How to Calculate and Submit Your SPRS Score (NIST 800-171)

Your SPRS score is a number you calculate yourself, post yourself, and are held to by the government. Nobody checks your arithmetic before it goes in. That combination is why so many small defense contractors have a score in SPRS that does not survive contact with a government assessor.

This walks through the actual scoring methodology, the point values almost every published summary gets wrong, how to get access to the system, what fields you have to fill in, and a worked example that lands on a real number.

Where the score comes from, and the scale it uses

The governing document is the NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1, dated June 24, 2020. That is still the current version. It has not been superseded, updated for CMMC, or revised in 2026 — despite the document itself saying DoD would eventually codify the methodology in policy.

It scores against NIST SP 800-171 Revision 2, which remains the standard for DoD contractors. A class deviation locked DFARS 252.204-7012 to Revision 2, and the CMMC program rule incorporates Revision 2 as well. A proposed FAR rule published in June 2026 would apply Revision 3 government-wide, but it is not final. Do not score against Rev 3.

You start at 110 and subtract the weighted value of every requirement you have not implemented. The floor is −203.

Here is where most write-ups go wrong. The commonly circulated breakdown — “42 controls worth 5 points, 14 worth 3, and 54 worth 1” — is arithmetically impossible. It produces a floor of −196, which contradicts DoD’s own figure. The actual distribution in Annex A is:

  • 42 requirements worth 5 points
  • 2 requirements scored “3 to 5” with partial credit — 3.5.3 (multifactor authentication) and 3.13.11 (FIPS-validated cryptography)
  • 14 requirements worth 3 points
  • 51 requirements worth 1 point
  • 1 requirement not scored at all — 3.12.4, the system security plan

Check the math: (42 × 5) + (2 × 5) + (14 × 3) + (51 × 1) = 210 + 10 + 42 + 51 = 313. And 110 − 313 = −203. That is where the floor comes from, and the only breakdown that produces it.

The error in the common version is double-counting the two partial-credit requirements into the 42 and treating the system security plan as a one-pointer.

The system security plan is not worth points — it is a precondition

Annex A lists 3.12.4 with a value of “NA.” Its absence does not cost you points. It ends the assessment. The methodology states that missing an SSP “would result in a finding that an assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012.”

The scoring methodology is explicit that the assessment is based on reviewing the system security plan. No plan, no assessment. If you do not have one yet, that is the first piece of work, not the last.

The two partial-credit requirements — and why they matter more than any others

3.5.3, multifactor authentication. Three points are subtracted if MFA is implemented only for remote and privileged users. Five points are subtracted if MFA is not implemented for anyone. Full credit requires MFA for local and network access to privileged accounts and network access to non-privileged accounts.

3.13.11, FIPS-validated cryptography. If encryption is employed but is not FIPS validated, three points are subtracted. If encryption is not employed at all, five points come off. The methodology is blunt about a common misunderstanding: the cryptographic module must be validated under FIPS 140. Using an approved algorithm is not sufficient. Running AES does not make you FIPS validated.

These are the only two requirements with partial credit. Everything else is binary. They are also, according to assessment data circulated by DCMA, the two most commonly failed requirements in the entire standard — which is not a coincidence. They are the two where “we sort of did it” is most tempting.

For a small shop, that makes them the cheapest points on the board. Finishing an MFA rollout and switching disk encryption to FIPS mode can be a six-point swing for close to no money.

“Not applicable” is a real lever — with a condition

Several five-point requirements carry explicit instructions not to deduct when the capability does not exist in your environment: 3.1.12 and 3.1.13 (remote access), 3.1.16 and 3.1.17 (wireless), and 3.1.18 (mobile devices).

But there is a catch, and it is stated directly in the methodology: if the company disallows remote, wireless, or mobile access, it must also have policy and procedure in place to ensure those capabilities are not inadvertently enabled. Without that, a point is assessed. Turning the Wi-Fi off is not enough. You need a documented, enforced prohibition.

Two related provisions are worth knowing. Requirements the DoD CIO formally adjudicated as not applicable, or as met by alternative measures, are scored as implemented — but the adjudication has to be in your SSP. And isolated enduring exceptions, such as specialized manufacturing or lab equipment, described with mitigations in the SSP, are also scored as implemented.

A plan of action earns you nothing

This one surprises people every time. The methodology states that plans of action “are not a substitute for a completed requirement,” and that requirements not implemented “whether a plan of action is in place or not, will be assessed as not implemented.”

The worked example in the document is pointed: if an MFA rollout is 75% complete with a plan of action still running, 3.5.3 is not implemented. Not three-quarters implemented. Not implemented.

There is a second-order trap. If you have unimplemented requirements and no plan of action for them, then 3.12.2 itself scores as not implemented — costing you another three points on top of everything else.

Getting into SPRS

Budget one to two weeks. The sequence:

  1. Confirm your SAM.gov registration is active with an Electronic Business POC and your CAGE codes present.
  2. Verify your CAGE hierarchy in SAM. If a CAGE does not appear, fix it in SAM — SPRS typically syncs within 24 to 48 hours. A broken hierarchy means the right CAGEs will not be selectable later.
  3. Designate a Contractor Account Administrator for each CAGE, normally the SAM Electronic Business POC or a designee.
  4. Register in PIEE and request the SPRS Cyber Vendor User role. This is the role that enables data entry. The view-only role will not show you the button.
  5. Wait for approval. SPRS says this takes multiple business days. Useful edge case for a small firm: if your company has only one Contractor Account Administrator and that person requests the role for themselves, PIEE activates it automatically.

Do the SSP and the plan of action before you touch SPRS. The Quick Entry Guide is explicit that both should be complete prior to entering results. SPRS does not calculate anything. It stores a number you computed elsewhere.

The fields you actually fill in

In PIEE, open SPRS, go to Cyber Reports, select the NIST SP 800-171 Assessments tab, and add a new assessment. You will create a header with the highest-level-owner CAGE, the assessment standard, and a confidence level — Basic is the only option available to contractors. Note that headers cannot be deleted once created.

Then:

  • Assessment Date
  • Score — the summary score only, not per-requirement values
  • Assessing Scope — Enterprise, Enclave, or Contracts
  • Plan of Action Completion Date — required if your score is below 110
  • System Security Plan Assessed — the document name
  • SSP Version/Revision — optional
  • SSP Date
  • Included CAGEs — selected from the CAGE hierarchy

On save, SPRS assigns a DoD Unique Identifier. One clarification worth making because it confuses people constantly: the CMMC UID is a different thing on a different tab. It is assigned only after your Affirming Official completes the affirmation. It is not a field on the NIST SP 800-171 form.

What the “date of 110” field really commits you to

The Plan of Action Completion Date is defined as the date a score of 110 is expected to be achieved — meaning all requirements implemented, derived from your actual plan of action.

Understand what you are signing. It is a date-certain representation to the government that every one of the 110 requirements will be in place by then. It is visible to every contracting officer evaluating you. And sailing past your own stated date with the same gaps open is about the cleanest evidence of a knowing misrepresentation that anyone could ask for.

The field is editable, and it should be edited as remediation slips or accelerates. Failing to update it is the risk. Pick a date you can actually hit and calendar a review before it arrives.

A worked example

Ridgeline Defense Systems is a five-person subcontractor on a Navy IT support contract carrying DFARS 252.204-7012. Microsoft 365 GCC High, five Windows 11 laptops, no on-premise servers, a small leased office with Wi-Fi, staff working remotely.

They complete the SSP and plan of action, then score against Annex A and find seventeen gaps:

  • Partial credit (−6 total): MFA enforced for cloud and admin accounts but not local workstation logon (−3); BitLocker enabled but not in FIPS mode (−3).
  • Five-point misses (−30): 3.3.5 audit correlation, 3.4.8 application allow-listing, 3.11.2 vulnerability scanning, 3.14.6 traffic monitoring, 3.12.3 ongoing control monitoring, 3.7.5 MFA for nonlocal maintenance.
  • Three-point misses (−9): 3.1.5 least privilege (all five users are local admins), 3.8.8 unidentified portable storage, 3.14.7 identifying unauthorized use.
  • One-point misses (−6): 3.3.3, 3.4.9, 3.5.6, 3.6.3, 3.8.9, 3.13.14.

Total deduction: 51. 110 − 51 = a score of 59.

Three lessons hide in that number. First, Ridgeline uses office Wi-Fi, so 3.1.16 and 3.1.17 are in scope — had they prohibited wireless with a documented, enforced policy, those two five-pointers would simply not have been assessable. Second, partial credit saved them four points; with no MFA and no encryption at all they would be at 55. Third, they have a plan of action covering all seventeen gaps and the score is still 59 — but because the plan exists, 3.12.2 scores as implemented, saving them another three.

One more thing about 59. Under the CMMC rule, Conditional Level 2 status requires your score divided by the total number of requirements to be at least 0.8 — that is 88 of 110. At 59, Ridgeline does not qualify even conditionally. A mediocre score is not just a competitive disadvantage; it is a hard bar.

How long a score lasts

DFARS 252.204-7019 requires a current assessment, defined as not more than three years old unless a lesser time is specified in the solicitation. Read the solicitation — a specific one can demand something fresher. DFARS 252.204-7020 applies the same three-year rule down the supply chain before you award a subcontract.

On the CMMC side, affirmation is required on achieving status, annually thereafter, and after any plan-of-action closeout. SPRS displays assessments in red once they pass three years, which is a useful visual tell.

A score also goes stale before three years if you have a security-relevant change, or if the SSP it describes has been materially revised. The score describes a specific plan at a specific version and date.

Why accuracy is now the whole game

In June 2026 the Justice Department settled False Claims Act allegations with LOGZONE, Inc. for $507,144, covering conduct from May 2021 through March 2025 on two Navy contracts. A DCMA assessment scored the company at −170 against a range DOJ described as −203 to 110. The settlement resolved allegations only, with no determination of liability.

The mechanism is the part to internalize. A government assessment begins with your own self-assessment and validates against it — the methodology says so explicitly. That means the delta between what you claimed and what exists is structurally visible, numeric, and government-generated. It is a much simpler case to make than any argument about whether your controls were adequate.

The practical conclusion runs opposite to what a lot of consultants sell: an honest low score with a real plan of action carries far less legal risk than a flattering score your SSP cannot support.

Key takeaways

  • Scores run 110 down to −203, using the DoD Assessment Methodology v1.2.1 against NIST SP 800-171 Rev 2.
  • The correct point distribution is 42 five-point, 2 partial-credit, 14 three-point, 51 one-point, and 3.12.4 unscored. Most published breakdowns are wrong.
  • No SSP means the assessment cannot be completed — it is not a point deduction.
  • MFA and FIPS-validated cryptography are the only partial-credit requirements and the two most commonly failed. They are also the cheapest points to recover.
  • A plan of action never earns credit, and having none costs you three more points on 3.12.2.
  • Budget one to two weeks for PIEE access and the SPRS Cyber Vendor User role.
  • The Plan of Action Completion Date is a date-certain representation that all 110 will be implemented. Keep it honest and keep it updated.

Frequently asked questions

Does SPRS calculate my score for me? No. You compute the score using the DoD Assessment Methodology and enter the summary figure. SPRS stores it and displays it to contracting officers.

Should I scope to an enclave instead of my whole network? Many small contractors do, because a narrower boundary is genuinely easier to secure to 110. Be aware of the trade-off: an enclave score only describes the enclave, so any CUI that leaks outside that boundary is both unassessed and unprotected. Scope honestly and enforce the boundary.

What if my score is negative? A negative score is legal to post and does not disqualify you from every opportunity, though it will bar you from Conditional CMMC Level 2 status. Posting an accurate negative score with a credible plan of action is a far better position than posting a number you cannot defend.

Working through a self-assessment and want it reviewed before it goes into SPRS? Veteran Forge Strategies helps small federal contractors with NIST 800-171 scoring and remediation planning. Related reading: NIST 800-171 for small contractors and CMMC compliance for defense contractors.

Similar Posts