SPRS Scoring Explained · 2026

How your SPRS score is calculated, and why the number on file may be wrong

For Defense Industrial Base contractors preparing for CMMC Level 2. Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending.

SPRS is the Supplier Performance Risk System, the Department of Defense system where your NIST 800-171 self-assessment score and your CMMC Status are recorded (32 CFR 170.4 and 170.16). It is worth knowing how that number was derived and whether it still holds.

The scoring method, in plain terms

The DoD Assessment Methodology scores the 110 security requirements in NIST SP 800-171 Rev. 2, as does the CMMC Scoring Methodology in 32 CFR 170.24. It does not award points for what you have done. It starts you at a perfect score and subtracts for what you have not.

Start at 110
Each requirement is weighted 1, 3, or 5 points by risk
Subtract the weighted value of every requirement not fully met
Result range: 110 down to a floor of -203 (every weight in 32 CFR 170.24(c)(2) subtracted)

A perfect, fully implemented environment scores 110. The weights are not equal: higher-risk requirements, such as multifactor authentication (3.5.3), carry 5 points, so a single unmet high-weight control can move your score more than several minor ones. Two requirements, multifactor authentication (3.5.3) and FIPS-validated encryption (3.13.11), allow partial credit under specific conditions (32 CFR 170.24(c)(2)(i)(B)(4)). Because the deductions are weighted, two contractors with the same number of open controls can post very different scores.

Why the number on file can be wrong

An SPRS score is a self-attestation captured at a moment in time. It is a snapshot, not a live reading. It does not recalculate on its own when your environment changes, for example:

The gap that matters is between your reported score and what an assessor would compute today. That difference becomes visible the moment a prime or contracting officer asks for current evidence. See where you likely stand, free, from 10 questions →

Reported score versus your measured evidence

When a C3PAO assesses you, they do not take the SPRS number at face value. They assess your environment against the same 110 requirements and score what they find (32 CFR 170.17 and 170.24). DoD may also conduct a DCMA DIBCAC assessment of a self-assessed contractor (32 CFR 170.16(a)(1)(iv)). Measuring your own posture first tells you whether the number on file still holds.

Find out what your environment actually scores

The free gap check gives you a directional read on ten questions, seven of them on 5-point controls. The CMMC Level 2 Readiness Snapshot maps your connected-cloud findings and intake answers against the 110-control NIST 800-171 baseline and returns a PDF within minutes of intake, for $999 one time. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2.

Run the free 10-question gap check See the $999 Level 2 Readiness Snapshot

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. The free gap check is a directional self-assessment and is not an official SPRS score. Patent Pending. ElasticD3M, LLC, Texas.