Skip to main content

Submitting Your SPRS Score to DoD

Written by Brady Price

Before you submit

Once your Supplier Performance Risk System (SPRS) score reflects your implementation work, you report it to the Department of Defense (DoD) through the SPRS portal. Your organization enters its own self-assessment results directly in SPRS. This article covers what you need first, how to get access, and the submission process.

SPRS stores your assessment results; it does not perform the assessment. Have these in place first:

  • A completed System Security Plan (SSP) and assessment. SPRS instructs that the assessment methodology and SSP be completed before entering results. The submission form collects summary details about your SSP, such as its name and date. See Building and Managing a System Security Plan (SSP).

  • Your assessment score from Secureframe. Your live score and its supporting documentation come from your System Security Plan. Learn more: Understanding Your SPRS Score in Secureframe

The process below follows SPRS's official NIST SP 800-171 Quick Entry Guide, which includes screenshots of each screen.


Step 1: Get SPRS access

SPRS does not have its own separate login. It is accessed through the Procurement Integrated Enterprise Environment (PIEE), the DoD's procurement platform. Before you can enter a score, you need two things:

  • A PIEE account: Register at piee.eb.mil.

  • The SPRS Cyber Vendor User role: Request access to SPRS with this role, which is what allows you to enter and edit self-assessment information. SPRS publishes step-by-step instructions for requesting it in the SPRS Access Cyber Reports guide.

Once your access is approved, you can add assessments for any CAGE (Commercial and Government Entity) code that falls within your company hierarchy.


Step 2: Enter your assessment

  1. Log in at piee.eb.mil and select the SPRS icon.

  2. Open the Cyber Reports module, select your company hierarchy from the dropdown, and click Run Cyber Reports. An asterisk next to a hierarchy entry indicates you hold the SPRS Cyber Vendor User role there.

  3. Open the NIST SP 800-171 Assessments tab and click Add New Assessment.

  4. Complete the assessment summary fields, including your assessment date, score, scope, plan of action completion date, confidence level, your SSP's name, version, and date, and the included CAGE codes.

  5. Save. Your record is assigned a DoD Unique Identifier.

To update a score later, edit the record with the pencil icon on the Basic tab, updating as necessary to reflect your company's current status. Basic confidence level assessments are the only ones vendors maintain themselves in SPRS. Assessment results turn red in SPRS once the assessment date is more than three years old.


Frequently Asked Questions (FAQ)

Does Secureframe submit my score to the DoD for me?

  • No. Secureframe calculates your score and maintains the supporting documentation, and your organization's SPRS Cyber Vendor User enters it in the portal.

Which score do I submit?

  • The live SPRS score shown on your System Security Plan dashboard, as of your assessment date.

The Add New Assessment button isn't showing. Why?

  • Adding and editing assessments requires the SPRS Cyber Vendor User role. Check your role status in PIEE. The SPRS website publishes access instructions for requesting the role.

Where can I get help with the portal?

  • SPRS publishes a NIST SP 800-171 Quick Entry Guide and an entry tutorial video on its NIST SP 800-171 page.

Did this answer your question?