SPRS Score Calculator for Defense Manufacturers
Score CMMC / NIST SP 800-171 readiness for SPRS — for manufacturers handling controlled technical information.
Defense manufacturers receive and generate controlled technical information — government and prime drawings, specifications, process sheets, and inspection data. That material is CUI, so manufacturers that hold it fall under CMMC Level 2 (NIST SP 800-171).
The wrinkle for manufacturing is the shop floor: CNC machines, PLCs, and other operational-technology (OT) gear often can't run modern security agents, yet they may receive program drawings. Under 32 CFR 170.19 those are typically Specialized Assets — reviewed through your SSP rather than assessed against all 110 requirements — which keeps the assessment focused on the IT systems that actually store and transmit CUI.
Get the categorization right and the scope (and the work) shrinks dramatically; get it wrong and you either over-build or leave a gap an assessor will find.
What's typically in scope for Defense Manufacturing
How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.
| Asset | Category | What it means |
|---|---|---|
| ERP/MES and file shares holding drawings, specs, and process data | CUI | Store/transmit CTI — assessed against all Level 2 requirements. |
| Engineering and quality workstations with program data | CUI | In scope as CUI Assets. |
| CNC machines / PLCs / OT that receive drawings but can't be fully secured | Specialized | Reviewed via the SSP; not assessed against every requirement (§170.19). |
| A managed-security provider or SIEM protecting the CUI network | Security Protection | Assessed against the requirements relevant to its capability. |
| Front-office / non-program IT with no CUI, separated | Out-of-Scope | Out of scope if you can justify the separation. |
Where Defense Manufacturing teams usually focus
Common areas to shore up — your real gaps come from the assessment, not a generic list.
- Categorizing OT/CNC correctly so the shop floor doesn't pull everything into scope
- Media protection, marking, and controlled disposal of drawings
- Physical protection of areas where CUI is handled
- Configuration management and least-privilege on engineering/quality systems
- FIPS-validated encryption for CUI in transit between sites and customers
Which CMMC level you need
Handling CUI puts manufacturers at Level 2. Self-assessment vs C3PAO depends on whether the CUI is in the DoD OIG — many build-to-print shops self-assess, but a prime can require certification; confirm against your contract.
Run the level-determination wizardWhat you need to know
- Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
- A score of 110 is a Final self-assessment; 88–109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
- A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Clauses that likely apply to you

Know your score before you submit
Run a full 110-requirement self-assessment free — no account required to see your score.
Start free assessmentFree tools
Frequently asked questions
- Are drawings and specifications considered CUI?
- Controlled technical information — drawings, specs, and process data — is CUI, so manufacturers handling it fall under Level 2 (NIST SP 800-171).
- We only make parts to a spec — are we really in scope?
- If the government drawings or specs you receive are marked or qualify as CUI/CTI, yes. The first step is scoping each system that stores or transmits that data.
- How do we keep the shop floor out of scope?
- Assets that cannot handle CUI and are separated can be Out-of-Scope; CNC/OT equipment may qualify as Specialized Assets reviewed via the SSP. Accurate 32 CFR 170.19 categorization is the key.
- We're build-to-print — is the data really ours to protect?
- Yes. If the government or prime drawings and specs you receive are CUI/CTI, you're responsible for protecting them on your systems while you hold them, regardless of who owns the design.
- Do we need Level 1 or Level 2?
- FCI-only work (basic contract info, no CUI) is Level 1 — 15 FAR 52.204-21 safeguards. The moment you receive CUI/CTI, Level 2 (the 110 NIST SP 800-171 requirements) becomes the floor.
- How much will compliance cost a small manufacturer?
- It depends entirely on your gaps — the assessment is free here; the cost is remediating not-met requirements. Scope and self-assess first before budgeting.
Related industries
Related guides
Go deeper on scoring, levels, and POA&Ms.