industry

SPRS Score Calculator for Defense Manufacturers

Score CMMC / NIST SP 800-171 readiness for SPRS — for manufacturers handling controlled technical information.

Defense manufacturers receive and generate controlled technical information — government and prime drawings, specifications, process sheets, and inspection data. That material is CUI, so manufacturers that hold it fall under CMMC Level 2 (NIST SP 800-171).

The wrinkle for manufacturing is the shop floor: CNC machines, PLCs, and other operational-technology (OT) gear often can't run modern security agents, yet they may receive program drawings. Under 32 CFR 170.19 those are typically Specialized Assets — reviewed through your SSP rather than assessed against all 110 requirements — which keeps the assessment focused on the IT systems that actually store and transmit CUI.

Get the categorization right and the scope (and the work) shrinks dramatically; get it wrong and you either over-build or leave a gap an assessor will find.

What's typically in scope for Defense Manufacturing

How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.

AssetCategoryWhat it means
ERP/MES and file shares holding drawings, specs, and process data
CUI
Store/transmit CTI — assessed against all Level 2 requirements.
Engineering and quality workstations with program data
CUI
In scope as CUI Assets.
CNC machines / PLCs / OT that receive drawings but can't be fully secured
Specialized
Reviewed via the SSP; not assessed against every requirement (§170.19).
A managed-security provider or SIEM protecting the CUI network
Security Protection
Assessed against the requirements relevant to its capability.
Front-office / non-program IT with no CUI, separated
Out-of-Scope
Out of scope if you can justify the separation.

Where Defense Manufacturing teams usually focus

Common areas to shore up — your real gaps come from the assessment, not a generic list.

  • Categorizing OT/CNC correctly so the shop floor doesn't pull everything into scope
  • Media protection, marking, and controlled disposal of drawings
  • Physical protection of areas where CUI is handled
  • Configuration management and least-privilege on engineering/quality systems
  • FIPS-validated encryption for CUI in transit between sites and customers
Map the 800-171 ↔ CMMC controls

Which CMMC level you need

Handling CUI puts manufacturers at Level 2. Self-assessment vs C3PAO depends on whether the CUI is in the DoD OIG — many build-to-print shops self-assess, but a prime can require certification; confirm against your contract.

Run the level-determination wizard

What you need to know

  • Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
  • A score of 110 is a Final self-assessment; 88109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
  • A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Read the full walkthrough

Clauses that likely apply to you

DFARS 252.204-7012
DFARS 252.204-7019
DFARS 252.204-7021
FAR 52.204-21
See what each clause requires
SentryNexus scoring dashboard: 106 of 110 but No CMMC Status — one disqualifying gap that can't be placed on a POA&M.
A 106/110 that's still “No CMMC Status” — one disqualifying gap that can't be deferred (32 CFR 170.21). The split a score-only calculator misses.

Know your score before you submit

Run a full 110-requirement self-assessment free — no account required to see your score.

Start free assessment

Free tools

Frequently asked questions

Are drawings and specifications considered CUI?
Controlled technical information — drawings, specs, and process data — is CUI, so manufacturers handling it fall under Level 2 (NIST SP 800-171).
We only make parts to a spec — are we really in scope?
If the government drawings or specs you receive are marked or qualify as CUI/CTI, yes. The first step is scoping each system that stores or transmits that data.
How do we keep the shop floor out of scope?
Assets that cannot handle CUI and are separated can be Out-of-Scope; CNC/OT equipment may qualify as Specialized Assets reviewed via the SSP. Accurate 32 CFR 170.19 categorization is the key.
We're build-to-print — is the data really ours to protect?
Yes. If the government or prime drawings and specs you receive are CUI/CTI, you're responsible for protecting them on your systems while you hold them, regardless of who owns the design.
Do we need Level 1 or Level 2?
FCI-only work (basic contract info, no CUI) is Level 1 — 15 FAR 52.204-21 safeguards. The moment you receive CUI/CTI, Level 2 (the 110 NIST SP 800-171 requirements) becomes the floor.
How much will compliance cost a small manufacturer?
It depends entirely on your gaps — the assessment is free here; the cost is remediating not-met requirements. Scope and self-assess first before budgeting.

Related industries

Related guides

Go deeper on scoring, levels, and POA&Ms.