What Is an SPRS Score?
SPRS (Supplier Performance Risk System) is the DoD system where defense contractors submit their self-assessed cybersecurity score. Your SPRS score is a number between −203 and 110, calculated based on how many NIST SP 800-171 requirements you've fully implemented.
Contracting officers can view your SPRS score when evaluating bids and making award decisions. A low or negative score is a red flag. Under DFARS 252.204-7019, having a SPRS score on file is required before contract award on most DoD contracts.
How the Score Is Calculated
Start at 110 points. For each requirement that is not fully implemented, subtract its assigned point value. The total after all deductions is your SPRS score.
A company that meets 0 of the 110 requirements would score: 110 − 313 = −203. The total point value of all 110 requirements is 313 points.
Point Weight Categories
Each of the 110 requirements is assigned one of three point weights based on its criticality:
| Point Value | Meaning | Count |
|---|---|---|
| 5 points | Highest criticality — these are the controls most likely to prevent or detect serious breaches. Failing to implement even one of these has an outsized impact on your score. | 44 requirements |
| 3 points | High importance — core security controls that form the backbone of a strong CUI protection program. | 14 requirements |
| 1 point | Standard controls — important but less weighted. These add up, but individually have smaller impact. | 51 requirements |
Self-Assessment vs. C3PAO Assessment
There are two ways your SPRS score can be established:
Self-Assessment (DFARS 252.204-7019)
You calculate your own score, have a senior company official affirm it, and submit it to SPRS. This is acceptable for some contracts, but it comes with legal risk — the False Claims Act has been used to pursue contractors who submitted inaccurate scores. Your self-assessment needs to reflect reality.
C3PAO Assessment (CMMC Level 2)
A Certified Third-Party Assessor Organization independently verifies your implementation and submits results. This is required for most contracts with CMMC Level 2 requirements. The C3PAO-submitted score carries more weight and provides legal protection because the assessment is independently verified.
How 1TEN Tracks Your SPRS Score
1TEN calculates your SPRS score in real time as you assess requirements. As you mark each requirement Met, Not Met, or Not Applicable, the platform applies the correct DoD point weights and shows you your current score, projected score, and the impact of remediating specific gaps.
The dashboard shows your score trend over time — useful for demonstrating continuous improvement to contracting officers and C3PAO assessors. Your POA&M items are directly linked to the requirements driving score deductions, so you can prioritize remediation by point impact.
How to Improve Your SPRS Score
Because requirements carry different point weights, the fastest way to improve your SPRS score is to remediate high-point-value requirements first. A single 5-point requirement has the same score impact as five 1-point requirements — but typically requires the same effort as remediating one control.
Prioritize by Point Weight
Start with any unmet 5-point requirements, then move to the 3-point requirements. The 44 five-point requirements are all POA&M-ineligible — they must be fully implemented before a C3PAO assessment. Together they account for 220 of the 313 total possible deduction points. The 14 three-point requirements can appear on a POA&M but carry significant score weight, so remediating them early has the most impact.
Common Quick Wins
Some 3-point requirements can be addressed relatively quickly with proper tool configuration: enabling audit logging, enforcing session timeouts, implementing account lockout policies, and configuring encryption for CUI at rest and in transit. These are often already partially implemented but not formally documented — which still counts as "not met" for scoring purposes.
Document What You've Already Done
Many organizations are already performing security activities that satisfy NIST 800-171 requirements but haven't formally documented them. An accurate self-assessment often reveals that the gap is in documentation, not implementation. Your System Security Plan captures this documentation — every implementation statement you complete is one less SPRS deduction.
What Is a Good SPRS Score?
There is no official "passing" SPRS score — the score exists to inform contracting officers about your cybersecurity posture. That said, practical benchmarks exist:
| Score Range | What It Signals |
|---|---|
| 110 | All 110 requirements fully implemented. This is the target for CMMC Level 2 certification. |
| 88 – 109 | Strong posture with minor gaps. Typical for organizations actively preparing for C3PAO assessment with a manageable POA&M. |
| 50 – 87 | Moderate gaps requiring focused remediation. Common starting point for organizations beginning their CMMC journey. |
| Below 50 | Significant implementation gaps. Likely to raise concerns with contracting officers reviewing bids. |
| Negative scores | Most requirements unmet. Indicates early-stage compliance or a legacy environment without formal controls. |
For CMMC Level 2 conditional certification, your SPRS score must be at least 88 out of 110 — that is, 80% of the maximum possible score. If your unmet requirements drive your score below 88, you will not qualify for conditional certification regardless of whether those items are on a POA&M.
SPRS Score and Contract Award
Under DFARS 252.204-7019, contractors must have a current SPRS score on file before a DoD contract can be awarded. This applies to contracts that require implementation of NIST SP 800-171 — which covers most contracts involving Controlled Unclassified Information (CUI).
Contracting officers can access your SPRS score during source selection. While the DoD hasn't established a minimum score for award, a low or negative score signals risk. In competitive procurements, a higher SPRS score demonstrates stronger cybersecurity maturity — and some contracting officers are using scores as a differentiator.
As CMMC Phase 2 rolls out in late 2026, contracts will increasingly require not just an SPRS score but a C3PAO-verified assessment. Your self-assessed SPRS score will need to align with your C3PAO results — discrepancies between the two create legal exposure under the False Claims Act.
Frequently Asked Questions
What does SPRS stand for?
SPRS stands for Supplier Performance Risk System. It is the DoD's centralized system where defense contractors submit cybersecurity self-assessment scores based on their implementation of NIST SP 800-171 requirements.
How often must I update my SPRS score?
DFARS 252.204-7019 requires contractors to reassess and update their SPRS score at least annually, or whenever there is a significant change to the security posture of the assessed system.
Can I get a DoD contract with a negative SPRS score?
Having a score on file is required for contract award, but there is no official minimum score. However, a negative score is visible to contracting officers and signals significant gaps that may affect award decisions in competitive procurements.
What is the difference between SPRS and CMMC?
SPRS is a self-reported score reflecting your current NIST 800-171 implementation. CMMC is a certification program that independently verifies that implementation through a C3PAO assessment. Your SPRS score should align with your CMMC assessment results.
Which requirements are worth 5 points?
There are 44 requirements weighted at 5 points under the DoD Assessment Methodology. These include foundational controls like access control (3.1.1, 3.1.2), audit logging (3.3.1), incident response (3.6.1, 3.6.2), and boundary protection (3.13.1, 3.13.2). Two controls — 3.5.3 (MFA) and 3.13.11 (FIPS encryption) — are variable: worth 5 points if completely unimplemented, or 3 points if partially implemented. None of the 5-point requirements can be placed on a POA&M.