SPRS · 2026-08-03
Your SPRS Score, Explained: How the −203 to +110 Math Actually Works
How the SPRS score really works: the −203 to +110 range, DoD's 1/3/5-point weights, worked examples, who sees your score, and how to raise it.
Your SPRS score is a single number, between −203 and +110, that summarizes how much of NIST SP 800-171 your company has actually implemented. You calculate it yourself under the DoD Assessment Methodology, post it to the Supplier Performance Risk System (SPRS), and it becomes the number the Department of Defense and your primes use to judge whether you can be trusted with controlled unclassified information. A perfect score is 110. Most companies doing the math honestly for the first time land far below that, and many land below zero. This article explains exactly how the number is computed, why the scale is built the way it is, and what to do about a low score.
Where the score comes from
Three DFARS clauses create the obligation.
DFARS 252.204-7012 (in contracts since 2017) says that if you handle DoD controlled unclassified information (CUI), you must implement the 110 security requirements of NIST SP 800-171, describe how in a System Security Plan (SSP), and cover any gaps with plans of action.
DFARS 252.204-7019 says that to be considered for award, you must have a current NIST SP 800-171 assessment score, no more than three years old, posted in SPRS.
DFARS 252.204-7020 flows the same obligation down the supply chain: a contractor may not award a subcontract involving CUI unless the subcontractor also has a current assessment on file.
The scoring rules themselves live in one document: the NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 (June 24, 2020). Everything below comes from that document, and the link is in the sources at the end. When you self-assess, you are performing what the methodology calls a Basic Assessment. The government can also perform Medium and High assessments of your environment; all three use identical scoring. The only difference is the confidence level attached to the result, and a self-generated Basic score is explicitly assigned "Low" confidence.
The math: start at 110, subtract weights
The methodology does not award points for good behavior. It subtracts points for gaps.
You start at 110, one point of headroom per requirement. For every requirement that is not met, you subtract that requirement's assigned weight. The weights are 1, 3, or 5 points, assigned by the DoD based on how much damage an unimplemented requirement invites:
- 5 points for requirements whose absence could lead to significant exploitation of the network or exfiltration of CUI. Example: 3.1.1, limiting system access to authorized users. If you fail this one, every other access-control requirement is decorative. There are 42 fixed five-point requirements.
- 3 points for requirements whose absence has a specific, confined effect. Example: 3.8.2, limiting access to CUI on system media. Failing it exposes the CUI on that media, not the whole network. There are 14 fixed three-point requirements.
- 1 point for everything else, requirements with limited or indirect effect. There are 51 of these.
That accounts for 107 requirements. The remaining three are special cases, and they matter.
The two partial-credit exceptions
The methodology states plainly that it is not designed to credit partial implementation. A requirement that is 75% rolled out is scored not met, full deduction. There are exactly two exceptions, where partial credit is built into the weight itself:
3.5.3, multifactor authentication. Subtract 5 if MFA is not implemented for anyone. Subtract only 3 if it is implemented for remote and privileged users but not yet for general users. MFA is typically rolled out to the small, critical population first, and the scoring acknowledges that.
3.13.11, FIPS-validated cryptography. Subtract 5 if no encryption is employed where CUI confidentiality requires it. Subtract 3 if encryption is employed but the cryptographic module is not FIPS-validated. Note the trap here: using an approved algorithm like AES is not enough. The specific software or hardware module implementing it must hold a FIPS 140 validation.
You will find blog posts claiming that any partially implemented requirement subtracts half its weight. That is wrong. It appears nowhere in the methodology. These two requirements are the entire universe of partial credit.
The requirement worth zero points
Requirement 3.12.4 is the SSP itself. It carries no point value, and the reason is structural: the entire assessment is a review of your SSP. No SSP means there is nothing to assess. The methodology's exact consequence is a finding that "an assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012."
That is worse than a low score. A −100 in SPRS is a company that measured itself honestly. No score at all is a company that cannot be considered for award under 7019. The SSP is the price of admission to the scoring system.
Why the floor is −203
Now the arithmetic. Assume the worst case: every scoreable requirement not met, MFA absent entirely, no encryption at all.
| Category | Count | Points each | Total deduction |
|---|---|---|---|
| Fixed 5-point requirements | 42 | 5 | 210 |
| Fixed 3-point requirements | 14 | 3 | 42 |
| Fixed 1-point requirements | 51 | 1 | 51 |
| 3.5.3 (MFA) at maximum | 1 | 5 | 5 |
| 3.13.11 (FIPS) at maximum | 1 | 5 | 5 |
| 3.12.4 (SSP) | 1 | n/a | 0 |
| Total | 110 | 313 |
110 − 313 = −203. That is the floor, and it is not an arbitrary number; it falls directly out of the weight table.
The asymmetry is the point. The 44 requirements that can cost 5 points represent 220 of the 313 possible deduction points, 70% of the downside concentrated in 40% of the requirements. The DoD is telling you, in arithmetic, which gaps it considers dangerous.
It also means scores go negative fast. Miss just the 23 five-point basic requirements, the foundational ones like access control, audit logging, and incident response, and you have lost 115 points: you are at −5 with 87 requirements still scored as met. A shop that has never run a deliberate security program does not start "somewhere in the middle." It starts deeply negative, and that is by design.
What does and does not restore points
Four rules from the methodology decide most of the arguments that come up during a self-assessment.
A POA&M does not restore points. A plan of action for an unimplemented requirement is required paperwork under 3.12.2, but the requirement it covers is still scored not met. The methodology's own example: an MFA rollout that is 75% complete, with an active plan of action, scores as not implemented, minus the full deduction. One wrinkle: failing to have plans of action for your gaps means 3.12.2 itself is scored not met, costing 3 more points.
Temporary deficiencies score as implemented. If a requirement was implemented and then broke through no plan of yours (the methodology's example: a patch invalidated a module's FIPS validation), and you have a plan of action showing progress toward the fix, the requirement scores as implemented. The distinction from the POA&M rule above is timing: a temporary deficiency arises after implementation. "We haven't gotten to it yet" is not a temporary deficiency.
Enduring exceptions score as implemented. Some environments genuinely cannot satisfy a requirement, the classic case being specialized manufacturing equipment that cannot be patched or fitted with modern controls. Document the exception and its mitigations in the SSP, and it scores as implemented. This matters enormously for shops with OT on the floor.
"Not permitted" can mean no deduction. For remote access (3.1.12, 3.1.13), wireless (3.1.16, 3.1.17), and mobile devices (3.1.18), if your company simply does not allow the capability, the assessor does not subtract points, five-point requirements made moot by policy. The catch: you need an actual policy and procedure ensuring the capability stays off, or a government assessor can assess a point.
Two worked examples
Example 1: the nearly-there shop. A 40-person machine shop has done serious work. Remaining gaps: MFA covers remote and privileged users but not the shop-floor general accounts (−3 under the 3.5.3 partial rule); backups are encrypted, but with a non-FIPS-validated module (−3 under 3.13.11); no correlation of audit review across systems, 3.3.5 (−5); no periodic vulnerability scanning, 3.11.2 (−5); incident response plan exists but has never been tested, 3.6.3 (−1).
Deductions: 17. Score: 93. Five gaps, and two of them, both five-pointers, account for most of the damage.
Example 2: the honest first pass. A shop new to this scores itself candidly and finds 40 requirements not met: 15 five-pointers (−75), 10 three-pointers (−30), 15 one-pointers (−15), plus MFA nowhere (−5) and no relevant encryption (−5).
Deductions: 130. Score: −20. Thirty-six percent of the requirements unmet produced a negative number. If that just happened to you, the math, not your program, is why it feels disproportionate. It is also your remediation map: the fifteen five-point gaps are 58% of the deficit.
Who actually sees your score
Inside SPRS, your score is visible to DoD personnel, contracting officers checking the 7019 requirement before award, and to your own company's authorized representatives through PIEE. Alongside the number, SPRS records the assessment date, the SSP and CAGE codes it covers, and one more field worth taking seriously: the date you project reaching 110, pulled from your plans of action. That projection is a statement of record.
Your primes are the audience that generates the letters. Under 7020 they must confirm a subcontractor has a current assessment before sharing CUI, but they cannot browse your score in SPRS themselves. So they ask you, through questionnaires, portals like Exostar, and flow-down attestations. When Lockheed or L3Harris demands your SPRS score in writing, that is a prime doing its own compliance homework, and "we haven't posted one" reads exactly how you think it reads.
For companies heading toward CMMC Level 2, the same score has one more job: under 32 CFR 170, a conditional certification requires a minimum score of 88, with only limited one-point items left open on a POA&M, closed within 180 days. Different program, same arithmetic.
Stale scores and the three-year clock
A score older than three years no longer satisfies 7019, but treating the score as a triennial event misses what the number claims to be. Your score describes a system: people, machines, configurations. Fire the IT manager who ran access reviews, migrate a server, let training records lapse, and the posted number describes a company that no longer exists. Since a senior official must affirm continuing compliance annually (the subject of the next article in this series), a score that drifted from reality is not a paperwork problem. It is a signed federal representation that stopped being true.
The operational answer is to treat the score as a living computation: when a requirement's status changes, the number changes, and someone re-posts it. This is precisely the job Valontir was built for. It tracks all 110 requirements against the 320 assessment objectives of SP 800-171A, computes your score from the official weights as statuses change, including the 3.5.3 and 3.13.11 partial rules, and keeps the evidence behind each "met" timestamped, so the number you post is one you can defend.
Raising the score: triage by weight
The weight table is a priority list the DoD wrote for you.
- Confirm the no-deduction cases first. If you genuinely prohibit remote, wireless, or mobile access, write the policy that proves it. Free points recovered, sometimes 25 of them.
- Take the built-in partial credit. MFA for remote and privileged users converts a −5 to a −3 immediately. Encryption that exists but is not FIPS-validated is −3, not −5, and swapping in a validated module clears the rest.
- Work the five-pointers. Fifteen five-point fixes recover 75 points. The same effort spent on one-pointers recovers 15.
- Reclassify honestly. Broken-after-implementation items with active plans of action, and documented enduring exceptions, score as implemented. Many first-pass self-assessments are lower than the methodology actually requires.
- Keep the POA&M real. It restores nothing, but its absence costs 3 points and its completion date is posted in SPRS next to your name.
FAQ
Can my SPRS score really be negative? Yes. The scale runs from −203 to 110, and any company missing a few dozen weighted requirements will be negative. A negative score is an honest measurement, not a clerical error.
Does a POA&M give partial credit? No. Requirements with open plans of action are scored not met. The only partial credit in the methodology is built into 3.5.3 (MFA) and 3.13.11 (FIPS cryptography).
Do primes see my score in SPRS? Not directly. SPRS visibility is limited to DoD personnel and your own company. Primes verify your status by requiring you to disclose it, which is why the demand letters come to you.
How often must I update the score? It must be no more than three years old to satisfy 7019, but it should be re-posted whenever your implementation status materially changes, because a senior official affirms its continuing accuracy annually.
Is 110 required to win contracts? DFARS 7019 requires a current score on file, not a perfect one. Award decisions and prime flow-downs increasingly scrutinize low scores, and if CMMC Level 2 certification applies to your contracts, a conditional certification requires at least 88.
Valontir is a compliance workspace for small defense contractors: every 800-171 requirement, every piece of evidence, and your live SPRS score in one place, so your annual affirmation has evidence behind it. Book a demo or request access.
Sources: NIST SP 800-171 DoD Assessment Methodology, v1.2.1 (June 24, 2020) · DFARS 252.204-7012 · DFARS 252.204-7019 · DFARS 252.204-7020 · NIST SP 800-171 Rev. 2 · NIST SP 800-171A · 32 CFR Part 170