SPRS Score Calculator for Professional & Staffing Services
Score CMMC / NIST SP 800-171 readiness for SPRS — for professional-services and staffing firms whose teams handle CUI.
Consulting, engineering-support, and staffing firms often create or receive CUI while performing services for defense clients. Whether your own systems are in scope hinges on where that CUI actually lives — and on a clearly documented boundary in your SSP.
If CUI only ever sits on the client's systems and never touches yours, your scope can be limited; the moment it lands on your laptops, email, or file shares, those become CUI Assets. Scope deliberately and assess at the objective level.
What's typically in scope for Professional & Staffing Services
How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.
| Asset | Category | What it means |
|---|---|---|
| Staff laptops / email / file shares that receive CUI | CUI | Assessed against all Level 2 requirements once CUI lands there. |
| Collaboration / PM systems holding client CUI | CUI | In scope as CUI Assets. |
| A managed IT/security provider for those systems | Security Protection | Assessed against the capability it provides. |
| Systems used only on client-owned environments | Out-of-Scope | Out of scope if CUI never lands on your systems — document the boundary. |
Where Professional & Staffing Services teams usually focus
Common areas to shore up — your real gaps come from the assessment, not a generic list.
- Deciding where CUI is allowed to live (and keeping it there)
- Access control + MFA on systems that touch CUI
- A documented SSP boundary for client work
- Encryption + media handling
- Staff training on CUI handling
Which CMMC level you need
FCI-only services point to Level 1; any CUI on your systems raises the floor to Level 2.
Run the level-determination wizardWhat you need to know
- Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
- A score of 110 is a Final self-assessment; 88–109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
- A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Clauses that likely apply to you

Know your score before you submit
Run a full 110-requirement self-assessment free — no account required to see your score.
Start free assessmentFree tools
Frequently asked questions
- Do professional and staffing firms handle CUI?
- If your staff create, receive, or store CUI while performing services, your systems are in scope for Level 2.
- Our people work on the client's systems — are we in scope?
- If CUI only ever lives on the client's systems and never touches yours, your scope may be limited — but you must be able to justify it. Document the boundary in your SSP.
- Level 1 or Level 2?
- FCI-only work points to Level 1; any CUI raises the minimum to Level 2.
- Our staff are embedded at the client site — are we in scope?
- If they only handle CUI on the client's systems, your scope may be limited — but document it. If they bring CUI onto your laptops or accounts, those systems are in scope.
- How do we keep scope minimal?
- Set a policy that CUI stays on client systems or a single controlled enclave, enforce it, and document the boundary in your SSP so unrelated systems are defensibly Out-of-Scope.
Related industries
Related guides
Go deeper on scoring, levels, and POA&Ms.