What the number actually is
The Supplier Performance Risk System is the Department of Defense's system of record for supplier risk information, and cybersecurity is one part of it. The entry that concerns you is an assessment of your implementation of NIST SP 800-171, computed with the DoD Assessment Methodology, and it is a piece of arithmetic rather than a judgement. You begin at 110 — one point for each requirement — and subtract the weight of every requirement you have not implemented: 5, 3, or 1 point, depending on how much damage its absence could do. The published floor is negative 203, which is the clearest possible signal that the number is a measurement and not a mark out of a hundred.
Two requirements have a defined halfway state. Multifactor authentication costs three points instead of five when it is implemented for remote and privileged users but not for everyone. FIPS-validated cryptography costs three instead of five when encryption is in use but the module is not validated. Those two partial credits are worth knowing because they are the two places where being most of the way there is worth something.

The number does not travel alone. Posted alongside it are the standard you assessed against, the date, the scope — which systems and which CAGE codes the score covers — and the date by which you expect to reach a score of 110. That last field is the one people skip past, and it is a commitment in a government system about your own plan.
You are probably here because
- A solicitation says you need a current assessment in SPRS and you do not have one
- A prime asked for your score and you do not know what is posted
- Someone posted a number three years ago and nobody can explain how it was derived
- Your score is low and you want to know whether that costs you awards
The section on what the clause actually requires is the one that resolves most of the worry. Read it before you consider adjusting a number.
The clause asks for current, not high
Here is the part that changes how people feel about a low score. DFARS 252.204-7019 requires an offeror to have a current assessment — one not more than three years old, unless a different period is specified — posted in SPRS in order to be considered for award of a covered contract. It sets a recency condition. It does not set a minimum score.
That is genuinely important and widely misunderstood. A firm with a low but current and defensible score satisfies the clause. A firm with no assessment at all does not, and a firm whose assessment lapsed past three years does not either. The most common actual problem we see is not a bad score. It is an absent or expired one, discovered a week before a proposal is due, when getting system access takes longer than that.
The related clause, 252.204-7020, does two other things worth knowing. It preserves the Government's right to conduct its own assessment at a higher confidence level, and it flows the requirement down to subcontractors on covered work. Your primes read your score. So do the primes considering whether to add you to a team.
CMMC layers on top of this rather than replacing it. A Level 2 self-assessment status carries the same 110 arithmetic, but a Conditional status requires a score of at least 88 with a plan of action for the remaining eligible gaps, closed within 180 days. So the same number is a recency question under one clause and a threshold question under another, and knowing which conversation you are in prevents a lot of confusion.
Three levels of confidence, and who does each
The methodology defines three assessment types. They compute the same score; what differs is who performed it and how much the Government trusts the result.
| Type | Who performs it | What it is worth |
|---|---|---|
| Basic | You, against your own system security plan | Low confidence, by design, because it is self-generated. It is also the one nearly every firm posts, and it is a valid answer to the clause |
| Medium | The Government, reviewing your system security plan and how you arrived at your answers | Medium confidence. A document review that tests whether the plan supports the score you claimed |
| High | The Government, on site or virtually, examining evidence and demonstrations | High confidence. This is the one that finds the difference between a plan and an environment |
The existence of the second and third types is the reason to be careful with the first. A self-assessment is not a private document. It is a claim the Government can come and test, and the test is a comparison between what you posted and what your systems do.
The three ways a posted score goes quietly wrong
In our experience, when a score is a problem it is almost never because someone deliberately inflated it. It is one of these three, and all three are quiet.
It is stale. A number posted before a cloud migration, an acquisition, a new office or an identity platform change describes a company that no longer exists. Nothing prompts an update. The three-year window makes staleness a compliance problem eventually, but the environment can diverge in three months.
The scope is wrong. A score covers particular systems and particular CAGE codes. If it was computed for the corporate network and the work is performed in an enclave, or computed for one location while a second facility does the actual work, the number is accurate about the wrong thing. Scope errors are harder to spot than staleness because the number looks fine.
Nobody can reconstruct it. Someone worked through a spreadsheet, reached a total, entered it, and left the company. There is no record of which requirements were marked implemented or why. This is the worst of the three, because the fix is a fresh assessment and because it is the state that makes an affirmation impossible to sign honestly.
Against all three, the remedy is the same and it is not technical: keep the worksheet. Every requirement, the answer, the reason, the evidence pointer, the date, the name of the person who decided. If your score cannot be reconstructed from a document you hold, you do not really have a score. You have a number.
Raising it, in the order that pays
The arithmetic tells you exactly where to spend, and the answer is rarely the order the control list is printed in.
- Start with the five-point requirements you have not implemented. Forty-two requirements carry that weight and they hold most of the available points
- Take the two partial credits. Extending multifactor and moving to a validated cryptographic mode each recover points without a full project
- Check the six that can never sit on a plan of action — external systems, publicly accessible content, the system security plan, and the three physical access requirements. These gate a conditional status regardless of your total
- Sweep the one-point items in a batch. Individually trivial, collectively fifty-four points, and many are settings you can change in a week
- Re-score honestly and re-post. An improved score has no effect until it is entered
- Update the plan date. The date by which you expect to reach 110 should track reality, not the optimism of whoever first entered it
Points recovered per unit of effort — our read
Our judgement of points recovered relative to effort, not a survey. The bottom row is often necessary and almost never the place to start.
Why an honest low score is the safer position
The temptation with a self-assessment is obvious, and it should be resisted for a reason that has nothing to do with virtue.
The score sits in a government system attached to your company, and under CMMC a named official at your firm affirms continuing compliance. Statements made to obtain or keep federal contract dollars are the subject matter of the False Claims Act, and the Department of Justice has an active initiative aimed specifically at cybersecurity representations by contractors. That is a matter of public record and it is worth reading about before anyone rounds a number up.
Set the legal exposure aside and the commercial logic points the same way. A low score that is accurate is a plan with a date on it, and a prime evaluating you can work with that. A high score that cannot be substantiated is discovered during a Medium or High assessment, or during an incident, or during a prime's own diligence — and at that moment you have not lost a compliance argument, you have lost the relationship. The recoverable position is the honest one.
There is a practical version of this too. Your score should be reproducible from your worksheet by someone who was not there. If it is, you can defend it, improve it, and affirm it. If it is not, every one of those becomes a guess.
Getting access, which takes longer than you think
Posting a score requires an account with the right role, obtained through the Government's enterprise access portal, and approved by an administrator at your own company. This is ordinary administrative work and it is also the step that surprises people, because it involves identifying who at your firm holds the administrator role — a question that in small companies frequently has no known answer.
Start it early, and start it before you need it. Confirm today who can log in, what role they hold, and whether they still work there. Role names and portal navigation change; check the current guidance rather than an old internal note. The failure mode here is not complexity, it is lead time: a firm that discovers on Monday that nobody can log in does not fix it before Friday.
- Posting a number with no worksheet behind it, which makes both improvement and affirmation impossible
- Letting the score expire and discovering it during a proposal
- Scoring the wrong scope — the corporate network when the work happens in an enclave, or one CAGE when the contract sits under another
- Assuming a low score disqualifies you, when the clause asks for a current assessment rather than a passing one
- Rounding up in a system where the Government can test the claim
- Improving the environment and never re-posting, so the work is invisible to every prime who looks
- Scoring against the wrong revision of the standard — confirm which one applies to your contract before you compute anything
What we would do in the first week
If you are starting cold, this is a week of work and most of it is not technical.
- Find out what is posted today, for which CAGE codes, on what date, and by whom
- Confirm who can log in and fix that first if the answer is nobody
- Locate the system security plan the score was based on, or note that there is not one
- Re-score against the current environment with a worksheet that records the reason for every answer
- Compare. If the new number differs materially from what is posted, that gap is your actual project
- Post the honest result with a realistic date for reaching 110, and put a calendar reminder to revisit it
One honest note on where outside help is worth paying for. If you have a competent IT provider and a reasonably documented environment, this is a two-week internal exercise with a spreadsheet, and hiring someone to do it is optional. Bring in an outside reader when the environment is genuinely complicated, when a posted number cannot be explained by anyone still at the company, or when you want a second opinion before a Government assessment. Those are the situations where an independent read earns its cost. A first self-assessment on a simple estate usually is not.
Bottom line
The score is a measurement, the clause asks for currency rather than excellence, and the thing that makes a score valuable is that it can be reconstructed. Keep the worksheet. Raise the number in weight order and take the two partial credits early. Re-post when the environment changes rather than when the calendar forces it. And never post a figure you could not walk someone through, because the whole point of the system is that somebody may ask.
Frequently asked questions
DFARS 252.204-7019 requires a current assessment — generally not more than three years old — posted in SPRS as a condition of being considered for award. It does not set a minimum score. CMMC is a different matter: a Level 2 Conditional status requires a score of at least 88 with a plan of action for the remaining eligible gaps. Know which of those two conversations a given solicitation is having.
Yes, and it is common for firms early in their implementation. The methodology starts at 110 and subtracts weighted points for each requirement not implemented, with a published floor of negative 203. A negative number is not a scandal; it is an accurate description of an environment that has not yet done the work. What matters is whether it is current, defensible, and moving.
The clause sets a three-year outer limit. Practice should be tighter: re-score whenever the environment changes materially — a migration, an acquisition, a new site, a change of identity platform or managed provider — and at least annually otherwise, particularly if you are affirming continuing compliance. A score that has not moved in three years is describing a company that has.
A Basic assessment is performed by you, against your own system security plan, and is what most firms post. Medium and High assessments are performed by the Government at higher confidence levels. You can engage an outside firm to help you prepare or to review your work, but the self-assessment remains yours: your worksheet, your posting, and your official's affirmation.
Because an improved environment has no effect until it is re-scored and re-posted. This is the single most common piece of unclaimed value we see — firms that spent a year on remediation, and a prime pulling their record still sees the number from before the work started. Re-scoring is a day. Doing it is what makes the year of work visible.
