Calculate your Supplier Performance Risk System (SPRS) score under the official DoD Assessment Methodology. Establish baseline scoping, map compliance gaps, and output an audit-ready POA&M status report.
Assessment Parameters & Metadata
Quick Readiness PresetsSimulate different assessment baselines instantly:
Access Control (AC)0 / 22 Met
||
Requirement 3.1.1Deduction: -5 pts
Limit system access to authorized users, processes acting on behalf of authorized users, or devices (including other systems).
Requirement 3.1.2Deduction: -5 pts
Limit system access to the types of transactions and functions that authorized users are permitted to execute.
Requirement 3.1.3Deduction: -5 pts
Control the flow of CUI in accordance with approved authorizations.
Requirement 3.1.4Deduction: -1 pt
Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
Requirement 3.1.5Deduction: -3 pts
Employ the principle of least privilege, including for specific security functions and privileged accounts.
Requirement 3.1.6Deduction: -1 pt
Use non-privileged accounts or roles when accessing non-security functions, and limit administrative privileges to only necessary activities.
Requirement 3.1.7Deduction: -1 pt
Prevent non-privileged users from executing privileged functions and audit the execution of such functions.
Requirement 3.1.8Deduction: -1 pt
Limit unsuccessful logon attempts.
Requirement 3.1.9Deduction: -1 pt
Provide privacy and security notices consistent with applicable CUI rules.
Requirement 3.1.10Deduction: -1 pt
Prevent system and device identification from being displayed before establishing an authenticated connection.
Requirement 3.1.11Deduction: -5 pts
Terminate (automatically) a user session after a defined condition for inactivity.
Requirement 3.1.12Deduction: -5 pts
Monitor and control remote access sessions.
Requirement 3.1.13Deduction: -5 pts
Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
Requirement 3.1.14Deduction: -1 pt
Route remote access via managed access control points.
Requirement 3.1.15Deduction: -1 pt
Authorize remote execution of privileged commands and security-relevant information.
Requirement 3.1.16Deduction: -5 pts
Authorize wireless access prior to allowing such connections.
Requirement 3.1.17Deduction: -5 pts
Protect wireless access using authentication and encryption.
Requirement 3.1.18Deduction: -5 pts
Control connection of mobile devices.
Requirement 3.1.19Deduction: -3 pts
Encrypt CUI on mobile devices and mobile computing platforms.
Requirement 3.1.20Deduction: -5 pts
Verify and control/limit connections to and use of external systems.
Requirement 3.1.21Deduction: -1 pt
Limit use of organizational portable storage devices on external systems.
Requirement 3.1.22Deduction: -5 pts
Control information posted or processed on publicly accessible systems.
Awareness and Training (AT)0 / 3 Met
||
Audit and Accountability (AU)0 / 9 Met
||
Configuration Management (CM)0 / 9 Met
||
Identification and Authentication (IA)0 / 11 Met
||
Incident Response (IR)0 / 3 Met
||
Maintenance (MA)0 / 6 Met
||
Media Protection (MP)0 / 9 Met
||
Personnel Security (PS)0 / 2 Met
||
Physical Protection (PE)0 / 6 Met
||
Risk Assessment (RA)0 / 3 Met
||
Security Assessment (CA)0 / 4 Met
||
System and Communications Protection (SC)0 / 16 Met
||
System and Information Integrity (SI)0 / 7 Met
||
Official SPRS Scorecard
-185Out of +110 Maximum
Completed0 / 110
Gaps (POA&M)110 Controls
Invalid Score SubmissionRule 3.12.4 (SSP) is unimplemented. You cannot legally submit an SPRS score without an SSP.
Invalid Score SubmissionRule 3.12.2 (POA&M) is unimplemented. Unmet controls must be linked to an active POA&M.
DoD SPRS Submission String
When uploading your score to the Supplier Performance Risk System (SPRS), you must submit this formatted string alongside your System Security Plan:
CMMC 2.0 Level 2 relies on the identical 110 controls of NIST SP 800-171. However, unlike SPRS which permits a negative score with a POA&M, CMMC does not allow long-term POA&Ms for certification. All controls must be fully met, or satisfy strict 180-day time-limited criteria.
Plan of Action & Milestones (POA&M) Status
Below are your identified cybersecurity compliance gaps. Assign an expected completion date and remediation owner for each item before printing your final System Security Plan package.
Control ID
Required Security Practice Description
Weight
Target Date
Remediation Owner
3.1.1
Limit system access to authorized users, processes acting on behalf of authorized users, or devices (including other systems).
-5
3.1.2
Limit system access to the types of transactions and functions that authorized users are permitted to execute.
-5
3.1.3
Control the flow of CUI in accordance with approved authorizations.
-5
3.1.4
Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
-1
3.1.5
Employ the principle of least privilege, including for specific security functions and privileged accounts.
-3
3.1.6
Use non-privileged accounts or roles when accessing non-security functions, and limit administrative privileges to only necessary activities.
-1
3.1.7
Prevent non-privileged users from executing privileged functions and audit the execution of such functions.
-1
3.1.8
Limit unsuccessful logon attempts.
-1
3.1.9
Provide privacy and security notices consistent with applicable CUI rules.
-1
3.1.10
Prevent system and device identification from being displayed before establishing an authenticated connection.
-1
3.1.11
Terminate (automatically) a user session after a defined condition for inactivity.
-5
3.1.12
Monitor and control remote access sessions.
-5
3.1.13
Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
-5
3.1.14
Route remote access via managed access control points.
-1
3.1.15
Authorize remote execution of privileged commands and security-relevant information.
-1
3.1.16
Authorize wireless access prior to allowing such connections.
-5
3.1.17
Protect wireless access using authentication and encryption.
-5
3.1.18
Control connection of mobile devices.
-5
3.1.19
Encrypt CUI on mobile devices and mobile computing platforms.
-3
3.1.20
Verify and control/limit connections to and use of external systems.
-5
3.1.21
Limit use of organizational portable storage devices on external systems.
-1
3.1.22
Control information posted or processed on publicly accessible systems.
-5
3.2.1
Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities.
-1
3.2.2
Ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.
-1
3.2.3
Provide insider threat awareness training.
-1
3.3.1
Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
-5
3.3.2
Ensure that organizational systems audit records contain information to establish what events occurred, the sources, and the outcomes.
-3
3.3.3
Review and update logged events.
-1
3.3.4
Alert in the event of an audit logging process failure.
-1
3.3.5
Correlate audit record review, analysis, and reporting processes for investigation and response to indications of inappropriate, unusual, or suspicious activity.
-5
3.3.6
Provide a system capability that compares and correlates audit records from multiple sources with other records to support security-relevant investigations.
-1
3.3.7
Provide a system-wide time source that is used to synchronize the clocks on system components.
-1
3.3.8
Protect audit information and audit tools from unauthorized access, modification, and deletion.
-1
3.3.9
Limit management of audit logging functionality to only a subset of privileged users.
-1
3.4.1
Establish and maintain baseline configurations and inventories of organizational systems throughout the respective system development life cycles.
-5
3.4.2
Enforce security configuration settings for information technology products employed in organizational systems.
-5
3.4.3
Track, review, approve, and audit changes to organizational systems.
-1
3.4.4
Analyze the security impact of changes prior to implementation.
-1
3.4.5
Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
-5
3.4.6
Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.
-5
3.4.7
Restrict, disable, or prevent the use of nonessential software.
-5
3.4.8
Apply deny-by-exception (blacklisting) or allow-all-by-exception (whitelisting) to control application execution.
-5
3.4.9
Control and monitor user-installed software.
-1
3.5.1
Identify system users, processes acting on behalf of users, or devices.
-5
3.5.2
Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational systems.
-5
3.5.3
Use multi-factor authentication (MFA) for local and network access to privileged accounts and for network access to non-privileged accounts.
Prevent reuse of identifiers for a defined period.
-1
3.5.6
Disable identifiers after a defined period of inactivity.
-1
3.5.7
Enforce minimum password complexity and change characters when new passwords are created.
-1
3.5.8
Establish password reuse rules.
-1
3.5.9
Limit temporary password use.
-1
3.5.10
Store and transmit only cryptographically-protected passwords.
-5
3.5.11
Obscure feedback during authentication process.
-1
3.6.1
Establish an operational incident-handling capability for organizational systems.
-1
3.6.2
Track, document, and report incidents to designated officials and/or authorities.
-1
3.6.3
Test the organizational incident-handling capability.
-1
3.7.1
Perform maintenance on organizational systems.
-3
3.7.2
Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.
-1
3.7.3
Ensure equipment containing CUI is sanitized before off-site maintenance.
-1
3.7.4
Control media containing diagnostic and test programs.
-3
3.7.5
Enforce safeguards for tools, techniques, mechanisms, and personnel used to conduct system maintenance.
-5
3.7.6
Supervise maintenance personnel without required access authorizations.
-1
3.8.1
Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.
-3
3.8.2
Limit access to CUI on system media to authorized users.
-3
3.8.3
Sanitize or destroy system media containing CUI before disposal or release for reuse.
-5
3.8.4
Mark media containing CUI with applicable security markings.
-1
3.8.5
Control access to media containing CUI and maintain accountability.
-1
3.8.6
Control the removal of media containing CUI from designated areas.
-1
3.8.7
Control the use of removable media on system components.
-5
3.8.8
Prohibit the use of portable storage devices when such devices have no identifiable owner.
-3
3.8.9
Protect the confidentiality of backup media containing CUI during transport.
-1
3.9.1
Screen individuals prior to authorizing access to organizational systems containing CUI.
-3
3.9.2
Ensure that organizational systems containing CUI remain protected upon transfer or termination of personnel.
-1
3.10.1
Limit physical access to organizational systems, equipment, and operating environments to authorized individuals.
-5
3.10.2
Protect and monitor physical facility and support infrastructure.
-1
3.10.3
Escort visitors and monitor visitor activity.
-5
3.10.4
Maintain audit logs of physical access.
-5
3.10.5
Control and manage physical access devices.
-5
3.10.6
Protect power and cabling infrastructure from damage/interception.
-1
3.11.1
Periodically assess the risk to organizational operations, assets, and individuals.
-3
3.11.2
Scan for vulnerabilities in organizational systems and applications periodically.
-5
3.11.3
Remediate vulnerabilities in accordance with risk assessments.
-1
3.12.1
Periodically assess the security controls in organizational systems to determine if they are effective.
-1
3.12.2
Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities.
-3
3.12.3
Monitor organizational system security controls on an ongoing basis.
-1
3.12.4
Develop, document, and periodically update system security plans (SSP) that describe system boundaries and security requirements.
-0
3.13.1
Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries.
-5
3.13.2
Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security.
-5
3.13.3
Separate user functionality from system management functionality.
-1
3.13.4
Prevent unauthorized and unintended information transfer via shared system resources.
-1
3.13.5
Implement subnetworks for publicly accessible system components.
-5
3.13.6
Deny network communications traffic by default and allow network communications traffic by exception.
-1
3.13.7
Prevent remote devices from establishing unauthorized connections.
-1
3.13.8
Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission.
-3
3.13.9
Terminate network connections associated with communications sessions upon defined conditions.
-1
3.13.10
Establish system-wide time synchronization.
-1
3.13.11
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
-5
3.13.12
Prohibit direct connection of collaborative devices to external systems.
-1
3.13.13
Control mobile code.
-1
3.13.14
Control Voice over IP (VoIP) technologies.
-1
3.13.15
Protect authenticity of communications sessions.
-1
3.13.16
Protect the confidentiality of CUI at rest.
-5
3.14.1
Identify, report, and correct system and information flaws in a timely manner.
-5
3.14.2
Provide protection from malicious code at appropriate locations.
-5
3.14.3
Monitor system security alerts and advisories and take appropriate actions.
-1
3.14.4
Update malicious code protection mechanisms when new releases are available.
-5
3.14.5
Perform periodic scans of organizational systems and real-time scans of files from external sources.
-5
3.14.6
Monitor organizational systems to detect attacks and indicators of potential attacks.
-1
3.14.7
Identify unauthorized use of organizational systems.
-3
Advertisement
Bottom Banner Ad (728x90)
Understanding NIST SP 800-171 & The DoD SPRS Scoring Methodology
Under the Defense Federal Acquisition Regulation Supplement (DFARS) Clause 252.204-7012, all defense contractors and subcontractors handling Controlled Unclassified Information (CUI) must implement the 110 cybersecurity requirements set forth in NIST SP 800-171. To prove compliance, the Department of Defense (DoD) requires contractors to conduct a self-assessment following the official DoD Assessment Methodology and submit their score to the Supplier Performance Risk System (SPRS).
How the SPRS Scoring Methodology Works
Instead of starting at zero and adding points as requirements are implemented, the SPRS assessment methodology operates on a deductive point model. The assessment begins with a perfect starting score of +110. For every security requirement that is not fully implemented, a weighted point deduction is subtracted from the score.
The point weights reflect the criticality of the security control and are defined as follows:
5-Point Deductions (42 Controls): Basic safeguards and critical derived security requirements. These represent essential parameters that, if missing, severely undermine systemic data integrity (e.g., multi-factor authentication, network boundary monitoring, and FIPS-validated encryption modules).
3-Point Deductions (14 Controls): Important requirements with a direct, but more localized, impact on the security of the network and CUI (e.g., least privilege controls, mobile device encryption, and physical media security).
1-Point Deductions (54 Controls): Administrative, organizational, or supportive security protocols that represent the remainder of the 110 controls.
If an organization has implemented zero controls, the total deduction sums to 313 points, resulting in a minimum possible score of -203.
The Two Key "Partial Credit" Exceptions
The official DoD scoring methodology allows for minor, partial credit on exactly two controls if specific sub-elements are satisfied, avoiding the full 5-point deduction:
Control 3.5.3 (Multi-Factor Authentication): If MFA is not implemented at all, a 5-point deduction is taken. However, if MFA is actively enforced for all remote and privileged access, but not yet completed for internal general network access, the deduction is reduced to 3 points.
Control 3.13.11 (FIPS-Validated Cryptography): If cryptography is not employed at all where required, a 5-point deduction is taken. If encryption is utilized to protect CUI but the cryptographic modules are not formally validated by NIST (FIPS 140-2 or 140-3 certification), the deduction is reduced to 3 points.
Critical Submission Prerequisites: The SSP and POA&M
There are two mandatory requirements in NIST SP 800-171 that carry a deduction value of 0 points but represent structural blockades if unimplemented:
System Security Plan (SSP) - Control 3.12.4: You cannot legally perform or submit an SPRS score if you do not have an active SSP. The SSP outlines the system boundaries, network architectures, and hardware/software inventories carrying CUI.
Plan of Action & Milestones (POA&M) - Control 3.12.2: If your organization has any score less than +110, you must have an active POA&M documenting how and when you plan to remediate the unimplemented gaps.
Our tool actively monitors the status of these two controls. If either is set to unimplemented, a prominent validation warning is displayed to prevent invalid compliance reporting.
Transitioning from SPRS to CMMC 2.0 Level 2
The upcoming Cybersecurity Maturity Model Certification (CMMC 2.0) standard codifies NIST SP 800-171 compliance into a formal third-party audit program. Organizations requiring a CMMC Level 2 (Advanced) certification will be assessed on the exact same 110 controls.
While the SPRS self-assessment score accommodates low and negative scores provided there is an active POA&M, CMMC 2.0 certifications are binary (Pass/Fail). To achieve CMMC certification, an organization must achieve a perfect score of +110, or temporarily utilize very limited 180-day POA&Ms for a specific subset of minor controls, which must be fully closed prior to final registration.