industry

SPRS Score Calculator for IT Services & MSPs

Prepare CMMC / NIST SP 800-171 scoring for SPRS — for IT and managed service providers in the defense supply chain.

IT-services firms and MSPs usually enter CMMC scope from a different door than their clients: as External Service Providers (ESPs). If you store, process, or transmit a client's CUI — or provide security-protection capabilities for it — your relevant services are assessed as part of, or alongside, that client's assessment.

Two distinctions decide everything. First, are you handling CUI, only providing security protection (Security Protection Data), or neither? A provider that touches neither CUI nor SPD isn't an ESP at all. Second, if you run cloud that handles CUI you're a Cloud Service Provider — and a CSP handling CUI must meet the FedRAMP Moderate baseline or demonstrate FedRAMP Moderate equivalency under DFARS 252.204-7012.

Your relationship and services belong in the client's SSP, with an ESP service description and a Customer Responsibility Matrix (CRM) that draws the line between what you secure and what they do. Getting that boundary precise is what keeps both sides defensible.

What's typically in scope for IT Services & Managed Service Providers

How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.

AssetCategoryWhat it means
Help-desk / RMM / admin tooling that can reach the client's CUI environment
Security Protection
Provides a management/security capability to the scope — assessed against the relevant requirements.
A cloud platform you operate that stores or transmits client CUI
CUI
A CUI-handling CSP must meet FedRAMP Moderate (or equivalency) under DFARS 252.204-7012.
SIEM / EDR / managed detection you provide for the client's CUI
Security Protection
Security Protection Assets — assessed against the capabilities they provide.
Your corporate systems that never touch client CUI or SPD
Out-of-Scope
Not an ESP relationship for those systems — out of scope, with justification.

Where IT Services & Managed Service Providers teams usually focus

Common areas to shore up — your real gaps come from the assessment, not a generic list.

  • Drawing the ESP boundary in the client SSP + a Customer Responsibility Matrix
  • FedRAMP Moderate (or equivalency) for any cloud that handles CUI
  • Privileged-access management and MFA for admin/RMM tooling
  • Audit logging and monitoring across the services you provide
  • Multi-tenant separation so one client's CUI never bleeds into another's
Map the 800-171 ↔ CMMC controls

Which CMMC level you need

MSPs aren't usually “certified” on their own — your in-scope services are assessed within the client's Level 2 assessment. If you also hold CUI under your own DoD contract (with DFARS 7019/7020), you carry your own SPRS obligation too.

Run the level-determination wizard

What you need to know

  • Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
  • A score of 110 is a Final self-assessment; 88109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
  • A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Read the full walkthrough

Clauses that likely apply to you

DFARS 252.204-7012
DFARS 252.204-7019
DFARS 252.204-7021
DFARS 252.204-7020
See what each clause requires
SentryNexus scoring dashboard: 106 of 110 but No CMMC Status — one disqualifying gap that can't be placed on a POA&M.
A 106/110 that's still “No CMMC Status” — one disqualifying gap that can't be deferred (32 CFR 170.21). The split a score-only calculator misses.

Know your score before you submit

Run a full 110-requirement self-assessment free — no account required to see your score.

Start free assessment

Free tools

Frequently asked questions

Are MSPs in CMMC scope?
If you handle CUI, or provide security-protection capabilities for a client's CUI, your relevant services are assessed — as an External Service Provider — as part of or alongside the client's assessment.
Does our cloud need FedRAMP?
If you are a Cloud Service Provider handling CUI, the service must meet the FedRAMP Moderate baseline or equivalency under DFARS 252.204-7012.
How do we document our part?
Your ESP relationship and services go in the client's SSP, along with an ESP service description and a Customer Responsibility Matrix (CRM).
We never touch the client's CUI — are we still in scope?
If you provide security-protection capabilities for their CUI (SIEM, EDR, identity), those assets are Security Protection Assets and are assessed. If you handle neither CUI nor security-protection data, you're not an ESP for CMMC purposes.
What does FedRAMP Moderate equivalency actually require?
Under DFARS 252.204-7012 a CSP handling CUI must meet the FedRAMP Moderate baseline or demonstrate equivalency — which carries its own bodies-of-evidence requirements per the DoD memo. Plan for the documentation that proves it, not just a self-claim.
Can one assessment cover all our clients?
No single assessment certifies an MSP across clients, but a well-documented, consistently-applied service can be referenced in each client's SSP/CRM. Strong multi-tenant separation and uniform controls make that far easier.

Need a provider?

As an External Service Provider, the right MSP/MSSP, vCISO, or C3PAO can shorten the path. Browse vetted providers — free, no account.

Explore the provider marketplace

Related industries

Related guides

Go deeper on scoring, levels, and POA&Ms.