SPRS scoring explained: how to calculate your NIST SP 800-171 score
By the Atom Cybersecurity team
Almost every contractor handling Controlled Unclassified Information has been asked for a number: their NIST SP 800-171 score, posted in the Supplier Performance Risk System. Fewer can explain where the number comes from. It is not a percentage and it is not subjective. It is produced by a specific, published method — the DoD Assessment Methodology — and once you see the arithmetic, the score stops being mysterious and starts being something you can manage on purpose.
Start at 110, then subtract
The methodology begins from the assumption that you meet every control, awarding a perfect score of 110 — one notional point for each of the 110 security requirements in NIST SP 800-171. From that ceiling it subtracts points for each requirement you have not fully implemented. Crucially, a control is binary in scoring terms: it is either met in full or it is not met. There is no partial credit for a control that is half-done.
Because deductions can exceed the number of controls, the score is not bounded at zero. A contractor with many high-value gaps can land well below zero — a negative SPRS score is entirely possible and, in the early days of self-assessment, common. The floor is far lower than most people expect the first time they run the numbers honestly.
Why some controls cost 5 and others cost 1
Not every unmet control subtracts the same amount. The methodology assigns each requirement a weight of 1, 3, or 5 points based on how much risk its absence introduces to the protection of CUI. The heavier the security impact, the heavier the deduction.
- 5-point controls are the ones whose absence exposes CUI most directly — think multifactor authentication, boundary protection at the network edge, and other foundational safeguards. Missing one of these moves your score five times as far as a minor gap.
- 3-point controls carry meaningful but more contained risk — important safeguards whose absence weakens the environment without immediately opening the front door.
- 1-point controls are still required, but their individual absence has the least isolated impact on the confidentiality of CUI.
A handful of requirements have partial-credit nuances tied to how far a specific practice has been deployed, but the mental model that serves you well is simple: weighted subtraction from 110. This is why two contractors with the same count of open gaps can post very different scores — the weights, not the tally, are what move the number.
How a POA&M shows up in the score
A Plan of Action & Milestones does not earn back points. If a control is not met, the deduction applies whether or not you have a plan to fix it. The POA&M documents your intent and timeline to close the gap; it does not change today's score. This surprises people who expect "we're working on it" to soften the number. Under the methodology, the score reflects the environment as it actually stands on the assessment date.
The distinction matters even more under CMMC, where not every control is eligible to sit on a POA&M at all, and eligible items carry a strict closeout window. For the SPRS score itself, the rule to internalize is blunt: a POA&M records the debt; it does not pay it down.
Where the score lives — and who reads it
The score is posted in the Supplier Performance Risk System (SPRS), the government-of-record database for supplier assessment data. This is not a private worksheet. Once entered, the score — along with the assessment date and the scope it covers — is visible to the Department of Defense and to primes evaluating you for flow-down work.
The obligation to have a current score in SPRS traces back to DFARS 252.204-7012 and its companion assessment clauses; CMMC then builds verification on top of it via DFARS 252.204-7021. Practically, this means your self-reported number is a live business signal. A prime deciding whether to route CUI work your way can look it up, and a weak or stale score is a reason to route the work elsewhere.
A worked example
Suppose a mid-sized manufacturer runs the methodology honestly and finds the following open gaps:
- Multifactor authentication is not enforced for network access — a 5-point control, not met.
- Security event logging exists but is not reviewed — a 3-point control, not met.
- Two 3-point controls around configuration management are unmet — 3 + 3.
- Four low-impact administrative controls at 1 point each are unmet — 4 × 1.
The arithmetic: start at 110, then subtract 5 + 3 + 3 + 3 + 1 + 1 + 1 + 1 = 18 points. The posted SPRS score is 92. Notice that a single missed 5-point control did as much damage as five of the 1-point items combined — which is exactly the prioritization signal the weighting is designed to send.
How to raise it — in the right order
Because the deductions are weighted, the fastest path to a higher score is rarely the longest list of quick wins. It is closing the heavy controls.
- Close 5-point gaps first. Each one recovered is worth five 1-point fixes. MFA, boundary protection, and encryption of CUI in transit are common high-value targets.
- Score against the real boundary. A score is only meaningful for a defined system boundary. Padding the scope to look better does not survive a C3PAO and misrepresents your posture in SPRS.
- Put controls into genuine operation. A control counts as met only when it is actually running — not merely purchased. Turn it on, configure it, and generate the evidence.
- Re-score and re-post. As gaps close, recompute and update SPRS so the record reflects reality. A stale low score can cost you work you now qualify for.
Where Atom fits — and where we do not
We run the DoD Assessment Methodology with contractors the way an assessor would — scoping the CUI boundary, scoring all 110 controls without inflation, and translating the result into a prioritized remediation plan that moves the number for the least effort. We then keep the controls running so the score holds between affirmations. We are direct about one boundary: Atom is not a C3PAO and does not issue CMMC certifications. Our work is to make your SPRS score honest, defensible, and as high as your environment can legitimately support.
Find out what your SPRS score really is.
Request a readiness assessment. We scope your CUI environment, score it against NIST SP 800-171 using the DoD Assessment Methodology, and hand you a weighted, prioritized plan to raise it.
Request a Readiness Assessment →