industry
SPRS Score Calculator for Cybersecurity Firms
Self-score CMMC / NIST SP 800-171 for SPRS — for cybersecurity firms serving DoD customers.
Cybersecurity firms frequently provide security-protection capabilities to defense clients and may handle CUI or security-protection data themselves. Precise scoping of those assets drives an accurate SPRS score.
What you need to know
- Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
- A score of 110 is a Final self-assessment; 88–109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
- A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Clauses that likely apply to you
DFARS 252.204-7012
DFARS 252.204-7019
DFARS 252.204-7021
DFARS 252.204-7020
Know your score before you submit
Run a full 110-requirement self-assessment free — no account required to see your score.
Start free assessment