Skip to main content

Breaking Down SPRS

Written by Brady Price

What SPRS is

The Supplier Performance Risk System (SPRS) is the Department of Defense (DoD) database where contractors' cybersecurity assessment scores live. If your organization handles Controlled Unclassified Information (CUI) under DoD contracts, your SPRS score is how the government, and the primes you work with, see your cybersecurity readiness. It influences your eligibility for federal contracts.


What the score measures

Your SPRS score reflects a NIST SP 800-171 assessment of your environment: how many of the 110 security requirements you meet, weighted by how much each one matters.

  • Scoring starts at 110, the maximum, representing full compliance.

  • Each unmet requirement deducts 1, 3, or 5 points depending on its criticality.

  • The minimum possible score is -203, representing no requirements met.

The DoD allows limited partial credit for two requirements, multi-factor authentication (MFA) and FIPS-validated encryption, with specific deduction rules. A low or even negative starting score is normal, and the score rises as you implement requirements.


Why it matters

  • Contracting officers and primes check SPRS when awarding work, so a current score on file is part of staying eligible.

  • Scores should be updated at least annually and after significant changes to your security posture.

  • As of July 13, 2026, the DoD suspended the CMMC Phase II third-party assessment requirement pending a program review. Self-assessments and score submission remain required in the interim.


How Secureframe fits in

Secureframe calculates your SPRS score live from your System Security Plan, so you always know where you stand and what to fix. When you are ready, you submit the score to the DoD's SPRS portal.

Questions? Contact [email protected] or reach out to your CSM.

Did this answer your question?