How to Calculate Your SPRS Score: A Guide for Small Defense Suppliers

Start at 110. For every NIST SP 800-171 requirement you haven’t fully implemented, subtract its weight: 5, 3, or 1 point. The result, anywhere from 110 down to –203, is your SPRS score. You need a System Security Plan before any of it counts.

Who this is for

Small manufacturers and suppliers whose DoD contracts include DFARS 252.204-7019 or -7020, or whose prime has asked, “What’s your SPRS score?”

What an SPRS score is

SPRS (Supplier Performance Risk System) is the DoD database where contractors post their NIST SP 800-171 self-assessment results. Contracting officers and primes can see your score. It’s calculated with the DoD Assessment Methodology, and a basic self-assessment stays current for three years, though you should update it whenever your environment changes.

Step 1: Have a System Security Plan first

Your SSP describes your system boundary, your assets, and how you meet each of the 110 requirements. Without one, the methodology says an assessment can’t be completed. Write the SSP before you score.

Step 2: Assess all 110 requirements honestly

For each requirement, decide: fully implemented (no deduction) or not fully implemented (deduct its full weight). A requirement counts only if it’s working in practice. “We have a policy” or “it’s mostly done” doesn’t count, and items on your Plan of Action & Milestones (POA&M) don’t earn points until they’re finished.

Use NIST SP 800-171A to test each requirement. It breaks the 110 requirements into 320 specific assessment objectives, and every objective must be met.

Step 3: Apply the weights

WeightTypical areasWhy it’s weighted that way
5 pointsAccess control basics, authentication, audit logging, malware protection, boundary protection, incident responseA gap here can directly expose CUI
3 pointsSelected controls such as some media and remote access protectionsModerate impact
1 pointMost remaining derived requirements, such as some training and maintenance detailsLower individual impact, but they add up

The DoD Assessment Methodology lists the weight for every requirement. Use that table, not a guess.

Step 4: Know the two partial-credit rules

Only two requirements allow partial credit:

  • 3.5.3 Multi-factor authentication: subtract 5 if MFA isn’t used; subtract 3 if it’s used for remote and privileged access but not for all users
  • 3.13.11 FIPS-validated encryption: subtract 5 if CUI isn’t encrypted; subtract 3 if it’s encrypted but the encryption isn’t FIPS-validated

A worked example

A 20-person machine shop finds these gaps:

GapDeduction
No MFA for regular users (MFA on admin and remote only)–3
Audit logs not created or retained (3.3.1)–5
No incident response testing–1
Laptops encrypted, but not with FIPS-validated modules–3
Security awareness training doesn’t cover insider threat–1
Score110 – 13 = 97

Fixing the MFA and logging gaps alone would raise this shop to 105. (Weights shown are illustrative; confirm each one in the methodology’s scoring table.)

Step 5: Post it in SPRS

In SPRS (accessed through PIEE), you’ll enter the assessment date, the score, the scope (which CAGE codes it covers), your SSP’s name and date, and the date you expect to finish your POA&M. A senior company official is responsible for affirming it.

Common mistakes

  • Scoring without an SSP
  • Giving credit for controls on the POA&M
  • Taking partial credit on requirements that don’t allow it
  • Counting a requirement as met when only some of its objectives are
  • Never updating the score after changes to systems or staff
  • Rounding up “to be safe.” An inflated score is a False Claims Act risk.

Want a second set of eyes on your score?

I help small defense suppliers calculate an honest, defensible SPRS score, write the SSP behind it, and prioritize the fixes that raise it fastest. I’m a CMMC Registered Practitioner and Service-Disabled Veteran with 20+ years in DoD cybersecurity.

Book a free 20-minute call: (770) 315-1839, or see the CMMC Readiness Package. Related: CMMC Phase 2 is paused: what you still have to do.

This article is general guidance, not legal advice. Always score against the current DoD Assessment Methodology.

Sources

Leave a comment