At some point every small defense contractor gets the email: a prime or contracting officer asking for your "SPRS score" — often with a deadline and no explanation. This is the complete picture: why the requirement exists, what has to be true before you log in, how it relates to CMMC, and the exact submission steps, portal quirks included.
Why Submit at All?
Two contract clauses do the forcing. DFARS 252.204-7019 says a contracting officer cannot award you a contract involving CUI unless a current NIST SP 800-171 self-assessment score — no more than three years old — is posted in SPRS, the DoD's Supplier Performance Risk System. DFARS 252.204-7020 obligates you to give DoD access to verify it and to flow the same requirement down to your own subcontractors — which is why primes chase their subs for scores.
So the honest answer to "why do it" is: because you can't sell to the DoD without it. A missing score doesn't trigger a fine; it quietly makes you unawardable, and increasingly it filters you out of prime supplier lists before you ever see the solicitation.
SPRS vs. CMMC — They're Not the Same Thing
These get conflated constantly, especially since the Department of War (DoW) paused CMMC Phase 2 in July. The distinction:
| SPRS score | CMMC certification | |
|---|---|---|
| What it is | A self-assessed score against NIST SP 800-171, posted to a DoD database | A program that (at Level 2) has a third-party assessor verify the same 110 controls |
| Who does the assessing | You | A certified assessor (C3PAO) or, for some contracts, you with an executive affirmation |
| Status right now | Fully in force — required for award under DFARS 7019 | Phase 2 suspended July 13, 2026 pending a reform review |
| The standard behind it | The same one: NIST SP 800-171's 110 controls. Work done for one transfers to the other. | |
Think of it this way: SPRS is you telling the government where you stand, on your signature. CMMC is the government checking. The checking is paused; the telling never was.
Level 1 vs. Level 2 — Which Are You?
- Level 1 — you handle FCI only. Federal Contract Information: information provided by or generated for the government under contract, not intended for public release — but not CUI. Requirement: the 15 basic safeguards of FAR 52.204-21, an annual self-assessment, and an affirmation. No scored −203-to-110 submission.
- Level 2 — you handle CUI. Controlled Unclassified Information: technical data, drawings, specs, export-controlled material. Requirement: all 110 NIST SP 800-171 controls, the scored self-assessment, and the SPRS posting this guide covers. Not sure which you are? Start here — most contractors guess wrong in one direction or the other.
- Rule of thumb: if your contracts carry DFARS 252.204-7012, you're in Level 2 territory and the scored SPRS submission applies to you.
What Must Be True Before You Log In
The portal takes minutes. The prerequisites are the actual work:
- A real self-assessment of all 110 controls, scored per the DoD Assessment Methodology — met, not met, or justified N/A, with unmet controls subtracting their 1, 3, or 5 point weight from 110. The full scoring method.
- A System Security Plan. The portal asks for your SSP's name and version — and under the methodology, no SSP means no valid assessment to report. What goes in one.
- A POA&M with a completion date for whatever isn't met — the portal asks for that date too. POA&M mechanics.
- Your assessment date and scope — typically "enterprise" for a small shop where one network covers everything, or a narrower scope if you've built an enclave.
- The evidence, retained. Nothing gets uploaded, but everything can be asked for. The documentation stack.
Get to a defensible score — free
CMMC Map walks all 110 controls in plain English and computes your SPRS score live as you answer — free, no credit card. When you need the SSP and POA&M the portal asks about, they generate from your answers at $149/month. You arrive at the portal with every field already in hand.
Do the assessment first →The Submission, Step by Step
- Confirm your SAM registration is active. Everything downstream keys off your CAGE code. If you hold DoD contracts you almost certainly have this; verify it hasn't lapsed at sam.gov.
- Get a PIEE account. SPRS is accessed through the Procurement Integrated Enterprise Environment at piee.eb.mil. Register as a vendor, tied to your CAGE code.
- Request the right role. In PIEE, add the SPRS role "Cyber Vendor User" — that's the role that can enter and edit NIST SP 800-171 assessment results. Your company's PIEE administrator approves it (in a small shop, that administrator is probably you).
- Open SPRS and go to the cyber reports section. From PIEE, launch SPRS (sprs.apps.mil) and navigate to the NIST SP 800-171 assessment area.
- Add your assessment. Enter the assessment date, your score, the scope, your POA&M completion date (if anything is unmet), your SSP name and version, and the CAGE code(s) the assessment covers.
- Save and verify. Confirm the record shows as your current Basic (self-assessed) entry. That posted record is what contracting officers and primes check.
After You Submit
- The three-year clock starts — your score must stay no more than three years old to count for awards. Practically, re-assess annually or whenever your environment changes materially.
- Update it as you improve. Closed five POA&M items? Re-run the assessment and post the better number — primes see the improvement, and the update costs you nothing.
- Diarize the annual affirmation. CMMC statuses require a yearly re-affirmation in SPRS by your Affirming Official; a lapsed affirmation invalidates the status. How affirmations work.
None of this is glamorous work. But a contractor with an honest posted score, a real SSP behind it, and a shrinking POA&M is — right now, during the pause — ahead of most of the field, and ready for whatever CMMC looks like when it restarts.