Your SPRS score is the number that decides whether your organization can win Department of War/Defense (DoW/DoD) contracts. Most contractors submit scores well below the 110 that a Final CMMC Level 2 certification ultimately requires, and the gap between where a contractor sits today and where the DoW/DoD expects it to be is often larger than leadership realizes. Understanding how the score is calculated, how it can be improved, and how a Plan of Action and Milestones (POA&M) fits into the certification path is what separates contractors who move quickly through assessment from those who stall.
Your SPRS score measures how well your organization complies with NIST SP 800-171, and the DoW/DoD uses it to check whether you can protect sensitive information. A poor score can block your organization from contract awards or make prime contractors treat you as a high-risk subcontractor.
This piece gives you a complete breakdown of SPRS scoring, POA&Ms, whether you really need a perfect 110, and CMMC compliance requirements. Whether you are starting your CMMC readiness or working to enhance your current setup, you will find here what you need to move through CMMC Level 2 requirements.
Understanding SPRS Scoring in the Context of CMMC 2.0

The Supplier Performance Risk System (SPRS) sits at the heart of the DoW/DoD cybersecurity compliance framework. The section below explains how the system works within the CMMC 2.0 program and why it drives certification outcomes across the Defense Industrial Base.
SPRS as a DoW/DoD Risk Evaluation Tool
SPRS operates as a web-enabled enterprise application that helps the DoW/DoD collect, process, and display supplier performance data. The system started as a procurement risk analysis tool covering price, item, and supplier risks, and has now become a central cybersecurity assessment platform.
The system serves as the authoritative source to retrieve supplier and product performance information for the DoW/DoD acquisition community. Contracting officers use SPRS to assess item risk for products, analyze price risk for both products and services, review overall supplier risk based on documented performance, and check cybersecurity compliance status.
SPRS also alerts users about possible risks related to diminishing manufacturing sources, material shortages, and counterfeiting history. It helps contracting officers determine fair and reasonable prices, which is why the platform sits at the center of the DoW/DoD risk management strategy.
Connection Between SPRS and NIST SP 800-171
The SPRS scoring methodology links directly to NIST SP 800-171 compliance requirements. Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 required contractors to implement NIST SP 800-171 fully by December 31, 2017. Those requirements are the foundation of the SPRS scoring system.
Your SPRS score ranges from 110 (perfect compliance) to -203 (worst possible score). This range shows how well your organization has implemented the 110 security controls in the NIST SP 800-171 framework, which cover 14 cybersecurity domains including access control, configuration management, and incident response.
The scoring system weights each requirement based on its importance:
- 5 points for requirements that could lead to major network exploitation or CUI theft if missing
- 3 points for requirements with specific but limited security effects
- 1 point for requirements with minimal security impact
Your assessment starts at -203. Your score increases by the corresponding value (1, 3, or 5 points) as you meet each requirement, potentially reaching the perfect score of 110.
Why SPRS Scores Matter for CMMC Level 2
SPRS scores are decisive for organizations seeking CMMC Level 2 certification. Level 1 uses a simple pass/fail approach without numerical scoring, but Level 2 requires a thorough assessment against all 110 NIST SP 800-171 controls.
Organizations should target an SPRS score of at least 88 after internal preparation and self-assessment before pursuing CMMC Level 2 certification. That value represents the minimum needed for Conditional certification status, assuming other criteria are also met.
The DoW/DoD added this verification requirement because Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) research found that many self-reported perfect scores of 110 were inaccurate on independent review. That finding drove the shift toward third-party assessments in CMMC 2.0.
Organizations must keep their CMMC status current in SPRS to qualify for contracts with CMMC requirements. Your SPRS score directly affects your eligibility for DoW/DoD contracts, which makes it a business-critical metric, not just a compliance artifact.
Note that organizations must fully implement all 1-point controls without using a POA&M. That constraint alone forces contractors to prioritize certain controls even before assessment begins.
How the SPRS Scoring Methodology Works

The SPRS scoring system works differently from what many organizations expect. Contractors do not earn points, they lose them. Understanding this calculation method is essential for any organization aiming at CMMC Level 2 certification.
Starting Score of 110 and Deduction Tiers
The SPRS calculation takes a different approach from regular scoring systems. You start with a perfect score of 110 points, representing full implementation of the 110 security controls in NIST SP 800-171. Your score drops for each control you have not fully implemented.
There is no partial credit. A control is either fully implemented or it triggers the full deduction. Many organizations going through their first CMMC assessment process
see lower scores at first, but these improve as more controls come online.
The system weighs each control based on its security importance. The point deductions fall into three categories:
| Deduction | Risk Level | Description |
|---|---|---|
| 5 points | High | Critical controls that address major security risks |
| 3 points | Medium | Controls with specific but limited security effects |
| 1 point | Low | Controls with minimal or indirect security impact |
Your baseline score of 110 drops by these values for each missing security requirement. The score can drop quickly if several controls remain unimplemented.
Weighted Controls: 1, 3, and 5-Point Deductions
The DoW/DoD prioritizes some security controls over others in CMMC scoring. Controls worth 5 points protect against critical vulnerabilities that could lead to major security breaches. These include foundational security measures such as multi-factor authentication implementation, proper access control measures, and audit logging capabilities.
Controls worth 3 points address specific security needs with moderate effects. The 1-point controls still matter, but they carry less immediate security impact.
This weighting is what turns a compliance checklist into a prioritized roadmap. Organizations that fix the 5-point controls first see the biggest score improvements per dollar invested.
Negative Scores and What They Signal
Many organizations are surprised to learn that SPRS scores can drop below zero. The full range runs from 110 down to -203, and a negative score usually means basic controls are missing across several domains.
A negative score does not mean the organization has failed the assessment outright, but it does signal large gaps that need immediate attention. Many contractors score below zero on their first internal assessment.
Interpreting the score bands:
- 110: All NIST SP 800-171 controls fully implemented.
- 88 to 109: Passing range for Conditional Level 2, POA&M required for remaining gaps.
- Below 88: Significant gaps. The organization cannot receive Conditional Level 2 status until the score rises to at least 88, and cannot continue to work with CUI without remediation. Any organization scoring below zero falls in this category, and the gaps are more severe: critical (5-point) controls are almost certainly among the missing set and must be fully implemented before certification, since they cannot be carried on a POA&M.
DoW/DoD procurement officials and prime contractors use these bands to evaluate cybersecurity risk. A low score can label your organization as high-risk regardless of how strong the rest of your business case is.
Do You Need a Perfect SPRS Score of 110?
One of the most common misconceptions about the SPRS score is that a defense contractor must reach a perfect 110 before pursuing CMMC Level 2 certification. That is not how the process works, and believing it can delay your certification path unnecessarily.
A perfect SPRS score of 110 means every one of the 110 NIST SP 800-171 controls is fully implemented. It is the goal, and it is what a Final CMMC Level 2 certification ultimately requires. An organization does not, however, need to reach 110 before it engages in the assessment. A contractor with a passing score and a limited set of open items can receive a Conditional Level 2 status, provided those items are documented in a POA&M and closed within 180 days through a closeout assessment.
There are limits to this flexibility. Not every control is eligible to be placed on a POA&M. Certain requirements must be fully implemented before certification regardless of the overall score, and the exact list is defined in the CMMC rule. This is why the SPRS score alone does not tell the whole story: two contractors with the same number can be in very different positions depending on which controls are unmet.
The practical takeaway is to stop treating a perfect 110 as the entry ticket and start treating it as the destination. Prioritize the highest-weighted controls first, because a single unmet 5-point requirement costs more than five unmet 1-point requirements. Confirm which of your gaps can be carried on a POA&M and which cannot before you schedule an assessment. To map your current score and the fastest path to a passing result, Book a Readiness Call.
Role of POA&M in CMMC Readiness
The POA&M plays a vital role in the CMMC certification process. Organizations can achieve Conditional certification while they work toward full compliance, and the POA&M is the artifact that turns “we know we have gaps” into “we have a plan and a deadline to close them.” POA&Ms provide structure to address security gaps within specific timeframes during the CMMC assessment process.
What a POA&M Is and When It Applies
A POA&M is a corrective action plan that documents security deficiencies and outlines the steps to fix them. The document lists tasks, resources, milestones, and completion dates.
Organizations use POA&Ms in these cases:
- Security gaps show up during a CMMC assessment
- The organization needs to show a clear path to full compliance
- The organization seeks Conditional certification during remediation
A POA&M signals steadfast commitment to fixing cybersecurity weaknesses step by step. It goes beyond a simple checklist for CMMC readiness. It functions as a formal accountability artifact that shows assessors the organization understands its security gaps and knows how to close them.
POA&M Eligibility Criteria for Conditional Certification
The DoW/DoD has set clear rules for POA&M usage. Not every security requirement qualifies, and POA&Ms are not permitted at all CMMC levels:
- CMMC Level 1: POA&Ms are not allowed.
- CMMC Level 2: POA&Ms are allowed only under specific conditions.
- CMMC Level 3: Additional restrictions apply for advanced requirements.
Organizations can use POA&Ms for CMMC Level 2 requirements if all these conditions are met:
- The assessment score divided by total security requirements equals or exceeds 0.8 (a minimum score of 88).
- Each security requirement on the POA&M has a point value of 1 (one exception exists: SC.L2-3.13.11 for CUI encryption can be included if encryption is used but not FIPS-validated).
- Critical controls (higher-value requirements) must be fully implemented and cannot go on a POA&M.
These restrictions ensure that only organizations with solid security foundations can receive Conditional certification. The POA&M cannot become a shortcut around basic protections.
Remediation Timeline: 180-Day Window
CMMC compliance requirements set a firm timeline for POA&M items. All NOT MET requirements must be closed within 180 days of receiving Conditional CMMC Status. The six-month deadline is fixed.
A POA&M closeout assessment must verify the proper implementation of all POA&M items. The verifier differs by level:
- Level 2 self-assessment: The Organization Seeking Assessment (OSA) performs the closeout the same way it performed the original assessment.
- Level 2 certification assessment: The same C3PAO that performed the original assessment must handle the closeout.
- Level 3 certification assessment: DCMA DIBCAC performs the closeout.
Organizations achieve Final CMMC Status after all POA&M items are verified. If requirements remain unremediated after 180 days, Conditional Status expires and standard contract penalties kick in.
The tight timeline is deliberate. POA&Ms are not get-out-of-jail-free cards or “pass now, fix later” schemes. They are a time-bound commitment to close specific security gaps quickly, and the DoW/DoD enforces the deadline.
SPRS Score Requirements for Each CMMC Level

Preparation for assessment depends on the specific SPRS scoring requirements set at each CMMC level. Understanding those requirements upfront lets your organization scope its cybersecurity investment and timeline accurately.
CMMC Level 1: Pass/Fail Without Numerical Score
CMMC Level 1 works on a simple pass/fail basis and doesn’t use the numerical scoring system that higher levels require. This simple level only looks at the 17 basic safeguarding requirements found in FAR 52.204-21.
CMMC Level 1 assessments have these rules:
- You either get “MET” or “NOT MET” with no partial credit
- Plans of Action and Milestones (POA&Ms) aren’t allowed
- You need to do self-assessment yearly with executive confirmation
- Results must go into SPRS after completion
To receive a MET finding on a Level 1 assessment, all security requirements must be fully implemented. A single NOT MET fails the entire assessment. That makes Level 1 straightforward but unforgiving.
CMMC Level 2: Minimum Score of 88 for Conditional Status
CMMC Level 2 uses numerical scoring against the 110 security controls in NIST SP 800-171. The score can range from -203 (worst case) to 110 (perfect compliance).
Level 2 certification thresholds:
- 110 points for Final certification status.
- At least 88 points for Conditional certification status.
Scores between 88 and 109 qualify for Conditional status but require a POA&M to close remaining gaps. The organization has 180 days to close those gaps and preserve the certification.
When you submit Level 2 self-assessment results to SPRS, include:
- Your overall Level 2 self-assessment score (out of 110)
- POA&M status and compliance (if the score falls between 88 and 109)
- CMMC Level and Status Date
- CMMC Assessment Scope
- Every industry CAGE code linked to your assessed information system
An organization whose self-assessment score falls below the minimum threshold receives “No CMMC Status.”
CMMC Level 3: 24-Point Scale Based on NIST SP 800-172
CMMC Level 3 sits at the top of the CMMC framework with additional requirements beyond Levels 1 and 2. Scoring is simpler at this level: each requirement counts as one point.
A Level 3 assessment covers:
- Everything from CMMC Levels 1 and 2
- 24 enhanced security controls drawn from NIST SP 800-172
Level 3 certification thresholds:
- All 24 enhanced requirements implemented for Final Level 3 status
- At least 20 of 24 requirements (80% minimum) for Conditional Level 3 status
Under Conditional Level 3 certification, any unmet requirements must be documented in a POA&M. Some requirements listed in 32 CFR 170.21(a)(a)(3)(ii) cannot be placed on a POA&M.
Only government personnel through the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) can conduct Level 3 assessments. Third-party assessors are not permitted at this level.
How to Calculate and Submit Your SPRS Score
DoW/DoD Assessment Methodology
NIST SP 800-171 and NIST SP 800-171A
| AC | AT | AU | CM | IA | IR | MA | MP | PS | PE | RA | CA | SC | SI |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3.1.1* | 3.2.1 | 3.3.1 | 3.4.1 | 3.5.1* | 3.6.1 | 3.7.1 | 3.8.1* | 3.9.1* | 3.10.1* | 3.11.1 | 3.12.1 | 3.13.1* | 3.14.1* |
| 3.1.2* | 3.2.2 | 3.3.2 | 3.4.2 | 3.5.2* | 3.6.2 | 3.7.2 | 3.8.2 | 3.9.2* | 3.10.2 | 3.11.2 | 3.12.2 | 3.13.2 | 3.14.2* |
| 3.1.3 | 3.2.3 | 3.3.3 | 3.4.3 | 3.5.3 | 3.6.3 | 3.7.3 | 3.8.3* | 3.10.3* | 3.11.3 | 3.12.3 | 3.13.3 | 3.14.3 | |
| 3.1.4 | 3.3.4 | 3.4.4 | 3.5.4 | 3.7.4 | 3.8.4 | 3.10.4* | 3.12.4 | 3.13.4 | 3.14.4* | ||||
| 3.1.5 | 3.3.5 | 3.4.5 | 3.5.5 | 3.7.5 | 3.8.5 | 3.10.5* | 3.13.5* | 3.14.5* | |||||
| 3.1.6 | 3.3.6 | 3.4.6 | 3.5.6 | 3.7.6 | 3.8.6 | 3.10.6 | 3.13.6 | 3.14.6 | |||||
| 3.1.7 | 3.3.7 | 3.4.7 | 3.5.7 | 3.8.7 | 3.13.7 | 3.14.7 | |||||||
| 3.1.8 | 3.3.8 | 3.4.8 | 3.5.8 | 3.8.8 | 3.13.8 | ||||||||
| 3.1.9 | 3.3.9 | 3.4.9 | 3.5.9 | 3.8.9 | 3.13.9 | ||||||||
| 3.1.10 | 3.5.10 | 3.13.10 | |||||||||||
| 3.1.11 | 3.5.11 | 3.13.11 | |||||||||||
| 3.1.12 | 3.13.12 | ||||||||||||
| 3.1.13 | 3.13.13 | ||||||||||||
| 3.1.14 | 3.13.14 | ||||||||||||
| 3.1.15 | 3.13.15 | ||||||||||||
| 3.1.16 | 3.13.16 | ||||||||||||
| 3.1.17 | |||||||||||||
| 3.1.18 | |||||||||||||
| 3.1.19 | |||||||||||||
| 3.1.20* | |||||||||||||
| 3.1.21 | |||||||||||||
| 3.1.22* |
* Also required under FAR 52.204-21 / CMMC Level 1
Calculating and submitting your SPRS score is a vital step to achieve CMMC Level 2 certification. Your organization’s future contract eligibility depends on the number you submit, and the process behind that number needs to be defensible.
Gap Assessment Against NIST SP 800-171
The starting point is a detailed gap analysis that compares current security controls against NIST SP 800-171 requirements. The process has three parts:
- Review all 110 NIST SP 800-171 security controls.
- Document implementation status for each control.
- Apply the DoW/DoD Assessment Methodology scoring system.
The methodology does not allow partial credit. Each control must be fully implemented to avoid deductions. Score drops by 1, 3, or 5 points per unimplemented control, based on its security impact. Baseline starts at 110 (perfect compliance) and decreases with each gap.
Need expert guidance with your gap assessment? Book a Readiness Call to help your organization reach the best defensible SPRS score.
Completing the System Security Plan (SSP)
The System Security Plan is the document that outlines your cybersecurity approach for protecting Controlled Unclassified Information. DoW/DoD guidance requires that your SSP:
- Address each NIST SP 800-171 security requirement
- Explain implementation methods (policy, technology, or both)
- Include version number and date
The SSP must document your security controls thoroughly before you begin the SPRS submission. No assessment can proceed without a complete SSP. The NIST SSP template published on the CSRC website is a solid starting point for contractors.
Submission via PIEE and the SPRS Portal
The submission process requires specific access credentials and follows five steps:
- Register in the Procurement Integrated Enterprise Environment (PIEE).
- Request the SPRS Cyber Vendor User role for your account.
- Log into SPRS through the PIEE portal.
- Select your company hierarchy and CAGE code.
- Enter assessment details including score, SSP information, and POA&M completion date.
The DoW/DoD allows encrypted email submission to [email protected] if the portal is not accessible. That path works best for first-time submissions.
DoW/DoD procurement officials can view your assessment information after submission. Self-assessment information can be updated as the score improves.
Common SPRS and POA&M Mistakes to Avoid
Errors in SPRS submissions and POA&M management can be expensive. They can lead to False Claims Act penalties and debarment from DoW/DoD contracts. Understanding the common failure modes helps protect your organization’s CMMC assessment process.
Overstating Compliance in Self-Assessments
Legal and financial consequences follow when contractors inflate their SPRS score. The Department of Justice actively pursues contractors that misrepresent their cybersecurity posture, and companies have paid millions in settlements. Self-assessment demands an all-or-nothing approach: controls must have all assessment objectives fully implemented to receive credit.
MORSE Corporation is the case the industry now cites. The company represented that it had implemented required cybersecurity controls when subsequent review found the actual implementation was materially weaker. The 2024 settlement under the False Claims Act reinforced that inaccurate SPRS submissions carry direct legal exposure, not just compliance risk. Confirm exact numbers and settlement terms against the DOJ press release before quoting specific figures.
Misaligned SSP and Actual Implementation
Your SSP must reflect operational reality, not aspirational goals. The Defense Contract Management Agency (DCMA) runs random spot-checks to verify SSP accuracy against actual implementation. A defensible SSP hits these points:
- Clear description of system boundaries and data flows
- Evaluated status for all 110 controls
- Implementation details for all 320 assessment objectives
Red flags appear during assessment when documentation describes an environment that does not match what assessors see when they walk the operation.
Failure to Track POA&M Remediation Progress
Current regulations require POA&M closure within 180 days, unlike the earlier treatment of POA&Ms as open-ended exemptions. POA&Ms work when the organization:
- Breaks remediation into 30 to 45-day checkpoints instead of a single deadline
- Defines clear budget estimates rather than “TBD” placeholders
- Assigns single ownership for each task to avoid shared responsibility
- Collects ongoing evidence to show steady progress
POA&M management gets complex quickly without specialized expertise. Book a Readiness Call with cybersecurity specialists who can guide your organization past these common pitfalls and accelerate CMMC readiness.
Conclusion
The CMMC certification path presents major challenges for Defense Industrial Base organizations, and SPRS scoring is the number that ties technical implementation back to contract eligibility. A score of 110 represents full compliance, but many contractors start with negative scores and improve steadily through disciplined implementation work.
The SPRS score affects contract eligibility directly. Prime contractors use these numbers to evaluate subcontractor risk. The tiered 1, 3, and 5-point structure is a clear prioritization signal: contractors should start with the 5-point controls that produce the largest score improvements per dollar invested.
POA&Ms enable Conditional certification but come with strict rules and deadlines. All POA&M items must be closed within 180 days, and not every control is eligible for inclusion. The three CMMC levels demand different approaches: Level 1 is pass/fail, Level 2 uses the 110-point NIST SP 800-171 scale, and Level 3 adds the 24-point NIST SP 800-172 enhancement.
Misrepresenting cybersecurity compliance status can lead to severe penalties, including False Claims Act violations and potential debarment from future DoW/DoD contracts. Honest self-assessment and documentation that matches operational reality are non-negotiable throughout the certification process.
Expert guidance shortens the path. Book a Readiness Call with Elevate to work with cybersecurity specialists who know the nuances of CMMC requirements and can build a compliance roadmap for your specific environment.
CMMC requirements continue to evolve. Staying current with compliance updates is what preserves competitive edge in defense contracting. Cybersecurity compliance goes beyond regulatory obligation. It is a business necessity that protects your organization and the national security information in your care.
Key Takeaways
SPRS scoring and POA&M requirements are the operational backbone of CMMC certification. The five points below capture what a DIB contractor needs to internalize before scheduling an assessment.
- SPRS scoring starts at 110 and deducts 1, 3, or 5 points per unimplemented NIST SP 800-171 control based on security impact.
- CMMC Level 2 requires a minimum score of 88 for Conditional certification. POA&Ms are generally limited to 1-point requirements, with higher-value controls needing full implementation before certification.
- POA&M remediation must be completed within 180 days or Conditional certification expires and contractual consequences follow.
- Misrepresenting compliance status carries direct legal exposure under the False Claims Act, including potential debarment from DoW/DoD contracts.
- Level 1 uses pass/fail without numerical scoring; Level 3 adds 24 enhanced requirements drawn from NIST SP 800-172, assessed on a separate scale.
Success requires honest self-assessment, systematic remediation planning, and treating SPRS scoring as a direct input to contract competitiveness, not as a compliance formality.
Frequently Asked Questions
Q1. What is the SPRS scoring system and why is it important for CMMC certification? The Supplier Performance Risk System (SPRS) scoring system measures a contractor’s compliance with NIST SP 800-171 cybersecurity controls. It is crucial for CMMC certification because it directly affects eligibility for DoW/DoD contracts and determines readiness for CMMC Level 2 assessment. A minimum score of 88 out of 110 is required for Conditional certification.
Q2. How does the SPRS scoring methodology work? SPRS scoring starts at 110 points (perfect compliance) and deducts points for each unimplemented NIST SP 800-171 control. Deductions are 1, 3, or 5 points per control based on security impact. There is no partial credit: a control is either fully implemented or triggers the full deduction. Scores can range from 110 down to -203.
Q3. What role do Plans of Action and Milestones (POA&Ms) play in CMMC readiness? POA&Ms allow organizations to achieve Conditional certification while working toward full compliance. For CMMC Level 2, POA&Ms are generally limited to 1-point requirements if the overall score is at least 88, with one narrow exception for CUI encryption (SC.L2-3.13.11) when encryption is used but not FIPS-validated. All POA&M items must be closed within 180 days to maintain certification status.
Q4. How do I calculate and submit my SPRS score? Calculate the score by performing a gap assessment against NIST SP 800-171 requirements, documenting implementation status for each control, and applying the DoW/DoD Assessment Methodology. Submit the score through the SPRS portal via the Procurement Integrated Enterprise Environment (PIEE) after completing a comprehensive System Security Plan (SSP).
Q5. What are common mistakes to avoid when dealing with SPRS scores and POA&Ms? The three most common failure modes are overstating compliance in self-assessments, submitting an SSP that describes an environment that does not match operational reality, and failing to track POA&M remediation progress against the 180-day deadline. Honest scoring, documentation that matches implementation, and active POA&M management with clear ownership and timelines are non-negotiable.