Skip to main content

Elevate

SPRS Score and CMMC Level 2: Scoring, POA&Ms and the 110 Question

Your SPRS score is the number that now carries the full weight of your cybersecurity claim to the Department of War, with no third-party assessor standing behind it. The July 2026 suspension of CMMC Phase 2 removed certification assessments as a condition of award, and a class deviation signed on September 3, 2026 carried that removal into acquisition regulation. What did not change is DFARS 252.204-7012, the 110 requirements in NIST SP 800-171 Revision 2, the SPRS submission, or the annual senior official affirmation attached to it. The score you post is the assertion of record.

This guide covers how the scoring methodology actually works, where the commonly repeated version of it is wrong, whether a perfect 110 is required, and how Plans of Action and Milestones fit into the current picture.

What the Suspension Changed for SPRS Scores

The Department of War suspended CMMC Phase 2 on July 13, 2026, pausing the November 10, 2026 transition that would have made a Level 2 certification assessment by a C3PAO a condition of award. Phases 3 and 4 were frozen alongside it. For the duration of the review, requiring activities may designate only CMMC Level 1 (Self) or Level 2 (Self), and no waivers are being granted.

A current NIST SP 800-171 self-assessment posted in SPRS, with annual senior official affirmation, remains a condition of eligibility. Elevate covers the broader implications in its analysis of what the CMMC Level 2 Phase 2 suspension means.

The practical effect on the score is a shift in who verifies it. Before the suspension, a self-assessment score was a planning figure that a C3PAO would eventually test. Now it is the figure a contracting officer relies on and the figure the False Claims Act tests if it turns out to be wrong. The Department of Justice announced cybersecurity False Claims Act settlements during the review window, so enforcement did not pause with the program.

That raises the stakes on scoring accuracy rather than lowering them, and it is the reason the methodology deserves precision rather than the approximations that circulate in vendor material.

How SPRS Scoring Actually Works

The scoring methodology comes from the NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1. It is codified for CMMC purposes at 32 CFR 170.24. These are two documents, not one: the Assessment Methodology governs the calculation, and the regulation confirms it within the CMMC program.

The Score Starts at 110 and Subtracts

An assessment begins at 110, the maximum achievable score, and subtracts a weighted value for each of the 110 requirements that is not fully implemented. The direction matters because the opposite framing appears frequently and produces incorrect expectations: contractors do not accumulate points toward a target, they lose them from a ceiling.

The consequence is that two organizations with the same number of open gaps can post very different scores. A contractor missing four high-weight requirements is in a worse position than one missing a dozen low-weight requirements, even though the second has three times as many gaps. The weighting is a prioritization signal, not an accounting detail.

The Weighting Tiers

Each unmet requirement removes 5, 3 or 1 point depending on the risk its absence creates.

DeductionRisk characterizationWhat it covers
5 pointsSignificant risk of exploitation or exfiltration of CUIRequirements whose absence exposes the network or the data directly
3 pointsSpecific and confined effect on securityRequirements with a meaningful but bounded impact
1 pointLimited or indirect effectRequirements that matter but do not create direct exposure on their own

The weighting is what converts a checklist into a sequence. An organization with a limited remediation budget should close the 5-point gaps first, because a single unmet 5-point requirement costs the same as five unmet 1-point requirements. That arithmetic is the entire strategic content of the scoring system.

Where Partial Credit Applies

The methodology is not purely all-or-nothing, and the claim that it is appears in a great deal of published material. The regulation is explicit on this point: the CMMC Scoring Methodology credits partial implementation in limited cases, naming multi-factor authentication as an example.

Two requirements carry partial credit. IA.L2-3.5.3, multi-factor authentication, and SC.L2-3.13.11, FIPS-validated cryptography, can deduct 3 points rather than 5 in defined partial-implementation states. Every other requirement is scored as met or not met with no middle position.

This is worth knowing precisely because it is worth points. An organization that has deployed MFA for privileged users but not across the full scope, or that encrypts CUI without FIPS-validated modules, is in a partial state that the methodology recognizes. Treating those as total failures understates the score by four points and can be the difference between clearing a threshold and missing it.

Partial credit and POA&M eligibility are separate concepts and are frequently conflated. A requirement can carry partial credit in scoring and still be ineligible for a POA&M, or the reverse. Resolve each question against the rule rather than assuming they move together.

Negative Scores

A SPRS score can fall below zero. Deductions are cumulative and there is no floor in the methodology that stops the subtraction, so an organization that has not implemented many of the higher-weighted requirements will produce a negative number.

Figures circulate claiming a specific minimum, most often -203, derived by summing every possible deduction. That total is an arithmetic inference rather than a value stated in the Assessment Methodology or in 32 CFR 170.24, and it should not be presented as a regulatory floor. What matters operationally is not where the theoretical bottom sits but what a negative score signals: gaps across multiple families, almost certainly including high-weight requirements that cannot be deferred.

A negative score on a first honest self-assessment is common and is not a disqualification. A negative score visible to a contracting officer is a different matter, because it indicates an organization some distance from the standard its contract already requires.

The System Security Plan as a Hard Gate

One requirement sits outside the point structure. CA.L2-3.12.4, the System Security Plan, carries no routine point value. Under the scoring methodology, an assessment cannot be completed without an up-to-date SSP at all.

Treat it as a gate rather than a line item. An organization with a strong control environment and no current SSP does not post a reduced score, it has no assessable position. That distinction gets lost when the SSP is tracked in the same spreadsheet as the other 109 requirements.

Do You Need a Perfect 110?

The most persistent misconception in this area is that a contractor must reach 110 before pursuing CMMC Level 2. That is not how the rule works, and believing it delays readiness work that could proceed in parallel.

What 88 Actually Means

Under 32 CFR 170.21, Conditional CMMC Level 2 status requires a minimum score of 88 out of 110, with remaining gaps documented in a POA&M. The common error is arithmetic: 80 percent of 110 is 88, not 80. A contractor targeting a score of 80 is targeting a failing number.

A perfect 110 means every one of the 110 requirements is fully implemented and is what Final Level 2 status ultimately requires. It is the destination, not the entry ticket.

ScorePosition
110All requirements fully implemented, eligible for Final Level 2 status
88 to 109Eligible for Conditional Level 2 status with a compliant POA&M, 180 days to close
Below 88No CMMC Status, POA&M path unavailable until the score rises to 88
NegativeGaps across multiple families, high-weight requirements almost certainly among them

The bands describe eligibility, not risk. Two contractors at 92 can be in materially different positions depending on which requirements are open, because the ineligible-for-POA&M set does not move with the score.

Which Gaps Can Be Deferred

Not every requirement can be carried on a POA&M. Certain requirements must be fully implemented regardless of the overall score, and the specific list is defined in the CMMC rule rather than inferred from point values.

Confirm which of your open items are eligible before scheduling anything. An organization at 94 with two ineligible gaps is further from Conditional status than an organization at 89 whose open items are all deferrable. The score alone does not answer the question.

To map a current score and the shortest defensible path to a passing result, book a readiness call with an Elevate advisor.c security gaps quickly, and the DoW/DoD enforces the deadline.

POA&M Rules and the 180-Day Window

A POA&M is a corrective action plan documenting security deficiencies and the steps, owners, resources and dates to close them. Under CMMC it is narrower in use than most contractors assume.

Eligibility

32 CFR 170.21 permits POA&Ms only to reach Conditional status, and only when several conditions hold simultaneously. The assessment score must be at least 88. Every item on the plan must be a 1-point requirement, with one narrow exception for FIPS-validated encryption, SC.L2-3.13.11, in its partial state. None of the specifically prohibited requirements may appear on the plan.

POA&M items do not pause the score. The deduction stands while the item is open, which means the 88 threshold must be cleared with those deductions already counted. That catches organizations that model their score as if deferral were the same as implementation.

POA&Ms are not permitted at CMMC Level 1 at all. Level 3 carries its own restrictions on which enhanced requirements may be deferred.

The Closeout

Every POA&M item must be closed and verified through a closeout assessment within 180 days of the Conditional status date. Who performs the closeout depends on how the original assessment was conducted. For a Level 2 self-assessment, the organization performs the closeout the way it performed the original. For a certification assessment, the same C3PAO that conducted the original assessment handles it. For Level 3, DCMA DIBCAC performs it.

Final CMMC Status follows verification of all POA&M items. If items remain open at day 180, Conditional status expires and the organization loses eligibility for awards requiring that status.

Why 180 Days Is Fixed

Earlier practice treated POA&Ms as open-ended, which is where the habit of listing an item and moving on comes from. The current rule does not work that way, and the deadline is not extended for resource constraints.

POA&Ms that close on time share a few characteristics. Remediation is broken into 30 to 45 day checkpoints rather than a single distant date. Each item has one named owner rather than a shared department. Budget figures are real rather than placeholders. Evidence accumulates continuously rather than being assembled in the final weeks, which matters because evidence of operation takes calendar time that cannot be recovered. Elevate’s guide to building a POA&M for CMMC readiness covers the mechanics.

Requirements by CMMC Level

LevelRequirementsScoringPOA&M
Level 1Basic safeguarding requirements from FAR 52.204-21MET or NOT MET, no numerical score, no partial creditNot permitted
Level 2110 requirements, NIST SP 800-171 Revision 2Weighted, starts at 110, minimum 88 for ConditionalPermitted under 32 CFR 170.21 conditions
Level 3Level 2 plus 24 enhanced requirements from NIST SP 800-172Each enhanced requirement counts as one pointRestricted, with specific requirements ineligible

Level 1 is unforgiving in a way the numerical levels are not. A single NOT MET fails the assessment outright, because there is no score to fall back on and no plan to defer against. Level 3 requires a Final Level 2 certification first and is assessed only by DCMA DIBCAC, never by a third party.

Level 2 self-assessment results submitted to SPRS include the overall score, POA&M status where the score falls between 88 and 109, the CMMC level and status date, the assessment scope, and every CAGE code associated with the assessed information system. An organization whose score falls below the threshold receives no CMMC Status.t Center (DIBCAC) can conduct Level 3 assessments. Third-party assessors are not permitted at this level.

How to Calculate and Submit Your SPRS Score

DoW/DoD Assessment Methodology

NIST SP 800-171 and NIST SP 800-171A

Control weightings for the 110 NIST SP 800-171 security controls across 14 families under the DoW/DoD Assessment Methodology. Cells shaded teal indicate a Must Do (SSP) requirement, dark navy indicates a 5-point deduction, purple indicates 5 or 3 points, muted navy indicates 3 points, and light gray indicates 1 point. An asterisk indicates the control is also required under FAR 52.204-21 / CMMC Level 1.
AC AT AU CM IA IR MA MP PS PE RA CA SC SI
3.1.1*3.2.13.3.13.4.13.5.1*3.6.13.7.13.8.1*3.9.1*3.10.1*3.11.13.12.13.13.1*3.14.1*
3.1.2*3.2.23.3.23.4.23.5.2*3.6.23.7.23.8.23.9.2*3.10.23.11.23.12.23.13.23.14.2*
3.1.33.2.33.3.33.4.33.5.33.6.33.7.33.8.3*3.10.3*3.11.33.12.33.13.33.14.3
3.1.43.3.43.4.43.5.43.7.43.8.43.10.4*3.12.43.13.43.14.4*
3.1.53.3.53.4.53.5.53.7.53.8.53.10.5*3.13.5*3.14.5*
3.1.63.3.63.4.63.5.63.7.63.8.63.10.63.13.63.14.6
3.1.73.3.73.4.73.5.73.8.73.13.73.14.7
3.1.83.3.83.4.83.5.83.8.83.13.8
3.1.93.3.93.4.93.5.93.8.93.13.9
3.1.103.5.103.13.10
3.1.113.5.113.13.11
3.1.123.13.12
3.1.133.13.13
3.1.143.13.14
3.1.153.13.15
3.1.163.13.16
3.1.17
3.1.18
3.1.19
3.1.20*
3.1.21
3.1.22*
Must Do (SSP) 5 points 5 or 3 points 3 points 1 point

* Also required under FAR 52.204-21 / CMMC Level 1

Gap Assessment

The starting point is a documented comparison of the current environment against all 110 requirements in NIST SP 800-171 Revision 2, using the assessment objectives in NIST SP 800-171A. Each requirement gets a documented implementation status, then the Assessment Methodology weighting is applied.

The distinction between a requirement and its assessment objectives is where most self-assessments go soft. A requirement is met when all applicable objectives are satisfied based on evidence, and that evidence must be in final form rather than draft. An organization that assesses at the requirement level without walking the objectives underneath it will overstate its score, usually without intending to.

Elevate’s SPRS score calculator walks the arithmetic itself, and its NIST 800-171 assessment guidance covers the objective-level review.

The System Security Plan

The SSP documents how each requirement is satisfied: by policy, by technology, or by both. It needs a version number and a date, a clear description of system boundaries and data flows, and an evaluated status for every requirement in scope. No assessment proceeds without it.

The failure mode is not an absent SSP. It is an SSP that describes an intended environment rather than the running one. The Defense Contract Management Agency conducts spot-checks against actual implementation, and a document that does not match the operation produces findings faster than a missing control does.

Submission via PIEE

Submission runs through the Procurement Integrated Enterprise Environment. Register in PIEE, request the SPRS Cyber Vendor User role, log into SPRS through the PIEE portal, select the company hierarchy and CAGE code, then enter the assessment details including score, SSP information and POA&M completion date. Scores can be updated as the position improves.

Where Contractors Get This Wrong

Overstating Compliance

Inflated scores carry direct legal exposure. The Department of Justice actively pursues contractors that misrepresent cybersecurity posture under the False Claims Act, and settlements have run into the millions. The exposure includes contract termination, suspension and debarment alongside financial penalties.

The mechanism is usually not deliberate fraud. It is an assessment conducted at the requirement level rather than the objective level, by someone who understands the intent of a control but has not verified its operation, and then signed by a senior official who had no way to test the number. Elevate covers the legal dimension in its analysis of False Claims Act liability in CMMC compliance.

With third-party assessment suspended, this is the concentrated risk in the program. There is no assessor whose findings would have surfaced the gap before it became an affirmation.

An SSP That Does Not Match Reality

Documentation describing an environment that assessors do not find is the most common source of findings. The test is simple enough to run internally: pick three requirements at random from the SSP, hand them to someone who administers the relevant system, and ask them to demonstrate the control as described. Disagreement between the document and the administrator is the finding, and it is better discovered internally.

POA&M Drift

Items that sit at the same status for sixty days are not being worked, they are being tracked. The 180-day clock does not pause for reprioritization, and an item that has not moved by day 90 will not close by day 180 without an intervention that has not happened yet.

Conclusion

The SPRS score connects technical implementation to contract eligibility, and the suspension of third-party assessment made that connection more direct rather than less. A score posted today is relied upon by contracting officers without independent verification and tested only if something goes wrong, which concentrates the risk on the accuracy of the self-assessment and the honesty of the affirmation attached to it.

The methodology itself rewards precision. Understanding that the score starts at 110 and subtracts, that two requirements carry partial credit, that the SSP is a gate rather than a line item, and that 80 percent means 88 rather than 80, changes both the target and the sequence of work to reach it. Organizations that prioritize high-weight gaps first improve their position faster per dollar spent than those working a checklist in order.

Nothing about the current pause reduces the underlying obligation. DFARS 252.204-7012 and the 110 requirements are unchanged, the affirmation is still required, and the enforcement mechanism is still active. Contractors that want an independent read on where their score actually stands before signing an affirmation can book a readiness call with an Elevate advisor.

Key Takeaways

Several widely repeated descriptions of SPRS scoring are inaccurate, and the differences are worth points.

  • The score starts at 110 and subtracts. Each unmet requirement removes 5, 3 or 1 point based on the risk its absence creates. Contractors lose points from a ceiling rather than accumulating them toward a target.
  • Partial credit exists for exactly two requirements. IA.L2-3.5.3 multi-factor authentication and SC.L2-3.13.11 FIPS-validated cryptography can deduct 3 rather than 5 in defined partial states. The regulation names partial implementation explicitly. Treating every requirement as all-or-nothing understates the score.
  • Eighty percent of 110 is 88, not 80. Conditional Level 2 status under 32 CFR 170.21 requires a minimum of 88, with POA&M deductions already counted against that threshold.
  • The System Security Plan is a gate. CA.L2-3.12.4 carries no routine point value, and an assessment cannot be completed without a current SSP at all.
  • POA&M items are limited to 1-point requirements, with one narrow exception for FIPS-validated encryption in its partial state, and every item must close within 180 days of the Conditional status date or the status expires.
  • The self-assessment is now the assessment of record. With Level 2 (C3PAO) designations suspended, no independent party tests the number before a contracting officer relies on it, which places the full False Claims Act exposure on the affirming official.

FAQs

How is a SPRS score calculated? The score starts at 110 and subtracts a weighted value for each of the 110 NIST SP 800-171 Revision 2 requirements that is not fully implemented. Each unmet requirement removes 5 points where its absence creates significant risk of exploitation or exfiltration, 3 points where the effect is specific and confined, or 1 point where the effect is limited or indirect. The methodology comes from the NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1, and is codified for CMMC at 32 CFR 170.24.

Is there partial credit in SPRS scoring? Yes, in limited cases. The regulation states that the CMMC Scoring Methodology credits partial implementation only in limited cases and names multi-factor authentication as its example. Two requirements carry it: IA.L2-3.5.3 for multi-factor authentication and SC.L2-3.13.11 for FIPS-validated cryptography, each of which can deduct 3 points instead of 5 in defined partial-implementation states. All other requirements are scored as met or not met.

Can a SPRS score be negative? Yes. Deductions are cumulative and the methodology contains no floor that stops the subtraction, so an organization missing many high-weight requirements will produce a negative number. A negative score on a first honest self-assessment is common and is not a disqualification, but it does signal gaps across multiple requirement families, and high-weight requirements that cannot be carried on a POA&M are almost certainly among them.

Do you need a perfect 110 for CMMC Level 2? Not to begin. A perfect 110 is what Final Level 2 status ultimately requires, but Conditional Level 2 status under 32 CFR 170.21 requires a minimum score of 88 with remaining gaps documented in a compliant POA&M and closed within 180 days. Note that 80 percent of 110 is 88, not 80, which is a common and expensive arithmetic error. Not every requirement is eligible for a POA&M, so the score alone does not determine whether Conditional status is reachable.

Does the CMMC Phase 2 suspension change SPRS requirements? No. The suspension paused Level 2 (C3PAO) and Level 3 (DIBCAC) designations as conditions of award. A current NIST SP 800-171 self-assessment posted in SPRS, with annual senior official affirmation, remains a condition of eligibility, and DFARS 252.204-7012 is unchanged. What changed is that no independent assessor now tests the score before a contracting officer relies on it, which concentrates False Claims Act exposure on the affirming official.