Want to learn more about services? Book a free introductory call - "Here"
What Your SPRS Score Actually Means
A negative SPRS score isn't automatic disqualification. Here's how the DoD's NIST SP 800-171 scoring methodology actually works, and how to prioritize
CMMC BLOG
Daniel McLain
8/28/20266 min read
What Your SPRS Score Actually Means (and Why a Negative Number Isn't the End of the Story)
If you just logged into the Supplier Performance Risk System (SPRS) and saw a score like -47, your first reaction was probably "is that bad?" The honest answer is: it depends, but a negative number by itself doesn't mean your company is disqualified from anything. It means you have gaps, the system just told you how significant they are relative to each other, and there's a defined way to work the number back up.
This article walks through how the score is actually calculated, why some gaps hurt your score far more than others, and how to think about remediation priorities once you know where you stand.
What SPRS is, in plain terms
SPRS is the Department of Defense (DoD) database where contractors submit the results of their NIST SP 800-171 self-assessment. If your contract includes DFARS clause 252.204-7019 or 252.204-7020, you're required to have a current score on file there before you can be awarded certain contracts, and to keep it current afterward. NIST SP 800-171 is the federal standard that defines the 110 security requirements for protecting Controlled Unclassified Information (CUI) on non-federal systems, and it's also the practice set behind Cybersecurity Maturity Model Certification (CMMC) Level 2.
The score itself is calculated using the DoD's official scoring methodology, and that methodology is what most people misunderstand.
The scoring mechanics: start at 110, no partial credit
The current governing document is the NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1, dated June 24, 2020, still the version referenced by DoD's official safeguarding guidance as of this writing. Every self-assessment starts from a maximum of 110 points, representing full implementation of all 110 NIST SP 800-171 Rev 2 requirements. From there, points are subtracted for every requirement marked NOT MET.
Here's the part people trip over: there's no partial credit. A requirement is either fully implemented (MET) or it isn't, and if it isn't, the full point value tied to that requirement comes off your score. There's no "we're 80% of the way there" adjustment. Under the DoD methodology, partial implementation of a requirement is treated the same as no implementation for scoring purposes.
Each of the 110 requirements is pre-assigned a deduction weight of 5, 3, or 1 points, based on how significant the security impact of that requirement is judged to be:
5-point deductions apply to requirements whose absence "could lead to significant exploitation of the network, or exfiltration of DoD CUI." This tier includes foundational controls such as limiting system access to authorized users (3.1.1) and boundary protection (3.13.1).
3-point deductions apply where the impact is more specific and confined, rather than network-wide. A few requirements have conditional weights: multi-factor authentication (MFA) for CUI access (3.5.3) is a 3-point deduction if you have MFA for remote and privileged access but not everywhere required, and a 5-point deduction if MFA isn't implemented at all. FIPS-validated encryption (3.13.11) works similarly: 3 points if you're encrypting but haven't validated it against FIPS, 5 points if you're not encrypting at all.
1-point deductions apply to the remaining requirements, generally ones with a more limited or indirect effect on network security, often documentation, policy, or lower-impact procedural requirements.
That weighting structure is documented in the DoD's scoring methodology (see the NIST 800-171 DoD Assessment Methodology PDF hosted by the University of Texas at Arlington's DoD contracting resource center, which reproduces the government's own tables).
Yes, the score can go negative, and there's a floor
Because deductions stack, a company with several NOT MET requirements, especially high-weight ones, can end up below zero. The lowest possible score is commonly reported as -203, reflecting every one of the 110 requirements marked NOT MET at its assigned weight. You'll see -203 cited consistently across industry compliance guides covering SPRS scoring, though it doesn't appear as a single explicit number in the DoD methodology document itself; it's the mathematical floor of the weighting table. If your score is negative, you're not "broken" or disqualified by that fact alone. You're somewhere on a wide scale, and the number tells you how much work is likely ahead relative to another negative-scoring company, not whether you're allowed to compete.
A realistic (not literal) example
Picture a 60-person engineering subcontractor that's never done a formal gap assessment. They have decent basic hygiene: firewalls, antivirus, a reasonably locked-down network. But MFA is only enabled on their email platform, not on privileged accounts or remote access into their CUI environment. They don't have a written incident response plan, their System Security Plan (SSP) is out of date, and a handful of access control and configuration management practices are documented informally at best, if at all.
That company isn't failing everything. But the MFA gap alone could be a 3- or 5-point deduction depending on exactly what's missing, and it stacks with several 1-point deductions for the missing documentation and process items. It's easy to see how a company that "feels" reasonably secure day to day ends up with a score in negative territory once every gap is weighted and totaled. This is illustrative, not a claim about any real assessment or a specific point total; your actual score depends entirely on your specific environment and which requirements you can honestly mark MET.
Where to focus remediation first
As a general prioritization principle, and this is our professional read on the methodology rather than a rule stated anywhere in the DoD document, fixing your highest-weight NOT MET requirements first is usually the more efficient path to a materially higher score, since a handful of 5-point fixes typically require less overall project effort than chasing the same total number of points across many 1-point items. The practical takeaway: pull your NOT MET list, sort it by point value, and start at the top.
MFA is worth calling out specifically. It's one of the most commonly failed requirements across the Defense Industrial Base (DIB), and it also happens to be one of the highest-value fixes available, both in SPRS points and in actual security terms. Enabling MFA for privileged and remote access into your CUI environment is something most organizations can implement faster than they expect, and it closes a gap that's frequently exploited in real-world breaches regardless of what any score says. The same logic applies to FIPS-validated encryption: it's a common gap, it carries real weight in the scoring, and it's foundational to protecting the data, not just a box to check for the assessment.
That said, don't ignore the 1-point items entirely. An outdated or missing SSP is technically low point value on its own, but it's also the document assessors and contracting officers expect to see, and gaps there tend to surface other gaps you didn't know you had.
What a negative score does, and doesn't, mean for a contract
A negative SPRS score signals to a contracting officer that there are unresolved gaps in your NIST SP 800-171 implementation. What that means for a specific award decision depends on the specific solicitation, the sensitivity of the information involved, and that contracting officer's own risk assessment; it is not an automatic disqualifier under a blanket rule, and we're not aware of one that makes it so. At the same time, don't assume a negative score is a non-issue either. It can factor into award decisions, and if your contract includes DFARS 252.204-7019 or -7020, you're contractually required to have a current, accurate score on file regardless of what that number is.
For CMMC Level 2 specifically, note that a self-assessment currently must be submitted or updated at least every three years, or sooner if your security posture or SSP changes materially, and an annual affirmation is required in the years between full assessments. Plans of Action and Milestones (POA&Ms), which let you document a remediation timeline for certain unmet practices rather than fixing everything before submitting, are permitted only for a defined subset of practices and conditions, and any POA&M items must be closed out within 180 days. If you want more detail on how CMMC's phased rollout and current status affects your specific timeline, we cover that in a separate article on our site; we won't re-cover it here.
The bottom line
Your SPRS score is a snapshot, not a verdict. It's calculated using a specific, public methodology: start at 110, subtract weighted points for every NOT MET requirement, no partial credit. A negative number tells a contracting officer, and tells you, that there are real gaps, and it tells you roughly which ones matter most by how much weight they carry. It doesn't automatically end your eligibility for DoD work, and it isn't something to ignore either.
Before you assume the worst about a low or negative score, or before you invest in fixing the wrong things first, it's worth having someone walk through your actual NOT MET list and confirm which gaps are carrying the most weight and which are quick wins. This is general informational guidance based on the DoD's published scoring methodology, not legal advice or a substitute for a formal assessment; for a specific compliance determination or before submitting a score you plan to rely on, consult a Registered Practitioner Organization (RPO) or, for a Level 2 certification assessment, a Certified Third-Party Assessment Organization (C3PAO).
ICTS USA can help you translate your NIST SP 800-171 gap assessment into a prioritized, realistic remediation plan, and help you understand what your current score means for the contracts you're pursuing, before you spend money in the wrong order.
Official resources
NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 (DoD, June 24, 2020)
DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements (Acquisition.gov)
DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements (Acquisition.gov)
32 CFR 170.16, CMMC Level 2 self-assessment and affirmation requirements (eCFR)
