CMMC and NIST 800-171
Your SPRS Score: How It Is Calculated and Why the Average Is 60
If you are a defense contractor or part of the Defense Industrial Base (DIB), your SPRS score is more than just a number. It is a requirement for working with Controlled Unclassified Information (CUI) under DFARS 252.204-7012 and DFARS 252.204-7019. Understanding how your SPRS score is calculated, what a negative score means, and why the average is far below the required 110 is critical to maintaining eligibility for defense contracts and managing your compliance risk.
How is your SPRS score calculated?
Your SPRS (Supplier Performance Risk System) score reflects your self-assessment against the 110 controls in NIST SP 800-171 Rev 2, as required for Level 2 compliance. Each control is tied to a set of specific assessment objectives, totaling 320 across all controls (NIST SP 800-171A).
The scoring method is defined by the Department of Defense. You start with a base score of 110. For every NIST SP 800-171 control you have not fully implemented, you subtract a specific number of points. Some controls are weighted more heavily, so missing certain foundational practices can drop your score quickly. If you have not implemented enough controls, your SPRS score can be negative.
To be fully compliant, you need to implement all 110 controls and meet every assessment objective under each control. Only then can you claim a score of 110. If you are missing controls, you must document them in your System Security Plan (SSP) and track them in a Plan of Actions and Milestones (POA&M).
What does a negative SPRS score mean?
A negative SPRS score means you have significant gaps in your NIST SP 800-171 implementation. The scoring system allows for a negative total because some controls have higher point values, and missing several key controls can result in a score below zero.
A negative score signals to the Department of Defense that your organization is not adequately protecting CUI. It also increases your risk of government scrutiny and may jeopardize your eligibility for new contracts or contract renewals. The higher your score, the closer you are to meeting the full requirements of NIST SP 800-171, but a negative score indicates foundational issues that require immediate attention.
Why is the average SPRS score in the DIB only about 60?
As of now, the average SPRS score across the Defense Industrial Base is about 60, while the required score for full compliance is 110. This gap exists for several reasons:
- Many companies have not fully implemented all 110 controls or met the 320 assessment objectives.
- Fewer than half of companies have completed their System Security Plans or POA&M documentation.
- The complexity and cost of achieving full compliance are substantial. Most mid-sized DIB companies spend between 200,000 and 500,000 dollars in the first year, covering gap assessments, remediation, documentation, consulting, and personnel.
- The process of documenting intent (policy), describing how (procedure), and collecting real evidence for execution is both time-consuming and resource-intensive.
This means that most organizations are still in the process of closing gaps, and their SPRS scores reflect partial implementation rather than full compliance.
What happens now that CMMC certification is suspended?
On July 13, 2026, the Department of War suspended the CMMC Phase II third party certification requirement, pending a strategic review. This suspension affects only the requirement for a C3PAO (Certified Third Party Assessment Organization) to certify Level 2 compliance before contract award. It does not suspend DFARS 252.204-7012, NIST SP 800-171 Rev 2, the requirement for Level 1 and Level 2 self-assessments, SPRS score posting, or the annual senior official affirmation.
With third party certification suspended, your self-assessment and the signature of your senior official are the only assurances of compliance. The Department of War has stated it will continue to enforce requirements through self-assessments and select government-led assessments. This increases your exposure under the False Claims Act if you overstate your SPRS score, as there is no independent assessor between your self-attestation and the government.
What are the consequences of inflating your SPRS score?
Inflating your SPRS score or falsely claiming compliance can have serious consequences. Recent False Claims Act cases illustrate the risks:
- Health Net Federal Services certified compliance without scanning and remediating known vulnerabilities on a Defense Health Agency contract.
- MORSECORP failed to meet NIST SP 800-171 controls on Army and Air Force contracts, used non-FedRAMP email, and had no SSP on file.
- Aero Turbine failed controls and shared defense data with an unauthorized foreign entity. The private equity owner was named in the settlement.
Liability is not limited to the contractor. It can extend to primes, subcontractors, affiliates, and private equity owners. Whistleblowers can also file actions on the government's behalf.
How do you improve your SPRS score?
To raise your SPRS score, you must:
- Review your current implementation of all 110 NIST SP 800-171 controls.
- Complete your System Security Plan and POA&M documentation for any gaps.
- Implement missing controls and collect evidence that each assessment objective is being met.
- Update your SPRS submission whenever you make progress, as required by DFARS 252.204-7019.
If you are unsure where to start, a gap assessment can help identify which controls you are missing and what evidence you need. The CMMC Scoping and Assessment Guides specify that you must identify your CUI assets, security protection assets, contractor risk managed assets, specialized assets, and out-of-scope assets, and produce artifacts such as a CUI flow diagram, network boundary diagram, physical site diagram, and authorized user list.
For more details on DFARS and self-assessment requirements, you can review the Supplier Performance Risk System (SPRS) page from the Department of Defense.
Common questions
What is the highest possible SPRS score? The highest possible SPRS score is 110, which you achieve by fully implementing all 110 controls from NIST SP 800-171 Rev 2.
Do I need a third party to assess my SPRS score? Currently, third party certification for Level 2 is suspended. You must perform a self-assessment and have a senior official affirm your score.
Can my SPRS score be negative? Yes, your SPRS score can be negative if you are missing enough high-value controls. This indicates significant compliance gaps.
Improve Your SPRS Score Effectively
If you have not yet completed a thorough gap assessment or your SPRS score is well below 110, now is the time to act. For qualifying defense contractors, the Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant delivered as services, covering all 110 NIST 800-171 controls. This can help you understand exactly where you stand and what you need to do next. Learn more about this opportunity at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.