How to Calculate and Improve Your SPRS Score
The DoD Assessment Methodology turns 110 security requirements into a single number between −203 and 110. Here is exactly how the arithmetic works, what the score does and does not prove, and the highest-leverage way to raise it without gaming it.
Almost every conversation about defense cybersecurity compliance eventually collapses into a single number: your SPRS score. Contracting officers look at it, primes ask subcontractors for it, and it is the figure you are required to keep current before you can be awarded certain DoD work. Yet a surprising number of contractors post a score they cannot fully explain. This post takes the number apart — where it comes from, precisely how it is calculated, what it actually signals, and where the real leverage is when you want to move it up.
Where the score lives and why it is mandatory
SPRS is the Supplier Performance Risk System, a Department of Defense database. Three DFARS clauses put your cybersecurity posture into it and give it consequences. DFARS 252.204-7012 is the long-standing clause requiring you to safeguard covered defense information and to report cyber incidents to DoD within 72 hours. DFARS 252.204-7019 requires that you have a current NIST SP 800-171 assessment on file and that your summary score be posted in SPRS in order to be eligible for award. DFARS 252.204-7020 obligates you to provide the government access to conduct its own higher-level (Medium or High) assessment and to flow the requirement down to subcontractors. Together these clauses mean the score is not a marketing artifact; it is a gate, and an inaccurate one carries legal weight we return to below.
The calculation itself follows the DoD Assessment Methodology (the current published version is 1.2.1, dated June 24, 2020), applied against the 110 security requirements of NIST SP 800-171 Revision 2. That methodology is public, which is what makes the score reproducible rather than a black box.
The arithmetic, exactly
The model is deliberately simple, and understanding it removes most of the mystery. You start at 110, the score you earn if every one of the 110 requirements is fully implemented. For each requirement that is not implemented, you subtract a weighted value of 1, 3, or 5 points. The weight reflects how much the DoD believes that control matters to protecting CUI: the highest-impact requirements carry a 5-point subtractor, moderate ones a 3, and the least impactful a 1. Because the weights are uneven, a company that has missed a handful of heavy controls can score far worse than a company that has missed a larger number of light ones.
The fixed-weight census is 42 five-point, 14 three-point and 51 one-point requirements. Two more requirements have variable deductions: MFA (3.5.3) and FIPS-validated cryptography (3.13.11), each deducting 0 when MET, 3 for the methodology's specified partially effective case, or 5 when not implemented. The remaining requirement is the SSP (3.12.4), which is a prerequisite with no numeric weight. That accounts for all 110 requirements. The maximum deduction is 42×5 + 14×3 + 51×1 + 5 + 5 = 313, yielding the −203 arithmetic floor from a starting score of 110. This does not describe a valid assessment without an SSP: a current, complete SSP is required to perform the assessment. DoD methodology v1.2.1, section 5 and Annex A.
For MFA, the 3-point deduction applies when implemented only for remote and privileged users; no MFA earns the 5-point deduction. For CUI encryption, employed but non-FIPS-validated cryptography receives the specified 3-point deduction; no encryption receives 5. Review the actual requirements, evidence and methodology exceptions rather than assigning generic partial credit. POA&M eligibility is a separate requirement-level decision under 32 CFR 170.21; not every one-point requirement may be deferred.
What the number proves, and what it does not
Here is the honest limit of an SPRS score, and it is the same limit that applies to any self-reported metric. The score assumes every requirement you marked MET is genuinely and fully implemented, with evidence behind it. A self-assessment is only as truthful as the person filling it in, and optimism is common. That is precisely why the CMMC program layers a third-party certification assessment on top for CUI work: a C3PAO tests the reality behind your claims against the 320 assessment objectives in NIST SP 800-171A, using the Examine, Interview, and Test methods. A perfect 110 posted in SPRS does not mean you are certified, and it does not mean you would pass an independent assessment — it means you have asserted full implementation. The score is the on-ramp; the assessment is the gate. Treat your SPRS number as a planning instrument and an eligibility ticket, not as a finish line.
The highest-leverage way to raise it
Use recoverable points as one planning input after checking requirement eligibility, actual security impact, scope, dependencies and available evidence. Closing a fixed five-point gap recovers five times the arithmetic points of a fixed one-point gap, but that does not make the lower-weight item safe to defer. Several one-point requirements are expressly excluded from a Conditional Level 2 POA&M, while the narrow encryption exception depends on its implementation. Prioritize the actual work needed for your assessment path and security objective, then compare cost and score impact.
The SSP is a prerequisite, not a point to recover: without a current, complete SSP, an assessment cannot be completed. Once that prerequisite is met, accurate documentation and evidence can substantiate requirements already implemented. Missing evidence must be resolved through review; writing a description alone does not make a control MET.
The one thing you must not do
There is a tempting shortcut that has become a genuine liability: inflating the self-score. Because SPRS is self-reported, it is technically easy to post a number higher than your environment supports. It is also increasingly dangerous. The U.S. Department of Justice's Civil Cyber-Fraud Initiative, announced in October 2021, has pursued contractors under the False Claims Act for misrepresenting compliance with cybersecurity requirements, including NIST SP 800-171, and there have been public settlements over exactly this conduct. When a C3PAO assessment or a DoD Medium/High assessment later tests the reality, the gap between your posted score and your actual posture stops being a compliance problem and becomes a fraud problem. The correct move is always to post an honest score and close the gap, never to close the gap on paper alone.
From a number to a program
The most productive way to use your SPRS score is as the entry point to a real readiness sequence: get an honest baseline, rank the weighted gaps, fix the technical and documentation deficiencies, and track your posture against the 320 objectives that an assessor will actually examine. Our free SPRS score estimator provides a planning range from counts for the 107 fixed-weight requirements, leaving MFA and encryption unassessed. It is not a requirement-level baseline, a reportable score or a POA&M eligibility decision. It runs in your browser with no email required; use it to prepare questions, and then follow the broader path laid out on the CMMC overview. For how this fits the wider federal mandate set, see the federal and regulatory capability page.
Where Valty fits, honestly
To be precise about the boundary: Valty is not a C3PAO and cannot certify you or produce an official DoD assessment. What the platform does is compute and continuously monitor your SPRS score under the DoD Assessment Methodology, track your environment against all 320 assessment objectives, and rank open gaps by the score impact and effort of closing them — so remediation dollars go to the controls that move the number most. It also generates the OSCAL System Security Plan and POA&M artifacts that make an honest score defensible to an assessor. That is decision-support for reaching a real score, not a way to manufacture one. The distinction is the entire point: a score is only worth what it will survive when someone else tests it.
Inspect the fictional sample decision memo, or request a platform demo to explore the supported workflow with illustrative data. Company scope, evidence handling, access, onboarding and commercial terms are agreed separately before evaluation.


