CMMC guide
SPRS score: how it is calculated, and why a negative number is normal
Your SPRS score is 110 minus a weighted deduction for every NIST SP 800-171 requirement you have not fully met. Each of the 110 requirements is worth 5, 3 or 1 points, so the lowest possible score is minus 203 and a first honest assessment often lands below zero. The number is posted to the Supplier Performance Risk System under DFARS 252.204-7019 and 7020, where contracting officers and primes read it before award.
How is the score calculated?
Start at 110. For every requirement that is not met, subtract its weight. The weights come from the Department's assessment methodology, not from the assessor's mood.
- 5 points: 42 requirements whose absence creates major exposure. Examples include limiting system access to authorized users, encrypting CUI on mobile devices, and monitoring for unauthorized use.
- 3 points: 14 requirements with significant but more contained effects.
- 1 point: 52 requirements with lesser or indirect effects, many of them documentation and process items.
- Two requirements have their own band. Multifactor authentication (3.5.3) costs 5 points if nobody has it and 3 points if administrators and remote users have it but general users do not. FIPS validated encryption (3.13.11) costs 5 points if CUI is not encrypted and 3 points if it is encrypted with something that is not FIPS validated.
That adds up: 42 plus 2 plus 14 plus 52 is 110. A requirement that is partly done counts as not met and loses its full weight, except for those two.
Why are first scores often negative?
Because the deductions are bigger than the starting number. Miss the 42 five point requirements alone and you are at minus 100 before the others are counted. A small supplier with no multifactor authentication, no central logging, no configuration baseline, no formal incident response and no System Security Plan will typically score between minus 80 and plus 20 on an honest first pass, and that is a company doing reasonable everyday IT. The average posted score across the defense industrial base has sat around 60 for years, which tells you how many self assessments were done against a questionnaire rather than against evidence.
A negative number is not a verdict on your business. It is the starting line, and it is the only number worth posting, because of what the score promises.
What does the score promise, and what does it not?
Under DFARS 252.204-7019 a current score has to be in SPRS before award, and under 7020 the government can come and assess you against it. The posting is accompanied by the date of the assessment, the scope it covers, and the date by which you expect to reach 110. A senior official signs an annual affirmation that it is accurate.
What the score does not do is make you compliant. It describes how far from the 110 requirements you are on a given date. A score of 110 says every requirement is met and evidenced. A score of 70 says you are 40 weighted points short and have a plan to close them.
What it does do is create liability if it is wrong. A knowingly inflated score, followed by invoices on the contract, is the pattern behind the False Claims Act settlements of 2025. Those were paid by contractors who posted the number they wanted rather than the number they had.
What are the two mistakes that get a score challenged?
Scoring the policy instead of the system. The requirement is met when the control is implemented and the evidence shows it, not when a policy says it should be. "We require MFA" with a quarter of the accounts still on passwords alone is a 3 point deduction, not a met requirement.
Scoring the wrong boundary. The score covers the systems that process, store or transmit CUI. If the assessment covered the three computers in the engineering office and the drawings also sit on the owner's laptop and the shared file server, the scope is wrong and the score with it. Draw where CUI goes first, then score what the drawing shows.
How does a gap assessment produce the number?
By testing each of the 110 requirements against the environment and the evidence, one by one, with the deduction recorded next to each. The output is three things: the score, the list of unmet requirements in weight order, and what closing each one takes. The weight order matters. Twelve 1 point documentation gaps can be closed in a fortnight and move the score twelve points. One 5 point gap, say logging that cannot tie an action to a named person, can take a quarter and a new tool.
Our CMMC Level 2 gap assessment scores all 110 requirements this way and gives you the posting ready number for a published price.
What should you do with a low score?
- Post it. A real negative number with a plan is defensible. An invented 95 is not.
- Set the date. SPRS asks when you expect to reach 110. Pick a date the plan supports.
- Close by weight, with an eye on dependencies. Multifactor authentication, the boundary, logging and the System Security Plan move the score most and unlock other requirements.
- Re-score when the evidence exists, not when the work is planned, and update SPRS the same week.
Questions contractors ask
FAQIs a negative SPRS score allowed?
Yes. The scale runs from minus 203 to 110, and negative first scores are common. Posting an honest negative score with a plan is the intended use of the system.
Who can see my SPRS score?
Department of War contracting officers and personnel. Primes see it when they check a subcontractor's eligibility. Competitors do not.
Does a 110 mean I am CMMC certified?
No. 110 is the self assessed score. Certification is a separate assessment process; see the status of the third party requirement, suspended since July 2026.
How often do I update the score?
Whenever it changes materially, and at least every three years for the assessment date to stay current. In practice, update it each time a planned item closes.
Can my MSP post the score for me?
They can prepare it. A senior official of your company signs the affirmation, and that signature is the company's, not the provider's.
Already know you want to talk?
BOOK A CALLSkip the form. Pick a time and talk to us directly.
What happens in 30 minutes
- We learn about your business and the defense contracts you hold or are bidding on.
- We walk you through a gap assessment, the first step toward CMMC, and what it covers.
- If you qualify, we help you apply for an in-kind grant from Cyber Grants Alliance to cover it. No slides.
Defense supplier under 25 people? Start with the grant.
Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the work itself, including CMMC Level 1 and Level 2 gap assessments, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.