Schedule a call

Compliance

Your SPRS score, and why it is negative

Cloud Kings

There is a number attached to your business in a federal database, it is probably negative, and a fair proportion of contractors either do not know it exists or assume the negative sign means something has gone wrong.

It has not. The scoring is built to produce negative numbers, and understanding why turns a frightening figure into a working measurement.

What the number is

Defense contractors handling Controlled Unclassified Information are required to assess themselves against NIST SP 800-171 and post the result to the Supplier Performance Risk System — SPRS. The obligation sits in DFARS 252.204-7019 and 252.204-7020, and it has been in force since well before CMMC’s assessment regime arrived.

That last point is worth pausing on, because a great deal of confusion follows from missing it. This requirement is not new and it is not waiting for CMMC. It applies now, it has applied for years, and CMMC Level 2 is a mechanism for verifying the same 110 requirements rather than a replacement for them.

How it is calculated

The arithmetic is simple and the consequences are not.

You start at 110 — one point notionally available for each requirement in NIST SP 800-171. For every requirement you have not fully implemented, points come off:

  • 5 points for the requirements assessed as having the greatest impact if missing.
  • 3 points for the middle band.
  • 1 point for the rest.

There is no floor at zero. Take every deduction and the arithmetic bottoms out at -203. That is why negative scores are unremarkable: a business at the beginning of this work, with several of the five-point requirements outstanding, lands below zero almost immediately.

The weightings are set out in the DoD Assessment Methodology, and they are not arbitrary. The requirements that cost you five points are the ones that, absent, leave the whole environment exposed regardless of what else is in place.

The rule that catches everybody

Partial implementation scores nothing.

There is no half credit for a control that is mostly there. Multi-factor authentication deployed to the office but not to the three people who work remotely takes the full deduction, exactly as though you had none at all. An access control policy written but not enforced in configuration scores the same as no policy.

This is the single most common reason a first score comes back far lower than expected, and people reasonably assume they have miscounted. They have not. The methodology is binary on purpose — a control that applies to most of your environment does not protect the part it misses, and the scoring refuses to pretend otherwise.

It also produces a genuinely useful side effect. It surfaces the requirements that were declared done, some time ago, on the strength of a purchase rather than a deployment.

Who is actually reading it

Not the public. Your score is not indexed, published, or discoverable by searching.

It is visible to the Department of Defense, to contracting officers, and to primes performing due diligence on their supply chains. The last group is the one that has changed. Primes are increasingly answerable for the security of the suppliers beneath them, and looking up a subcontractor’s posted score is a cheap way to discharge some of that.

So the practical position is: assume anyone deciding whether to award you work can see it. Not because it is public, but because the people who matter have access and have started using it.

A low score is not the problem

This is the part worth internalising before you do anything else.

Nobody expects a small manufacturer to post 110. What a prime or a contracting officer is looking for is not a high number in isolation — it is whether the number is accurate, whether there is a credible POA&M behind it, and whether it is moving.

A contractor at 62 with a dated plan, evidence of progress, and a rescored assessment six months later is a manageable supply-chain risk. A contractor claiming 110 that nobody can substantiate is a different kind of problem entirely, and the second one is far easier to spot than people assume.

Which leads to the part that deserves more attention than it usually gets.

The affirmation is signed by a person

The score is submitted with an affirmation by a named senior official. Not by the company as an abstraction — by someone, personally.

A score you cannot evidence is a representation made to the federal government. The Department of Justice has pursued cybersecurity misrepresentation by contractors under civil fraud authorities, and those matters have generally begun with a claim made in a document exactly like this one.

The safe position is straightforward and slightly counter-intuitive: post the low, honest, evidenced number. A poor score with a real plan behind it is a commercial disadvantage you can work off over a couple of quarters. An optimistic one is a different category of risk that does not improve with time.

How to get to a real number

Four steps, in order, and the first two are where most of the value is.

Establish what is actually in scope. If CUI touches four people in engineering, you may be assessing a defined enclave rather than the entire business — and that decision changes the score, the cost and the ongoing burden more than anything else you will decide. Scope first, always.

Assess honestly against all 110, applying the binary rule without arguing with it. The temptation to score generously is strongest on the requirements that are nearly done, which are precisely the ones that will not survive scrutiny.

Write the POA&M as a plan you intend to follow, with dates that reflect reality. It is a working document, and an assessor reading one full of dates that have already passed learns something about the organization rather than about the controls.

Rescore when you have closed things, and post the update. The trajectory is the signal.

Where this connects to CMMC

The same 110 requirements underpin CMMC Level 2. Your self-assessment score and your Level 2 readiness are two views of one thing, which means the work is not duplicated — and it means a self-assessment done properly is the most useful preparation available for whatever assessment regime applies to your contracts.

If you are not yet certain whether any of this applies to you, the question underneath it is whether you hold CUI at all. That is worth settling first, because if you only hold Federal Contract Information your obligation is the lighter one and a good deal of this does not apply.

Our shared responsibility matrix covers all 14 families and which of the 110 typically sit with a provider rather than with you — useful for working out which parts of your score somebody else can move.

What to do this week

Look up your current score. A surprising number of businesses discover there isn’t one, or that the one there was posted by somebody who has since left and nobody has revisited it.

Then decide whether it is defensible. If it is, you are in better shape than you thought. If it is not, correcting it is a smaller piece of work than the consequences of leaving it.

We offer a free CMMC gap assessment for qualifying contractors, which produces exactly this: an honest score against all 110, with the evidence behind each one. Schedule a call if that would be useful.

Frequently asked

What is a good SPRS score?
110 is the maximum and means every one of the 110 NIST SP 800-171 requirements is fully implemented. Very few contractors start there. What matters more than the number itself is whether it is accurate, whether it is improving, and whether the POA&M behind it is credible — a contractor at 62 with a dated plan and visible progress is in a better position than one claiming 110 that nobody can evidence.
Why is my SPRS score negative?
Because the scoring subtracts rather than adds. You begin at 110 and lose 1, 3 or 5 points for every requirement not fully met, and there is no floor at zero — the lowest possible score is -203. A negative number does not mean you are doing badly relative to your peers; it means you have a number of the heavier requirements outstanding, which is ordinary for a business early in this work.
Do partially implemented controls earn partial credit?
Almost never. The methodology is deliberately binary: a requirement is either fully implemented or it scores nothing. Multi-factor authentication rolled out to some staff but not all takes the full deduction. This is the single most common reason a score comes back lower than someone expected, and it is not a mistake in the scoring.
Who can see our SPRS score?
The Department of Defense, contracting officers, and primes doing due diligence on their supply chain. It is not published to the world, and it is not private either. Assume that anyone deciding whether to award you work can see it, because increasingly they do look.
How often does the score need updating?
A self-assessment is generally treated as current for three years, but that is a ceiling rather than a schedule. The score is a statement about your environment, and environments change — if you close gaps, or if something regresses, the number in SPRS should follow. Leaving a stale score in place while telling customers you have improved is the worst of both.
What happens if we submit a score we cannot support?
It is a representation made to the federal government, so the exposure is not merely reputational. The Department of Justice has pursued cybersecurity misrepresentation by contractors under civil fraud authorities, and an affirmation is signed by a named senior official rather than by the company in the abstract. The safe position is a low, honest, evidenced score. Nobody has been penalised for accuracy.

Continue reading

Keep in the loop