Free SPRS Score Calculator

Run the full 110-requirement NIST SP 800-171 Rev 2 self-assessment and see your CMMC Level 2 score and status instantly. No account required to see your score.

No credit card · No account needed for your score · Not an official SPRS submission

How it works

Step 1

Answer 110 requirements

Work through all 110 requirements at the objective level — 319 SP 800-171A objectives — right in your browser.

Step 2

See your score

Get your live SPRS score, CMMC L2 status, and a breakdown of POA&M-eligible vs disqualifying gaps.

Step 3

Save your assessment (free)

Create a free account to save one assessment, resume later, review POA&M eligibility, and use the SPRS entry helper. Upgrade to Assess for evidence capture, remediation planning, and full SPRS-ready record exports.

Scored the right way

Scored against the NIST SP 800-171 Rev 2 DoD Assessment Methodology v1.2.1, with 32 CFR Part 170 thresholds — including correct partial credit for MFA (3.5.3) and FIPS-validated cryptography (3.13.11), and 32 CFR 170.21 POA&M eligibility. Baseline 110; 110 is Final, 88109 is Conditional.

Learn how SPRS scoring works

Plain-English guides to the methodology behind your score.

What this self-assessment covers

A CMMC Level 2 (Advanced) self-assessment is scored against the 110 security requirements in NIST SP 800-171 Rev 2 — the controls that protect Controlled Unclassified Information (CUI). This tool walks through all 110 requirements, organized into the 14 requirement families below, and assesses each at the level of its 319 NIST SP 800-171A assessment objectives.

  • Access Control22
  • Awareness and Training3
  • Audit and Accountability9
  • Configuration Management9
  • Identification and Authentication11
  • Incident response3
  • Maintenance6
  • Media Protection9
  • Personnel Security2
  • Physical Protection6
  • Risk Assessment3
  • Security Assessment4
  • System and Communications Protection16
  • System and Information Integrity7

How your score is calculated

Scoring follows the DoD Assessment Methodology: you start at a baseline of 110 (every requirement implemented), and each requirement that is not met subtracts its weighted value — 5 points for high-impact requirements, 3 for confined-effect requirements, and 1 for the rest. Because deductions stack, the score can go negative (as low as −203). You answer at the objective level and the result rolls up: a requirement is Met only when all of its applicable objectives are Met, and an objective marked N/A counts the same as Met. A score of 110 is a Final self-assessment; 88109 is Conditional (with a POA&M to close the gap); below 88 you cannot yet affirm a Conditional or Final status.

Partial credit for MFA and encryption

Two requirements carry built-in partial credit instead of a simple met/not-met. For multifactor authentication (3.5.3): −5 if MFA is not implemented at all, −3 if it covers only remote and privileged users, 0 if fully implemented. For cryptography (3.13.11): −5 if no cryptography is used, −3 if encryption is used but not FIPS-validated, 0 if FIPS-validated. The tool captures the right level so your score reflects partial implementation accurately.

Your answers stay in your browser

The guest assessment runs entirely in your browser. Your answers are saved to this browser's local storage only — nothing is sent to a server and no account is required to see your score, status, and gaps. When you're ready to keep your work, sign in with a free account and your in-progress assessment is claimed into it; until then it never leaves your device.

Free vs. paid

A free account saves one Level 2 self-assessment you can resume any time, and gives you your score, status, and gap summary — including which gaps are POA&M-eligible vs disqualifying — the validity & reaffirmation calendar, and the SPRS entry helper (a clean summary of exactly what to enter in SPRS).

Pro adds evidence capture per objective, the prioritized remediation plan, the full print/PDF assessment-record export, the NIST SP 800-171 Rev 3 readiness track, and email reaffirmation reminders.