CMMC & DFARS CMMC & SPRS
CMMC & SPRS guide

SPRS self-assessments, CMMC Level 2, and why your prime wants more than a score

SPRS gives primes a number. CMMC is asking for evidence behind that number. Here's what's driving the documentation requests — and what you need to prepare.

For several years, the DoD's primary mechanism for verifying subcontractor cybersecurity posture was the Supplier Performance Risk System (SPRS) score — a self-assessed number that summarizes how well a contractor's controls align with NIST SP 800-171. CMMC 2.0, whose final rule was published in October 2024, changes that picture significantly for contractors handling CUI on DoD programs.

What SPRS is and how the score works

SPRS is a DoD system where contractors record their self-assessment results against NIST SP 800-171 Rev 2. The scoring model starts at 110 points (if all 110 controls are fully implemented) and subtracts points for each control that is not fully implemented — with deficiency values ranging from 1 to 5 points depending on the control's weight. The theoretical minimum score is -203 (no controls implemented).

Contractors are required to complete a self-assessment and submit their score to SPRS under DFARS 252.204-7019. The assessment must be conducted using the NIST SP 800-171A assessment methodology, and the score must reflect the current state of your implementation — not your aspirational state after planned remediation.

The SPRS score is accessible to DoD contracting officers and prime contractors, who use it as one input in their risk assessment of the supply chain. A score near 110 signals strong NIST 800-171 alignment. A score well below that — especially without accompanying documentation of a remediation plan — raises questions.

SPRS scores are self-reported. Because contractors assess themselves, primes increasingly want to see the evidence behind the score, not just the number. Your System Security Plan (SSP) is the primary document that substantiates your SPRS assessment. Primes who request your SSP or your assessment evidence are verifying that the score reflects reality — not just that you submitted a number.

CMMC Level 2 and what it means for self-assessments

CMMC 2.0 defines three levels of cybersecurity maturity requirements for DoD contractors:

  • Level 1 — 17 basic safeguarding practices for Federal Contract Information (FCI). Annual self-assessment and affirmation by a senior company official required.
  • Level 2 — 110 practices aligned with NIST SP 800-171, for contractors handling CUI. Requires either an annual self-assessment (for non-critical programs) or a triennial third-party assessment by a Certified Third-Party Assessment Organization (C3PAO) for prioritized acquisitions.
  • Level 3 — 24+ additional practices from NIST SP 800-172, for the highest-sensitivity programs. Government-led assessment required.

For most defense subcontractors, CMMC Level 2 is the relevant standard. The self-assessment path (for non-prioritized programs) mirrors the existing SPRS self-assessment — you assess yourself against the 110 NIST 800-171 controls, record your score, and an authorized senior official of your company affirms the results. The C3PAO path requires an external assessment organization to validate your controls.

Why primes are asking for more than just a score

The shift from "what's your SPRS score?" to "can we see your SSP?" reflects two things happening simultaneously in the defense supply chain.

First, primes are increasingly aware that the SPRS self-assessment process allows for optimistic scoring. CMMC's third-party assessment requirement for prioritized programs exists precisely because self-reported scores aren't always reliable. Primes who manage significant program risk are doing their own due diligence by asking for the documentation that substantiates the score.

Second, CMMC phasing means that some primes are already operating under CMMC contract requirements and need to demonstrate supply chain posture to their own contracting officers. When a prime is required to verify your security posture as part of their own CMMC compliance, they need more than a number — they need evidence they can retain.

The questionnaire pattern that follows

When a prime asks for your security documentation beyond just the SPRS score, the request typically takes one of these forms:

  • A questionnaire that maps to specific NIST 800-171 control families — essentially asking you to summarize your SSP by domain.
  • A request to share your SSP or an executive summary of it, under NDA.
  • A request for your POA&M, to understand what controls are not yet implemented and when you expect to complete them.
  • A standard SIG Lite or CAIQ questionnaire that, while not DFARS-specific, covers enough of the same ground to serve as posture verification.

In all of these cases, your responses need to be grounded in your actual documentation. An answer about your access control practices should reference your access control policy. An answer about incident reporting should reference your runbook. Claims that can't be tied back to a document your security team has reviewed are claims that create liability if audited.

Reply Engine drafts questionnaire responses from the same documentation behind your SPRS score.

Your SSP, POA&M, and policies are already the source of truth for your NIST 800-171 posture. Reply Engine indexes them into a per-tenant corpus and drafts your prime's questionnaire from that documentation — every answer cited to a specific section, every response reviewed by your security team before it leaves. Drafts, not attestations.

Get started