How to Calculate Your SPRS Score (With a Worked Example)
ISO Cloud Consulting editorial team
Your SPRS score is 110 minus the point value of every NIST SP 800-171 requirement you have not fully met. Each of the 110 requirements is worth 5, 3 or 1 point under the DoD Assessment Methodology, so scores range from 110 down to −203. You need at least 88 for Conditional CMMC Level 2 status.
Key facts
- Maximum score 110; minimum −203, because the point values add up to 313.
- 44 requirements are worth up to 5 points, 14 are worth 3 and 51 are worth 1.
- 3.12.4 (System Security Plan) has no point value, but without a current SSP the assessment cannot be completed.
- Only two requirements allow partial credit: 3.5.3 (MFA) and 3.13.11 (FIPS-validated encryption).
- Conditional Level 2 needs 88 or more, with only eligible items on the POA&M, closed within 180 days.
- The scoring rules are set out in 32 CFR 170.24.
How does SPRS scoring work?
You start at 110 and subtract each unmet requirement's value. There is no credit for "mostly done": a requirement is met only when every one of its assessment objectives is met.
The values reflect impact. Requirements whose absence could lead to significant exploitation of the network or loss of CUI, such as multifactor authentication, audit logging, incident response and boundary protection, are worth 5. Those with a specific, confined effect, such as least privilege or protecting CUI in transit, are worth 3. The rest, with a limited or indirect effect, are worth 1.
Two exceptions allow partial credit. For 3.5.3, you lose 3 points instead of 5 if MFA covers remote and privileged users but not general users. For 3.13.11, you lose 3 instead of 5 if CUI is encrypted but the encryption is not FIPS-validated.
How do you calculate your SPRS score, step by step?
Scoring takes an afternoon once the assessment work is done. The assessment itself, testing 320 objectives with evidence, is where the time goes.
- Fix the scope. Decide which systems, people and locations handle CUI. Score that environment, not the whole company by default.
- Assess every objective. For each of the 110 requirements, test its objectives in NIST SP 800-171A and mark each one met, not met or not applicable, with evidence.
- Roll up to requirements. A requirement is met only if all its applicable objectives are met. One missing objective makes the whole requirement not met.
- Subtract. Deduct each not-met requirement's value, applying partial credit only for 3.5.3 and 3.13.11.
- Record and plan. Record the score, the assessment date and a POA&M for every open item, with the date you expect to reach 110.
What does a worked SPRS example look like?
Harborline Precision Machining (fictional) is a 38-person machine shop that receives controlled technical drawings. Its self-assessment finds eight requirements not met:
| Requirement | Topic | Finding | Points | POA&M eligible? |
|---|---|---|---|---|
| 3.5.3 | Multifactor authentication | MFA for remote and administrator accounts only | −3 | No |
| 3.13.11 | FIPS-validated cryptography | CUI encrypted, but the module is not FIPS-validated | −3 | Yes |
| 3.11.2 | Vulnerability scanning | No periodic scanning | −5 | No |
| 3.1.10 | Session lock | Shop-floor PCs never lock | −1 | Yes |
| 3.2.3 | Insider-threat awareness | Not covered in training | −1 | Yes |
| 3.4.9 | User-installed software | Users can install software freely | −1 | Yes |
| 3.8.9 | Backup CUI confidentiality | Backups not encrypted | −1 | Yes |
| 3.10.4 | Physical access logs | No log of who enters the engineering office | −1 | No |
Total deductions are 16 points, so Harborline's score is 110 − 16 = 94.
Does a score of 94 qualify for Conditional Level 2?
No. The score clears the 88 threshold, but three items on Harborline's list can never sit on a CMMC POA&M.
- 3.11.2 vulnerability scanning is worth 5 points. Only 1-point items are eligible.
- 3.5.3 MFA costs 3 points under partial credit. The only 3-point exception is 3.13.11.
- 3.10.4 physical access logs is worth 1 point but is excluded by name, along with 3.1.20, 3.1.22, 3.10.3, 3.10.5 and 3.12.4.
Harborline fixes those three before assessing again: it schedules monthly authenticated scans, extends MFA to all users and starts a sign-in log at the engineering office door. The new score is 110 − 7 = 103. The five remaining items (3.13.11 at 3 points, and four eligible 1-point items) go on the POA&M, giving Conditional Level 2 (Self) status. Harborline then has 180 days to close them and complete a closeout self-assessment.
Which requirements cost the most points?
The 5-point requirements dominate the score, and many of them are common gaps in small shops. Close these first:
- 3.5.3 multifactor authentication and 3.13.11 FIPS-validated encryption.
- 3.3.1 audit logs, and 3.3.5 correlating log review.
- 3.11.2 vulnerability scanning and 3.14.1 flaw remediation (patching).
- 3.6.1 and 3.6.2 incident handling and reporting.
- 3.2.1 and 3.2.2 security awareness and role-based training.
- 3.4.1 and 3.4.2 baseline configurations and security settings.
- 3.13.1 boundary protection and 3.1.12 remote access control.
How do not applicable, exceptions and temporary deficiencies affect the score?
All four of these count as met when they are properly documented, so they cost no points. They are also where assessors look hardest, because they are the easiest way to overstate a score.
- Not applicable: an objective that genuinely does not apply is treated the same as met. The rule's own example is 3.13.5 when you have no publicly accessible systems.
- Enduring exceptions: a requirement that cannot be fully met for a lasting reason, such as a machine controller that cannot run anti-malware, is assessed as met when the exception and its mitigations are described in the SSP.
- Temporary deficiencies: a requirement that was implemented but has a short-term problem is assessed as met when it is tracked in an operational plan of action showing reviews and progress.
- DoD CIO adjudications: if DoD has formally accepted an alternative measure as equally effective, include the adjudication in your SSP and the requirement is assessed as met.
None of these covers a control you simply have not implemented yet. That is not met, and it is deducted.
What is the difference between your SPRS score and your CMMC status?
Your SPRS score is a number from 110 down to −203. Your CMMC status is a label, such as Final Level 2 (Self) or Conditional Level 2 (Self), that depends on the score, the POA&M rules and an affirmation.
Both come from the same assessment of the same 110 requirements. The difference is what each one is used for. DFARS 7019 asks for a current score, and any honest score can be posted. A CMMC Level 2 (Self) requirement asks for a status: Final needs 110, and Conditional needs 88 or more with only eligible items open. A company can therefore have a valid SPRS score and still not meet a CMMC requirement in a solicitation.
How do you report the score in SPRS?
For a NIST SP 800-171 Basic Assessment under DFARS 252.204-7019, the summary includes the standard assessed, who did the assessment, the CAGE codes covered by each SSP, the date completed, the summary score (for example, 94 out of 110) and the date you expect to reach 110.
A CMMC Level 2 (Self) entry adds the CMMC level, status date, assessment scope and POA&M status, followed by your Affirming Official's affirmation. Enter the true score, and keep the working that produced it for six years.
What scoring mistakes should you avoid?
- Rounding up. Marking a requirement met when four of its five objectives are met.
- Policy equals practice. A signed policy is evidence of intent, not of implementation.
- Inventing partial credit. Only 3.5.3 and 3.13.11 have it.
- Scoring POA&M items as met. Anything on a POA&M is not met and must be deducted.
- Overusing not applicable. Every N/A needs a reason an assessor would accept.
- Ignoring your providers. If your IT provider or cloud service covers a requirement, you need its customer responsibility matrix and your own evidence.
The CMMC Level 2 / NIST 800-171 Assessment Workbook ($79) scores all 110 requirements and calculates the SPRS total for you, and the CMMC Level 2 Starter Bundle ($175, was $207) adds the SSP and POA&M templates. For the wider context, see what still applies in 2026 and the CMMC hub. The workbook calculates the number; the honesty of the inputs is yours.
Last reviewed: 29 September 2026. CMMC rules are still moving. Check your contract, your prime's flowdown and the current rule before you rely on any date.