SPRS Score Explained: How Arizona Contractors Can Improve Their Rating

What your SPRS score actually means

Every Arizona defense contractor bidding on DoD contracts must have a current SPRS (Supplier Performance Risk System) score posted. The score ranges from -203 to 110, where 110 means full compliance with all NIST SP 800-171 controls and -203 means you haven’t implemented anything.

Your SPRS score is calculated by assessing each of the 110 NIST 800-171 security controls and assigning weighted point values to controls that aren’t met. Controls that protect CUI confidentiality carry the heaviest weights, some worth 5 points each.

The DOJ is actively pursuing contractors who submit inaccurate SPRS scores. The LOGZONE case resulted in a $507,000 settlement for false attestation. Your score needs to reflect your actual security posture, not where you hope to be.

Which controls carry the most weight

Not all 110 controls are weighted equally. The controls that cost the most points when missing are:

  • 3.13.11 FIPS-validated cryptography: -5 points. If you’re not using FIPS 140-2 validated encryption, this single control drops your score significantly.
  • 3.1.1 Account management: -5 points. Basic access control that most small shops struggle with.
  • 3.5.3 Multi-factor authentication: -5 points. MFA on all CUI systems is non-negotiable.
  • 3.13.1 Boundary protection: -5 points. Network segmentation between CUI and non-CUI systems.
  • 3.4.1 System configuration baselines: -5 points. Documented secure configurations for all CUI systems.

Implementing these five controls alone can improve your score by 25 points.

A prioritized remediation plan

Phase 1: Quick wins (weeks 1-2)

Deploy MFA on all systems (3.5.3), implement basic access controls (3.1.1), and enable audit logging (3.3.1). These are high-weight controls with relatively straightforward implementation.

Phase 2: Infrastructure (weeks 3-6)

Implement FIPS-validated encryption (3.13.11), configure network segmentation (3.13.1), and establish system baselines (3.4.1). These require more planning but deliver the biggest score improvements.

Phase 3: Documentation (weeks 6-10)

Build your System Security Plan, document your CUI handling procedures, create your incident response plan, and finalize your POA&M for any remaining gaps.

Phase 4: Validation (weeks 10-12)

Recalculate your SPRS score based on implemented controls, submit the updated score to the SPRS portal, and begin preparing for C3PAO assessment if pursuing CMMC Level 2.

Submitting your score

SPRS scores are submitted through the SPRS portal at sprs.csd.disa.mil. You need a current score on file to bid on DoD contracts containing DFARS 252.204-7012. The score must be updated whenever your security posture changes significantly.

Asteroid IT helps Arizona defense contractors assess their current NIST 800-171 compliance, identify the highest-impact remediation targets, and build a realistic path to their target SPRS score. Learn more about our CMMC compliance services.

Call us at 480-937-7021 or schedule a conversation.

Scroll to Top