
SPRS Scores Explained: A Guide for Defense Contractors
If you’re a defense contractor competing for Department of Defense work, your SPRS score isn’t just a number — it’s a snapshot of your cybersecurity posture that contracting officers can see before they ever read your proposal. A weak score won’t just raise eyebrows; in an increasingly competitive Defense Industrial Base, it can be the difference between winning a contract and being filtered out before the evaluation process begins.
Understanding what your SPRS score actually measures, how it’s calculated, and what you can do to move it in the right direction isn’t optional anymore. It’s table stakes.
What Is SPRS and Why Does It Matter for DoD Contractors?
The Supplier Performance Risk System (SPRS) is the DoD’s authoritative platform for tracking supplier performance, risk, and compliance data. While SPRS has long tracked delivery performance and quality ratings, its role expanded significantly in 2020 when DFARS provision 252.204-7019 required all contractors handling Controlled Unclassified Information (CUI) to post a current NIST SP 800-171 self-assessment score in the system.
That score — which ranges from -203 to +110 — is now part of your public-facing compliance record. Contracting officers routinely pull SPRS data during source selection. If your score is low, negative, or simply missing, it signals risk. And in a procurement environment shaped by CMMC requirements and heightened scrutiny of supply chain security, risk flags get noticed.
The bottom line: your SPRS score is your cybersecurity credibility score in the eyes of DoD. Treat it that way.
How Your SPRS Score Is Calculated
The NIST SP 800-171 assessment methodology assigns a maximum score of 110 points — one point per fully implemented security requirement across 14 control families. From there, it gets more nuanced. Each of the 110 requirements carries a specific point value based on its criticality, and failing to implement a requirement results in a deduction. Requirements that are only partially implemented, documented in a Plan of Action and Milestones (POA&M) for future remediation, still result in deductions at the time of assessment.
This means a contractor who hasn’t addressed access control, incident response, or configuration management requirements may score well below zero — and that negative number goes directly into SPRS.
A few critical mechanics to understand:
- Missing System Security Plan (SSP): If your SSP is absent or incomplete at the time of assessment, NIST guidance indicates an assessment cannot be completed. In SPRS, this results in “No Score” — which is arguably worse than a negative number.
- POA&M limitations: Under the CMMC framework (32 CFR Part 170), certain high-priority requirements cannot be placed on a POA&M. Attempting to defer them without remediation will prevent you from achieving a passing CMMC status.
- Score validity: DFARS 252.204-7019 requires that your posted score be no more than three years old. An expired score is treated as non-compliant.

The Most Common Gaps Dragging Down DIB Contractor Scores
Across the Defense Industrial Base, certain control families show up repeatedly as the primary drivers of low SPRS scores. If you’re doing a gap analysis ahead of a contract pursuit, these are the areas to examine first.
Access Control (AC) is consistently one of the highest-weighted families and one of the most commonly deficient. Requirements around least-privilege access, CUI system access enforcement, and remote access controls are frequently partially implemented or undocumented.
Audit and Accountability (AU) trips up organizations that lack centralized logging, log review processes, or the ability to demonstrate audit trail integrity. Without a managed SIEM or log aggregation capability, these requirements are difficult to satisfy on paper and nearly impossible to demonstrate under assessment.
Configuration Management (CM) requires documented baselines, change control processes, and restrictions on unauthorized software. Many smaller contractors rely on ad hoc IT practices that don’t produce the evidence an assessor would need.
System and Communications Protection (SC) covers network segmentation, CUI protection in transit and at rest, and enclave design. This is where investments in purpose-built infrastructure — such as a compliant enclave built on Azure Government or AWS GovCloud — become directly relevant to your score.
Identification and Authentication (IA) requirements, including multi-factor authentication for all CUI system access, remain partially unmet across a surprising number of DIB organizations.
If your current managed services provider isn’t actively mapping your environment against these families and helping you close gaps, that’s a conversation worth having.
Practical Steps to Improve Your SPRS Score Before Your Next Contract
Improving your SPRS score is a structured process, not a quick fix — but it’s absolutely achievable with the right approach and support. Here’s where to focus your energy:
Start with a thorough self-assessment. Walk through all 110 NIST SP 800-171 requirements methodically. Use the DoD assessment methodology to assign accurate point values. Don’t inflate the score — contracting officers and C3PAOs will verify, and an inaccurate self-assessment creates legal exposure under the False Claims Act.
Build or update your SSP. Your System Security Plan is foundational. It must accurately describe your environment, document which requirements are implemented, and be current. No SSP means no score in SPRS — full stop.
Prioritize high-value, high-risk control families. Use your gap analysis to sequence remediation by point value and assessment likelihood. Access control, audit logging, and configuration management improvements tend to yield the most significant score gains.
Leverage compliant cloud infrastructure. Moving CUI workloads into a purpose-built environment — such as a Microsoft 365 GCC-High tenant, an Azure Government enclave, or an AWS GovCloud deployment — can close a significant number of SC and AC requirements in a single infrastructure decision. The right managed services partner can stand this up and document it against NIST requirements simultaneously.
Document everything. SPRS scores are only as strong as the evidence behind them. Policies, procedures, configuration screenshots, and access logs aren’t just good practice — they’re what an assessor will ask for when it’s time for a third-party CMMC assessment.
Post your updated score promptly. Once remediation is complete and your SSP reflects your current state, post the updated score in SPRS. Don’t wait for a solicitation to trigger the update.
How VSO Helps Defense Contractors Strengthen Their SPRS Posture
VSO works directly with Defense Industrial Base organizations to assess, remediate, and document NIST SP 800-171 compliance — with the goal of producing a defensible SPRS score and a clear path to CMMC certification.
Our approach starts with a structured gap assessment against all 110 requirements, mapping your current environment to each control family and identifying both quick wins and long-term remediation priorities. From there, our managed services teams implement and document controls — including Zero Trust access policies, 24/7 SOC monitoring, MFA enforcement, and secure enclave design on Azure Government or AWS GovCloud — in a way that directly supports your SSP and your SPRS submission.
We’re CMMC Level 2 certified and ISO 9001:2015 certified. We’ve operated in classified, disconnected, and SCIF environments across the DoD enterprise. And as a veteran-led organization, we understand what mission accountability looks like — and we bring that same standard to every compliance engagement we take on.
Your SPRS score is on the clock. Let’s make sure it reflects the strength of your actual security posture.
Ready to Strengthen Your SPRS Score?
VSO’s compliance and managed services teams work with defense contractors across the DIB to assess gaps, implement controls, and build the documentation needed for a strong, defensible SPRS submission — and a clear path to CMMC certification.
Contact us today to schedule your NIST SP 800-171 gap assessment.
📞 (888) 805-0510 📧 sales@vso-inc.com 🌐 vso-inc.com
Frequently Asked Questions
What is the highest possible SPRS score?
The maximum SPRS score under the NIST SP 800-171 assessment methodology is 110, reflecting full implementation of all 110 security requirements. Most organizations don’t start there — the DoD has noted that the average initial self-assessment score across the DIB has historically been well below 100.
Is there a minimum SPRS score required to win a DoD contract?
DFARS 252.204-7019 does not specify a minimum passing score — it requires that a current score simply be posted in SPRS. However, under CMMC requirements (32 CFR 170), contractors pursuing Level 2 certification must meet a threshold score and cannot have certain high-priority requirements on open POA&Ms at the time of assessment.
Can I post my own SPRS score, or does it require a third-party assessment?
For CMMC Level 2, a self-assessment (Basic Assessment) is acceptable for many contracts, though DoD-led or third-party C3PAO assessments may be required for higher-sensitivity procurements. The assessment methodology and scoring process are the same regardless of who conducts it.
How long is my SPRS score valid?
Under DFARS 252.204-7019, your posted score must be no more than three years old at the time of contract award, unless the solicitation specifies a shorter timeframe. Annual affirmation of continued compliance is also required under CMMC rules.
What happens if my SPRS score is negative?
A negative score indicates that a significant number of NIST SP 800-171 requirements are not implemented. While there is no hard regulatory bar on bidding with a negative score under the current self-assessment framework, it is a visible risk signal to contracting officers and primes reviewing your record. It also suggests your organization may not be ready for a CMMC Level 2 assessment.
How does a compliant cloud environment affect my SPRS score?
Moving CUI workloads to a FedRAMP-authorized cloud environment — such as Azure Government, M365 GCC-High, or AWS GovCloud — can satisfy a meaningful number of System and Communications Protection (SC) and Access Control (AC) requirements, directly improving your score. The key is that the implementation must be accurately documented in your SSP and reflected in your assessment.





