SPRS Score Calculator for IT Services & MSPs
Prepare CMMC / NIST SP 800-171 scoring for SPRS — for IT and managed service providers in the defense supply chain.
IT-services firms and MSPs usually enter CMMC scope from a different door than their clients: as External Service Providers (ESPs). If you store, process, or transmit a client's CUI — or provide security-protection capabilities for it — your relevant services are assessed as part of, or alongside, that client's assessment.
Two distinctions decide everything. First, are you handling CUI, only providing security protection (Security Protection Data), or neither? A provider that touches neither CUI nor SPD isn't an ESP at all. Second, if you run cloud that handles CUI you're a Cloud Service Provider — and a CSP handling CUI must meet the FedRAMP Moderate baseline or demonstrate FedRAMP Moderate equivalency under DFARS 252.204-7012.
Your relationship and services belong in the client's SSP, with an ESP service description and a Customer Responsibility Matrix (CRM) that draws the line between what you secure and what they do. Getting that boundary precise is what keeps both sides defensible.
What's typically in scope for IT Services & Managed Service Providers
How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.
| Asset | Category | What it means |
|---|---|---|
| Help-desk / RMM / admin tooling that can reach the client's CUI environment | Security Protection | Provides a management/security capability to the scope — assessed against the relevant requirements. |
| A cloud platform you operate that stores or transmits client CUI | CUI | A CUI-handling CSP must meet FedRAMP Moderate (or equivalency) under DFARS 252.204-7012. |
| SIEM / EDR / managed detection you provide for the client's CUI | Security Protection | Security Protection Assets — assessed against the capabilities they provide. |
| Your corporate systems that never touch client CUI or SPD | Out-of-Scope | Not an ESP relationship for those systems — out of scope, with justification. |
Where IT Services & Managed Service Providers teams usually focus
Common areas to shore up — your real gaps come from the assessment, not a generic list.
- Drawing the ESP boundary in the client SSP + a Customer Responsibility Matrix
- FedRAMP Moderate (or equivalency) for any cloud that handles CUI
- Privileged-access management and MFA for admin/RMM tooling
- Audit logging and monitoring across the services you provide
- Multi-tenant separation so one client's CUI never bleeds into another's
Which CMMC level you need
MSPs aren't usually “certified” on their own — your in-scope services are assessed within the client's Level 2 assessment. If you also hold CUI under your own DoD contract (with DFARS 7019/7020), you carry your own SPRS obligation too.
Run the level-determination wizardWhat you need to know
- Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
- A score of 110 is a Final self-assessment; 88–109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
- A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Clauses that likely apply to you

Know your score before you submit
Run a full 110-requirement self-assessment free — no account required to see your score.
Start free assessmentFree tools
Frequently asked questions
- Are MSPs in CMMC scope?
- If you handle CUI, or provide security-protection capabilities for a client's CUI, your relevant services are assessed — as an External Service Provider — as part of or alongside the client's assessment.
- Does our cloud need FedRAMP?
- If you are a Cloud Service Provider handling CUI, the service must meet the FedRAMP Moderate baseline or equivalency under DFARS 252.204-7012.
- How do we document our part?
- Your ESP relationship and services go in the client's SSP, along with an ESP service description and a Customer Responsibility Matrix (CRM).
- We never touch the client's CUI — are we still in scope?
- If you provide security-protection capabilities for their CUI (SIEM, EDR, identity), those assets are Security Protection Assets and are assessed. If you handle neither CUI nor security-protection data, you're not an ESP for CMMC purposes.
- What does FedRAMP Moderate equivalency actually require?
- Under DFARS 252.204-7012 a CSP handling CUI must meet the FedRAMP Moderate baseline or demonstrate equivalency — which carries its own bodies-of-evidence requirements per the DoD memo. Plan for the documentation that proves it, not just a self-claim.
- Can one assessment cover all our clients?
- No single assessment certifies an MSP across clients, but a well-documented, consistently-applied service can be referenced in each client's SSP/CRM. Strong multi-tenant separation and uniform controls make that far easier.
Need a provider?
As an External Service Provider, the right MSP/MSSP, vCISO, or C3PAO can shorten the path. Browse vetted providers — free, no account.
Explore the provider marketplaceRelated industries
Related guides
Go deeper on scoring, levels, and POA&Ms.