Skip to main content
Compliance Guidance

Your SPRS Score: How DoD's NIST SP 800-171 Assessment Actually Works (2026 Update)

The Supplier Performance Risk System score isn't going anywhere — but the clauses that used to demand it just did. Here's how the number is built, and what changed on February 1, 2026.

Brandon Hancock, J.D., CMMC-RPPublished February 1, 2026Updated June 26, 20266 min read

The Supplier Performance Risk System score isn't going anywhere — but the clauses that used to demand it just did. Here's how the number is built, and what changed on February 1, 2026.

If you handle Controlled Unclassified Information on a Department of Defense contract, you have probably heard you need a "SPRS score." The short version: the Supplier Performance Risk System (SPRS) is the DoD database where contractors' NIST SP 800-171 assessment results live, and it remains DoD's system of record for those scores. What changed in early 2026 is which clause makes you produce one — not the substance of the assessment itself.

What Changed on February 1, 2026

For years, two DFARS clauses created the self-assessment obligation: 252.204-7019 made a current NIST SP 800-171 score a condition of award, and 252.204-7020 set out the assessment requirements.

As part of the Revolutionary FAR Overhaul, effective February 1, 2026, DoD deleted DFARS 252.204-7019 and renumbered 252.204-7020 to 252.240-7997. The self-assessment obligation was consolidated into CMMC under DFARS 252.204-7021. DFARS 252.204-7012 and the NIST SP 800-171 Rev 2 baseline are unchanged. SPRS remains the system of record.

How the Number Is Calculated

The score tops out at 110 and can fall to -203. Start at 110 and subtract for every unimplemented control: 5 points for high-impact controls, 3 points for moderate, 1 point for the rest. A negative score is normal for companies early in their journey. A POA&M doesn't erase the deduction — controls count against the score until they are actually implemented.

Self-Assessment vs. Government Assessment

  • Self-assessment — posted in SPRS; the path for CMMC Level 1 and some Level 2 contracts.
  • Medium/High — conducted by the Government (DIBCAC); addressed by the renumbered 252.240-7997.

Why Accuracy Is Non-Negotiable

Your SPRS score is a representation to DoD. Posting a number you cannot support is exactly the kind of misstatement the DOJ's Civil Cyber-Fraud Initiative has pursued under the False Claims Act. The discipline that protects you: assess honestly against all 110 Rev 2 controls, document evidence, fix high-weight gaps first.

Key Takeaways

  • SPRS remains DoD's system of record for NIST SP 800-171 scores.
  • DFARS 7019 deleted; 7020 renumbered to 252.240-7997 (Medium/High only). Self-assessment now flows through CMMC (DFARS 252.204-7021). DFARS 7012 and the 110-control Rev 2 baseline unchanged.
  • Scoring: start at 110, subtract 5/3/1 per gap, floor of -203; POA&M items still count against you.
  • The score is a representation to DoD — accuracy carries real False Claims Act exposure.

See how SPRS fits the broader standards on Frameworks and the DoD rollout on the Defense industry page, review enforcement risk on Enforcement & Penalties, and confirm what applies to your contracts with Find My Requirements.

Share
BH

Brandon Hancock

J.D. · CMMC Registered Practitioner (RP)

Brandon is the founder and principal advisor of GovConCyber. His advisory approach is shaped by roughly six years as a U.S. Army human intelligence collector, where information accuracy, source protection, classification discipline, need-to-know access, and controlled reporting were daily requirements. He brings that information-discipline mindset to GovConCyber's work helping government contractors understand and comply with federal cybersecurity obligations.

Was this post helpful?