Home / Resources / SPRS

SPRS

How the SPRS score is actually calculated.

Everyone knows the score starts at 110. Fewer know it can fall to minus 203, that requirements are weighted 5, 3, or 1, or that exactly two of them offer partial credit. The methodology, straight.

The arithmetic

The NIST SP 800-171 DoD Assessment Methodology starts every organization at 110, one point of potential for each requirement, then subtracts a weighted deduction for every requirement not fully implemented. Deductions are 5 points for requirements whose absence exposes the network broadly (multifactor authentication, FIPS-validated cryptography, and similar), 3 points for requirements with specific and confined impact, and 1 point for the remainder. Miss everything and the floor is minus 203.

110 starting score -5 / -3 / -1 per unmet requirement -203 the floor

The two partial-credit cases

Exactly two requirements allow a reduced deduction. 3.5.3, multifactor authentication: 5 points if you have no MFA, but only 3 if MFA covers remote access and privileged accounts while general users still lack it. 3.13.11, FIPS-validated cryptography: 5 points if CUI is not encrypted at all, 3 if it is encrypted but the cryptography is not FIPS-validated. Every other requirement is all or nothing.

The SSP rule people miss

Requirement 3.12.4, the System Security Plan, carries no point value for a reason: without an SSP, the assessment cannot be conducted at all. No document, no score, no defensible SPRS entry.

Why the number matters more now

Your score, its assessment date, and the scope it covers are submitted to SPRS, where contracting officers and primes can see it, and a senior official affirms it. An affirmed score that does not survive scrutiny is not just embarrassing: accuracy is enforceable, and False Claims Act cases in this space are no longer hypothetical. The score is also self-reported at the "basic" confidence level, which is exactly why primes increasingly ask what sits behind a suspiciously round 110.

Practical advice: score yourself honestly at the objective level, document the evidence behind every "met," and let the number be what it is while the plan of action closes the gap. A defensible 88 beats an indefensible 110 every time.

Questions about your situation?

A short conversation usually settles it. No pitch, just answers.

Talk to CyberDeka