Briefings · The record
SPRS scoring, explained
Your SPRS score is the single number the government sees before you win the award: a self-reported measure of how completely you have implemented NIST SP 800-171. It starts at a perfect 110 and loses ground for every requirement you have not met. What surprises most contractors the first time they run it honestly is how far below zero it can go.
The scale · at a glance
The short version
Start at 110. Subtract 5, 3, or 1 for each of the 110 requirements you have not fully met, weighted by how much each one matters. There is no partial credit for most requirements. Because 42 requirements are worth 5 points each, the deductions can exceed 110, so a barely-started shop bottoms out at -203. The number goes in SPRS, and it is a representation you are legally accountable for.
The scale
From -203 to 110
One track, three landmarks: the floor, the conditional threshold, and a perfect score.
The geometry tells the story. A perfect 110 sits at the far right. The conditional-status threshold of 88 is close behind it, not near the middle, because 88 is only 22 points down from perfect. Zero is nearly two-thirds of the way along the track, which means a score of zero already represents a great deal of unmet requirement. And the floor at -203 exists because the total available deductions are far larger than the 110 you begin with.
The weighting
Not every requirement costs the same
The heavy hitters 5 points
42 requirements carry the maximum weight, concentrated in access control, configuration management, identification and authentication, system and communications protection, and system and information integrity. Miss one of these and you lose five points at once. These are the requirements that move a score fastest, in both directions.
The middle weight 3 points
Requirements with a specific but more limited effect on the overall security posture. Meaningful, but not the make-or-break controls. A cluster of unmet three-pointers still adds up quickly.
The single points 1 point
Requirements with limited or indirect effect. These are also the only requirements that may sit on a plan of action for conditional status, which is why the math of reaching 88 forces every 5-point and 3-point requirement to be fully met.
Two narrow exceptions break the no-partial-credit rule. Multifactor authentication and validated encryption can be scored as partially implemented, with a reduced deduction, when they are in place but not fully to standard. Everything else is binary: a requirement is fully met, or you take the full deduction. There is no credit for "mostly."
Why 88, and why it's serious
The number behind the number
The threshold that matters most is 88. It is the minimum score for CMMC Level 2 conditional status, and it is not an arbitrary cutoff. Because only one-point requirements can be deferred to a plan of action, and because reaching 88 leaves just 22 points of room, the only way to hit it is to fully meet every 5-point and 3-point requirement and leave only single-pointers open. The score encodes a rule: the requirements that matter most cannot be the ones you postpone. The connection between 88, the plan of action, and the 180-day closeout is covered in the readiness-gaps briefing.
And the number is not just operational, it is legal. DFARS 252.204-7019 requires a current self-assessment score in SPRS at the time of award, no more than three years old, and the government relies on it to make award decisions. That makes your score a representation, not an internal metric. The Department of Justice has pursued False Claims Act settlements against contractors over inaccurate cybersecurity attestations, and the SPRS score is exactly the kind of statement those cases turn on. An honest low score is a position you can improve. An inflated score is a liability you are signing.
Which is the case for scoring yourself carefully rather than optimistically. The self-assessment briefing covers who signs and what that signature carries; the point here is that the number should be true before it is high. An engineered program helps by making the true number climb honestly: every implemented control is a deduction you stop taking, and the 93-step path is built to close the heaviest requirements first, which is where the points are.
Straight answers
Asked and answered
What's a good score?
110 is perfect. 88 is the conditional-status threshold that matters, and reaching it means every heavy requirement is met. Do not be alarmed if your first honest score is negative; that is common.
How is it calculated?
Start at 110, subtract 5, 3, or 1 for each unmet requirement by its weight. No partial credit except narrow allowances for MFA and validated encryption. Fully unimplemented lands at -203.
Why can it go negative?
Because 42 requirements are worth 5 points each, the total deductions exceed the 110 you start with. A shop that has done little can lose more than 110 points and land well below zero.
Is the score legally binding?
In effect, yes. It is required in SPRS at award and relied on by the government, which makes an inflated score a false representation with False Claims Act exposure.
Sources
- DoD NIST SP 800-171 Assessment Methodology (the 5/3/1 weighting, the -203 floor, partial-credit rules)
- SPRS: NIST SP 800-171 scoring (the official system of record)
- DFARS 252.204-7019 (score required in SPRS at award, three-year currency)
- 32 CFR Part 170 (the 88 conditional threshold and plan-of-action limits)
Next up
A scoping call reads where your real SPRS score sits today and which heavy requirements are costing you the most points, so the climb starts where it counts.
Schedule a Demo