Before an assessor ever visits, the Department of Defense may already have a number for your security posture: your Supplier Performance Risk System (SPRS) score. Under DFARS 252.204-7019 and -7020, contractors handling CUI must post a NIST SP 800-171 self-assessment score in SPRS and keep it current. It is often the first signal a contracting officer uses to gauge risk.

How the score works

The methodology starts at 110 — one point for each implemented requirement — and subtracts for each one you have not met. Not every control is weighted equally: some deductions are worth 1 point, others 3 or 5, based on their impact. Because the ceiling is 110 and some controls carry heavier weights, a score can even go negative if enough high-value requirements are open. The number is a snapshot of implementation, not a grade curve.

What a realistic score looks like

A perfect 110 straight out of the gate is rare, and frankly a little suspicious for an organization that has not done the work. What matters more is that the score is honest and improving, backed by a System Security Plan and a Plan of Action & Milestones (POA&M) that shows what is open and when it closes.

Common mistakes

  • Scoring optimistically. Marking a control ‘met’ because a policy exists, when the operational evidence is not there, is exactly the gap an assessment finds.
  • Letting it go stale. The score is expected to reflect your current state. A number posted 18 months ago and never touched is its own red flag.
  • Treating it as the finish line. The score supports the assessment; it does not replace it.

An accurate SPRS score is a readiness tool, not a marketing number — it tells you exactly where the work is. Try our CMMC Readiness Check to see where you stand.