Your IT provider says you're "at 96," a prime is asking for your score, and nobody has told you whether 96 is good. You start at 110 and lose 1, 3, or 5 points for every security requirement you haven't fully met. The lowest possible score is −203. Whether 96 is good depends on which requirements make up the missing 14 points, not on the number itself.
SPRS is the Supplier Performance Risk System, the Defense Department website where contractors post their cybersecurity score. If you handle CUI (controlled unclassified information: the drawings, specs, and technical data the government marks as sensitive), your contracts require that score to be on file before you can win work. The score measures how many of the 110 requirements in NIST SP 800-171, the government's security checklist for CUI, you have in place.
Where the 110 points come from
Every one of the 110 requirements has a weight. The weights come from DoD's scoring template (Assessment Methodology, Annex A), and the CMMC rule uses the same values (32 CFR 170.24).
- Forty-four requirements are worth 5 points. These are the ones where a gap lets an attacker in or lets data walk out: giving accounts only to people who should have them, keeping audit logs, patching, antivirus, firewalls at the edge of your network, security training, an incident response plan, and scanning for vulnerabilities.
- Fourteen are worth 3 points: gaps with a narrower effect, such as giving people more access than their job needs, or not reviewing the logs you keep.
- Fifty-one are worth 1 point. These are supporting requirements like locking a screen after inactivity or locking out an account after repeated bad passwords.
- One is worth nothing, because without it there is no assessment at all: the System Security Plan (SSP), the document that describes your systems and how each requirement is met. No up-to-date SSP means the assessment "could not be completed."
Miss all of them and you lose 313 points. That is where −203 comes from.
A score of 96, taken apart
Here is how a real-looking 96 is built. The requirement numbers are for your IT person; the descriptions are for you.
| What isn't done | Points | Running score |
|---|---|---|
| Start | 110 | |
| Multi-factor login is on for admins and remote access, but not for everyone (3.5.3) | −3 | 107 |
| No audit logs kept for the file server (3.3.1) | −5 | 102 |
| Engineers are administrators on their own laptops (3.1.5) | −3 | 99 |
| No lockout after repeated failed logins (3.1.8) | −1 | 98 |
| Screens don't lock when people walk away (3.1.10) | −1 | 97 |
| No log of who entered the building (3.10.4) | −1 | 96 |
Ninety-six looks close. It isn't. The audit-log gap is a 5-pointer, and the building-entry log is one of six requirements the rule never lets you leave open. This company has no CMMC status at all until both are fixed, and a contract that requires one is a contract it can't be awarded.
What your score actually means
At 110, everything is in place. It is the only score that earns Final status, the clean result that lasts three years with a yearly sign-off.
From 88 to 109, you can earn Conditional status, but only if every gap still open is a small one the rule allows on a POA&M (plan of action and milestones: your written list of what's unfinished and when it will be done). You then have 180 days to close every item, or the status expires. The rule sets the line at 80% of the maximum, which is 88 (32 CFR 170.21).
Below 88, there is no CMMC status. SPRS will not let you affirm a CMMC Level 2 self-assessment below 88 (SPRS CMMC entry guide).
A negative score is legal to post and often the honest one for a company early in the work. The older NIST score required by DFARS 252.204-7019 has no minimum; it asks for your summary score, the date, and the date you expect to finish (DFARS 252.204-7019). A −40 posted honestly is a starting line. A 104 that should have been −40 is a legal problem.
The 88 line is about which gaps, not how many
This is where most people misread their number. To claim Conditional, every open item must be worth 1 point, with a single exception: encryption that protects CUI but uses a module without FIPS validation (the government's certification for encryption software), which costs 3 points and may stay open. Every other 3- or 5-point gap has to be closed first.
Six requirements can never stay open, no matter your score (32 CFR 170.21):
- controlling connections to outside systems, such as personal cloud storage or a customer's network (3.1.20)
- controlling what gets posted on public websites (3.1.22)
- having the System Security Plan (3.12.4)
- escorting visitors (3.10.3)
- keeping a log of physical entry (3.10.4)
- managing keys, badges, and door codes (3.10.5)
SPRS enforces this for you. If any open requirement isn't allowed on a POA&M, the status shows "No CMMC Status regardless of score." The full Conditional and Final test →
Four ways companies miscount
The first is averaging the pieces. Each requirement breaks into smaller checks, called objectives. Access control (3.1.1) has six. If five pass and one fails, the whole requirement fails and you lose all 5 points. The rule says a requirement is met only when "all applicable objectives" are satisfied (32 CFR 170.24). The reverse also holds: three failed objectives inside 3.1.1 still cost 5 points, not 15. One requirement worked end to end →
The second is counting work in progress. Partial credit exists in exactly two places: multi-factor login (−3 instead of −5 if it covers admins and remote users but not everyone) and the encryption case above. Everything else is all or nothing. A drafted policy, a signed purchase order, or "most of the laptops" earns zero. The rule is blunt that evidence "must be in final form and not draft."
The third is treating the POA&M as points. Writing a gap onto your plan doesn't earn the points back. A requirement on the plan is still not met. Not having the plan at all costs another 3 points, because keeping one is itself a requirement (3.12.2).
The fourth is reading the score as a percentage. Five unmet 1-pointers leave you at 105. Five unmet 5-pointers leave you at 85. Same number of gaps, very different company.
One thing works in your favor. If a requirement truly doesn't apply to you, it counts as met. The rule's own example is separating public-facing systems (3.13.5) when you have none.
Who sees your score, and how long it lasts
Only DoD personnel and your own company can see your score in SPRS. Your prime can't look it up. The SPRS help desk tells primes to contact subcontractors directly (SPRS FAQ), which is why the request shows up in your inbox.
To post a score, someone at your company needs the "SPRS Cyber Vendor User" role in PIEE, the DoD procurement portal that also runs invoicing (WAWF). Your company's PIEE account administrator approves it. For a CMMC Level 2 self-assessment, you mark each requirement met or not met in SPRS, and the site calculates the score. The Affirming Official, a senior person at your company, then signs that the results are true. The SPRS entry, step by step →
The clock:
- A Conditional status lasts 180 days.
- A Final status lasts three years, and the Affirming Official must re-affirm it every year (32 CFR 170.22). What that signature means →
- The older NIST score counts as current for three years unless the solicitation asks for something newer.
Rounding up is the expensive mistake
In January 2021, a Massachusetts defense contractor called MORSECORP posted a score of 104. In July 2022, a consultant told the company its real score was −142. It didn't update SPRS until June 2023, three months after the government subpoenaed it. MORSECORP paid $4.6 million to settle False Claims Act allegations (U.S. Department of Justice).
Notice what the case was about. A low score didn't cost MORSECORP $4.6 million. A score that stayed high after the company knew better did. If your posted number is higher than what you can prove today, fix it now and call your lawyer before the next invoice goes out. What to do if you can't support your score →
Keep a score a stranger could check
Build the score in a spreadsheet that a second person can recalculate in ten minutes. One row per requirement, five columns:
| Column | Example |
|---|---|
| Requirement | 3.3.1 |
| Status | Not met |
| Objective that failed | Audit logs for the file server aren't kept |
| Points | 5 |
| Proof | Link to the log retention setting, or "none yet" |
Sum the points column and subtract from 110. If the second person gets a different number, you found a problem before an assessor did. When you close a gap, the points come back only when the fix is running and you can show it. What counts as proof →
Garde1 runs this check for you. It scores all 110 requirements, objective by objective, against evidence from your tools and the records you add, computes the SPRS score down to the −203 floor, and compares it with the score you've already posted.
Common questions
What is a good SPRS score? 110. A score from 88 to 109 is workable only if every open gap is a 1-pointer allowed on a POA&M. Below 88 you have no CMMC status, although an honest low score still satisfies the older DFARS 7019 posting requirement.
What is the lowest possible SPRS score? −203. That's 110 minus 313, the total of every weight. First-time scores below zero are common.
Do I need an SPRS score for CMMC Level 1? No. Level 1 covers FCI (federal contract information: non-public information about the contract itself, like pricing or delivery schedules) and has 15 requirements. It is pass or fail: all 15 must be met, nothing can sit on a POA&M, and you post the result and affirm it every year (32 CFR 170.15).
Can my prime see my SPRS score? No. Only DoD and your own company can. Primes still have to confirm you have a current assessment before awarding you a subcontract (DFARS 252.204-7020), so they will ask you for it.
Does a POA&M raise my score? No. A requirement on the plan is still unmet and still costs its full weight. The plan protects your status, if every item is allowed on it, and it keeps you from losing another 3 points for not having one.
How often should I update my score? Whenever it changes materially, in either direction, and at least before each annual affirmation. A fix that adds 5 points is worth posting. A new gap that drops you below what you posted is the one you can't sit on.
This week
- Pull up the score you posted in SPRS and the date you posted it.
- Rebuild it in the five-column sheet above, with a second person checking the math.
- Circle every 5-pointer and every one of the six never-open requirements. Those decide whether you have a status at all, so they go first in the fix order.
- If the rebuilt number is lower than what's posted, correct SPRS before your next invoice.
