industry

SPRS Score Calculator for Professional & Staffing Services

Score CMMC / NIST SP 800-171 readiness for SPRS — for professional-services and staffing firms whose teams handle CUI.

Consulting, engineering-support, and staffing firms often create or receive CUI while performing services for defense clients. Whether your own systems are in scope hinges on where that CUI actually lives — and on a clearly documented boundary in your SSP.

If CUI only ever sits on the client's systems and never touches yours, your scope can be limited; the moment it lands on your laptops, email, or file shares, those become CUI Assets. Scope deliberately and assess at the objective level.

What's typically in scope for Professional & Staffing Services

How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.

AssetCategoryWhat it means
Staff laptops / email / file shares that receive CUI
CUI
Assessed against all Level 2 requirements once CUI lands there.
Collaboration / PM systems holding client CUI
CUI
In scope as CUI Assets.
A managed IT/security provider for those systems
Security Protection
Assessed against the capability it provides.
Systems used only on client-owned environments
Out-of-Scope
Out of scope if CUI never lands on your systems — document the boundary.

Where Professional & Staffing Services teams usually focus

Common areas to shore up — your real gaps come from the assessment, not a generic list.

  • Deciding where CUI is allowed to live (and keeping it there)
  • Access control + MFA on systems that touch CUI
  • A documented SSP boundary for client work
  • Encryption + media handling
  • Staff training on CUI handling
Map the 800-171 ↔ CMMC controls

Which CMMC level you need

FCI-only services point to Level 1; any CUI on your systems raises the floor to Level 2.

Run the level-determination wizard

What you need to know

  • Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
  • A score of 110 is a Final self-assessment; 88109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
  • A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Read the full walkthrough

Clauses that likely apply to you

DFARS 252.204-7012
DFARS 252.204-7019
DFARS 252.204-7021
See what each clause requires
SentryNexus scoring dashboard: 106 of 110 but No CMMC Status — one disqualifying gap that can't be placed on a POA&M.
A 106/110 that's still “No CMMC Status” — one disqualifying gap that can't be deferred (32 CFR 170.21). The split a score-only calculator misses.

Know your score before you submit

Run a full 110-requirement self-assessment free — no account required to see your score.

Start free assessment

Free tools

Frequently asked questions

Do professional and staffing firms handle CUI?
If your staff create, receive, or store CUI while performing services, your systems are in scope for Level 2.
Our people work on the client's systems — are we in scope?
If CUI only ever lives on the client's systems and never touches yours, your scope may be limited — but you must be able to justify it. Document the boundary in your SSP.
Level 1 or Level 2?
FCI-only work points to Level 1; any CUI raises the minimum to Level 2.
Our staff are embedded at the client site — are we in scope?
If they only handle CUI on the client's systems, your scope may be limited — but document it. If they bring CUI onto your laptops or accounts, those systems are in scope.
How do we keep scope minimal?
Set a policy that CUI stays on client systems or a single controlled enclave, enforce it, and document the boundary in your SSP so unrelated systems are defensibly Out-of-Scope.

Related industries

Related guides

Go deeper on scoring, levels, and POA&Ms.