SPRS Score Calculator for Software & SaaS Providers
Prepare CMMC / NIST SP 800-171 scoring for SPRS — for software vendors and SaaS platforms that process DoD customers' CUI.
Software and SaaS providers that store, process, or transmit a customer's CUI are treated as External Service Providers — and, for cloud, as Cloud Service Providers. A CSP handling CUI must meet the FedRAMP Moderate baseline or demonstrate FedRAMP Moderate equivalency under DFARS 252.204-7012.
Your service is assessed as part of the customer's assessment, so the work is getting the boundary right: scope which components touch CUI, document the shared-responsibility split in a Customer Responsibility Matrix and the customer's SSP, and assess at the objective level.
A CSP handling CUI must meet FedRAMP Moderate (or equivalency) under DFARS 252.204-7012.
What's typically in scope for Software & SaaS Providers
How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.
| Asset | Category | What it means |
|---|---|---|
| The application tier / databases storing customer CUI | CUI | CUI-handling CSP — must meet FedRAMP Moderate or equivalency (DFARS 7012). |
| Admin / support tooling that can reach customer CUI | Security Protection | Assessed against the capability it provides. |
| Logging / monitoring you provide for the CUI service | Security Protection | Security Protection Assets. |
| Internal corporate systems with no customer CUI | Out-of-Scope | Out of scope with justified separation. |
Where Software & SaaS Providers teams usually focus
Common areas to shore up — your real gaps come from the assessment, not a generic list.
- FedRAMP Moderate (or equivalency) for the CUI-handling service
- A precise Customer Responsibility Matrix + SSP boundary
- Tenant isolation so CUI never crosses customers
- FIPS-validated encryption of CUI at rest and in transit
- Privileged-access management for support/admin
Which CMMC level you need
Your CUI-handling service is assessed within each customer's Level 2 assessment; the FedRAMP Moderate (or equivalency) bar applies to the cloud itself.
Run the level-determination wizardWhat you need to know
- Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
- A score of 110 is a Final self-assessment; 88–109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
- A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Clauses that likely apply to you

Know your score before you submit
Run a full 110-requirement self-assessment free — no account required to see your score.
Start free assessmentFree tools
Frequently asked questions
- Are software vendors selling to DoD in scope?
- If your product stores, processes, or transmits a customer's CUI, you are an External Service Provider (and, for cloud, a Cloud Service Provider) in scope — and CUI-handling cloud must meet FedRAMP Moderate or equivalency.
- We are SaaS — do we self-assess, or does our customer?
- Your service is assessed as part of the customer's assessment. You document your responsibilities in a Customer Responsibility Matrix and your SSP.
- What does the FedRAMP requirement mean for us?
- A CSP handling CUI must meet the FedRAMP Moderate baseline or equivalency under DFARS 252.204-7012 — plan for the bodies of evidence that demonstrate it.
- Do we get 'CMMC certified' as a SaaS vendor?
- Not on your own in most cases — your service is assessed within each customer's Level 2 assessment, documented via the CRM and their SSP. The separate bar is FedRAMP Moderate (or equivalency) for the cloud handling CUI.
- What if only part of our platform touches CUI?
- Scope to the components that store, process, or transmit CUI and separate them; clearly-isolated components with no CUI can stay Out-of-Scope, which shrinks both the assessment and the FedRAMP burden.
Need a provider?
As an External Service Provider, the right MSP/MSSP, vCISO, or C3PAO can shorten the path. Browse vetted providers — free, no account.
Explore the provider marketplaceRelated industries
Related guides
Go deeper on scoring, levels, and POA&Ms.