industry

SPRS Score Calculator for Cybersecurity Firms

Self-score CMMC / NIST SP 800-171 for SPRS — for cybersecurity firms serving DoD customers.

Cybersecurity firms usually enter scope as External Service Providers: providing security-protection capabilities for a defense client's CUI makes those assets Security Protection Assets, assessed against the requirements relevant to the capability — and handling CUI yourself pulls in the full Level 2 set.

The lever is precise §170.19 categorization. A SIEM, EDR, or identity service you run for a client is a Security Protection Asset; systems where the client's CUI lands are CUI Assets. Document the relationship and boundary in the client's SSP and a Customer Responsibility Matrix.

What's typically in scope for Cybersecurity Firms

How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.

AssetCategoryWhat it means
SIEM / EDR / MDR you operate for a client's CUI
Security Protection
Assessed against the capabilities provided (§170.19).
Identity/PAM and admin tooling reaching the client's CUI
Security Protection
Security Protection Asset — assessed against its capability.
Your systems that store or transmit client CUI
CUI
Assessed against all Level 2 requirements; CUI-handling cloud needs FedRAMP Moderate or equivalency.
Corporate systems with no client CUI or SPD
Out-of-Scope
Not an ESP relationship — out of scope with justification.

Where Cybersecurity Firms teams usually focus

Common areas to shore up — your real gaps come from the assessment, not a generic list.

  • Categorizing each service as a Security Protection Asset vs a CUI Asset
  • FedRAMP Moderate (or equivalency) for any CUI-handling cloud
  • Privileged-access management + MFA on admin tooling
  • Audit logging across delivered services
  • The ESP boundary in the client SSP + CRM
Map the 800-171 ↔ CMMC controls

Which CMMC level you need

Your in-scope services are assessed within the client's Level 2 assessment; if you also hold CUI under your own DoD contract, you carry your own SPRS obligation.

Run the level-determination wizard

What you need to know

  • Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
  • A score of 110 is a Final self-assessment; 88109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
  • A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Read the full walkthrough

Clauses that likely apply to you

DFARS 252.204-7012
DFARS 252.204-7019
DFARS 252.204-7021
DFARS 252.204-7020
See what each clause requires
SentryNexus scoring dashboard: 106 of 110 but No CMMC Status — one disqualifying gap that can't be placed on a POA&M.
A 106/110 that's still “No CMMC Status” — one disqualifying gap that can't be deferred (32 CFR 170.21). The split a score-only calculator misses.

Know your score before you submit

Run a full 110-requirement self-assessment free — no account required to see your score.

Start free assessment

Free tools

Frequently asked questions

Are we in scope if we only provide security services?
Providing security-protection capabilities for a client's CUI makes those assets Security Protection Assets, assessed against the relevant requirements; handling CUI yourself pulls in the full set.
How is a Security Protection Asset assessed?
Against the Level 2 requirements relevant to the capability it provides — not necessarily all 110. Accurate categorization under 32 CFR 170.19 sets the bar.
Do we need our own SPRS score?
If you handle CUI under a DoD contract with the DFARS 7019/7020 clauses, yes.
Are we an ESP if we never touch the client's CUI?
If you provide security-protection capabilities for their CUI, yes — those assets are Security Protection Assets. A provider handling neither CUI nor security-protection data isn't an ESP.
Does our SOC platform need FedRAMP?
If it's cloud that stores or transmits the client's CUI, it must meet FedRAMP Moderate or equivalency under DFARS 252.204-7012. A pure security-monitoring capability is scoped as a Security Protection Asset.

Need a provider?

As an External Service Provider, the right MSP/MSSP, vCISO, or C3PAO can shorten the path. Browse vetted providers — free, no account.

Explore the provider marketplace

Related industries

Related guides

Go deeper on scoring, levels, and POA&Ms.