Business Calculator

SPRS Score Calculator

Estimate a DoD SPRS NIST SP 800-171 score requirement by requirement using the 110-point methodology, 5/3/1 deductions, MFA/FIPS partial credit, SSP prerequisite, and controlled N/A handling.

Estimate a DoD NIST SP 800-171 Basic Assessment score from all 110 Rev. 2 requirements using the current SPRS scoring methodology, including MFA/FIPS partial credit and the system security plan prerequisite.

All processing happens in your browser. Requirement statuses are not submitted to SeriesCalculator by this tool. The result is an independent planning estimate, not an official SPRS submission or CMMC certification decision.
110Draft score
0 / 110Requirements answered
0Points deducted

Start with your evidence-based NIST SP 800-171 assessment. Controls are grouped by family. Nothing defaults to MET.

3.1 — Access Control 22 requirements 0 / 22
3.1.1 5-point requirement
3.1.2 5-point requirement
3.1.3 1-point requirement
3.1.4 1-point requirement
3.1.5 3-point requirement
3.1.6 1-point requirement
3.1.7 1-point requirement
3.1.8 1-point requirement
3.1.9 1-point requirement
3.1.10 1-point requirement
3.1.11 1-point requirement
3.1.12 5-point requirement · N/A permitted by SPRS methodology when condition does not exist
3.1.13 5-point requirement · N/A permitted by SPRS methodology when condition does not exist
3.1.14 1-point requirement
3.1.15 1-point requirement
3.1.16 5-point requirement · N/A permitted by SPRS methodology when condition does not exist
3.1.17 5-point requirement · N/A permitted by SPRS methodology when condition does not exist
3.1.18 5-point requirement · N/A permitted by SPRS methodology when condition does not exist
3.1.19 3-point requirement
3.1.20 1-point requirement
3.1.21 1-point requirement
3.1.22 1-point requirement
3.2 — Awareness and Training 3 requirements 0 / 3
3.2.1 5-point requirement
3.2.2 5-point requirement
3.2.3 1-point requirement
3.3 — Audit and Accountability 9 requirements 0 / 9
3.3.1 5-point requirement
3.3.2 3-point requirement
3.3.3 1-point requirement
3.3.4 1-point requirement
3.3.5 5-point requirement
3.3.6 1-point requirement
3.3.7 1-point requirement
3.3.8 1-point requirement
3.3.9 1-point requirement
3.4 — Configuration Management 9 requirements 0 / 9
3.4.1 5-point requirement
3.4.2 5-point requirement
3.4.3 1-point requirement
3.4.4 1-point requirement
3.4.5 5-point requirement
3.4.6 5-point requirement
3.4.7 5-point requirement
3.4.8 5-point requirement
3.4.9 1-point requirement
3.5 — Identification and Authentication 11 requirements 0 / 11
3.5.1 5-point requirement
3.5.2 5-point requirement
3.5.3 5-point requirement · partial = −3
3.5.4 1-point requirement
3.5.5 1-point requirement
3.5.6 1-point requirement
3.5.7 1-point requirement
3.5.8 1-point requirement
3.5.9 1-point requirement
3.5.10 5-point requirement
3.5.11 1-point requirement
3.6 — Incident Response 3 requirements 0 / 3
3.6.1 5-point requirement
3.6.2 5-point requirement
3.6.3 1-point requirement
3.7 — Maintenance 6 requirements 0 / 6
3.7.1 3-point requirement
3.7.2 5-point requirement
3.7.3 1-point requirement
3.7.4 3-point requirement
3.7.5 5-point requirement
3.7.6 1-point requirement
3.8 — Media Protection 9 requirements 0 / 9
3.8.1 3-point requirement
3.8.2 3-point requirement
3.8.3 5-point requirement
3.8.4 1-point requirement
3.8.5 1-point requirement
3.8.6 1-point requirement
3.8.7 5-point requirement
3.8.8 3-point requirement
3.8.9 1-point requirement
3.9 — Personnel Security 2 requirements 0 / 2
3.9.1 3-point requirement
3.9.2 5-point requirement
3.10 — Physical Protection 6 requirements 0 / 6
3.10.1 5-point requirement
3.10.2 5-point requirement
3.10.3 1-point requirement
3.10.4 1-point requirement
3.10.5 1-point requirement
3.10.6 1-point requirement
3.11 — Risk Assessment 3 requirements 0 / 3
3.11.1 3-point requirement
3.11.2 5-point requirement
3.11.3 1-point requirement
3.12 — Security Assessment 4 requirements 0 / 4
3.12.1 5-point requirement
3.12.2 3-point requirement
3.12.3 5-point requirement
3.12.4 Prerequisite · unscored
3.13 — System and Communications Protection 16 requirements 0 / 16
3.13.1 5-point requirement
3.13.2 5-point requirement
3.13.3 1-point requirement
3.13.4 1-point requirement
3.13.5 5-point requirement
3.13.6 5-point requirement
3.13.7 1-point requirement
3.13.8 3-point requirement
3.13.9 1-point requirement
3.13.10 1-point requirement
3.13.11 5-point requirement · partial = −3
3.13.12 1-point requirement
3.13.13 1-point requirement
3.13.14 1-point requirement
3.13.15 5-point requirement
3.13.16 1-point requirement
3.14 — System and Information Integrity 7 requirements 0 / 7
3.14.1 5-point requirement
3.14.2 5-point requirement
3.14.3 5-point requirement
3.14.4 5-point requirement
3.14.5 3-point requirement
3.14.6 5-point requirement
3.14.7 3-point requirement
Important: This independent SPRS score calculator is a planning aid. It does not submit data to the Supplier Performance Risk System, does not replace an authorized assessment, and does not determine CMMC certification.

What Is an SPRS Score?

An SPRS score is the summary score produced by the DoD NIST SP 800-171 assessment methodology for a covered contractor information system. The published Basic Assessment method begins at 110 points and subtracts points for requirements that are not implemented. The maximum is 110 and the lowest possible score is −203.

The current DFARS 252.204-7019 framework still directs contractors to the DoD NIST SP 800-171 Assessment Methodology when a current assessment is required in SPRS. Although NIST published SP 800-171 Revision 3 in 2024, the current DoD/CMMC scoring structure referenced by the sources for this calculator continues to score the 110 requirements from Revision 2. Always follow the version and contract clause that actually applies to your organization.

How the SPRS Score Calculator Works

Mark each of the 110 NIST SP 800-171 Rev. 2 requirements as MET or NOT MET based on evidence from your assessment. Nothing is pre-marked as compliant. The calculator starts at 110 and applies the published weighted deductions.

Requirement type Deduction when NOT MET
High-value requirements 5 points
Medium-value requirements 3 points
Other scored requirements 1 point
3.5.3 MFA special case 3 points for the published partial case; 5 points when not implemented
3.13.11 cryptographic protection special case 3 points for the published partial case; 5 points when not implemented
3.12.4 System Security Plan Unscored prerequisite; without a current SSP the assessment cannot be completed

SPRS N/A Rules

The DoD assessment methodology allows a narrow set of requirements to be treated as not applicable when the underlying capability is not permitted or does not exist in the assessed system. This calculator exposes N/A only for 3.1.12 and 3.1.13 when remote access is not permitted, 3.1.16 and 3.1.17 when wireless access is not permitted, and 3.1.18 when mobile-device connection is not permitted.

Do not use N/A simply because a requirement is inconvenient or not yet implemented. CMMC assessment handling of not-applicable requirements has its own rules, so an SPRS planning score should not be treated as a substitute for a CMMC assessment determination.

SPRS Score vs. CMMC Level 2

SPRS scoring and CMMC Level 2 are closely related but are not interchangeable. Current CMMC Level 2 scoring also uses the 110-point structure. A conditional Level 2 result has a numerical floor of 88, but reaching 88 is not enough by itself: POA&M restrictions, assessment scope, evidence, required practices, closeout timing, and the authorized assessment process also matter.

The calculator therefore shows the 88-point threshold only as context. It never labels a user “CMMC certified” based on a score.

Why the Calculator Uses All 110 Requirements

A shortcut that asks only how many 5-, 3-, and 1-point controls failed can produce the arithmetic, but it loses important assessment context. The control-by-control approach prevents accidental mixing of weights, makes the two partial-credit exceptions explicit, enforces the SSP prerequisite, and makes the narrow N/A handling visible.

How to Use This SPRS Score Calculator

  1. Work from your current NIST SP 800-171 assessment evidence and system security plan.
  2. Open each control family and mark every requirement.
  3. Use Partial only for 3.5.3 or 3.13.11 when the published partial-credit condition actually applies.
  4. Use N/A only where the calculator offers it and the methodology’s condition is genuinely absent.
  5. Calculate the score and review every requirement causing a deduction or blocking completion.
  6. Use the official DoD workflow and authorized personnel for the actual SPRS submission.

Frequently Asked Questions

What is a good SPRS score?

110 is the maximum score and means no points were deducted under the scoring methodology. A lower score identifies gaps, but the practical meaning depends on contract requirements, remediation obligations, and any applicable CMMC rules.

Can an SPRS score be negative?

Yes. The published methodology can produce scores down to −203 when all scored requirements receive their maximum deductions.

Is 88 a passing SPRS score?

SPRS itself should not be reduced to a universal pass/fail number. The 88 figure is important because it is the current CMMC Level 2 conditional numerical floor, subject to additional POA&M and assessment conditions.

Does NIST SP 800-171 Rev. 3 change this calculator?

NIST Rev. 3 is the newer NIST publication, but current DoD contractual/CMMC scoring sources still use the 110 Rev. 2 requirements for this assessment score. If DoD transitions the operative scoring methodology, this calculator should be updated rather than silently mixing revisions.

Does this calculator send my security-control data anywhere?

No. The calculator logic runs in the browser. It does not submit the requirement selections to SeriesCalculator.

Methodology and Sources

The scoring model is based on the DoD NIST SP 800-171 Assessment Methodology v1.2.1, current DFARS 252.204-7019, the SPRS program FAQs, NIST’s SP 800-171 Rev. 2 and Rev. 3 publication pages, and current CMMC Level 2 scoring/POA&M rules in 32 CFR Part 170.