Required under DFARS 252.204-7012, this score measures whether a contractor has implemented the security requirements defined in NIST Special Publication 800-171, which also serve as the basis for CMMC Level 2 requirements outlined in MAD Security’s overview of CMMC compliance.
The SPRS score directly affects a contractor’s ability to compete for, retain, and renew Department of Defense contracts. It also serves as a key readiness indicator for Cybersecurity Maturity Model Certification Level 2. An unsupported, outdated, or inaccurate score can result in increased scrutiny, delayed awards, or loss of contract eligibility.
This article explains what an SPRS score represents, how it is calculated, what documentation supports it, and why accuracy is essential. It also outlines how the score factors into CMMC Level 2 preparation and long-term contract viability.
Scores range from -203 to +110. A score of +110 indicates that all 110 requirements are fully implemented with no deficiencies. Lower scores reflect gaps in implementation, with point deductions applied based on the severity and impact of each unmet requirement.
Contractors are required to maintain an active, current SPRS score to demonstrate compliance with DFARS 252.204-7012. This obligation applies to both prime contractors and subcontractors that store, process, or transmit Controlled Unclassified Information. The score must be supported by verifiable documentation rather than estimates or plans.
NIST SP 800-171 defines 110 security requirements across 14 control families, including access control, incident response, audit and accountability, and system integrity. These same requirements form the foundation of CMMC Level 2 and are central to the guidance provided on MAD Security’s CMMC hub.
Because of this alignment, the SPRS score functions as a practical snapshot of CMMC Level 2 readiness. When security requirements are not fully implemented, those deficiencies are reflected in the score. For organizations preparing for certification, the score helps identify areas where remediation is still needed.
The Department of Defense scoring methodology begins with a maximum of 110 points, representing full implementation of all NIST SP 800-171 requirements. Point deductions are applied for each requirement that is not fully implemented.
Deductions fall into three categories:
| 1-point deductions for lower-impact deficiencies | |
| 3-point deductions for moderate-risk deficiencies | |
| 5-point deductions for higher-risk deficiencies |
Requirements associated with access enforcement, multifactor authentication, audit logging, and system integrity typically carry higher deductions because failures in these areas introduce greater risk.
As deficiencies accumulate, the overall score decreases. Negative scores indicate widespread gaps and limited security maturity. A score of +110 reflects full implementation and represents the expected benchmark for CMMC Level 2 certification.
Contractors must also clearly identify which systems fall within scope for Controlled Unclassified Information. Poorly defined boundaries lead to inaccurate scoring and failed assessments. For each requirement, supporting evidence such as policies, configurations, logs, or screenshots should exist to validate implementation claims.
During Department of Defense reviews, prime contractor validations, or CMMC assessments, the submitted score, the System Security Plan, and supporting evidence must align. Inconsistencies can raise concerns about compliance and credibility.
Once all deductions are accounted for, the final score is submitted through the SPRS portal. Scores must be submitted at least annually and before contract award, and they must be updated when significant system changes occur. Both prime contractors and subcontractors are responsible for keeping their submissions current and accurate.
Submitting a score represents a formal attestation that the assessment is accurate and supported by evidence.
This responsibility extends beyond collecting a numerical score. Prime contractors are expected to evaluate whether subcontractor scores are reasonable, current, and defensible. Unsupported or inflated scores increase risk across the supply chain.
To manage this risk, primes often request System Security Plans, supporting documentation, or independent validation. Security gaps at the subcontractor level can affect contract eligibility for all parties involved.
Maintaining an accurate, defensible score helps reduce friction during procurement and renewal cycles while demonstrating a consistent commitment to compliance.
Accurate scoring requires technical understanding, thorough documentation, and disciplined evaluation. Treating the process casually increases long-term compliance risk.
By aligning technical controls with documentation, MAD Security helps organizations prepare for DFARS compliance and CMMC Level 2 certification. The objective is to produce a score that withstands scrutiny from prime contractors, auditors, and assessors.
By understanding the scoring methodology, maintaining strong evidence, and addressing gaps early, organizations reduce compliance risk and improve contract readiness. Contractors that approach SPRS scoring with discipline are better positioned for sustained success within the defense industrial base.
Original Publish Date: February 17, 2026
By: MAD Security