industry

SPRS Score Calculator for Software & SaaS Providers

Prepare CMMC / NIST SP 800-171 scoring for SPRS — for software vendors and SaaS platforms that process DoD customers' CUI.

Software and SaaS providers that store, process, or transmit a customer's CUI are treated as External Service Providers — and, for cloud, as Cloud Service Providers. A CSP handling CUI must meet the FedRAMP Moderate baseline or demonstrate FedRAMP Moderate equivalency under DFARS 252.204-7012.

Your service is assessed as part of the customer's assessment, so the work is getting the boundary right: scope which components touch CUI, document the shared-responsibility split in a Customer Responsibility Matrix and the customer's SSP, and assess at the objective level.

A CSP handling CUI must meet FedRAMP Moderate (or equivalency) under DFARS 252.204-7012.

What's typically in scope for Software & SaaS Providers

How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.

AssetCategoryWhat it means
The application tier / databases storing customer CUI
CUI
CUI-handling CSP — must meet FedRAMP Moderate or equivalency (DFARS 7012).
Admin / support tooling that can reach customer CUI
Security Protection
Assessed against the capability it provides.
Logging / monitoring you provide for the CUI service
Security Protection
Security Protection Assets.
Internal corporate systems with no customer CUI
Out-of-Scope
Out of scope with justified separation.

Where Software & SaaS Providers teams usually focus

Common areas to shore up — your real gaps come from the assessment, not a generic list.

  • FedRAMP Moderate (or equivalency) for the CUI-handling service
  • A precise Customer Responsibility Matrix + SSP boundary
  • Tenant isolation so CUI never crosses customers
  • FIPS-validated encryption of CUI at rest and in transit
  • Privileged-access management for support/admin
Map the 800-171 ↔ CMMC controls

Which CMMC level you need

Your CUI-handling service is assessed within each customer's Level 2 assessment; the FedRAMP Moderate (or equivalency) bar applies to the cloud itself.

Run the level-determination wizard

What you need to know

  • Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
  • A score of 110 is a Final self-assessment; 88109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
  • A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Read the full walkthrough

Clauses that likely apply to you

DFARS 252.204-7012
DFARS 252.204-7019
DFARS 252.204-7021
DFARS 252.204-7020
See what each clause requires
SentryNexus scoring dashboard: 106 of 110 but No CMMC Status — one disqualifying gap that can't be placed on a POA&M.
A 106/110 that's still “No CMMC Status” — one disqualifying gap that can't be deferred (32 CFR 170.21). The split a score-only calculator misses.

Know your score before you submit

Run a full 110-requirement self-assessment free — no account required to see your score.

Start free assessment

Free tools

Frequently asked questions

Are software vendors selling to DoD in scope?
If your product stores, processes, or transmits a customer's CUI, you are an External Service Provider (and, for cloud, a Cloud Service Provider) in scope — and CUI-handling cloud must meet FedRAMP Moderate or equivalency.
We are SaaS — do we self-assess, or does our customer?
Your service is assessed as part of the customer's assessment. You document your responsibilities in a Customer Responsibility Matrix and your SSP.
What does the FedRAMP requirement mean for us?
A CSP handling CUI must meet the FedRAMP Moderate baseline or equivalency under DFARS 252.204-7012 — plan for the bodies of evidence that demonstrate it.
Do we get 'CMMC certified' as a SaaS vendor?
Not on your own in most cases — your service is assessed within each customer's Level 2 assessment, documented via the CRM and their SSP. The separate bar is FedRAMP Moderate (or equivalency) for the cloud handling CUI.
What if only part of our platform touches CUI?
Scope to the components that store, process, or transmit CUI and separate them; clearly-isolated components with no CUI can stay Out-of-Scope, which shrinks both the assessment and the FedRAMP burden.

Need a provider?

As an External Service Provider, the right MSP/MSSP, vCISO, or C3PAO can shorten the path. Browse vetted providers — free, no account.

Explore the provider marketplace

Related industries

Related guides

Go deeper on scoring, levels, and POA&Ms.