SPRS Scores Explained: What Your Number Means and How to Raise It
Your SPRS score is a self-assessed number between minus 203 and positive 110 that tells the Department of Defense how much of NIST SP 800-171 you have actually implemented. The math starts at 110 and subtracts a weighted deduction for every requirement you have not met: 5 points for the highest impact requirements, 3 for a middle band, 1 for the rest. A perfect 110 means everything is implemented; a deep negative means little more than a firewall and good intentions. Contracting officers and prime contractors check the number before awards under DFARS 252.204-7019 and 7020, and overstating it is False Claims Act exposure. That combination, commercial gatekeeping plus legal liability, is why the number deserves more care than most contractors give it.
How the math works
The DoD Assessment Methodology assigns every one of the 110 requirements a weight of 5, 3, or 1. The five point requirements are the ones whose absence makes everything else unreliable: multifactor authentication, incident response capability, flaw remediation, boundary protection, and their peers. More than a third of the requirements carry that full five point weight, which is why scores fall fast. Miss twenty of the wrong requirements and you can be below zero while feeling, internally, like a reasonably careful company.
There is no partial credit, with two documented exceptions. MFA implemented for remote and privileged access but not yet for general users deducts 3 instead of 5. Encryption that is deployed but not FIPS validated also deducts 3 instead of 5. Everything else is binary: implemented on every in-scope system or not implemented at all.
One more prerequisite hides in the methodology: the score describes a System Security Plan. No SSP, no valid score, because there is nothing for the number to be a score of.
Why primes and DoD check it before awards
DFARS 252.204-7019 requires a current score in SPRS, no more than three years old, for you to be considered for award on contracts involving covered defense information. DFARS 252.204-7020 flows the obligation down through the supply chain and gives the government the right to conduct its own higher level assessment of your environment. DIBCAC, the Defense Industrial Base Cybersecurity Assessment Center, has been exercising that right for years, and self-scores have a long record of collapsing when DIBCAC checks the evidence. The score also feeds the government's own supplier risk picture, sitting alongside delivery and quality records when contracting officers compare bidders.
Primes read SPRS for a simpler reason: their compliance depends on their subcontractors. A missing or low score does not usually produce a phone call or a rejection letter. It produces silence. You quietly stop appearing on teaming arrangements, and nobody tells you why. Under CMMC, the same system carries certification statuses, so the score sits next to your certification record and both get read together.
Submission mechanics
Scores are posted through the Procurement Integrated Enterprise Environment, PIEE, into SPRS against your CAGE code. A submission carries four things: the score itself, the date of the self-assessment, the SSP the assessment describes, and the date by which you plan to reach the full 110. Companies with multiple CAGE codes or divisions can post separate scores against the hierarchy, which matters when one business unit is far ahead of another.
Keep the score current. Three years is the regulatory maximum age, but the practical rule is to resubmit whenever your posture materially changes, and especially after you close a batch of POA&M items. Walking a score up over successive submissions reads as a program making progress. A single unexplained jump from 40 to 110 reads as something else.
Do the computation with the methodology document open rather than from memory, because several requirements read as implemented until their assessment objectives are checked one at a time. The people best placed to score are the ones who run the controls, with someone independent in the room to challenge the generous answers. An afternoon of scoring theater produces a number. A real internal assessment produces a number you can defend eighteen months later, in front of an assessor or an investigator, whichever arrives first.
The False Claims Act problem
An SPRS score is a representation to the federal government, and the Department of Justice treats it that way. Since the Civil Cyber-Fraud Initiative launched in 2021, DOJ has pursued contractors for misrepresented cybersecurity compliance, and the settlements are public: Aerojet Rocketdyne paid $9 million in 2022 after a whistleblower alleged misrepresented NIST 800-171 compliance, and Penn State paid $1.25 million in 2024 over its own attestations. The pattern in these cases is not exotic hacking. It is a gap between what was claimed and what was true, surfaced by an insider who knew the difference and had a financial incentive to report it, since whistleblowers share in recoveries.
CMMC raises the stakes further with annual affirmations: a named senior official signs, every year, that the company continues to meet its requirements. That signature belongs to a person, not a brand.
The defensive posture is straightforward. Score what you can evidence. Keep the scoring worksheet that shows how you judged each requirement, and file the evidence behind each MET. If a requirement is arguable, take the deduction and put the fix on the POA&M, because a defensible 85 beats an indefensible 110 in every scenario that involves lawyers.
The fastest legitimate ways to raise it
Chasing one point items feels productive and barely moves the number. The real gains sit in a handful of five point requirements that are also, not coincidentally, the controls that stop actual intrusions:
- Multifactor authentication everywhere it belongs. Full coverage recovers five points. If budget forces phasing, covering remote and privileged access first at least moves the deduction from 5 to 3, and modern identity platforms make the remainder a rollout problem rather than an engineering one.
- FIPS validated cryptography. Recovers three to five points depending on where you started. Turn on FIPS mode where your platforms support it, replace the encryption products that cannot produce a validation certificate, and record the certificate numbers in the SSP.
- An incident response capability that exists. A written plan with roles, a reporting path that meets the DFARS 72 hour clock, trained people, and one tabletop exercise with notes. This is five points recoverable in weeks, not quarters.
After those, the one pointers do add up, and many of them are administrative: session banners, CUI marking, position risk designations. A focused quarter can routinely move a score 30 to 50 points without a single hardware purchase.
Sequence matters more than enthusiasm. Clear the five point items that block certification eligibility first, then the three point band, then sweep the administrative one pointers in a single documentation push at the end. Companies that invert the order spend six months polishing policies while the number barely moves, and the prime's security team notices the difference.
What a given number says
A rough translation for reading scores, yours or a subcontractor's. A posted 110 means fully implemented, and it earns the follow-up question about evidence, because it is also the most commonly inflated number in the system. Scores of 88 and above sit in the zone where CMMC conditional certification is achievable, with the open items confined to low weight requirements. The band from roughly 40 to 87 usually describes a real program with the expensive work, full MFA coverage, FIPS validation, logging depth, still in flight. Zero and below is common as a starting point and not shameful; it mostly means the five point requirements are unmet, and fewer than two dozen of those can put a company underwater on their own. What a prime reads in the number is trajectory and honesty, not the starting position.
Self-score versus assessed score
Under CMMC Level 2, a C3PAO assessed score eventually lands in the same system your self-score lives in, and the two get compared. A self-posted 110 followed by an assessed 70 is not just a failed assessment; it is a documented overstatement with your signature history attached. The time to find the real number is before anyone else does. That is the job of a CMMC gap assessment: all 110 requirements scored against their assessment objectives, a defensible SPRS number with the worksheet to back it, and a prioritized path to raise it for real. If you are staring at the certification timeline as well, start with how the CMMC deadlines actually work, and make sure the SSP your score describes would survive a read, which is covered in our SSP guide.
