At some point every small defense contractor gets the email: a prime or contracting officer asking for your "SPRS score" — often with a deadline and no explanation. This is the complete picture: why the requirement exists, what has to be true before you log in, how it relates to CMMC, and the exact submission steps, portal quirks included.

Why Submit at All?

Two contract clauses do the forcing. DFARS 252.204-7019 says a contracting officer cannot award you a contract involving CUI unless a current NIST SP 800-171 self-assessment score — no more than three years old — is posted in SPRS, the DoD's Supplier Performance Risk System. DFARS 252.204-7020 obligates you to give DoD access to verify it and to flow the same requirement down to your own subcontractors — which is why primes chase their subs for scores.

So the honest answer to "why do it" is: because you can't sell to the DoD without it. A missing score doesn't trigger a fine; it quietly makes you unawardable, and increasingly it filters you out of prime supplier lists before you ever see the solicitation.

SPRS vs. CMMC — They're Not the Same Thing

These get conflated constantly, especially since the Department of War (DoW) paused CMMC Phase 2 in July. The distinction:

SPRS scoreCMMC certification
What it isA self-assessed score against NIST SP 800-171, posted to a DoD databaseA program that (at Level 2) has a third-party assessor verify the same 110 controls
Who does the assessingYouA certified assessor (C3PAO) or, for some contracts, you with an executive affirmation
Status right nowFully in force — required for award under DFARS 7019Phase 2 suspended July 13, 2026 pending a reform review
The standard behind itThe same one: NIST SP 800-171's 110 controls. Work done for one transfers to the other.

Think of it this way: SPRS is you telling the government where you stand, on your signature. CMMC is the government checking. The checking is paused; the telling never was.

Level 1 vs. Level 2 — Which Are You?

What Must Be True Before You Log In

The portal takes minutes. The prerequisites are the actual work:

  1. A real self-assessment of all 110 controls, scored per the DoD Assessment Methodology — met, not met, or justified N/A, with unmet controls subtracting their 1, 3, or 5 point weight from 110. The full scoring method.
  2. A System Security Plan. The portal asks for your SSP's name and version — and under the methodology, no SSP means no valid assessment to report. What goes in one.
  3. A POA&M with a completion date for whatever isn't met — the portal asks for that date too. POA&M mechanics.
  4. Your assessment date and scope — typically "enterprise" for a small shop where one network covers everything, or a narrower scope if you've built an enclave.
  5. The evidence, retained. Nothing gets uploaded, but everything can be asked for. The documentation stack.
Sign it like a federal statement: the score you post is a representation to the government, relied on for contract award. An inflated score isn't a rounding error — it's False Claims Act exposure. A defensible 70 beats an indefensible 95 every time someone checks.

Get to a defensible score — free

CMMC Map walks all 110 controls in plain English and computes your SPRS score live as you answer — free, no credit card. When you need the SSP and POA&M the portal asks about, they generate from your answers at $149/month. You arrive at the portal with every field already in hand.

Do the assessment first →
Free to assess · No credit card · Documents $149/mo

The Submission, Step by Step

  1. Confirm your SAM registration is active. Everything downstream keys off your CAGE code. If you hold DoD contracts you almost certainly have this; verify it hasn't lapsed at sam.gov.
  2. Get a PIEE account. SPRS is accessed through the Procurement Integrated Enterprise Environment at piee.eb.mil. Register as a vendor, tied to your CAGE code.
  3. Request the right role. In PIEE, add the SPRS role "Cyber Vendor User" — that's the role that can enter and edit NIST SP 800-171 assessment results. Your company's PIEE administrator approves it (in a small shop, that administrator is probably you).
  4. Open SPRS and go to the cyber reports section. From PIEE, launch SPRS (sprs.apps.mil) and navigate to the NIST SP 800-171 assessment area.
  5. Add your assessment. Enter the assessment date, your score, the scope, your POA&M completion date (if anything is unmet), your SSP name and version, and the CAGE code(s) the assessment covers.
  6. Save and verify. Confirm the record shows as your current Basic (self-assessed) entry. That posted record is what contracting officers and primes check.

After You Submit

None of this is glamorous work. But a contractor with an honest posted score, a real SSP behind it, and a shrinking POA&M is — right now, during the pause — ahead of most of the field, and ready for whatever CMMC looks like when it restarts.