BriefingThe recordReviewed July 23, 2026

Briefings · The record

SPRS scoring, explained

Your SPRS score is the single number the government sees before you win the award: a self-reported measure of how completely you have implemented NIST SP 800-171. It starts at a perfect 110 and loses ground for every requirement you have not met. What surprises most contractors the first time they run it honestly is how far below zero it can go.

The scale · at a glance

Top of the scale, a perfect score110
Floor−203 · nothing implemented
Deductions5, 3, or 1 point each
Conditional88 · Level 2 threshold
ReviewedJuly 23, 2026

The short version

Start at 110. Subtract 5, 3, or 1 for each of the 110 requirements you have not fully met, weighted by how much each one matters. There is no partial credit for most requirements. Because 42 requirements are worth 5 points each, the deductions can exceed 110, so a barely-started shop bottoms out at -203. The number goes in SPRS, and it is a representation you are legally accountable for.

The scale

From -203 to 110

One track, three landmarks: the floor, the conditional threshold, and a perfect score.

Nothing implementedFully implemented

The geometry tells the story. A perfect 110 sits at the far right. The conditional-status threshold of 88 is close behind it, not near the middle, because 88 is only 22 points down from perfect. Zero is nearly two-thirds of the way along the track, which means a score of zero already represents a great deal of unmet requirement. And the floor at -203 exists because the total available deductions are far larger than the 110 you begin with.

The weighting

Not every requirement costs the same

01

The heavy hitters 5 points

42 requirements carry the maximum weight, concentrated in access control, configuration management, identification and authentication, system and communications protection, and system and information integrity. Miss one of these and you lose five points at once. These are the requirements that move a score fastest, in both directions.

02

The middle weight 3 points

Requirements with a specific but more limited effect on the overall security posture. Meaningful, but not the make-or-break controls. A cluster of unmet three-pointers still adds up quickly.

03

The single points 1 point

Requirements with limited or indirect effect. These are also the only requirements that may sit on a plan of action for conditional status, which is why the math of reaching 88 forces every 5-point and 3-point requirement to be fully met.

Two narrow exceptions break the no-partial-credit rule. Multifactor authentication and validated encryption can be scored as partially implemented, with a reduced deduction, when they are in place but not fully to standard. Everything else is binary: a requirement is fully met, or you take the full deduction. There is no credit for "mostly."

Why 88, and why it's serious

The number behind the number

The threshold that matters most is 88. It is the minimum score for CMMC Level 2 conditional status, and it is not an arbitrary cutoff. Because only one-point requirements can be deferred to a plan of action, and because reaching 88 leaves just 22 points of room, the only way to hit it is to fully meet every 5-point and 3-point requirement and leave only single-pointers open. The score encodes a rule: the requirements that matter most cannot be the ones you postpone. The connection between 88, the plan of action, and the 180-day closeout is covered in the readiness-gaps briefing.

And the number is not just operational, it is legal. DFARS 252.204-7019 requires a current self-assessment score in SPRS at the time of award, no more than three years old, and the government relies on it to make award decisions. That makes your score a representation, not an internal metric. The Department of Justice has pursued False Claims Act settlements against contractors over inaccurate cybersecurity attestations, and the SPRS score is exactly the kind of statement those cases turn on. An honest low score is a position you can improve. An inflated score is a liability you are signing.

Which is the case for scoring yourself carefully rather than optimistically. The self-assessment briefing covers who signs and what that signature carries; the point here is that the number should be true before it is high. An engineered program helps by making the true number climb honestly: every implemented control is a deduction you stop taking, and the 93-step path is built to close the heaviest requirements first, which is where the points are.

Straight answers

Asked and answered

Q01

What's a good score?

110 is perfect. 88 is the conditional-status threshold that matters, and reaching it means every heavy requirement is met. Do not be alarmed if your first honest score is negative; that is common.

Q02

How is it calculated?

Start at 110, subtract 5, 3, or 1 for each unmet requirement by its weight. No partial credit except narrow allowances for MFA and validated encryption. Fully unimplemented lands at -203.

Q03

Why can it go negative?

Because 42 requirements are worth 5 points each, the total deductions exceed the 110 you start with. A shop that has done little can lose more than 110 points and land well below zero.

Q04

Is the score legally binding?

In effect, yes. It is required in SPRS at award and relied on by the government, which makes an inflated score a false representation with False Claims Act exposure.

Sources