A step-by-step walkthrough of how the DoD Assessment Methodology converts 110 NIST SP 800-171 controls into a single number — plus a working calculator with detailed implementation guidance for every control.
The score is a deduction model. You start at 110 — a perfect score — and subtract weighted points for every NIST 800-171 control that isn't fully implemented. The math is deliberately punishing to discourage half-measures.
Other than the two controls above, every other control is binary: either fully MET, or fully unmet with the full weight deducted. "We've done most of it" earns zero points. This is why scoring is so unforgiving and why first self-assessments often produce negative numbers for organizations that thought they were "pretty close."
| Weight | Count | What These Controls Cover | Examples |
|---|---|---|---|
| 5 pt × 42 | 42 | Highest impact on CUI security. Missing these would let an attacker walk in. Core access control, audit logging, encryption, boundary protection, incident response. | 3.1.1 limit access · 3.5.3 MFA · 3.13.1 boundary · 3.14.1 patching |
| 3 pt × 14 | 14 | Specific but more limited security impact. Important but not single-points-of-failure. | 3.1.11 session lock · 3.13.8 transit encryption · 3.10.6 alternate work site |
| 1 pt × 52 | 52 | Hygiene, documentation, and supporting practices. Lower individual impact but they add up fast. | 3.2.1 training · 3.4.3 change control · 3.11.1 risk assessment |
| 3 / 5 × 2 | 2 | Tiered scoring with partial credit allowed. | 3.5.3 MFA · 3.13.11 FIPS-validated crypto |
Sum of all weights = 313. That's why the floor is 110 − 313 = −203.
SPRS records scores at one of three confidence levels: Low (self-assessment — what you'll do in Phase 1), Medium (DoD review of your SSP), or High (on-site DoD assessment). A CMMC L2 certification from a C3PAO produces a High confidence score. Your Phase 1 baseline is always Low — that's expected and fine.
Generating a defensible baseline isn't just clicking through a checklist. The DoD Assessment Methodology requires that your score be based on an actual System Security Plan — even a draft one. Without an SSP, your score can't be officially submitted.
Submission is mandatory before a DFARS 7019 contract is awarded — the score must be in SPRS no older than 3 years. For Phase 1 of the playbook, the baseline is for internal use — to size the remediation effort. Many organizations choose not to post an early ugly baseline; they remediate first, then submit a healthier number. Coordinate this with your contracting officer or RPO.
An interactive working calculator covering all 110 NIST 800-171 R2 controls with the official DoD weights. Each control includes a detailed "What's needed to be MET" panel describing the implementation requirements and typical evidence. Mark each as MET / PARTIAL / NOT MET — the score updates in real time.
SPRS lives inside the PIEE portal. Submission is required under DFARS 252.204-7019 when a contract demands it. The mechanics are simple — the prep is the real work.
| Step | Action | Where |
|---|---|---|
| 1 | Register your company in SAM.gov (if not already) | sam.gov |
| 2 | Register in PIEE (Procurement Integrated Enterprise Environment) | piee.eb.mil |
| 3 | Request the "SPRS Cyber Vendor User" role for your CAGE | PIEE |
| 4 | Wait for company administrator approval (can take 1–7 days) | — |
| 5 | Log into SPRS, navigate to NIST SP 800-171 Assessments module | sprs.csd.disa.mil |
| 6 | Enter your assessment data; submit | SPRS |
| 7 | Confirm submission appears against your CAGE; print/save record | SPRS |
SPRS submissions are signed and attestable. Submitting a score that you can't substantiate has been used as the basis for False Claims Act actions against defense contractors — including a $9M settlement in 2023. Document your work. Keep your SSP, evidence, and assessment workings together. Have your CEO review and sign off on what gets submitted.