COMPANION DOCUMENT · CMMC L2 PLAYBOOK DOD ASSESSMENT METHODOLOGY V1.2.1
PHASE 01 · DISCOVERY & SCOPING

Baseline
SPRS Scoring.

A step-by-step walkthrough of how the DoD Assessment Methodology converts 110 NIST SP 800-171 controls into a single number — plus a working calculator with detailed implementation guidance for every control.

110 NIST 800-171 R2 controls scored with official weights
Detailed implementation guidance for each control
Aligned to DoD Assessment Methodology v1.2.1
SPRS Score Range: −203 to +110
+110
PERFECT SCORE
−203
LOWEST POSSIBLE
3
WEIGHT TIERS: 1, 3, 5
2
PARTIAL CREDIT EXCEPTIONS
Deduction Model:  Start at 110 — subtract weight (1, 3, or 5) for every unmet control
No Partial Credit:  Either fully MET or full deduction (except 3.5.3 MFA and 3.13.11 FIPS)
SSP Required:  Score is invalid without a System Security Plan describing implementation
01 / MECHANICS

How SPRS scoring works.

The score is a deduction model. You start at 110 — a perfect score — and subtract weighted points for every NIST 800-171 control that isn't fully implemented. The math is deliberately punishing to discourage half-measures.

DOD ASSESSMENT METHODOLOGY V1.2.1 · SCORING FORMULA OFFICIAL
SPRS Score = 110 − Σ ( weight of each unimplemented control ) Where: weight ∈ { 1, 3, 5 } Σ = sum across all 110 controls in NIST SP 800-171 R2 Floor = −203 (sum of all weights exceeds 110, so score can go negative) Special cases — partial credit allowed: 3.5.3 Multi-Factor Authentication → 0 deduction if implemented for ALL users → 3 deduction if implemented for remote / privileged only → 5 deduction if not implemented at all 3.13.11 FIPS-Validated Cryptography → 0 deduction if FIPS-validated encryption is employed → 3 deduction if encryption is employed but NOT FIPS-validated → 5 deduction if no encryption is employed at all
The No-Partial-Credit Rule

Other than the two controls above, every other control is binary: either fully MET, or fully unmet with the full weight deducted. "We've done most of it" earns zero points. This is why scoring is so unforgiving and why first self-assessments often produce negative numbers for organizations that thought they were "pretty close."

The three weight tiers.

WeightCountWhat These Controls CoverExamples
5 pt × 42 42 Highest impact on CUI security. Missing these would let an attacker walk in. Core access control, audit logging, encryption, boundary protection, incident response. 3.1.1 limit access · 3.5.3 MFA · 3.13.1 boundary · 3.14.1 patching
3 pt × 14 14 Specific but more limited security impact. Important but not single-points-of-failure. 3.1.11 session lock · 3.13.8 transit encryption · 3.10.6 alternate work site
1 pt × 52 52 Hygiene, documentation, and supporting practices. Lower individual impact but they add up fast. 3.2.1 training · 3.4.3 change control · 3.11.1 risk assessment
3 / 5 × 2 2 Tiered scoring with partial credit allowed. 3.5.3 MFA · 3.13.11 FIPS-validated crypto

Sum of all weights = 313. That's why the floor is 110 − 313 = −203.

Score Confidence Levels

SPRS records scores at one of three confidence levels: Low (self-assessment — what you'll do in Phase 1), Medium (DoD review of your SSP), or High (on-site DoD assessment). A CMMC L2 certification from a C3PAO produces a High confidence score. Your Phase 1 baseline is always Low — that's expected and fine.

02 / METHOD

The six-step baseline workflow.

Generating a defensible baseline isn't just clicking through a checklist. The DoD Assessment Methodology requires that your score be based on an actual System Security Plan — even a draft one. Without an SSP, your score can't be officially submitted.

FIGURE 2.1 — BASELINE SPRS SCORE GENERATION WORKFLOW
STEP 01 Define scope & boundary DAYS 1–2 STEP 02 Draft SSP (template version OK) DAYS 2–4 STEP 03 Score each control: MET / NOT DAYS 4–6 STEP 04 Calculate deductions → baseline DAY 6 STEP 05 Build gap remediation backlog DAY 7 STEP 06 Submit to SPRS (via PIEE) WHEN READY INTERNAL — INFORMS PHASES 2–4 ARCHITECTURE & IMPLEMENTATION EXTERNAL — DFARS 7019

Step Detail

STEP 01 — DEFINE SCOPE & BOUNDARY (DAYS 1–2)
STEP 02 — CREATE OR UPDATE THE SYSTEM SECURITY PLAN (DAYS 2–4)
STEP 03 — SCORE EACH CONTROL: MET OR NOT MET (DAYS 4–6)
STEP 04 — CALCULATE DEDUCTIONS AND ARRIVE AT BASELINE (DAY 6)
STEP 05 — BUILD THE GAP REMEDIATION BACKLOG (DAY 7)
STEP 06 — SUBMIT TO SPRS (WHEN CONTRACTUALLY REQUIRED)
When You Must Submit vs. When You Should Wait

Submission is mandatory before a DFARS 7019 contract is awarded — the score must be in SPRS no older than 3 years. For Phase 1 of the playbook, the baseline is for internal use — to size the remediation effort. Many organizations choose not to post an early ugly baseline; they remediate first, then submit a healthier number. Coordinate this with your contracting officer or RPO.

03 / CALCULATOR

Score your environment now.

An interactive working calculator covering all 110 NIST 800-171 R2 controls with the official DoD weights. Each control includes a detailed "What's needed to be MET" panel describing the implementation requirements and typical evidence. Mark each as MET / PARTIAL / NOT MET — the score updates in real time.

Baseline SPRS Calculator
DOD ASSESSMENT METHODOLOGY V1.2.1 · NIST SP 800-171 R2
CURRENT SCORE
110
Controls MET
110
Controls NOT MET
0
Points Deducted
0
Confidence Level
Low (Self)
How to Interpret Your Result
110
Ready for assessment. Validate with mock assessment in Phase 5.
88 – 109
Achievable in 45 days. POA&M permitted for some controls if you're on the path.
70 – 87
Tight but possible. Likely needs 60–90 days. Engage an RPO.
50 – 69
4–6 month program. Don't book the C3PAO yet.
< 50
Significant cyber maturity gap. Plan a 6–9 month program with structured help.
04 / SUBMISSION

Submitting your score to SPRS.

SPRS lives inside the PIEE portal. Submission is required under DFARS 252.204-7019 when a contract demands it. The mechanics are simple — the prep is the real work.

What you'll submit.

SPRS BASIC ASSESSMENT — REQUIRED FIELDS PER DFARS 7020
CAGE Code: [Your 5-character CAGE] SSP Name: e.g., "[Company] CUI Enclave SSP" SSP Version: e.g., "1.0" SSP Date: YYYY-MM-DD Assessment Date: YYYY-MM-DD Assessment Score: [-203 to +110] Assessment Scope: Enterprise | Enclave | Contract Plan-to-110 Date: YYYY-MM-DD (when you'll reach perfect score) Confidence Level: Low (Basic / Self-Assessment) Optional but recommended: Brief description of scope boundary Included CAGE codes (if hierarchy) Notes on remediation in progress

The submission pathway.

StepActionWhere
1Register your company in SAM.gov (if not already)sam.gov
2Register in PIEE (Procurement Integrated Enterprise Environment)piee.eb.mil
3Request the "SPRS Cyber Vendor User" role for your CAGEPIEE
4Wait for company administrator approval (can take 1–7 days)
5Log into SPRS, navigate to NIST SP 800-171 Assessments modulesprs.csd.disa.mil
6Enter your assessment data; submitSPRS
7Confirm submission appears against your CAGE; print/save recordSPRS
The False Claims Act Reality

SPRS submissions are signed and attestable. Submitting a score that you can't substantiate has been used as the basis for False Claims Act actions against defense contractors — including a $9M settlement in 2023. Document your work. Keep your SSP, evidence, and assessment workings together. Have your CEO review and sign off on what gets submitted.