Skip to main content
Category: CMMC & DIB Assessment

SPRS Score

Also known as: SPRS, Supplier Performance Risk System Score
Simply put

An SPRS score is a rating maintained within the Department of Defense's Supplier Performance Risk System, which is DoD's single authorized application for retrieving supplier information. In the cybersecurity context, contractors generally record a self-assessment score in SPRS that reflects how well they meet applicable security requirements. Contracting officials use these scores to help identify higher-risk suppliers and assess the likelihood that contract terms may not be fulfilled.

Formal definition

The Supplier Performance Risk System (SPRS) is described in the evidence as the Department of Defense's single, authorized application for retrieving supplier information, functioning as a procurement risk analysis tool that addresses Price, Item, and Supplier risk. A SPRS score in the cybersecurity compliance context is generally a self-assessment score entered by a DoD contractor to indicate its ability to meet applicable security compliance requirements, and the Supplier Risk tool provides contracting officials an overall score used to identify riskier suppliers and evaluate the likelihood of non-fulfillment of contract terms. Practitioners should note that the sources vary in how they characterize the score's relationship to specific frameworks: one source ties it to CMMC compliance while others describe it as a self-assessment of security requirements, so readers must verify against current official SPRS and DoD guidance which requirement set, assessment methodology, and scoring scale apply to their situation. This entry does not cover the specific scoring methodology, thresholds, contract clause requirements, or the distinction between assessment and any related authorization, all of which should be confirmed against current authoritative sources.

Why it matters

For DoD contractors, the SPRS score functions as a visible signal of cybersecurity posture that contracting officials can retrieve directly, since SPRS is described as the Department of Defense's single, authorized application for retrieving supplier information. Because the score is generally self-recorded and then available to contracting officials, it becomes one of the inputs used to identify "riskier" suppliers and to assess the likelihood that contract terms may not be fulfilled. A score that is missing, outdated, or inaccurate can therefore affect how a supplier is perceived during procurement risk analysis, which the sources frame as spanning Price, Item, and Supplier risk.

Practitioners should treat the score as a self-assessment reflecting an organization's ability to meet applicable security compliance requirements rather than as an independent authorization or a guarantee of security. It is important not to conflate recording a score with achieving compliance in an absolute sense; the score reflects self-reported alignment with requirements at a point in time. The evidence sources also vary in how they characterize the score: one ties it directly to CMMC compliance, while others describe it more generally as a self-assessment of security requirements. Given this variation, readers should verify against current official SPRS and DoD guidance which requirement set and methodology apply to their contracts rather than assuming a single fixed interpretation.

This entry does not establish the specific scoring methodology, thresholds, applicable contract clauses, or the relationship between a self-assessment score and any formal assessment or authorization. Contractors should confirm those specifics against current authoritative sources, because the requirement sets and how they map to SPRS entries can change across revisions and as DoD cybersecurity frameworks continue to evolve.

Who it's relevant to

Government Contractors and Suppliers
DoD contractors and suppliers generally need to record and maintain a self-assessment score in SPRS reflecting their ability to meet applicable security compliance requirements. Because contracting officials can retrieve this score to gauge supplier risk, contractors should confirm which requirement set and methodology apply to their contracts and keep their entries current rather than treating a one-time score as permanent.
Contracting Officers and Procurement Officials
Contracting officials use the overall SPRS score to help identify riskier suppliers and assess the likelihood of non-fulfillment of contract terms as part of broader procurement risk analysis addressing Price, Item, and Supplier risk. They should recognize that a self-assessment score reflects self-reported alignment with requirements and is one input among others, not an independent authorization or a substitute for verifying compliance specifics.
Compliance Officers and ISSMs at Defense Suppliers
Those responsible for cybersecurity compliance within a contractor organization should understand how their security posture is translated into an SPRS entry. Given that sources vary in tying the score to CMMC versus a general self-assessment of security requirements, these practitioners should verify against current official SPRS and DoD guidance which requirement set, methodology, and scoring scale apply before relying on any particular interpretation.
Auditors and Assessors
Auditors reviewing a supplier's readiness should note the distinction between a self-assessment score recorded in SPRS and any formal assessment or authorization, which this entry does not address. They should confirm the applicable scoring methodology, thresholds, and contract clause requirements against current authoritative sources rather than assuming the SPRS score alone demonstrates a complete or independently validated compliance state.

Inside SPRS

Self-Assessment Basis
An SPRS score generally reflects a contractor's self-assessment of its implementation of the NIST SP 800-171 security requirements applicable to Controlled Unclassified Information (CUI), rather than an independent certification. Practitioners should verify the current assessment methodology against official DoD sources.
Scoring Methodology
The score is derived from the DoD Assessment Methodology, which assigns a starting value and deducts points for each unimplemented requirement, with different weights reflecting the relative impact of a given control. The exact point values and starting baseline should be confirmed against the current published methodology.
Plan of Action and Milestones (POA&M) Considerations
Requirements not yet implemented at the time of assessment are generally reflected as deductions and may be tracked through a POA&M, which can affect the reported score until remediation is complete.
System Security Plan (SSP) Linkage
The assessment underlying an SPRS score is typically documented in and supported by an SSP describing the boundary and how requirements are met, which serves as the reference for the scored implementation status.
Reporting and Storage Function
SPRS (Supplier Performance Risk System) is a DoD system used to store and make assessment scores available to authorized DoD stakeholders in connection with acquisition and contract eligibility processes. Specific access and reporting mechanics should be verified against current DoD guidance.
Assessment Level Context
The DoD Assessment Methodology generally contemplates different assessment levels (for example, self-assessment versus government-conducted reviews), and the level associated with a score affects its assurance value. Readers should confirm current level definitions against authoritative sources.

Common questions

Answers to the questions practitioners most commonly ask about SPRS.

Does a passing SPRS score mean my organization is CMMC compliant?
No. An SPRS score reflects a self-assessment of implementation against the NIST SP 800-171 requirements pursuant to DFARS clause 252.204-7019/7012, and it is not the same as a CMMC assessment or certification. CMMC, maintained under the DoD program, establishes its own assessment and certification structure that may involve third-party or government assessment depending on the level and the applicable revision. A self-reported SPRS score generally does not substitute for a CMMC determination where CMMC is required, and you should verify current requirements against the governing regulation and contract terms.
Once I submit my SPRS score, is it good indefinitely?
No. An SPRS score reflects the state of your assessment as of the date it was performed, and it is expected to be kept current as your System Security Plan and implementation change. Scores are generally understood to have a limited period of currency, and a stale score may not accurately represent your posture. Treat scoring as an ongoing activity tied to continuous monitoring of your implementation rather than a one-time submission, and confirm any specific currency or refresh expectations against the applicable DFARS provisions and contract requirements.
How is the SPRS score calculated?
The score is generally derived using the DoD Assessment Methodology, which starts from a defined maximum value and deducts weighted point values for each NIST SP 800-171 requirement that is not fully implemented, based on the associated System Security Plan and any Plan of Action and Milestones (POA&M). Different requirements carry different point weights under the methodology. Because the specific point values and the maximum are set by the published methodology and may be revised, you should calculate against the current official DoD Assessment Methodology document rather than relying on a remembered figure.
Who is responsible for entering the SPRS score, and where is it submitted?
The score is self-reported by the contractor (or entered on behalf of the assessed organization, depending on the assessment level) into the Supplier Performance Risk System (SPRS), which is a DoD system. The submission is generally tied to the organization's identifying information and to the relevant System Security Plan. Roles for who performs the assessment and who has authority to enter data can vary with the assessment level (self, medium, or high, per the DoD methodology), so confirm the appropriate access, roles, and submission process against current SPRS guidance and your contractual obligations.
What should I include in my System Security Plan and POA&M to support the score?
The score should be traceable to a System Security Plan that documents how each applicable NIST SP 800-171 requirement is implemented, and to a POA&M that identifies requirements not yet fully met along with planned remediation. Maintaining this supporting documentation is important because the score is a summary that reviewers may expect to reconcile against the underlying SSP and POA&M. Specific content, format, and any limits on the use of POA&Ms can be shaped by contract terms and applicable DoD guidance, which you should verify against current sources.
Does a subcontractor need its own SPRS score, or does the prime's score cover it?
A prime contractor's SPRS score generally reflects that prime's own assessment and does not automatically extend to subcontractors handling covered information. Where the applicable DFARS provisions flow down NIST SP 800-171 requirements, subcontractors that store, process, or transmit the relevant information may be expected to conduct and report their own assessment. Because flow-down obligations and reporting expectations depend on the specific clauses in the contract and the information involved, confirm each party's responsibilities against the current contract language and applicable DFARS provisions.

Common misconceptions

An SPRS score is the same as a CMMC certification.
A self-reported SPRS score based on the NIST SP 800-171 DoD Assessment Methodology is distinct from a CMMC assessment or certification, which involves its own separately governed program. The two should not be treated as interchangeable, and contractors should confirm which obligation applies to a given contract.
A high or perfect SPRS score means the organization is secure.
A score reflects self-assessed implementation status of a defined set of requirements at a point in time and is a compliance indicator, not a guarantee of security. Compliance and actual security posture are not equivalent, and status can change as systems and threats evolve.
Once a score is posted it remains valid indefinitely.
An SPRS score reflects the assessment as of a particular date and is generally expected to be kept current as the environment, controls, or POA&M status change. Practitioners should confirm applicable currency expectations against current DoD guidance.

Best practices

Maintain a current System Security Plan that clearly defines the assessment boundary so the scored implementation status is accurate and defensible.
Apply the current DoD Assessment Methodology and verify point values, weighting, and the starting baseline against the official published version before calculating or reporting a score.
Document unimplemented requirements in a Plan of Action and Milestones and track remediation, updating the reported score as items are completed.
Reassess and update the posted score when the environment, controls, or POA&M status materially change rather than treating a prior score as permanent.
Confirm which contractual obligation applies to a given award, since a self-reported SPRS score based on NIST SP 800-171 is distinct from any separate CMMC requirement.
Verify assessment level definitions, access mechanics, and current methodology directly against authoritative DoD sources rather than relying on assumptions or outdated summaries.