An SPRS score is the numeric result of a NIST SP 800-171 self-assessment, posted to the Department of Defense’s Supplier Performance Risk System (SPRS) under DFARS 252.204-7019 and 252.204-7020. It is not a pass/fail badge and it is not the same thing as CMMC certification — it is a single “X out of 110” summary number that tells a contracting officer, before award, how completely a contractor’s or subcontractor’s information system implements the 110 security requirements of NIST SP 800-171. Universities and research institutions that hold a Department of Defense contract, grant, or subaward involving Controlled Unclassified Information (CUI) need one on file, current, and accurate. This guide covers the arithmetic of the score itself and the mechanics of getting it into SPRS. For the underlying 110 requirements and when a university becomes subject to them in the first place, see CASRAI’s companion guide, NIST SP 800-171 and CUI in University Research.
SPRS Score at a Glance
| Element | What it is |
|---|---|
| Starting point | 110 — one point for each of the 110 security requirements in NIST SP 800-171, awarded only when a requirement is fully implemented |
| Maximum possible score | 110 (every requirement implemented) |
| Minimum possible score | -203, per the DoD’s published NIST SP 800-171 DoD Assessment Methodology (deductions can take the running total negative if most higher-weighted requirements are unimplemented) |
| Who calculates it | The contractor or subcontractor, for a Basic (self) Assessment; DoD assessors for Medium and High Assessments |
| What gets submitted | A single summary-level score (e.g., “95 out of 110”) plus the assessment date, scope, and expected date all 110 requirements will be met — not a requirement-by-requirement breakdown |
| Where it’s submitted | The Supplier Performance Risk System (SPRS), via a DoD-designated encrypted-email intake for Basic Assessments, or directly by contractors with an appropriate PIEE/SPRS role |
| How long it’s valid | Not more than 3 years old, unless a shorter period is specified in the solicitation (DFARS 252.204-7019) |
| Legal basis | DFARS 252.204-7019 (solicitation provision) and 252.204-7020 (contract clause, flows down to subcontractors) |
How the 110-Point Scoring Methodology Works
The scoring method comes from the DoD’s NIST SP 800-171 DoD Assessment Methodology, not from NIST SP 800-171 itself. It works as a deduction from a perfect score:
- Every organization starts at 110 points — the total number of NIST SP 800-171 security requirements, one point each.
- For every requirement that is not fully implemented, the DoD methodology subtracts a fixed number of points assigned to that specific requirement: 5, 3, or 1, depending on how much impact DoD has determined that requirement’s absence has on the system’s overall security posture. These weights are pre-assigned per requirement in the methodology’s published tables — an assessor does not choose the weight, they look it up.
- The deductions are summed and subtracted from 110. The result is the summary-level score, and it can go negative — down to a published floor of -203 — if a large share of the higher-weighted (5-point) requirements are unimplemented.
- That single number, not a control-by-control list, is what gets submitted to SPRS.
As a general pattern, requirements DoD weighted at 5 points tend to be ones it considers to have outsized security impact if missing entirely (for example, controls around multifactor authentication, boundary protection, and use of validated cryptography fall into the higher-weighted bands); 3-point requirements are treated as moderate-impact; 1-point requirements tend to be more procedural or documentation-oriented. The exact weight assigned to any individual requirement should be confirmed against the current published DoD Assessment Methodology tables before you finalize a real score — this guide describes the deduction mechanism, not a substitute for that requirement-by-requirement table.
Worked Example (Illustrative)
The figures below are an illustrative composite for demonstration only — they are not a real institution’s assessment. A university research computing environment reviews its System Security Plan against all 110 requirements and finds:
- 2 unimplemented requirements weighted at 5 points each = 10 points
- 3 unimplemented requirements weighted at 3 points each = 9 points
- 3 unimplemented requirements weighted at 1 point each = 3 points
Total deduction: 10 + 9 + 3 = 22 points. Starting from 110, the summary-level score is 110 – 22 = 88. That “88” — not a list of which 8 requirements are open — is what would be entered into SPRS, alongside the date the assessment was performed and the date all 110 requirements are expected to be met.
Step by Step: Calculating Your Own Score
- Confirm your System Security Plan (SSP) is current. The SSP is the document-of-record showing, requirement by requirement, whether each of the 110 NIST SP 800-171 controls is implemented, partially implemented, or not implemented. The score calculation is only as accurate as the SSP behind it.
- Mark each requirement met or not met. “Met” earns the requirement’s full point value; anything short of full implementation earns zero for that requirement (there is no partial credit within a single requirement under the standard Basic Assessment approach).
- Look up the point value for every requirement marked “not met.” Use the current DoD Assessment Methodology’s published requirement tables — each of the 110 requirements has a pre-assigned value of 5, 3, or 1.
- Sum the deductions and subtract from 110. That result is your summary-level score.
- Document a Plan of Action and Milestones (POA&M) for every unimplemented requirement, with a realistic target date for full implementation — DFARS 252.204-7019 requires offerors to state the date by which a score of 110 is expected to be achieved.
- Have someone other than the assessor sanity-check the arithmetic before submission. Because the number that reaches SPRS is a single summary figure with no visible detail, an arithmetic error is not something a reviewer downstream can easily catch.
Basic, Medium, and High Assessments
Not every SPRS score is calculated the same way. DFARS 252.204-7020 defines three assessment tiers:
| Assessment type | Who conducts it | Confidence level | Basis |
|---|---|---|---|
| Basic | The contractor itself (self-assessment) | Low | Contractor’s own review of its SSP against the NIST SP 800-171 DoD Assessment Methodology |
| Medium | DoD (government-conducted) | Medium | Review of the contractor’s Basic Assessment plus document review and discussions with the contractor |
| High | DoD (government-conducted) | High | Basic Assessment review, document review, system verification/demonstration, and discussions, assessed against NIST SP 800-171A |
Most universities and research institutions will encounter the Basic Assessment — it is the one the contractor performs and submits itself. Medium and High Assessments are DoD-initiated and are far less common outside of higher-risk programs.
How to Submit a Score to SPRS
- Complete the Basic Assessment following the calculation steps above, using the current version of your SSP.
- Submit the summary-level result. Per DFARS 252.204-7019, contractors without a current score on file submit their Basic Assessment results — cybersecurity standard assessed, assessing organization, CAGE code(s), system security plan scope, assessment date, summary-level score, and the expected date a score of 110 will be achieved — to the DoD-designated encrypted email intake for SPRS posting. Contractors that already hold the appropriate PIEE (Procurement Integrated Enterprise Environment) account role can enter Basic Assessment results directly in SPRS themselves rather than routing through the email intake.
- Confirm the posting. DFARS 252.204-7019 specifies scores submitted via the email intake are expected to be posted to SPRS within 30 days.
- Keep it current. A score more than 3 years old (or older than a shorter period the solicitation specifies) no longer satisfies DFARS 252.204-7019 — re-assess and resubmit before it lapses, not after a solicitation flags it as missing.
Only the summary-level score and the metadata above are visible in SPRS to contracting officers — the underlying requirement-by-requirement detail stays in the contractor’s own SSP and POA&M, which DoD can request to see but which is not itself submitted as part of routine SPRS posting.
SPRS Scores and CMMC
The SPRS score and CMMC certification are related but not identical. The 110-point Basic Assessment methodology described above is the same technical basis CMMC Level 2 self-assessments use, and SPRS is where CMMC status gets recorded. As explained in CASRAI’s companion guide to CMMC compliance for universities: CMMC Level 1 requires an annual self-assessment submitted through SPRS by a senior company official; the Level 2 self-assessment track (available for a defined subset of Level 2 programs) similarly relies on annual self-assessment with a senior-official affirmation; and the Level 2 certification track — required for most Level 2 programs — adds a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO) on a triennial cycle, with annual affirmation in the years between assessments. A DFARS 252.204-7019/7020 Basic Assessment score and a CMMC self-assessment are closely related obligations that can, depending on the specific contract, be satisfied by the same underlying assessment work — but confirm which regime a specific solicitation invokes, since the two clauses are not always triggered together.
Common Mistakes to Avoid
- Submitting a requirement count instead of a point total. “102 of 110 requirements met” is not the same number as the point-weighted score — because requirements are weighted 5, 3, or 1, two organizations with the same count of unmet requirements can have very different scores depending on which specific requirements those are.
- Letting the score lapse silently. The 3-year validity window in DFARS 252.204-7019 is a hard eligibility gate for new awards, not a soft guideline — treat re-assessment as a recurring compliance task with an owner and a calendar reminder, not a one-time project.
- Assuming a positive score means “compliant.” A score of 88, or even 105, still reflects unimplemented requirements with an open POA&M — it is not the same as a full 110 implementation, and some solicitations may require a higher bar than a merely-positive score.
- Treating the SPRS score and CMMC certification as interchangeable. They rely on overlapping requirements and often the same underlying assessment work, but they are distinct regulatory obligations (DFARS 252.204-7019/7020 versus the CMMC rule) — confirm which one, or both, a specific contract requires.
Frequently Asked Questions
What is a good SPRS score?
There is no single universal “passing” score published in DFARS 252.204-7019/7020 itself — the requirement is a current score on file, with a credible plan (POA&M) and target date for reaching 110. That said, a low or negative score, or one with no realistic path to 110, is far more likely to draw contracting-officer scrutiny or affect award decisions than a high score with a small, well-documented remainder.
Can an SPRS score be negative?
Yes. Because unimplemented higher-weighted requirements each subtract up to 5 points and there is no floor at zero, the published methodology allows scores as low as -203 if most 5-point requirements are unimplemented.
Who is allowed to submit a Basic Assessment score to SPRS?
The contractor performs and submits its own Basic Assessment — either via the DoD-designated encrypted-email intake, or directly if the contractor holds the relevant PIEE account role for SPRS. Medium and High Assessments, by contrast, are conducted and entered by DoD assessors.
How often does an SPRS score need to be resubmitted?
At least every 3 years, per DFARS 252.204-7019 — sooner if a specific solicitation specifies a shorter period, and immediately if your implementation status has materially changed since the last assessment.
Is an SPRS score the same as CMMC certification?
No. The SPRS score is a DFARS 252.204-7019/7020 submission; CMMC certification (Level 1, 2, or 3) is a separate framework that also posts status through SPRS and often draws on the same underlying assessment, but the two are governed by different clauses and can be required independently of each other. See CASRAI’s CMMC compliance guide for the certification-track detail.
Where can I find the exact point value for a specific NIST SP 800-171 requirement?
In the DoD’s published NIST SP 800-171 DoD Assessment Methodology document, which lists all 110 requirements with their assigned 5-, 3-, or 1-point weight. This guide explains how those weights are used in the calculation; it is not a substitute for that requirement-by-requirement table, which should be confirmed directly before a live assessment.
Last verified August 16, 2026, against DFARS 252.204-7019 and DFARS 252.204-7020 (acquisition.gov). Assessment methodology point-weighting and score-floor figures are drawn from the DoD’s published NIST SP 800-171 DoD Assessment Methodology and are widely and consistently reported; confirm the current published weight tables directly before relying on any single requirement’s point value in a live assessment. This page addresses CUI-related cybersecurity assessment scoring only — see CASRAI’s Controlled Unclassified Information (CUI) definition, CUI Basic vs. CUI Specified, and Who Is Responsible for CUI Compliance at a University? for the institutional-responsibility side of this obligation.







