points are subtracted.
Both "not implemented" states subtract the same number of points. The distinction matters for CMMC -- assessors view active POA&Ms as evidence of organizational commitment, while missing POA&Ms suggest the gap is unacknowledged.
Calculation Example
Organization with 95 practices implemented, 10 with POA&Ms (4 at 5pts, 3 at 3pts, 3 at 1pt), and 5 without POA&Ms (2 at 3pts, 3 at 1pt):
Score = 110 - (4x5) - (3x3) - (3x1) - (2x3) - (3x1) = 110 - 20 - 9 - 3 - 6 - 3 = 69
The 5-Point Requirements That Move Your Score Most
The five-point requirements carry outsized weight. These cluster in the highest-impact security domains:
Access Control (AC): Limiting system access to authorized users and transaction types, controlling CUI flow, authorizing remote privileged commands.
Identification and Authentication (IA): Password complexity, password reuse prohibition, cryptographic password protection, and multi-factor authentication for all access to CUI systems.
System and Communications Protection (SC): Monitoring external boundaries, segmenting publicly accessible components, employing FIPS-validated cryptography, and managing cryptographic keys.
Audit and Accountability (AU): Unique user identification for accountability, audit log creation and retention, and protecting audit information from unauthorized access.
Missing just six five-point requirements drops your score by 30. Missing twelve drops it by 60. The math is unforgiving -- which is precisely why prioritizing these requirements first produces the fastest score improvement.
The Contrarian Take on SPRS Scoring
A score of 70 with honest POA&Ms beats a score of 110 that cannot survive an auditor's first question. The defense industrial base is filled with companies carrying inflated scores based on policy documents that have no operational enforcement, partially deployed tools counted as fully implemented, and inherited controls claimed without verifying the provider's actual authorization. When the C3PAO arrives, every "implemented" claim requires evidence of operational effectiveness -- not just existence. The organizations that will thrive through CMMC are not those with the highest self-assessed scores today. They are those whose scores are defensible under independent scrutiny.
How to Submit Your SPRS Score
- Conduct a self-assessment using the DoD Assessment Methodology v1.2.1
- Document results in your System Security Plan and POA&M
- Access the SPRS portal at https://www.sprs.csd.disa.mil
- Submit your score with the assessment date, scope, and assessor information
- Update regularly -- scores must be current (assessed within 3 years, annual affirmation recommended)
What Contracting Officers See
When a contracting officer queries your organization, they see your numeric score, the assessment date, the assessment type (Basic, Medium, or High confidence), the scope, and whether POA&Ms exist. A low score does not automatically disqualify you -- but an inaccurate score can end your contracting career entirely.
Strategies to Improve Your Score
Prioritize 5-Point Items First
Every 5-point practice you implement gains maximum impact. Many overlap with security fundamentals you may already have partially in place:
- MFA everywhere: Multi-factor authentication for all access to CUI systems (3.5.3)
- FIPS-validated encryption: FIPS 140-2/3 validated modules for CUI at rest and in transit (3.13.11)
- Audit logging: Enable and protect audit logs across all CUI-scoped systems (3.3.1)
- Access control: Role-based access with least privilege across CUI boundary (3.1.1, 3.1.2)
Address Quick Wins
Some requirements can be implemented in days:
- Password policies (3.5.7, 3.5.8): Configure in Active Directory or your identity provider
- Session locks (3.1.10): Set automatic screen locks after 15 minutes of inactivity
- Security awareness training (3.2.1): Deploy training for all users with CUI access
- Audit log retention (3.3.1): Configure retention to meet the minimum period
Close Your POA&Ms
While POA&Ms do not change your numeric score, they demonstrate progress and are required for CMMC assessments. A well-managed POA&M program shows gaps are tracked, resourced, and on a path to closure within the 180-day CMMC window.
Scope Your CUI Environment
Reducing scope is one of the most effective score improvement strategies. Fewer systems in scope means fewer places where controls must be implemented:
- CUI enclaves: Isolate CUI processing to a dedicated network segment
- Cloud-based CUI environments: Leverage a cloud provider that inherits many controls
- Managed security services: Inherit monitoring and incident response capabilities
Common Mistakes
Inflating Your Score
Submitting a score higher than your actual implementation level violates the False Claims Act. The DOJ Civil Cyber-Fraud Initiative has made examples of contractors who misrepresented compliance. The $9 million Aerojet Rocketdyne settlement demonstrated that the government takes SPRS accuracy seriously -- and the initiative has only expanded since.
Confusing Policy with Implementation
The most common inflation pattern: a policy document exists, so the practice is marked "implemented." But a policy stating "all users shall use MFA" is not implementation -- operational MFA enforced at the technical control layer is implementation. Assessors verify operational effectiveness, not document existence.
Not Updating After Changes
Your score must reflect current state. New systems, removed controls, and personnel changes all affect compliance. Reassess and update when your environment changes materially.
Assessing Too Broadly
Including systems that do not process CUI inflates the controls you must implement. Define your CUI boundary precisely using data flow diagrams and your system security plan.
SPRS and CMMC: The Connection
Your SPRS score is the quantitative foundation for CMMC Level 2. A score of 110 means you have self-assessed that all 110 practices are implemented -- the prerequisite for C3PAO assessment.
However, the SPRS self-assessment and C3PAO assessment use different levels of rigor. Many organizations discover during assessment that practices they considered "implemented" do not meet the assessor's standard for evidence and operational effectiveness. A realistic self-assessment, even if it produces a lower initial score, is far better preparation than an optimistic one that creates a gap between your submitted score and reality.
Key Takeaways
- SPRS scores range from -203 to 110; the five-point requirements carry outsized weight.
- An honest score of 70 is safer than an inflated 110 that fails independent verification.
- DOJ False Claims Act enforcement makes SPRS accuracy a legal obligation, not just a compliance one.
- Prioritize 5-point requirements first for maximum score improvement per dollar invested.
- Your SPRS score is the prerequisite for CMMC Level 2 -- it must survive C3PAO scrutiny.
Frequently Asked Questions
What is a "good" SPRS score for winning DoD contracts?
There is no universal minimum, but most competitive solicitations favor scores above 70. Some agencies specify minimum thresholds in their evaluation criteria. More important than the absolute number is the trajectory -- a score of 70 with POA&Ms showing active remediation signals a maturing program, while a score of 100 with no POA&Ms and no evidence raises questions about accuracy.
How often do we need to update our SPRS score?
The DoD Assessment Methodology requires assessments be current within three years, with annual affirmation recommended. However, you should reassess and update whenever material changes occur -- new systems entering the CUI boundary, controls being added or removed, or organizational changes affecting security posture. Stale scores invite scrutiny.
Can a subcontractor see the prime's SPRS score?
No. SPRS scores are visible only to the organization that submitted them and to DoD contracting officers with a need to evaluate the organization. Primes cannot directly view subcontractor scores in SPRS, though they may contractually require subcontractors to disclose their scores.
What happens if our score drops after submission?
Update it immediately. The obligation is to maintain an accurate score on file. If environmental changes reduce your compliance posture, submit the revised score. Maintaining a stale high score while knowing your actual posture has degraded is precisely the misrepresentation the DOJ Civil Cyber-Fraud Initiative targets.
Does a POA&M improve our SPRS score?
No -- POA&Ms do not change the numeric calculation. A practice with a POA&M is still "not implemented" and still subtracts points. The value of POA&Ms is in demonstrating intent, satisfying CMMC POA&M requirements (180-day closure window), and showing contracting officers that gaps are acknowledged and resourced rather than ignored.
How Advisedly Helps
Advisedly computes your SPRS score automatically from the control implementation status tracked across your NIST 800-171 compliance program. As you mark practices implemented and attach evidence, the score updates in real time -- giving you an accurate, defensible number rather than a spreadsheet estimate. The platform weights each practice according to the DoD Assessment Methodology, highlights your highest-impact gaps (5-point items first), and tracks POA&M remediation timelines so nothing slips past the 180-day CMMC window. Contact begin@advisedly.ai to see your score computed against your current posture.
<!-- LI hook: Your SPRS score is a legal filing -- treat it like one. -->