If your company handles Controlled Unclassified Information for the Department of Defense, you have an SPRS score, whether you have looked at it recently or not. It is the number that tells the government how well you meet NIST SP 800-171. Primes can see it. Contracting officers can see it. An inflated one is a liability, not an asset.
Here is what the score is, how it works, and how to make yours honest and defensible.
What SPRS Is
SPRS is the Supplier Performance Risk System, a Department of Defense database. Under DFARS 252.204-7019 and 7020, contractors that handle CUI must perform a NIST 800-171 self-assessment and post the resulting score in SPRS. It is how the government gauges the cybersecurity posture of its supply base without auditing every contractor.
How the Score Is Calculated
The assessment starts at 110, one point for each NIST 800-171 control, and subtracts points for controls you do not meet. Not every control is weighted equally. Some gaps subtract one point, others subtract three or five, based on their security impact. Because the ceiling is 110 and some controls carry heavy weights, the score can go negative. A company meeting only part of the standard can post a score well below zero.
The number is not the point. It is a snapshot of a real assessment. The System Security Plan and Plan of Action and Milestones behind it are what actually matter.
Why an Inflated Score Is a Liability
It is tempting to post a generous number to stay competitive. That is a mistake. Your score is a representation to the federal government. Claiming a posture you do not have is exactly the kind of misstatement that has produced False Claims Act settlements against contractors. A high score you cannot back up with evidence is worse than an honest lower one.
An accurate score, paired with a credible plan to close the gaps, is defensible. A fabricated one is exposure.
How to Improve It, Honestly
- Run a real self-assessment against all 110 controls, not a checkbox exercise.
- Document how you meet each control in your System Security Plan.
- Capture every gap in a Plan of Action and Milestones with owners and dates.
- Close the highest-weighted gaps first, since they move the score the most.
- Reassess and update your posted score as you make real progress.
Improvement is not about gaming the number. It is about actually meeting the controls and letting the score follow.
Frequently Asked Questions
What is a good SPRS score?
110 means you meet every control. Many contractors start well below that, sometimes negative. The goal is an accurate score backed by evidence and a plan, and steady progress toward 110.
Who can see my SPRS score?
The Department of Defense and, in practice, the primes you work under. It factors into contract eligibility and supply-chain risk decisions, which is why accuracy matters.
Does CMMC change the SPRS requirement?
The self-assessment and SPRS reporting obligations under DFARS 7019 and 7020 apply now, independent of CMMC's rollout status. They did not go away with the CMMC Phase 2 pause.
If you are not sure your SPRS score reflects reality, a NIST 800-171 assessment gives you an honest number and a plan to raise it. Talk with a senior advisor at JBW Group.