What should I do if I cannot support my SPRS score?

Freeze what you submitted, list the answers you can't prove, and call counsel before you change the record. The order matters.

Can't support your score?. Freeze what you submitted. Call counsel first. Fix, then correct SPRS. Working guide.
In this guide

Updated September 29, 2026

A new IT lead goes through the evidence folder and tells you the perfect score you posted two years ago doesn't hold up. Keep a copy of exactly what was submitted, write down which answers you can't prove and why, and get a lawyer who handles government contracts on the phone before anyone edits the record. Fix the security gaps right away. Change the record once counsel has seen the facts.

If you're not sure what "the record" is: defense contractors that handle sensitive government technical data score themselves against 110 security requirements from a standard called NIST SP 800-171, and post the result in SPRS, the Supplier Performance Risk System, a DoD website. 110 is a perfect score. A company official stands behind that number, and contracting officers and primes (the larger contractors you work under) rely on it to decide who gets work.

That's why the order matters. The number is a statement to the government, and a false one can fall under the False Claims Act, the federal fraud law that allows triple damages plus a penalty for each false claim. Since October 2021, the Justice Department's Civil Cyber-Fraud Initiative has used that law against contractors that knowingly misrepresent their cybersecurity. It also rewards companies that come forward. In July 2025, Aero Turbine and its private equity owner settled for $1.75 million over gaps against that same standard, and DOJ credited them for disclosing it themselves, cooperating, and fixing the problems. What you do in the next month becomes part of the story either way.

The first two days

Save the submitted record as it stands: the score, the date, the scope (which systems it covered), the CAGE codes (the government's ID for each of your business locations), and who signed off. Next to it, save everything that backed it on that date: the scoring spreadsheet, the version of your system security plan (the written description of your security setup) in use at the time, and the evidence folder. Write a short note of who found the problem, when, and what they saw. Nobody edits any of these from here on.

Then have your IT lead go through every requirement that was marked as met and pull out the ones you can't support. Each one gets sorted into one of two columns, and that split is the whole conversation you'll have with counsel. A table like this does it:

Requirement Submitted as What we found Evidence lost, or control never in place?
3.5.3 multi-factor login Met Policy says everyone uses a second login factor. Microsoft Entra shows 11 of 24 accounts with none set up. Never in place
3.3.1 audit logs Met Logging was on, but the export proving 90 days of history was deleted in a cleanup Evidence lost
3.6.1 incident response Met A response plan exists but was written last month Not in place at the time

A lost file, a misread requirement, and a knowing misstatement are different facts with different consequences. Your lawyer decides which one you have and what to tell the contracting officer or the prime. Your job is to hand them this table fast.

Fix the exposure while legal works

You don't need to wait on anyone to turn on multi-factor login for those 11 accounts. Do it this week and write down the date it went live. That date is the only one it gets. Backdating an approval, or presenting a new control as if it were running during the old assessment, turns a correctable error into the kind of case DOJ builds.

Then correct the record

Recalculate the score from what's true today (the scoring rules). With counsel, settle who gets told and in what words, including any prime you gave the old number to. Then update SPRS by editing the record or filing a new assessment; DoD's quick-entry guide covers both. Keep the original.

Put a one-page change summary in the file for whoever asks next:

Original submission: [score], [date], scope [name], affirmed by [name]. Found: [date], by [role]. Requirements not supported: [IDs], with the reason for each. Corrected score: [score], filed [date]. Fixes: [control], live [date], evidence [location]. Owner: [name]. Notifications: [who], [date], per counsel.

If the security plan was the weak point, the 90-day plan rebuilds it on facts. Next time, have a second person trace every "met" to a piece of evidence before anyone signs. That's cheaper than the lawyer. Submitting in SPRS

Mock assessment

Find the answers that won't hold up before someone else does.

Garde1 scores every requirement against your evidence and shows where its number and the score you posted in SPRS disagree.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE