← All articles

Understanding Your SPRS Score: How to Calculate and Submit to the DOD

Understanding Your SPRS Score: How to Calculate and Submit to the DOD

Author: Adam Rosenman · August 12, 2026*

Achieving a perfect score of 110 in the Supplier Performance Risk System is the gold standard for defense contractors, yet many organizations struggle to reach this benchmark. If your company processes or stores Controlled Unclassified Information (CUI), your ability to win contracts depends entirely on how you handle this numerical rating. This guide breaks down the math, the methodology, and the mandatory steps to ensure your submission stands up to Department of Defense (DOD) scrutiny.

Key Takeaways

  • The SPRS score range starts at 110 and can drop to a minimum of -203 for non-compliant contractors (DOD, 2026).
  • Contractors must possess a current System Security Plan (SSP) before a valid score can be generated or submitted.
  • Submission through the Procurement Integrated Enterprise Environment (PIEE) is mandatory before any contract award.

What is an SPRS Score?

An SPRS score is a numerical rating that reflects how well a defense contractor has implemented the 110 cybersecurity controls in NIST SP 800-171 (DOD, 2026). This rating helps the government determine the risk level associated with awarding a contract to a specific supplier. It serves as the primary metric for verifying that a contractor can protect sensitive federal data from unauthorized access or exfiltration.

While many contractors view the score as a static number, it is actually a dynamic representation of your organization's risk profile. The DOD uses this data to prioritize which contractors receive government-led assessments, meaning an inaccurate or low score increases your chances of an audit. Understanding your sprs score cmmc is no longer a preparation exercise; it is an active requirement for contract eligibility.

Why is Your SPRS Score Critical for DOD Contracts?

Contracting officials must review SPRS self-assessment scores for all contractors handling CUI before making an award decision (DFARS 252.204-7019, 2025). Failure to have a current score in the system can lead to immediate disqualification from the bidding process. Additionally, an inflated score that does not match the actual environment can trigger False Claims Act investigations, which have resulted in multimillion-dollar settlements.

In our experience, prime contractors have become significantly more aggressive in auditing their subcontractors' scores. Since the prime is responsible for the security of the entire supply chain, they will often refuse to flow down work to any partner with a score below a certain internal threshold. This means your score impacts your ability to compete not just for direct government work, but for subcontracts with major defense players as well.

How Do You Calculate Your SPRS Score (CMMC)?

Every organization starts with a baseline score of 110, representing full implementation of all NIST 800-171 requirements (DOD Methodology v1.2.1, 2024). From this starting point, you must subtract a weighted value for every control that is not fully implemented. You cannot calculate a valid score without first completing a System Security Plan (SSP) that details how your environment meets or misses each requirement.

Our analysis of recent DIB self-assessments shows that the most common reason for a negative score is the absence of a comprehensive SSP. Without this foundational document, every control is technically "not implemented," leading to a rapid descent into negative territory. To avoid this, ensure your SSP is finalized and reflects the current state of your network architecture before you begin the subtraction process.

What Are the SPRS Scoring Point Values?

The DOD assigns a weighted subtractor of 1, 3, or 5 points to each NIST 800-171 requirement based on its security impact (DOD, 2025). High-risk controls, such as those governing multi-factor authentication and incident response, carry the maximum 5-point deduction. Lower-impact controls, like those for physical access logs or visitor escorts, typically carry a 1-point deduction if missing.

  • 5 Points: Critical controls where absence leads to network exploitation.
  • 3 Points: Important controls with a confined effect on network security.
  • 1 Point: Supporting controls with a limited or indirect effect.

You only subtract points for what is not implemented. If you have a Plan of Action and Milestones (POA&M) for a control, it is still considered "not implemented" for scoring purposes, though it shows the government your commitment to remediation.

Can You Receive Partial Credit for Security Controls?

Partial credit is almost non-existent in the SPRS methodology, with the DOD requiring full implementation for a control to earn its points (DOD, 2026). There are only two specific exceptions: multi-factor authentication (3.5.3) and FIPS-validated cryptography (3.13.11). For these specific items, an organization may receive a partial deduction if they have implemented the security measure but failed to meet the exact federal standard, such as using non-FIPS encryption.

This lack of partial credit means that even if you are 90% of the way to implementing a complex control, you must still take the full deduction until the requirement is 100% satisfied. This binary approach ensures that there are no ambiguous gaps in the protection of CUI. When you are managing CMMC conditional status, you must be extremely precise about which controls are truly complete and which are still in the remediation phase.

How Do You Submit Your Score to the Supplier Performance Risk System?

Submission occurs exclusively through the Procurement Integrated Enterprise Environment (PIEE) portal, where an authorized user must enter the data into the SPRS application (DISA, 2026). The submission process requires you to input the date of the assessment, the score itself, and the date by which you expect to achieve full compliance (score of 110). You must also include the specific CAGE codes for the business units covered by the assessment.

We have seen many contractors lose two to three weeks of time simply waiting for PIEE account approvals. Do not wait until your bid is due to register for the portal. The "Cyber Vendor User" role must be approved by your organization's Government Administrator (GAM), which can be a slow process if you have not maintained your SAM.gov registration accurately.

When is the Deadline for SPRS Submission?

Contractors must have an SPRS score submitted by the time of contract award, and that score must have been recorded within the last three years (DFARS 252.204-7019, 2025). A new requirement introduced in 2025 mandates an annual affirmation. A senior company official must sign an electronic statement each year affirming that the score in the system is still accurate and that the organization's security posture has not degraded.

The deadline is essentially "now" for any company currently bidding on defense work. Because your next contract event triggers the requirement, a missing SPRS entry makes you ineligible for that contract action immediately. Maintaining CMMC readiness and updating your score as you complete items on your POA&M is the best way to maintain a competitive advantage.

FAQ

What is the lowest possible SPRS score? The lowest possible SPRS score is -203, which occurs if a contractor has failed to implement any of the 110 NIST 800-171 controls (DOD, 2026). A score this low indicates a high risk to the DOD and generally disqualifies the contractor from handling sensitive information until significant remediation occurs.

Do I need a third-party assessment to submit a score? No, the current requirement for most contractors is a self-assessment score (DOD, 2025). While the CMMC program will eventually require third-party verification for Level 2, the self-assessed SPRS score remains the legal standard for current contract awards and annual executive affirmations.

How often should I update my SPRS score? Scores must be updated at least every three years, but you should update yours whenever you complete a major remediation milestone (DOD, 2026). Regular updates demonstrate to the government and prime contractors that you are actively improving your cybersecurity posture and reducing supply chain risk.

What documentation do I need to support my score? You must have a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M) for all unimplemented controls (NIST, 2024). These documents serve as the evidence for your score and must be provided if the DOD performs a Medium or High-level assessment of your facility.

About the Author

Adam Rosenman is a Principal Compliance Consultant with 10 years of experience in defense cybersecurity. He is a Certified CMMC Professional (CCP) who has guided dozens of contractors through NIST 800-171 self-assessments and SPRS submissions. His focus is on translating complex federal regulations into actionable security strategies for the defense industrial base.

Conclusion

Calculating and submitting your SPRS score is a fundamental requirement for doing business with the Department of Defense in 2026. By starting with a perfect 110 and accurately subtracting for missing controls, you create a transparent and legally defensible record of your security posture. Remember that your score is more than just a number; it is a reflection of your commitment to protecting national security data. Ensure your System Security Plan is robust, your calculations follow the weighted methodology, and your PIEE access is ready long before your next contract deadline. If you have gaps in your compliance, use the POA&M process to strategically improve your score over time and maintain your standing in the defense industrial base.

Frequently asked questions

What is the lowest possible SPRS score?

The lowest possible SPRS score is -203, which occurs if a contractor has failed to implement any of the 110 NIST 800-171 controls (DOD, 2026). A score this low indicates a high risk to the DOD and generally disqualifies the contractor from handling sensitive information until significant remediation occurs.

Do I need a third-party assessment to submit a score?

No, the current requirement for most contractors is a self-assessment score (DOD, 2025). While the CMMC program will eventually require third-party verification for Level 2, the self-assessed SPRS score remains the legal standard for current contract awards and annual executive affirmations.

How often should I update my SPRS score?

Scores must be updated at least every three years, but you should update yours whenever you complete a major remediation milestone (DOD, 2026). Regular updates demonstrate to the government and prime contractors that you are actively improving your cybersecurity posture and reducing supply chain risk.

What documentation do I need to support my score?

You must have a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M) for all unimplemented controls (NIST, 2024). These documents serve as the evidence for your score and must be provided if the DOD performs a Medium or High-level assessment of your facility.