Learn about minimum SPRS score required for Conditional CMMC Level 2 certification, how to submit your SPRS score, how DoD uses SPRS scores, and more, through the Frequently Asked Questions (FAQs) below. If you are looking for certified CMMC Professionals and a customized solution for your organization, please schedule a free consultation.
Table of Contents
What is the SPRS scoring range for CMMC Level 2 and how is it calculated?
Summary: The SPRS scoring range for CMMC Level 2 runs from -203 (all controls unimplemented) to +110 (all 110 controls fully implemented), calculated using the DoD’s NIST SP 800-171 Assessment Methodology, which deducts points from a perfect score of 110 for each control found NOT MET based on the control’s assigned weight of 1, 3, or 5 points.
The calculation methodology starts at 110 and subtracts: 5 points for each 5-point control found NOT MET; 3 points for each 3-point control found NOT MET; and 1 point for each 1-point control found NOT MET. The maximum negative score of -203 results from all controls being unimplemented.
Partial implementation does not receive partial credit; a control must be fully implemented for the points to be retained. The score should reflect actual implementation status at the time it is submitted to SPRS. For C3PAO-conducted assessments, the score is calculated by the C3PAO based on their findings and submitted to eMASS; for self-assessments, the contractor calculates and self-submits the score.
What is the minimum SPRS score required for Conditional CMMC Level 2 certification?
The minimum SPRS score required for Conditional CMMC Level 2 certification is 88 out of 110, with the additional mandatory condition that all deficiencies contributing to the score below 110 must apply exclusively to controls weighted at 1 point. Any NOT MET finding on a 3-point or 5-point control disqualifies the organization from Conditional certification regardless of the overall score.
A score of 88 means the organization has successfully implemented controls worth 88 out of 110 total possible points, with the remaining 22 points reflecting unimplemented 1-point controls. At the 1-point weighting, this means a maximum of 22 unimplemented 1-point controls qualify an organization for Conditional status.
The 88-point threshold was established by the DoD as the minimum acceptable posture for any certification status, below this threshold, the number and significance of unimplemented controls is too great to permit even temporary certification. Organizations targeting Conditional certification should ensure their compliance program has addressed all 3-point and 5-point controls completely before undergoing a C3PAO assessment, leaving only 1-point control gaps to be resolved during the 180-day POA&M period if needed.
How do I submit my CMMC Level 1 self-assessment results to SPRS?
Summary: To submit CMMC Level 1 self-assessment results to the Supplier Performance Risk System (SPRS), the contractor accesses SPRS through the PIEE portal at piee.eb.mil, not directly at sprs.csd.disa.mil. The user must have the “SPRS Cyber Vendor User” role approved by their company’s PIEE Contractor Administrator (CAM) before CMMC data entry is available. Once logged into PIEE, they navigate to SPRS, select Cyber Reports (CMMC & NIST), choose the appropriate CAGE and hierarchy from the dropdown, and select “Add New Level 1 CMMC Self-Assessment.”
The entry form captures the assessment date, the assessing scope (Enterprise for the full organizational IT environment, or Enclave for a defined subset), the number of employees in scope, an overall FAR 52.204-21 compliance indicator, and the included CAGE codes pulled from the organization’s SAM-registered hierarchy. It cannot include CAGEs outside the company’s registered hierarchy.
Once the assessment data is entered and confirmed, the user either proceeds directly to affirmation (if they are the Affirming Official) or transfers the assessment to the Affirming Official (AO) via email from within SPRS. The assessment will show a status of “Pending Affirmation” until the AO acts.
The Affirming Official, as defined in 32 CFR 170.4, is the senior-level company representative responsible for ensuring compliance with CMMC Program requirements and who has authority to affirm continuing compliance. The AO logs into SPRS separately, locates the Pending Affirmation record, verifies their personal information (pulled automatically from their PIEE profile), reviews the submitted assessment data, and affirms by certifying the compliance statement. Once affirmed, the record receives a CMMC Unique Identifier (UID) and a status of “Final Level 1 Self-Assessment”, the only status visible to government contracting officers.
A Final Level 1 Self-Assessment is valid for one year from the assessment date. After one year it automatically changes to “No CMMC Status (Expired Assessment)”, turns red, and is no longer visible to government personnel. The entire process, self-assessment, data entry, and AO affirmation, must be repeated annually to maintain contract eligibility.
Organizations new to SPRS should begin the access process well in advance: establishing a SAM account, registering entities, validating CAGE data, setting up a PIEE vendor group, assigning a CAM, and obtaining the SPRS Cyber Vendor User role can collectively take several weeks.
How do I submit my CMMC Level 2 self-assessment results to SPRS?
Summary: CMMC Level 2 self-assessment results are submitted to SPRS through the SPRS portal at sprs.csd.disa.mil, but require additional data compared to Level 1, including the numerical SPRS score calculated under the DoD NIST SP 800-171 Assessment Methodology, POA&M status information, and annual affirmation by a senior Affirming Official.
The Level 2 self-assessment SPRS submission requires: the organization’s CAGE code(s) and hierarchy; the assessment completion date; the assessment scope designation; the SPRS score calculated based on the DoD’s weighted scoring methodology for all 110 controls; POA&M indicator, whether a POA&M exists for unimplemented controls and the overall POA&M compliance status; and the Affirming Official’s information.
Unlike Level 1, a Level 2 self-assessment can be submitted with a score below 110, the score represents the organization’s actual implementation state. A score below 88 submitted to SPRS indicates non-compliant status and will flag the organization’s CMMC posture to contracting officers and primes. The Affirming Official must affirm the submission annually. Organizations should use the CMMC Level 2 Self-Assessment Quick Entry Guide published by SPRS (available at sprs.csd.disa.mil) for step-by-step submission instructions.
How does the DoD use SPRS scores to evaluate contractor cybersecurity posture?
Summary: The DoD uses SPRS scores as a primary indicator of a defense contractor’s cybersecurity posture when evaluating contract eligibility, assessing supply chain risk, and prioritizing oversight activities, with contracting officers required under DFARS 252.204-7021 to verify that contractors hold a valid, current CMMC status in SPRS before awarding applicable contracts.
Contracting officers access contractor SPRS records during the pre-award evaluation phase to confirm that the contractor meets the CMMC level specified in the solicitation. A contractor with no SPRS entry, an expired entry, or an entry below the required CMMC level is ineligible for award. Prime contractors under DFARS 252.204-7021 must also verify subcontractor SPRS entries before awarding subcontracts involving CUI.
Beyond individual contract decisions, the DoD’s Defense Contract Audit Agency (DCAA) and the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) use SPRS data to identify contractors whose self-assessed scores are significantly inconsistent with their known operational environment, triggering prioritized compliance oversight activities. A history of inflated SPRS scores is a red flag that can trigger formal DoD investigation.
What is an Affirming Official (AO) and what is their legal responsibility in SPRS submissions?
Summary: An Affirming Official (AO) is a senior company executive, typically a CEO, COO, CIO, or equivalent officer, designated to review and formally affirm the accuracy of a contractor’s CMMC self-assessment results or compliance status in SPRS, and whose affirmation creates direct personal legal liability under the False Claims Act for the accuracy of the submitted record.
The AO role is defined in 32 CFR Part 170 as requiring a person with organizational authority and accountability to represent the contractor’s compliance status to the U.S. government. The AO’s affirmation is a legal certification to the federal government that the SPRS record is accurate and that the organization maintains the compliance posture it claims.
This affirmation, whether for Level 1 self-assessments, Level 2 self-assessments, or the annual affirmations required between C3PAO triennial certifications, triggers False Claims Act exposure if knowingly false. The Department of Justice’s Civil Cyber-Fraud Initiative explicitly targets executives who sign cybersecurity compliance affirmations without adequate verification of their organization’s actual security posture. AOs should require a formal internal compliance review before signing any SPRS affirmation.
How often must CMMC compliance be affirmed in SPRS after certification?
Following CMMC Level 2 C3PAO certification, the organization must submit annual affirmations of continued compliance in SPRS, once during Year 1 (within 12 months of the certification date) and once during Year 2 (within 24 months), with a new C3PAO assessment required in Year 3 to renew the three-year certification.
The annual affirmation is not a self-assessment, it does not require the organization to recalculate its SPRS score or conduct a full control review. It is a formal declaration by the Affirming Official that the organization has maintained the security posture reflected in its most recent C3PAO assessment findings, that the assessment boundary has not materially changed, and that all previously identified POA&M items remain closed.
If the organization has experienced significant changes, new systems, new personnel, new cloud services, or a security incident, those changes must be assessed for impact on the certification status before the affirmation is submitted. A false annual affirmation carries the same False Claims Act exposure as a false self-assessment submission.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties