How to Improve Your SPRS Score: A Practical Guide to NIST 800-171 Scoring
A working guide for defense contractors: what the Supplier Performance Risk System (SPRS) score actually measures, how the DoD’s weighted-point methodology calculates it, the gaps that cost contractors the most points, and a realistic remediation timeline to get from a low or negative score to Conditional Level 2 eligibility.
The 50-Word Answer
Your SPRS score starts at a perfect 110 and loses 1, 3, or 5 points for every NIST SP 800-171 control not fully implemented — no partial credit, floor of -203. Conditional CMMC Level 2 requires a score of at least 88. Fix the 5-point foundational gaps (MFA, FIPS-validated encryption, boundary protection) first — they move the score fastest.
What Is the SPRS Score?
The Supplier Performance Risk System (SPRS) is a DoD-wide database that, among other supplier-risk data, hosts the self-assessment scores defense contractors submit for their implementation of NIST Special Publication 800-171 — the 110-control standard for protecting Controlled Unclassified Information (CUI) on contractor information systems. The score itself is a single number, from a maximum of 110 down to a minimum of -203, that tells a contracting officer at a glance how far a company’s cybersecurity program is from full NIST 800-171 compliance.
The requirement to self-assess and post a score to SPRS traces to DFARS 252.204-7012, the clause that has long required contractors handling covered defense information to safeguard it per NIST 800-171 and report cyber incidents to DIBNet within 72 hours. Companies subject to 7012 are expected to keep an accurate System Security Plan, address identified deficiencies, and post a current self-assessment score to SPRS — obligations that exist independently of CMMC certification.
2026 update: On July 13, 2026, the Department of War (DoD) suspended Phase 2 of CMMC implementation — the rollout that would have made third-party C3PAO assessments mandatory starting November 10, 2026 — and stood up a CMMC Reform Task Force to review the program, with a report due within 60 days. The suspension is a policy pause on mandatory third-party assessments, not a repeal of the CMMC rule or the DFARS. Self-assessment and SPRS score-posting obligations under 252.204-7012 continue unchanged in the meantime, and any CMMC clause already in your contract (252.204-7021) still governs option-year exercise. Treat this as a reprieve on the certification deadline, not a reason to stop scoring and remediating.
Why it matters commercially: a current, credible SPRS score is frequently a pre-award gate. Contracting officers can and do check SPRS before award, primes flow the requirement down to subcontractors, and a stale or unsubmitted score can knock a bid out of contention before technical evaluation even starts.
How the Score Is Calculated
The DoD’s NIST SP 800-171 Assessment Methodology (v1.2.1) assigns each of the 110 security requirements across 14 control families a fixed weight of 1, 3, or 5 points. You start at 110 and subtract the weight of every requirement that is not fully implemented — there is no partial credit for a control that is half-built. The table below shows how the same requirement can carry a different deduction depending on how incomplete the implementation is.
| Control | Implementation State | Points Deducted |
|---|---|---|
| 3.5.3 — Multifactor Authentication | No MFA anywhere | −5 |
| 3.5.3 — Multifactor Authentication | MFA on remote & privileged access only | −3 |
| 3.13.11 — FIPS-Validated Cryptography | No validated cryptography in use | −5 |
| 3.13.11 — FIPS-Validated Cryptography | FIPS-approved algorithm used, module not validated | −3 |
| Lower-impact derived requirements | Not implemented | −1 |
5-point deductions are reserved for foundational Basic Security Requirements — if these aren’t met, the derived requirements that depend on them are considered ineffective too, which is why fixing them first has an outsized effect on the total score.
The Gaps That Cost Mid-Market Contractors the Most Points
Every environment is different, but the same handful of control families show up repeatedly as the biggest drags on a mid-market manufacturer’s SPRS score. All five carry 5-point (or 5/3-point tiered) weight, which is exactly why they matter more than the sheer number of open items suggests.
Multifactor authentication (3.5.3). The single most common finding. MFA missing on general network access, or present only for VPN and admin accounts, leaves this control at a 3- or 5-point deduction for most first-time assessors.
FIPS-validated cryptography (3.13.11). Using AES or TLS is not the same as using a FIPS 140-2/140-3 Validated module. Consumer-grade VPN clients, unmanaged BitLocker configurations, and standard email encryption frequently fail this distinction.
System and communications boundary protection (3.13.1 / 3.13.5). Flat networks with no segmentation between the CUI enclave and the rest of the corporate network are a recurring finding, especially on manufacturing shop floors where CAM and CNC workstations share a VLAN with general office traffic.
Access control & least privilege (3.1.1–3.1.5). Shared local admin accounts, no formal least-privilege review process, and stale accounts from departed employees are common in companies without a dedicated identity program.
Audit logging & review (3.3.1–3.3.5). Logs exist but nobody reviews them, retention is short, or coverage doesn’t extend to the systems that actually touch CUI. A control that’s “technically on” but not operationally maintained scores the same as one that was never built.
Score Every One of the 110 Controls — Don’t Sample
The remediation strategy starts with an honest, control-by-control gap assessment against all 110 NIST 800-171 requirements, not a spot-check of the ones that feel risky. Each control needs a real determination: Met, Not Met, or Not Applicable (with documented justification), plus evidence — a policy, a config screenshot, a log export — that would survive a DoD-led Medium or High assessment, not just a self-attestation.
This is also the point to draft or update your System Security Plan (SSP), the document that maps each control to how your organization actually implements it. The SSP is not paperwork for its own sake — it’s the artifact assessors compare against your environment, and gaps between what the SSP claims and what actually exists are one of the fastest ways to fail a validation.
Triage by Point Value, Not Alphabetically
Once every control has a status, sort the Not Met list by weight, not by control family number. A company sitting at 40 points below the maximum because of eight 5-point gaps and a scattering of 1-point items should fix the eight 5-point gaps first — that alone can close most of the deficit. Working the list in NIST numerical order instead is the single most common reason remediation projects take longer than they need to.
Group the 5-point items further into “quick wins” (policy and configuration changes achievable in days — enabling MFA on an identity provider you already own, turning on BitLocker with a validated configuration) versus “infrastructure projects” (network segmentation, email platform migration, endpoint fleet replacement) that need budget and a project timeline. Attack the quick wins immediately; scope and fund the infrastructure projects in parallel.
Build the POA&M Around What’s Actually Allowed
A Plan of Action & Milestones (POA&M) documents which controls aren’t fully met yet and when they will be. It is not a substitute for implementation, and CMMC’s rules on what can legitimately sit on a POA&M are strict: under 32 CFR 170.21, POA&M items are limited to select 1-point requirements, and only if the overall assessment score is at least 88 out of 110. Every 5-point and 3-point control has to be fully implemented before assessment — there is no POA&M path for the heaviest-weighted gaps.
Once results are submitted to SPRS (or eMASS for a formal C3PAO assessment), a 180-day clock starts on closing every open POA&M item. Miss it, and a Conditional Level 2 status reverts and a full re-assessment is required. Build the POA&M with realistic, funded closure dates — not aspirational ones — and assign a named owner to each item.
Submit the Score and Track the 3-Year Currency Clock
A self-assessment score submitted to SPRS is only “current” for three years, or less if a specific solicitation says so. Set a recurring calendar reminder well before the expiration date — a lapsed score can knock a company out of eligibility for option-year exercise or new award just as effectively as a low one. Re-score any time a material change happens in the environment: a new line of business that touches CUI, a platform migration, an acquisition, or a new facility.
Keep the supporting evidence package current alongside the score itself — the score is a number in SPRS, but the SSP, POA&M, and control evidence are what a DoD-led Medium or High assessment, or a future C3PAO Level 2 assessment, will actually inspect. A stale score backed by stale evidence is a bigger liability than no score at all.
How Long Does SPRS Score Remediation Actually Take?
Timelines vary by starting point and environment complexity, but a mid-market manufacturer or services firm starting with no formal program generally moves through four phases.
| Phase | Typical Duration | What Happens |
|---|---|---|
| Gap assessment & scoring | 2–4 weeks | All 110 controls assessed, current score calculated, SSP drafted |
| Quick wins | 30–60 days | MFA rollout, policy documentation, access reviews, log retention fixes |
| Infrastructure projects | 60–120 days | Network segmentation, FIPS-validated encryption rollout, email platform migration |
| Full program maturity | 6–12 months | All 110 controls implemented and operating, evidence retained, SPRS score submitted |
Companies with an existing IT security baseline (managed endpoints, centralized identity, some logging already in place) typically move through these phases faster than a company starting from a fully ad-hoc environment.
SPRS Score Improvement: Q&A
What is a good SPRS score?
A score of 110 reflects full implementation of all NIST SP 800-171 controls. For CMMC Level 2 purposes, a score of at least 88 (80% of 110) is required to qualify for Conditional Level 2 status under 32 CFR 170.21(a)(2)(i), with the remaining gap limited to specific 1-point requirements documented on a POA&M. Below 88, a Conditional status isn’t available and every remaining gap must be closed before assessment.
Can an SPRS score be negative?
Yes. Because deductions are cumulative across all 110 weighted requirements with no floor built into the arithmetic other than the total possible deduction, a company with almost no NIST 800-171 controls in place can score as low as -203. A negative score is not unusual for a company that has never run a formal gap assessment — it signals a starting point, not a disqualification.
Do I still need to submit an SPRS score now that CMMC Phase 2 is suspended?
Yes. The July 2026 suspension paused the rollout of mandatory third-party C3PAO assessments under CMMC Phase 2 — it did not repeal DFARS 252.204-7012, which still requires companies handling covered defense information to self-assess against NIST 800-171 and keep a current score posted to SPRS. Contracting officers can still check SPRS at award, and primes still flow the requirement down to subcontractors.
How often does the SPRS score need to be updated?
A self-assessment score is treated as current for up to three years, unless a specific solicitation requires a shorter interval, and should be refreshed sooner after any material change to the environment — a new CUI-touching business line, an acquisition, a platform migration, or a new facility.
Which controls should I fix first to raise my score fastest?
Start with the 5-point Basic Security Requirements — multifactor authentication (3.5.3), FIPS-validated cryptography (3.13.11), and boundary/network segmentation (3.13.1) are the most common high-weight gaps in mid-market environments. Closing a handful of 5-point items raises the score far faster than closing many scattered 1-point items.
Can I put every open control on a POA&M instead of fixing it before assessment?
No. Under CMMC’s rules, POA&M eligibility is limited to certain 1-point requirements, and only when the overall score is already at least 88. Every 3-point and 5-point control must be fully implemented before the assessment — there is no deferred path for the heaviest-weighted gaps.