CMMCDocsCMMCDocs.com

Home / Glossary / SPRS

SPRS

Also known as: Supplier Performance Risk System

Supplier Performance Risk System — the DoD's web-based portal where defense contractors post NIST SP 800-171 assessment scores and submit CMMC affirmations.

The Supplier Performance Risk System (SPRS) is the Department of Defense's web-based portal for tracking supplier performance, risk indicators, and cybersecurity assessment scores. For CMMC purposes, SPRS is where contractors post their NIST SP 800-171 self-assessment scores under DFARS 252.204-7019 and where the senior official annual affirmation is submitted.

The SPRS score is calculated using the DoD Assessment Methodology: starting at 110 (a perfect score), the contractor deducts 1, 3, or 5 points for each NIST SP 800-171 requirement that is not fully implemented, depending on the requirement's weight. A perfect score is 110; the worst possible score is -203.

A current SPRS score is required for contract award under contracts containing DFARS 252.204-7019. Under CMMC 2.0, the SPRS score is also where final and conditional certification statuses are recorded.

Stop Googling. Start working.

CMMCDocs has all 110 NIST SP 800-171 Rev 2 requirements built in — with the language, the templates, and the evidence vault you need. Spin up a free demo workspace and click around the way an assessor would.

Get my demo account