What Is a SPRS Score and How Do You Improve It?

Your SPRS score is the DoD's measure of your NIST 800-171 compliance — and overstating it is False Claims Act exposure. Here's how it's calculated, what a negative score actually means, and the fastest path to improving it.

If your company holds DoD contracts and handles Controlled Unclassified Information, your SPRS score is already on file with the federal government — or it should be. Here's what it means, how it's calculated, and what happens if it's wrong.


If you've been in the defense industrial base for any length of time, you've encountered the acronym. But most contractors we talk to have a fuzzy understanding of what their SPRS score actually represents, how it's calculated, and — more importantly — what the legal and commercial consequences of getting it wrong are.

This post covers all of it.


What Is SPRS?

SPRS stands for Supplier Performance Risk System. It's a Department of Defense database that consolidates supplier risk data — delivery history, quality records, and, most relevantly for this post, cybersecurity compliance scores.

The cybersecurity piece was added through DFARS 252.204-7019, which requires defense contractors to conduct a self-assessment of their compliance with NIST SP 800-171 and post the result to the SPRS database. That result is your SPRS score.

In plain terms: your SPRS score is a number between -203 and +110 that tells the DoD — and any prime contractor who asks — how much of the NIST 800-171 cybersecurity framework you have actually implemented.

Contracting officers review it before award. Prime contractors check it before bringing you on as a subcontractor. And if what's in the database doesn't match what's actually running on your network, you have a legal problem — which we'll get to.


How Is the Score Calculated?

The math starts at 110 — a perfect score, assuming every one of the 110 NIST 800-171 controls is fully in place.

Points are deducted for each control you haven't implemented. The deductions are weighted by the DoD's Assessment Methodology:

  • High-impact controls deduct 5 points when not met
  • Medium-impact controls deduct 3 points
  • Lower-impact controls deduct 1 point

Because the deductions are weighted — not flat — a handful of missing high-impact controls can crater your score quickly. That's why the floor is -203, not 0. It's mathematically possible to have a deeply negative score even if most of your lower-weight controls are in place.

What the numbers actually mean in practice:

Score RangeWhat It Signals
+90 to +110Strong compliance posture, most controls implemented
+50 to +89Solid foundation with meaningful gaps
0 to +49Moderate compliance, significant remediation needed
NegativeSerious gaps; contract eligibility at risk

Most contractors we assess fall somewhere in the +30 to +70 range before we engage — better than they expected in some areas, worse in others. The areas that tend to drag scores down most are audit and accountability (logging), incident response documentation, and security awareness training. These are controls that require deliberate setup and maintenance, not just good hardware.


Why It Matters Right Now

Two reasons SPRS scores matter more in 2026 than they did two years ago:

1. Prime contractors are asking for it.

DFARS 252.204-7020 requires prime contractors to verify that their subcontractors have a current SPRS score on file — meaning a score submitted within the last three years. Primes are now going further and asking for the score itself before awarding subcontracts. If you don't have one filed, or if it's significantly negative, you may not make it to award consideration.

2. The False Claims Act exposure is real and growing.

This is the part that most contractors aren't thinking about — and should be.

When you submit an SPRS score, you're making a formal representation to the federal government about your cybersecurity posture. If that score overstates what you've actually implemented, and you continue billing under DoD contracts where compliance was a condition of award, each invoice can be treated as a separate false claim.

The Department of Justice launched its Civil Cyber-Fraud Initiative in 2021 specifically to pursue this kind of misrepresentation. Cybersecurity-related False Claims Act settlements hit $51.8 million in fiscal year 2025 — up 233% from the year before. The cases are getting larger and more frequent.

A few examples worth knowing:

MORSECORP, Inc. — $4.6 million settlement. A Cambridge-based defense contractor submitted an SPRS self-assessment score of 104 out of 110. A third-party gap analysis found the actual score was -142. MORSE didn't update its SPRS entry until three months after the DoJ served them with a subpoena.

LOGZONE Inc. — $507,144 settlement (June 2026). A Huntsville, Alabama contractor failed to implement required NIST 800-171 controls on two Navy contracts. A Defense Contract Management Agency assessment put the actual score at -170. The gap between what was claimed and what was in place triggered the FCA liability.

The pattern in both cases is the same: the score on file didn't match the reality on the network. That gap is where the legal exposure lives.


How to Calculate Your Score Accurately

The DoD provides an Assessment Methodology document that maps each of the 110 NIST 800-171 controls to its point weight. To calculate an accurate score, you need to work through each control and honestly assess whether it's:

  • Fully implemented — no deduction
  • Partially implemented — full deduction still applies under DoD methodology
  • Not implemented — full deduction

This is harder than it sounds. Many contractors overcount partial implementations as full implementations. A control isn't "implemented" because you have a policy document that mentions it — it's implemented when the technical or administrative control is actually in place and functioning.

The assessment should be documented in your System Security Plan (SSP), which maps your environment and explains how each control is addressed. Controls that aren't yet met should be captured in your Plan of Action and Milestones (POA&M) with target remediation dates.

Once calculated, you submit the score to SPRS through the DoD's Procurement Integrated Enterprise Environment (PIEE) system, logged against your CAGE code. If your company has multiple CAGE codes, each needs its own submission.


The Most Common Controls Dragging Scores Down

After running gap assessments for Maryland defense contractors, the domains where we see the most unimplemented controls are consistent:

Audit and Accountability (9 controls) — Most organizations don't have comprehensive audit logging in place across their systems. Without logs, you can't demonstrate you're monitoring access to CUI — and you can't investigate an incident if one occurs.

Incident Response (3 controls) — Three controls, but they require a documented incident response plan, established capabilities, and testing. Most small contractors have none of this on paper.

Awareness and Training (3 controls) — Security awareness training must be documented and recurring. Verbal reminders don't satisfy the control. Records of what was trained, when, and who attended are required.

Security Assessment (4 controls) — Requires a periodic assessment of your security controls — which is exactly what the SPRS process is supposed to capture, but which most contractors aren't actually doing systematically.

These four domains account for a disproportionate share of negative SPRS scores. They're also among the least technically complex to address — the issue is usually documentation and process, not infrastructure.


How to Improve Your Score

Improving your SPRS score means closing the gaps that are causing deductions. There's no shortcut — each control either is or isn't implemented, and the DoD methodology doesn't allow partial credit.

The practical path:

1. Get an accurate gap assessment first. Don't guess. An honest, documented assessment against all 110 controls tells you exactly where you stand and which gaps are costing you the most points. This is the foundation everything else builds on.

2. Prioritize high-weight controls. Not all gaps are equal. A missing 5-point control costs you more than five missing 1-point controls. Focus remediation on the controls that will move your score most.

3. Build your SSP and POA&M. These documents aren't just paperwork — they're how you demonstrate that you know what your gaps are and have a plan to close them. A contractor with an accurate negative score and a credible remediation plan is in a better position than one with a falsely positive score and no documentation.

4. Implement the technical controls. Access controls, multi-factor authentication, encrypted communications, endpoint protection, audit logging. The technical work has to be done before the score reflects it.

5. Update your SPRS submission. Once you've closed gaps, update your score in PIEE. Scores must reflect your current posture — not aspirational compliance.


The temptation to submit an optimistic score is real. But as the MORSECORP and LOGZONE cases illustrate, overstating your score isn't a low-risk strategy — it's False Claims Act exposure with the DOJ's Civil Cyber-Fraud Initiative explicitly looking for it.

The safer approach: know your actual score, document your gaps honestly in a POA&M, and submit an accurate number. A negative score with a solid remediation plan is defensible. A falsely positive score with no documentation isn't.


What This Means for Maryland Defense Contractors

Southern Maryland has a dense concentration of DoD contractors — prime and sub — working across Navy, Air Force, and intelligence community programs. The SPRS requirement applies to all of them, and the enforcement trend suggests the DoD is moving toward tighter scrutiny of self-assessments across the supply chain.

If you haven't submitted a score, or if your last submission was more than three years ago, you need to address it before your next contract award — or before your prime asks.

Lewis IT helps Maryland defense contractors conduct accurate NIST 800-171 gap assessments, build SSP and POA&M documentation, and submit defensible SPRS scores. We're SAM.gov registered, NAICS 541519, Southern Maryland based.

Schedule a gap assessment →

Subscribe to Lewis IT Bin

Sign up now to get access to the library of members-only issues.
Jamie Larson
Subscribe
DigitalOcean Referral Badge