Supplier Performance Risk System
The Supplier Performance Risk System (SPRS) is a Department of Defense web-based application used to store and retrieve information about the risk associated with DoD suppliers. Among its uses, SPRS is the location where defense contractors post self-assessment scores reflecting their implementation of NIST SP 800-171 cybersecurity requirements. Contracting officials can consult SPRS when evaluating offerors and determining whether a supplier is responsible.
SPRS is described by the Department of Defense as its single, authorized application for retrieving supplier performance and risk information. As used in DoD contracting, SPRS supports risk assessments that may include price, item, and supplier risk, which contracting officers may use in the evaluation of offerors and in responsibility determinations. SPRS is also the DoD-designated repository for NIST SP 800-171 self-assessment scores. Practitioners should note the distinction between SPRS as the reporting and data system and the underlying NIST SP 800-171 assessment methodology itself; posting a score in SPRS records the result of an assessment but is not equivalent to a formal authorization, nor should an SPRS score be conflated with a CMMC certification, as CMMC requirements and their relationship to self-assessment reporting continue to evolve across program revisions. This entry does not cover the specific SPRS scoring calculation, contractual clause obligations, or current CMMC phasing, which the reader should verify against current official DoD sources.
Why it matters
SPRS occupies a central position in DoD supplier risk evaluation because the Department of Defense describes it as its single, authorized application for retrieving supplier performance and risk information. For contracting officials, this means SPRS data can directly inform the evaluation of offerors and responsibility determinations, so the accuracy and currency of what a contractor posts there carries real consequences for eligibility and competitiveness. A missing or stale NIST SP 800-171 self-assessment score can affect a contractor's standing in the acquisition process.
For defense contractors, SPRS matters because it is the DoD-designated repository where NIST SP 800-171 self-assessment scores are posted. Practitioners should be careful not to conflate the act of posting a score with the underlying work of implementing and assessing controls: recording a result in SPRS documents the outcome of a self-assessment but is not itself a formal authorization. Contractors should also avoid treating an SPRS score as equivalent to a CMMC certification. While some third-party sources describe SPRS scoring in relation to CMMC, CMMC requirements and their relationship to self-assessment reporting continue to evolve across program revisions, and readers should verify current obligations against official DoD sources.
Because SPRS bridges the technical result of a NIST SP 800-171 assessment and the contracting decisions that rely on it, errors or misunderstandings can propagate from the security team into procurement outcomes. Understanding what SPRS does record, and what it does not, helps organizations avoid the common mistake of equating a posted score with either a completed authorization or a certification.
Who it's relevant to
Inside SPRS
Common questions
Answers to the questions practitioners most commonly ask about SPRS.