SPRS Score Calculator for Cybersecurity Firms
Self-score CMMC / NIST SP 800-171 for SPRS — for cybersecurity firms serving DoD customers.
Cybersecurity firms usually enter scope as External Service Providers: providing security-protection capabilities for a defense client's CUI makes those assets Security Protection Assets, assessed against the requirements relevant to the capability — and handling CUI yourself pulls in the full Level 2 set.
The lever is precise §170.19 categorization. A SIEM, EDR, or identity service you run for a client is a Security Protection Asset; systems where the client's CUI lands are CUI Assets. Document the relationship and boundary in the client's SSP and a Customer Responsibility Matrix.
What's typically in scope for Cybersecurity Firms
How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.
| Asset | Category | What it means |
|---|---|---|
| SIEM / EDR / MDR you operate for a client's CUI | Security Protection | Assessed against the capabilities provided (§170.19). |
| Identity/PAM and admin tooling reaching the client's CUI | Security Protection | Security Protection Asset — assessed against its capability. |
| Your systems that store or transmit client CUI | CUI | Assessed against all Level 2 requirements; CUI-handling cloud needs FedRAMP Moderate or equivalency. |
| Corporate systems with no client CUI or SPD | Out-of-Scope | Not an ESP relationship — out of scope with justification. |
Where Cybersecurity Firms teams usually focus
Common areas to shore up — your real gaps come from the assessment, not a generic list.
- Categorizing each service as a Security Protection Asset vs a CUI Asset
- FedRAMP Moderate (or equivalency) for any CUI-handling cloud
- Privileged-access management + MFA on admin tooling
- Audit logging across delivered services
- The ESP boundary in the client SSP + CRM
Which CMMC level you need
Your in-scope services are assessed within the client's Level 2 assessment; if you also hold CUI under your own DoD contract, you carry your own SPRS obligation.
Run the level-determination wizardWhat you need to know
- Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
- A score of 110 is a Final self-assessment; 88–109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
- A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Clauses that likely apply to you

Know your score before you submit
Run a full 110-requirement self-assessment free — no account required to see your score.
Start free assessmentFree tools
Frequently asked questions
- Are we in scope if we only provide security services?
- Providing security-protection capabilities for a client's CUI makes those assets Security Protection Assets, assessed against the relevant requirements; handling CUI yourself pulls in the full set.
- How is a Security Protection Asset assessed?
- Against the Level 2 requirements relevant to the capability it provides — not necessarily all 110. Accurate categorization under 32 CFR 170.19 sets the bar.
- Do we need our own SPRS score?
- If you handle CUI under a DoD contract with the DFARS 7019/7020 clauses, yes.
- Are we an ESP if we never touch the client's CUI?
- If you provide security-protection capabilities for their CUI, yes — those assets are Security Protection Assets. A provider handling neither CUI nor security-protection data isn't an ESP.
- Does our SOC platform need FedRAMP?
- If it's cloud that stores or transmits the client's CUI, it must meet FedRAMP Moderate or equivalency under DFARS 252.204-7012. A pure security-monitoring capability is scoped as a Security Protection Asset.
Need a provider?
As an External Service Provider, the right MSP/MSSP, vCISO, or C3PAO can shorten the path. Browse vetted providers — free, no account.
Explore the provider marketplaceRelated industries
Related guides
Go deeper on scoring, levels, and POA&Ms.