A defense contractor submitted their NIST SP 800-171 self-assessment to the SPRS portal in 2021. Score: 104 out of 110. Clean, credible, near-perfect. They continued billing against DoD contracts for the next two years.

Then a third-party assessor ran the same math against the actual environment. Real score: -142.

That gap — 246 points between what MORSECORP submitted and what their systems actually reflected — cost them $4.6 million in a False Claims Act settlement with the Department of Justice in March 2025. It was the first FCA settlement explicitly tied to SPRS misrepresentation, and it will not be the last.

Your SPRS score is a number you submit. Your CMMC assessment is a number someone else calculates. What matters is the distance between those two figures and what happens when an assessor, a prime contractor, or a DoJ investigator discovers the gap before you do.

📋
Self-Assessment Resource: Don't guess your mathematical standing or rely on an unverified estimation before an official audit. Use the Theodosian CMMC Level 2 Compliance Checklist to run an honest, itemized assessment of your current 1-point, 3-point, and 5-point practices so you can accurately protect your legal standing in the SPRS portal.

What Is SPRS, and Why Does DoD Care?

The Supplier Performance Risk System is the DoD database where defense contractors submit self-assessed cybersecurity scores based on NIST SP 800-171. Before awarding contracts that involve Controlled Unclassified Information, contracting officers are required to check SPRS. If you don't have a score on file, you're ineligible. If your score is below what a prime contractor's flowdown requires, you may be dropped from consideration without ever getting on a call.

SPRS scores are visible to prime contractors. Your score affects your ability to win work, not just your ability to pass a formal assessment.

The SPRS requirement comes directly from DFARS 252.204-7012 and 252.204-7019, which together mandate that DIB contractors handling CUI conduct a NIST SP 800-171 self-assessment, submit the score to SPRS, and maintain a System Security Plan documenting how requirements are implemented.

What matters is that the score you submit is the score you can defend. The DoD's trust in the SPRS system depends on contractors reporting honestly. The False Claims Act treats a material misrepresentation, including a cybersecurity score that knowingly overstates your compliance, as fraud against the government.

An Unverified SPRS Score is a Multi-Million Dollar Liability

The SPRS portal blindly accepts whatever number you input, and it won't verify your data. But CMMC Level 2 changes this. When a third-party assessor evaluates your actual environment and any discrepancy between your self-attestation and reality, it isn't just a compliance failure; under the False Claims Act, it's considered fraud.

See How Theodosian Aligns With CMMC Compliance

How Does the SPRS Scoring Math Work?

The SPRS scoring methodology starts at 110 — perfect compliance — and subtracts points for each unmet NIST SP 800-171 requirement. The subtraction isn't linear; each of the 110 requirements carries a weighted value based on its security impact:

  • 5-point controls: The most critical requirements — primarily in the System and Communications Protection (SC) domain, Identification and Authentication (IA) domain, and Access Control (AC) domain. Fail one, and you lose five points.
  • 3-point controls: Significant requirements across Configuration Management (CM), Audit and Accountability (AU), and others. Each unmet control costs three points.
  • 1-point controls: Lower-impact requirements across remaining domains. Still important — missing multiple 1-point controls adds up quickly.

The math means a contractor who hasn't addressed a handful of high-weight controls can go negative fast. The theoretical minimum score, if you've implemented nothing, is -203. The maximum is +110.

That range matters because it makes the SPRS score highly sensitive to the controls you're most likely to have skipped: MFA deployment, FIPS 140-3 validated encryption, organization-controlled key management, and audit logging are all high-weight controls. A contractor who thinks they're "mostly compliant" and estimates a score of 70 often finds, under honest assessment, that they're at 20, or below zero.

The DoD's scoring methodology weights are published. You can run the calculation yourself with a spreadsheet. The question is whether the number you produce reflects your actual implementation or your interpretation of what you think you've implemented.

What the Numbers Look Like Across the DIB

CyberSheath's 2025 State of the Defense Industrial Base report puts the median SPRS score across DIB contractors at 60 out of 110 — up from a median of 20 in their 2022 study, but still far below the 110 required for full CMMC Level 2 compliance. 17% of contractors report negative scores outright. And 42% of respondents had not submitted a score to the SPRS portal at all.

That last number is the most operationally significant. If you're a contractor without a submitted SPRS score, you're not just behind on compliance; you're ineligible for new DoD contract awards that require CUI handling, effective immediately.

For contractors with submitted scores, the concern is accuracy. Self-assessments are exactly that: self-conducted evaluations of your own compliance posture. The SPRS portal takes whatever number you submit. It doesn't verify or audit. That verification is exactly what CMMC Phase 2 enforcement introduces — in the form of C3PAO assessments that calculate an independent score from direct examination of your environment.

The gap between what contractors submit and what assessors find has been the central story of CMMC readiness since the program launched. MORSECORP's 246-point discrepancy is an extreme case. A 30- to 50-point gap between a self-reported score and an independent assessment score is common, according to practitioners who have conducted pre-assessment gap analyses across the DIB.

The False Claims Act Exposure You May Not Have Priced In

The MORSECORP settlement introduced something new to the CMMC conversation: the idea that a contractor who submits an inflated SPRS score and continues billing DoD contracts is not just non-compliant; they're potentially committing fraud.

The False Claims Act is the federal statute that enables the DoJ to pursue contractors who knowingly submit false or fraudulent claims for payment. The civil cyber-fraud initiative, launched in 2021, is the DoJ's explicit program for applying FCA to cybersecurity misrepresentation. MORSECORP was its first major SPRS-specific settlement. The investigation was triggered by a whistleblower, an insider with knowledge of the gap between the submitted score and the real environment.

What this means for contractors:

Every person in your organization who knows your actual compliance posture is a potential qui tam relator. The whistleblower in the MORSECORP case received $851,000 — 18.5% of the settlement. That's a meaningful financial incentive structure. If your SPRS score is materially higher than your actual implementation supports, the risk is no longer abstract.

A correct SPRS score that reflects genuine gaps is legally protected. A SPRS score that overstates compliance and that you continue to bill against is the exposure.

What Your C3PAO Assessment Will Actually Measure

When your C3PAO arrives for a CMMC Level 2 assessment, they don't ask to see your SPRS portal submission. They examine your actual environment, interview your people, and test your technical controls against all 110 NIST SP 800-171 requirements. The score they calculate is independent of whatever you submitted.

What they're looking for that contractors most commonly fail:

Multi-Factor Authentication (MFA): Required for all privileged access and all CUI system access. Non-deferrable. Often partially implemented but not comprehensively enforced.

FIPS 140-3 Validated Encryption (SC.3.177): Encryption of CUI at rest and in transit using FIPS-validated cryptographic modules. Non-deferrable. Many contractors use tools with encryption that isn't FIPS-validated, or cannot demonstrate validation of the specific module in use.

Organization-Controlled Key Management (SC.3.187): Your encryption keys must remain under your organizational control. If a cloud provider can access your encrypted CUI without your active authorization, this control may not be met. Non-deferrable.

Audit Logging (AU domain): You need to demonstrate active log collection, protection, and review — not just that logging is enabled.

System Security Plan: Your SSP must document every system, component, and connection in scope for CUI handling. Undocumented assets are automatic gaps.

The controls with the highest failure rates in pre-assessment gap analyses are also the ones with the highest SPRS point weights. That's why the gap between self-reported scores and assessed scores tends to be larger than contractors expect. The controls they're most likely to have skipped are the ones that cost the most points.

How to Calculate Your Actual SPRS Score Before the Assessor Does

The DoD publishes the NIST SP 800-171 DoD Assessment Methodology, which includes the point values for each of the 110 requirements. You can run an honest self-assessment using that document and a spreadsheet, or use one of several commercial tools designed to map your actual implementation against the scoring criteria.

The practical steps:

  1. Map your CUI scope first: Before scoring anything, document every system, location, and individual that processes, stores, or transmits CUI. Your assessment scope determines which systems need to meet all 110 controls. Underscoping inflates your score artificially and is the first thing a C3PAO will challenge.

  1. Score honestly against each control: The DoD methodology defines three statuses for each requirement: Met, Not Met, and Not Applicable. "Partially implemented" is Not Met for scoring purposes. Many contractor self-assessments fail here; they score partially implemented controls as met.

  1. Apply the weights: Subtract 5 points for each Not Met high-value control, 3 for medium, 1 for low. Sum what remains.

  1. Compare to what you submitted: The number you generate is your actual compliance posture. The number in the SPRS portal is your legal representation to the DoD. The gap between them is what matters.

  1. Update the portal if they differ materially: MORSECORP's specific exposure was the failure to update their SPRS score after a third-party assessment produced a lower number. Once you know the accurate score, submitting it is not optional.

What Your SPRS Score Doesn't Tell You

A score of 88 out of 110 isn't a passing grade for CMMC Level 2, it's the minimum threshold for receiving a conditional CMMC certificate, which allows 180 days to remediate remaining gaps. The full certification requires 110 out of 110.

Your SPRS score also doesn't tell you whether your gaps are POA&M-eligible. Under 32 CFR 170.21, only 1-point controls can be deferred to a Plan of Action & Milestones. All 3-point and 5-point controls must be fully implemented before assessment. Since those are the controls with the most compliance failures and the highest point weights, a contractor calculating their SPRS score and assuming they can remediate through POA&Ms may be significantly underestimating what needs to be done before the C3PAO arrives.

Bridging the SPRS Gap with Data-Centric Security

The reason most defense contractors carry inaccurate or negative SPRS scores isn’t a lack of effort—it’s an architectural mismatch. They are trying to solve file-level regulatory requirements (like SC.3.177 and SC.3.187) using location-based network tools. When CUI is downloaded to a local machine, synced to a personal cloud, or shared with a subcontractor, standard platform controls disappear, and your SPRS points drop with them.

Theodosian flips this model by embedding FIPS 140-3 validated encryption and dynamic access policies directly into individual files. Because the protection travels with the data, your compliance posture doesn’t depend on where a file is stored or who owns the device it sits on.

cmmc sprs score gap

By turning the files themselves into self-defending assets, you secure the most heavily weighted 5-point and 3-point controls on the SPRS rubric out of the box:

  • Instant, Non-Deferrable Encryption (SC.3.177): Automatically wraps every piece of CUI in an independent layer of FIPS-validated cryptography at rest, in transit, and in use.
  • True Organization-Controlled Keys (SC.3.187): Implements a zero-knowledge, decentralized key management architecture, ensuring that you—and only you—hold the keys to decrypt your files.
  • Assessor-Ready Audit Trails (AU Domain): Generates persistent, unalterable logs of every single file access or decryption attempt globally, providing the exact empirical evidence C3PAOs demand.

Instead of spending months executing complex cloud migrations or trying to police unmanaged endpoints, data-centric security allows you to confidently submit—and defend—a perfect score on your highest-risk compliance domains in weeks, not years.

Stop Scoring Partial Implementations as "Met"

CMMC assessors view compliance as binary: a control is either fully operational or it's a critical point deduction. Instead of risking a devastating negative score on high-weight controls like FIPS encryption and key management, bake automated zero-trust security directly into the files themselves.

Discover How to Automate Your CMMC Defenses

FAQs: SPRS Score

What is a good SPRS score for CMMC?

For CMMC Level 2 certification, the target is 110 — full implementation of all 110 NIST SP 800-171 requirements. A score of 88 or above enables Conditional CMMC status with a 180-day remediation window for the remaining 1-point gaps. Anything below 88 means you cannot receive even a conditional certificate at assessment. Most prime contractor flowdowns require a minimum submitted SPRS score — check your specific contract.

Can I submit my SPRS score before I'm fully compliant?

Yes, but only if the score accurately reflects your actual implementation. Submitting an inflated score — one you cannot defend against independent verification — is the exposure MORSECORP created. Submit an honest score and maintain a POA&M documenting your path to full compliance. That's the legally defensible posture.

Does my SPRS score automatically update after a C3PAO assessment?

No. After a C3PAO assessment, you must update your SPRS portal submission to reflect the assessed score. This is where MorseCorp's specific liability arose; they failed to update after a third-party assessment revealed a lower score. The update obligation is on the contractor.

How often should I reassess my SPRS score?

DFARS 252.204-7019 requires reassessment at least every three years, or after any significant change to your CUI environment. In practice, any major system change, new tool deployment, or significant personnel change that affects your CUI handling warrants a reassessment and potential SPRS update.

Can a prime contractor require a specific SPRS score?

Yes. Prime contractors can, and increasingly do, include minimum SPRS score requirements in their subcontractor flowdowns as part of their own CMMC compliance program. If your score falls below their threshold, you may be removed from the supply chain regardless of your formal CMMC status.