industry

SPRS Score Calculator for Aerospace Contractors

Prepare your CMMC / NIST SP 800-171 score for SPRS — built for aerospace primes and suppliers handling CUI.

Aerospace primes and suppliers routinely handle controlled technical information (CTI) — engineering drawings, specifications, test and analysis data — alongside export-controlled (ITAR/EAR) material. Almost all of that is Controlled Unclassified Information, which places aerospace firms squarely in CMMC Level 2 (NIST SP 800-171) scope.

What makes aerospace distinctive is supply-chain depth: CUI flows down from primes through multiple supplier tiers by contract, so even small shops can inherit the obligation. The practical question is rarely “are we in scope” but “which of our systems are” — and that is a scoping exercise (32 CFR 170.19) before it is an assessment.

The defensible path is to inventory the systems that touch CTI/CUI, categorize every asset, then assess at the objective level — so partial credit (MFA, FIPS-validated encryption) and POA&M-eligibility are scored the way an assessor would, not the all-or-nothing estimate a quick calculator produces.

What's typically in scope for Aerospace Contractors

How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.

AssetCategoryWhat it means
PLM/PDM and CAD systems holding drawings and specs
CUI
Store and transmit CTI — assessed against all Level 2 requirements.
Engineering workstations and file shares with program data
CUI
Hold CUI directly; in scope as CUI Assets.
An MSP/MSSP or SIEM securing the CUI environment
Security Protection
Assessed only against the requirements relevant to the security capability it provides.
Test stands and lab/measurement equipment that can't be fully hardened
Specialized
Reviewed via the SSP, not assessed against every requirement (§170.19).
Corporate IT with no CUI and proper separation
Out-of-Scope
Out of scope — but you must be able to justify the separation.

Where Aerospace Contractors teams usually focus

Common areas to shore up — your real gaps come from the assessment, not a generic list.

  • Access control and multi-factor authentication across engineering and PLM systems
  • FIPS-validated encryption for CTI at rest and in transit
  • Media protection and CUI marking for drawings and specifications
  • Configuration management of CAD/PLM environments
  • Flowing the requirement down to lower-tier suppliers
Map the 800-171 ↔ CMMC controls

Which CMMC level you need

Aerospace firms handling CUI need Level 2 at minimum. Whether that is a self-assessment or a C3PAO certification turns on whether your CUI is in the DoD Organizational Index Grouping — confirm against your contract and prime; the level-determination wizard walks the decision.

Run the level-determination wizard

What you need to know

  • Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
  • A score of 110 is a Final self-assessment; 88109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
  • A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Read the full walkthrough

Clauses that likely apply to you

DFARS 252.204-7012
DFARS 252.204-7019
DFARS 252.204-7021
FAR 52.204-21
See what each clause requires
SentryNexus scoring dashboard: 106 of 110 but No CMMC Status — one disqualifying gap that can't be placed on a POA&M.
A 106/110 that's still “No CMMC Status” — one disqualifying gap that can't be deferred (32 CFR 170.21). The split a score-only calculator misses.

Know your score before you submit

Run a full 110-requirement self-assessment free — no account required to see your score.

Start free assessment

Free tools

Frequently asked questions

Do aerospace contractors handle CUI?
Most do. Controlled technical information — drawings, specifications, test data — and export-controlled (ITAR/EAR) data are CUI, which places you in Level 2 (NIST SP 800-171) scope.
Do I need a Level 2 self-assessment or a C3PAO certification?
It depends on where your CUI sits: CUI in the DoD Organizational Index Grouping requires C3PAO certification; otherwise a Level 2 self-assessment is the minimum. Confirm against your contract and prime.
What is the fastest path to a defensible score?
Define your scope first — which systems touch CTI/CUI — then assess at the objective level so partial credit and gaps are scored the way an assessor would.
Doesn't ITAR registration already cover this?
No — ITAR governs the export of defense articles and technical data; CMMC / NIST SP 800-171 governs how you protect CUI on your information systems. Aerospace firms typically need both, and ITAR/EAR data is itself CUI in your CMMC scope.
How does CMMC flow down to our suppliers?
If you pass CUI to a supplier the requirement flows with it: handling CUI makes Level 2 (Self) their minimum, and a prime requiring C3PAO certification can raise a subcontractor's floor (32 CFR 170.23). FCI-only suppliers fall to Level 1.
How much does CMMC cost an aerospace supplier?
It depends on your gaps — the assessment itself is free here; the cost is remediating not-met requirements. Scope and self-assess first to see where you stand before budgeting.

Related industries

Related guides

Go deeper on scoring, levels, and POA&Ms.