The purpose of the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 is to protect Controlled Unclassified Information (CUI) in nonfederal systems and organizations.
Businesses who want to fill Department of Defense (DoD) contracts must have their security controls in compliance with NIST 800-171 to meet the regulations. This is accomplished with the Supplier Performance Risk System (SPRS).
So, what do government contractors, or organizations who want to start contracting, need to know about SPRS?
Key Takeaways
- An SPRS score, ranging from -203 to 110, reflects a contractor’s self-assessed progress on the NIST SP 800-171 security requirements and must be posted before contract award or renewal.
- DFARS 252.204-7021 requires a designated Affirming Official to submit a separate annual affirmation of continuous compliance in SPRS.
- The DoW’s July 2026 suspension of CMMC Phase 2 paused third-party assessments, not the NIST SP 800-171 self-assessment or annual affirmation obligations contractors are responsible for.
- Submitting an inaccurate score or affirmation exposes both the company and the Affirming Official personally to False Claims Act liability.
Table of Contents
What is the Supplier Performance Risk System (SPRS)?
The Supplier Performance Risk System (SPRS) provides storage and retrieval capabilities for specific NIST SP 800-171r2 details. It is the authoritative source for gathering supplier and product performance information (PI) assessments for the DoW acquisition community to identify, assess, and monitor unclassified performance (DoDI 5000.79).
Businesses that want to fill DoW contracts must have their security controls in compliance with 800-171, which protects Controlled Unclassified Information (CUI). CUI is sensitive government data that isn’t classified but still requires protection. SPRS is where that compliance gets recorded and checked.
Empower your company with CMMC knowledge. This guide covers the process, benefits, maturity levels, and how to prepare for your CMMC audit.
What is an SPRS Assessment?
A SPRS assessment is the self-scored evaluation a contractor submits to show how completely it has implemented the 110 security requirements in NIST SP 800-171. As of November 30, 2020, Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7019 and 252.204-7020 require an accurate self-assessment score in SPRS before a contractor can be awarded a task order, delivery order, or option period of performance.
NOTE: This requirement exists on its own, separate from CMMC certification. You need a current score in SPRS no matter where your CMMC assessment stands.
What is an SPRS Score?
The SPRS score (pronounced “spurs” and also called a summary level score) is the number the DoW uses to gauge how thoroughly a defense contractor has implemented the 110 security requirements in NIST SP 800-171. Essentially, it’s a snapshot of how the contractor applies that framework.
That score also gives contracting officers one place to confirm whether you have reported your cybersecurity posture before a contract is awarded.
Posting an accurate score used to be the majority of the compliance story. However, now a separate, annual sign-off called the affirmation of compliance carries just as much legal weight. That requirement remains active even while CMMC Phase 2 is paused in Q3 of 2026.
What is the max SPRS score?
The highest score you can receive is 110. Each security control has a value attached to it: 1, 3, or 5. These values are deducted from the max score (i.e., 110) if the requirement is not met. The lowest score your business can get is -203. This is the equivalent of having no security controls in place.
Pro Tip: Do not avoid posting your score in fear that you will pale in comparison to your competitors. It is best to post your score because it’s a requirement for DoW contracts. So, having a score that’s visible is better than none at all. In fact, contractors and subcontractors must post a score indicating their progress toward NIST 800-171 compliance before a contract award or renewal of an existing contract.
Can you get DoD contracts with an SPRS score below 88?
Sometimes, yes. A score below 88 can be submitted to SPRS, but many contractors aim for 88 or higher because it has historically been associated with meeting DoW remediation expectations for critical requirements.
Lower scores indicate substantial unimplemented NIST SP 800-171 requirements and may impact your contract opportunities.
Ultimately, contract eligibility depends on the solicitation requirements, your assessment status, and the government’s evaluation of your cybersecurity posture.
How are SPRS scores calculated?
Scores are calculated using the NIST SP 800-171 DoD Assessment Scoring Template. This is a tedious process that requires a strong understanding of information technology solutions to produce an accurate result/score.
The self-assessment itself is very time intensive. It requires a thorough assessment of your security controls, analysis of your System Security Plan (SSP), and a Plan of Action and Milestone (POA&M) documentation to back it up.
Pro Tip: Always post an accurate score because you may be audited by the DoW. Such an audit requires documentation showing each security control has been met. Inaccurate scores, intentional or not, can put you on the hot seat. It’s bad for business.
What is the Annual Affirmation of Compliance in SPRS?
The annual affirmation is a separate, yearly attestation (required under DFARS 252.204-7021) in which a designated Affirming Official certifies in SPRS that the organization remains in continuous compliance with the CMMC level required for its contract.
Posting a numeric score does not satisfy this requirement; the affirmation is a distinct act by a named individual, and must be renewed at least once a year.
Put simply, every year a specific person at your company has to goes on record with the federal government stating that your environment is still compliant. That signature is what regulators and prime contractors rely on between CMMC assessments.
Why does the affirmation matter if a score is already posted?
Your posted score answers the question, “How compliant were we on the day we scored ourselves?” The affirmation explains whether you’re still that compliant.
So, you’re confirming that nothing has drifted out of compliance since the last assessment. This gives you the opportunity to catch emerging risk earlier, without you having to complete a full-blown audit every single year.
Who is the Affirming Official?
The Affirming Official is a senior company official with the authority to represent the organization. This is typically an owner or executive (not a compliance analyst or an outside consultant unlike some believe).
Because the affirmation is a personal attestation to the federal government tied to contract eligibility, it falls inside the reach of the False Claims Act.
How Does the CMMC Phase 2 Pause Affect SPRS And Affirmation Requirements?
It doesn’t change them. The Department of War paused CMMC Phase 2 requirements effective July 13, 2026, pausing the third-party assessment tier that was originally scheduled to take effect November 10, 2026. Phase 1 self-assessment requirements, along with the SPRS scoring and annual affirmation obligations under DFARS 252.204-7019, -7020, and -7021, remain fully in force.
Continue inputting accurate scores in SPRS, keep the Affirming Official’s annual sign-off current, and treat this pause as a reason to close security gaps rather than to set the program aside.
See a complete rundown in our coverage of the Department of War’s pause of CMMC Phase 2.
What You Need if You’re Improving Your Score
It’s perfectly acceptable if you’re currently working on improving your SPRS score. That said, there are a couple of things that you will need to complete before submitting your score sheet: the Plan of Action and Milestones (POA&M) and System Security Plan (SSP).
What is a System Security Plan (SSP)?
The SSP is a document that covers the scope of your computer network. It needs to provide a comprehensive overview of how you are securing your systems according to NIST SP 800-171 requirements – including the CUI environment, controls to protect CUI, and associated cybersecurity requirements.
The SSP should reflect how CUI is being protected because this is a central focus for both NIST 800-171 and CMMC. Information to cover includes:
- The types of CUI your business handles
- What you do with the CUI
- How you store, process, and transmit the CUI
- The controls in place to protect the CUI
- Known gaps in your compliance
Key access points to the network that should be noted are:
- Users
- IT providers
- Cloud service providers
- Other connected networks
What is a Plan of Action and Milestones (POA&M)?
As you’re creating your system security plan, make note of any NIST requirements that are not fulfilled. These items will require a POA&M to record:
- The steps that need to be taken to meet the requirements
- Who in your organization will ensure that each requirement is fulfilled
- When each requirement is expected to be completed
These are extensive documents that often require working with an expert compliance professional to complete – either with your in-house security team, a consultant, or an established managed IT service provider (MSP) experienced with CMMC requirements.
How can a managed IT service provider help with your SPRS score?
A qualified MSP – one with direct experience in regulated environments – can help you identify where your score is losing points, close the gaps that carry the highest weight, and make sure your documentation holds up if the DoW audits your self-assessment.
The hard part is finding the right one. Not every MSP understands DFARS, NIST SP 800-171, or what assessors expect to see. Before you bring a provider into your compliance program, it pays to ask the right questions first.
We put together a checklist specifically for defense contractors evaluating MSPs. It covers governance, shared responsibility, incident response, and the questions most contractors don’t think to ask until it’s too late.
Not sure whether your MSP candidates can deliver on CMMC? This checklist walks DIB contractors through the questions that separate qualified managed IT providers from those figuring it out alongside you.
Prioritize NIST 800-171 Now for Government Contracts Later
Think of NIST SP 800-171 as your requirement preparation checklist for your organization. They are the security elements your organization needs in place to earn contracts. Achieving a 110 SPRS score puts your organization in the best position for the future.
When the CMMC assessment arrives, everything needs to be checked off your “to-do” list. This will allow you to continue handling government contracts.
If you don’t have a perfect SPRS score, prioritize NIST 800-171 to set your organization up for success for when CMMC rolls out. Set realistic goals to complete your requirements but aim to complete them within 6 to 12 months.
Remember, an inaccurate score or an affirmation you can’t back up puts your contract eligibility and your Affirming Official’s personal liability on the line.
Speak with a Teal advisor about CMMC managed services and compliance consulting built to keep your SPRS score and your affirmation defensible today if you need help.
FAQ
What is SPRS?
SPRS, or the Supplier Performance Risk System, is the DoD system used to store and retrieve NIST SP 800‑171 DoD Assessment scores, including contractor self-reported Basic Assessments as well as Government Medium and High Assessments. A current and accurate SPRS score is required under DFARS 252.204-7019 and 252.204-7020 for eligibility for certain DoD contracts and serves as a prerequisite to CMMC Level 2 compliance and enforcement.
What happens if my SPRS score is inaccurate?
Do I still need to submit an annual affirmation if CMMC Phase 2 is suspended?
Yes. The affirmation requirement under DFARS 252.204-7021 is tied to Phase 1 self-assessment and to contracts that already require it. The Department of War’s suspension of Phase 2 does not remove the Affirming Official’s obligation to keep that annual sign-off current.




