RoutineMetric

NIST SP 800-171 SPRS Score & Gap Assessment Tool

Calculate your Supplier Performance Risk System (SPRS) score under the official DoD Assessment Methodology. Establish baseline scoping, map compliance gaps, and output an audit-ready POA&M status report.

Assessment Parameters & Metadata

Quick Readiness PresetsSimulate different assessment baselines instantly:
Access Control (AC)0 / 22 Met
||
Requirement 3.1.1Deduction: -5 pts

Limit system access to authorized users, processes acting on behalf of authorized users, or devices (including other systems).

Requirement 3.1.2Deduction: -5 pts

Limit system access to the types of transactions and functions that authorized users are permitted to execute.

Requirement 3.1.3Deduction: -5 pts

Control the flow of CUI in accordance with approved authorizations.

Requirement 3.1.4Deduction: -1 pt

Separate the duties of individuals to reduce the risk of malevolent activity without collusion.

Requirement 3.1.5Deduction: -3 pts

Employ the principle of least privilege, including for specific security functions and privileged accounts.

Requirement 3.1.6Deduction: -1 pt

Use non-privileged accounts or roles when accessing non-security functions, and limit administrative privileges to only necessary activities.

Requirement 3.1.7Deduction: -1 pt

Prevent non-privileged users from executing privileged functions and audit the execution of such functions.

Requirement 3.1.8Deduction: -1 pt

Limit unsuccessful logon attempts.

Requirement 3.1.9Deduction: -1 pt

Provide privacy and security notices consistent with applicable CUI rules.

Requirement 3.1.10Deduction: -1 pt

Prevent system and device identification from being displayed before establishing an authenticated connection.

Requirement 3.1.11Deduction: -5 pts

Terminate (automatically) a user session after a defined condition for inactivity.

Requirement 3.1.12Deduction: -5 pts

Monitor and control remote access sessions.

Requirement 3.1.13Deduction: -5 pts

Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.

Requirement 3.1.14Deduction: -1 pt

Route remote access via managed access control points.

Requirement 3.1.15Deduction: -1 pt

Authorize remote execution of privileged commands and security-relevant information.

Requirement 3.1.16Deduction: -5 pts

Authorize wireless access prior to allowing such connections.

Requirement 3.1.17Deduction: -5 pts

Protect wireless access using authentication and encryption.

Requirement 3.1.18Deduction: -5 pts

Control connection of mobile devices.

Requirement 3.1.19Deduction: -3 pts

Encrypt CUI on mobile devices and mobile computing platforms.

Requirement 3.1.20Deduction: -5 pts

Verify and control/limit connections to and use of external systems.

Requirement 3.1.21Deduction: -1 pt

Limit use of organizational portable storage devices on external systems.

Requirement 3.1.22Deduction: -5 pts

Control information posted or processed on publicly accessible systems.

Awareness and Training (AT)0 / 3 Met
||
Audit and Accountability (AU)0 / 9 Met
||
Configuration Management (CM)0 / 9 Met
||
Identification and Authentication (IA)0 / 11 Met
||
Incident Response (IR)0 / 3 Met
||
Maintenance (MA)0 / 6 Met
||
Media Protection (MP)0 / 9 Met
||
Personnel Security (PS)0 / 2 Met
||
Physical Protection (PE)0 / 6 Met
||
Risk Assessment (RA)0 / 3 Met
||
Security Assessment (CA)0 / 4 Met
||
System and Communications Protection (SC)0 / 16 Met
||
System and Information Integrity (SI)0 / 7 Met
||
Official SPRS Scorecard
-185Out of +110 Maximum
Completed0 / 110
Gaps (POA&M)110 Controls
Invalid Score SubmissionRule 3.12.4 (SSP) is unimplemented. You cannot legally submit an SPRS score without an SSP.
Invalid Score SubmissionRule 3.12.2 (POA&M) is unimplemented. Unmet controls must be linked to an active POA&M.

DoD SPRS Submission String

When uploading your score to the Supplier Performance Risk System (SPRS), you must submit this formatted string alongside your System Security Plan:

NIST 800-171 Rev 2; Score: -185; SSP Date: 2026-08-17; POA&M Date: 2027-02-17

CMMC 2.0 Alignment

Required LevelLevel 2 (Advanced)
Score StandardMin 110 for Certification

CMMC 2.0 Level 2 relies on the identical 110 controls of NIST SP 800-171. However, unlike SPRS which permits a negative score with a POA&M, CMMC does not allow long-term POA&Ms for certification. All controls must be fully met, or satisfy strict 180-day time-limited criteria.

Plan of Action & Milestones (POA&M) Status

Below are your identified cybersecurity compliance gaps. Assign an expected completion date and remediation owner for each item before printing your final System Security Plan package.

Control IDRequired Security Practice DescriptionWeightTarget DateRemediation Owner
3.1.1Limit system access to authorized users, processes acting on behalf of authorized users, or devices (including other systems).-5
3.1.2Limit system access to the types of transactions and functions that authorized users are permitted to execute.-5
3.1.3Control the flow of CUI in accordance with approved authorizations.-5
3.1.4Separate the duties of individuals to reduce the risk of malevolent activity without collusion.-1
3.1.5Employ the principle of least privilege, including for specific security functions and privileged accounts.-3
3.1.6Use non-privileged accounts or roles when accessing non-security functions, and limit administrative privileges to only necessary activities.-1
3.1.7Prevent non-privileged users from executing privileged functions and audit the execution of such functions.-1
3.1.8Limit unsuccessful logon attempts.-1
3.1.9Provide privacy and security notices consistent with applicable CUI rules.-1
3.1.10Prevent system and device identification from being displayed before establishing an authenticated connection.-1
3.1.11Terminate (automatically) a user session after a defined condition for inactivity.-5
3.1.12Monitor and control remote access sessions.-5
3.1.13Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.-5
3.1.14Route remote access via managed access control points.-1
3.1.15Authorize remote execution of privileged commands and security-relevant information.-1
3.1.16Authorize wireless access prior to allowing such connections.-5
3.1.17Protect wireless access using authentication and encryption.-5
3.1.18Control connection of mobile devices.-5
3.1.19Encrypt CUI on mobile devices and mobile computing platforms.-3
3.1.20Verify and control/limit connections to and use of external systems.-5
3.1.21Limit use of organizational portable storage devices on external systems.-1
3.1.22Control information posted or processed on publicly accessible systems.-5
3.2.1Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities.-1
3.2.2Ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.-1
3.2.3Provide insider threat awareness training.-1
3.3.1Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.-5
3.3.2Ensure that organizational systems audit records contain information to establish what events occurred, the sources, and the outcomes.-3
3.3.3Review and update logged events.-1
3.3.4Alert in the event of an audit logging process failure.-1
3.3.5Correlate audit record review, analysis, and reporting processes for investigation and response to indications of inappropriate, unusual, or suspicious activity.-5
3.3.6Provide a system capability that compares and correlates audit records from multiple sources with other records to support security-relevant investigations.-1
3.3.7Provide a system-wide time source that is used to synchronize the clocks on system components.-1
3.3.8Protect audit information and audit tools from unauthorized access, modification, and deletion.-1
3.3.9Limit management of audit logging functionality to only a subset of privileged users.-1
3.4.1Establish and maintain baseline configurations and inventories of organizational systems throughout the respective system development life cycles.-5
3.4.2Enforce security configuration settings for information technology products employed in organizational systems.-5
3.4.3Track, review, approve, and audit changes to organizational systems.-1
3.4.4Analyze the security impact of changes prior to implementation.-1
3.4.5Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.-5
3.4.6Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.-5
3.4.7Restrict, disable, or prevent the use of nonessential software.-5
3.4.8Apply deny-by-exception (blacklisting) or allow-all-by-exception (whitelisting) to control application execution.-5
3.4.9Control and monitor user-installed software.-1
3.5.1Identify system users, processes acting on behalf of users, or devices.-5
3.5.2Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational systems.-5
3.5.3Use multi-factor authentication (MFA) for local and network access to privileged accounts and for network access to non-privileged accounts.-5
3.5.4Employ replay-resistant authentication mechanisms.-1
3.5.5Prevent reuse of identifiers for a defined period.-1
3.5.6Disable identifiers after a defined period of inactivity.-1
3.5.7Enforce minimum password complexity and change characters when new passwords are created.-1
3.5.8Establish password reuse rules.-1
3.5.9Limit temporary password use.-1
3.5.10Store and transmit only cryptographically-protected passwords.-5
3.5.11Obscure feedback during authentication process.-1
3.6.1Establish an operational incident-handling capability for organizational systems.-1
3.6.2Track, document, and report incidents to designated officials and/or authorities.-1
3.6.3Test the organizational incident-handling capability.-1
3.7.1Perform maintenance on organizational systems.-3
3.7.2Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.-1
3.7.3Ensure equipment containing CUI is sanitized before off-site maintenance.-1
3.7.4Control media containing diagnostic and test programs.-3
3.7.5Enforce safeguards for tools, techniques, mechanisms, and personnel used to conduct system maintenance.-5
3.7.6Supervise maintenance personnel without required access authorizations.-1
3.8.1Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.-3
3.8.2Limit access to CUI on system media to authorized users.-3
3.8.3Sanitize or destroy system media containing CUI before disposal or release for reuse.-5
3.8.4Mark media containing CUI with applicable security markings.-1
3.8.5Control access to media containing CUI and maintain accountability.-1
3.8.6Control the removal of media containing CUI from designated areas.-1
3.8.7Control the use of removable media on system components.-5
3.8.8Prohibit the use of portable storage devices when such devices have no identifiable owner.-3
3.8.9Protect the confidentiality of backup media containing CUI during transport.-1
3.9.1Screen individuals prior to authorizing access to organizational systems containing CUI.-3
3.9.2Ensure that organizational systems containing CUI remain protected upon transfer or termination of personnel.-1
3.10.1Limit physical access to organizational systems, equipment, and operating environments to authorized individuals.-5
3.10.2Protect and monitor physical facility and support infrastructure.-1
3.10.3Escort visitors and monitor visitor activity.-5
3.10.4Maintain audit logs of physical access.-5
3.10.5Control and manage physical access devices.-5
3.10.6Protect power and cabling infrastructure from damage/interception.-1
3.11.1Periodically assess the risk to organizational operations, assets, and individuals.-3
3.11.2Scan for vulnerabilities in organizational systems and applications periodically.-5
3.11.3Remediate vulnerabilities in accordance with risk assessments.-1
3.12.1Periodically assess the security controls in organizational systems to determine if they are effective.-1
3.12.2Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities.-3
3.12.3Monitor organizational system security controls on an ongoing basis.-1
3.12.4Develop, document, and periodically update system security plans (SSP) that describe system boundaries and security requirements.-0
3.13.1Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries.-5
3.13.2Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security.-5
3.13.3Separate user functionality from system management functionality.-1
3.13.4Prevent unauthorized and unintended information transfer via shared system resources.-1
3.13.5Implement subnetworks for publicly accessible system components.-5
3.13.6Deny network communications traffic by default and allow network communications traffic by exception.-1
3.13.7Prevent remote devices from establishing unauthorized connections.-1
3.13.8Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission.-3
3.13.9Terminate network connections associated with communications sessions upon defined conditions.-1
3.13.10Establish system-wide time synchronization.-1
3.13.11Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.-5
3.13.12Prohibit direct connection of collaborative devices to external systems.-1
3.13.13Control mobile code.-1
3.13.14Control Voice over IP (VoIP) technologies.-1
3.13.15Protect authenticity of communications sessions.-1
3.13.16Protect the confidentiality of CUI at rest.-5
3.14.1Identify, report, and correct system and information flaws in a timely manner.-5
3.14.2Provide protection from malicious code at appropriate locations.-5
3.14.3Monitor system security alerts and advisories and take appropriate actions.-1
3.14.4Update malicious code protection mechanisms when new releases are available.-5
3.14.5Perform periodic scans of organizational systems and real-time scans of files from external sources.-5
3.14.6Monitor organizational systems to detect attacks and indicators of potential attacks.-1
3.14.7Identify unauthorized use of organizational systems.-3
Advertisement
Bottom Banner Ad (728x90)

Understanding NIST SP 800-171 & The DoD SPRS Scoring Methodology

Under the Defense Federal Acquisition Regulation Supplement (DFARS) Clause 252.204-7012, all defense contractors and subcontractors handling Controlled Unclassified Information (CUI) must implement the 110 cybersecurity requirements set forth in NIST SP 800-171. To prove compliance, the Department of Defense (DoD) requires contractors to conduct a self-assessment following the official DoD Assessment Methodology and submit their score to the Supplier Performance Risk System (SPRS).

How the SPRS Scoring Methodology Works

Instead of starting at zero and adding points as requirements are implemented, the SPRS assessment methodology operates on a deductive point model. The assessment begins with a perfect starting score of +110. For every security requirement that is not fully implemented, a weighted point deduction is subtracted from the score.

The point weights reflect the criticality of the security control and are defined as follows:

  • 5-Point Deductions (42 Controls): Basic safeguards and critical derived security requirements. These represent essential parameters that, if missing, severely undermine systemic data integrity (e.g., multi-factor authentication, network boundary monitoring, and FIPS-validated encryption modules).
  • 3-Point Deductions (14 Controls): Important requirements with a direct, but more localized, impact on the security of the network and CUI (e.g., least privilege controls, mobile device encryption, and physical media security).
  • 1-Point Deductions (54 Controls): Administrative, organizational, or supportive security protocols that represent the remainder of the 110 controls.

If an organization has implemented zero controls, the total deduction sums to 313 points, resulting in a minimum possible score of -203.

The Two Key "Partial Credit" Exceptions

The official DoD scoring methodology allows for minor, partial credit on exactly two controls if specific sub-elements are satisfied, avoiding the full 5-point deduction:

  1. Control 3.5.3 (Multi-Factor Authentication): If MFA is not implemented at all, a 5-point deduction is taken. However, if MFA is actively enforced for all remote and privileged access, but not yet completed for internal general network access, the deduction is reduced to 3 points.
  2. Control 3.13.11 (FIPS-Validated Cryptography): If cryptography is not employed at all where required, a 5-point deduction is taken. If encryption is utilized to protect CUI but the cryptographic modules are not formally validated by NIST (FIPS 140-2 or 140-3 certification), the deduction is reduced to 3 points.

Critical Submission Prerequisites: The SSP and POA&M

There are two mandatory requirements in NIST SP 800-171 that carry a deduction value of 0 points but represent structural blockades if unimplemented:

  • System Security Plan (SSP) - Control 3.12.4: You cannot legally perform or submit an SPRS score if you do not have an active SSP. The SSP outlines the system boundaries, network architectures, and hardware/software inventories carrying CUI.
  • Plan of Action & Milestones (POA&M) - Control 3.12.2: If your organization has any score less than +110, you must have an active POA&M documenting how and when you plan to remediate the unimplemented gaps.

Our tool actively monitors the status of these two controls. If either is set to unimplemented, a prominent validation warning is displayed to prevent invalid compliance reporting.

Transitioning from SPRS to CMMC 2.0 Level 2

The upcoming Cybersecurity Maturity Model Certification (CMMC 2.0) standard codifies NIST SP 800-171 compliance into a formal third-party audit program. Organizations requiring a CMMC Level 2 (Advanced) certification will be assessed on the exact same 110 controls.

While the SPRS self-assessment score accommodates low and negative scores provided there is an active POA&M, CMMC 2.0 certifications are binary (Pass/Fail). To achieve CMMC certification, an organization must achieve a perfect score of +110, or temporarily utilize very limited 180-day POA&Ms for a specific subset of minor controls, which must be fully closed prior to final registration.

Advertisement