Start at 110. For every NIST SP 800-171 requirement you haven’t fully implemented, subtract its weight: 5, 3, or 1 point. The result, anywhere from 110 down to –203, is your SPRS score. You need a System Security Plan before any of it counts.
Who this is for
Small manufacturers and suppliers whose DoD contracts include DFARS 252.204-7019 or -7020, or whose prime has asked, “What’s your SPRS score?”
What an SPRS score is
SPRS (Supplier Performance Risk System) is the DoD database where contractors post their NIST SP 800-171 self-assessment results. Contracting officers and primes can see your score. It’s calculated with the DoD Assessment Methodology, and a basic self-assessment stays current for three years, though you should update it whenever your environment changes.
Step 1: Have a System Security Plan first
Your SSP describes your system boundary, your assets, and how you meet each of the 110 requirements. Without one, the methodology says an assessment can’t be completed. Write the SSP before you score.
Step 2: Assess all 110 requirements honestly
For each requirement, decide: fully implemented (no deduction) or not fully implemented (deduct its full weight). A requirement counts only if it’s working in practice. “We have a policy” or “it’s mostly done” doesn’t count, and items on your Plan of Action & Milestones (POA&M) don’t earn points until they’re finished.
Use NIST SP 800-171A to test each requirement. It breaks the 110 requirements into 320 specific assessment objectives, and every objective must be met.
Step 3: Apply the weights
| Weight | Typical areas | Why it’s weighted that way |
|---|---|---|
| 5 points | Access control basics, authentication, audit logging, malware protection, boundary protection, incident response | A gap here can directly expose CUI |
| 3 points | Selected controls such as some media and remote access protections | Moderate impact |
| 1 point | Most remaining derived requirements, such as some training and maintenance details | Lower individual impact, but they add up |
The DoD Assessment Methodology lists the weight for every requirement. Use that table, not a guess.
Step 4: Know the two partial-credit rules
Only two requirements allow partial credit:
- 3.5.3 Multi-factor authentication: subtract 5 if MFA isn’t used; subtract 3 if it’s used for remote and privileged access but not for all users
- 3.13.11 FIPS-validated encryption: subtract 5 if CUI isn’t encrypted; subtract 3 if it’s encrypted but the encryption isn’t FIPS-validated
A worked example
A 20-person machine shop finds these gaps:
| Gap | Deduction |
|---|---|
| No MFA for regular users (MFA on admin and remote only) | –3 |
| Audit logs not created or retained (3.3.1) | –5 |
| No incident response testing | –1 |
| Laptops encrypted, but not with FIPS-validated modules | –3 |
| Security awareness training doesn’t cover insider threat | –1 |
| Score | 110 – 13 = 97 |
Fixing the MFA and logging gaps alone would raise this shop to 105. (Weights shown are illustrative; confirm each one in the methodology’s scoring table.)
Step 5: Post it in SPRS
In SPRS (accessed through PIEE), you’ll enter the assessment date, the score, the scope (which CAGE codes it covers), your SSP’s name and date, and the date you expect to finish your POA&M. A senior company official is responsible for affirming it.
Common mistakes
- Scoring without an SSP
- Giving credit for controls on the POA&M
- Taking partial credit on requirements that don’t allow it
- Counting a requirement as met when only some of its objectives are
- Never updating the score after changes to systems or staff
- Rounding up “to be safe.” An inflated score is a False Claims Act risk.
Want a second set of eyes on your score?
I help small defense suppliers calculate an honest, defensible SPRS score, write the SSP behind it, and prioritize the fixes that raise it fastest. I’m a CMMC Registered Practitioner and Service-Disabled Veteran with 20+ years in DoD cybersecurity.
Book a free 20-minute call: (770) 315-1839, or see the CMMC Readiness Package. Related: CMMC Phase 2 is paused: what you still have to do.
This article is general guidance, not legal advice. Always score against the current DoD Assessment Methodology.
Sources
- DoD Assessment Methodology for NIST SP 800-171 (link the current PDF)
- NIST SP 800-171 Rev. 2
- NIST SP 800-171A
- FutureFeed: SPRS NIST 800-171 scoring
Leave a comment