Free Tool

SPRS Score Calculator

Estimate your Supplier Performance Risk System (SPRS) score for a NIST SP 800-171 Rev 2 self-assessment. Toggle each control that is NOT fully implemented; we apply the DoD Assessment Methodology weights (-1, -3, or -5) and update your score live.

SPRS Score
110/ 110
Deductions
0
Implemented
110 / 110

A perfect score is +110. Most DoD primes accept 88 or higher; anything below 80 typically requires a POA&M and a closure plan. Negative scores indicate significant gaps and disqualify most contracts.

AC
Access Control
22 / 22 in place
  • 3.1.1Limit system access to authorized users
    -5
  • 3.1.2Limit system access to permitted transactions and functions
    -5
  • 3.1.3Control the flow of CUI
    -1
  • 3.1.4Separate duties of individuals
    -1
  • 3.1.5Employ least privilege
    -3
  • 3.1.6Use non-privileged accounts for non-security functions
    -1
  • 3.1.7Prevent non-privileged users from executing privileged functions
    -1
  • 3.1.8Limit unsuccessful logon attempts
    -1
  • 3.1.9Provide privacy and security notices
    -1
  • 3.1.10Use session lock with pattern-hiding displays
    -1
  • 3.1.11Terminate user session after defined condition
    -1
  • 3.1.12Monitor and control remote access sessions
    -5
  • 3.1.13Employ cryptographic mechanisms for remote access
    -5
  • 3.1.14Route remote access via managed access control points
    -1
  • 3.1.15Authorize remote execution of privileged commands
    -1
  • 3.1.16Authorize wireless access prior to allowing connections
    -5
  • 3.1.17Protect wireless access using authentication and encryption
    -5
  • 3.1.18Control connection of mobile devices
    -5
  • 3.1.19Encrypt CUI on mobile devices and mobile computing platforms
    -5
  • 3.1.20Verify and control external system connections
    -1
  • 3.1.21Limit use of portable storage devices on external systems
    -1
  • 3.1.22Control CUI posted or processed on publicly accessible systems
    -1
AT
Awareness and Training
3 / 3 in place
  • 3.2.1Ensure managers and users are aware of security risks
    -5
  • 3.2.2Ensure personnel are trained to carry out assigned duties
    -5
  • 3.2.3Provide insider threat awareness training
    -1
AU
Audit and Accountability
9 / 9 in place
  • 3.3.1Create and retain system audit logs
    -5
  • 3.3.2Ensure actions of individual users can be uniquely traced
    -3
  • 3.3.3Review and update logged events
    -1
  • 3.3.4Alert in the event of an audit logging process failure
    -1
  • 3.3.5Correlate audit record review and reporting processes
    -5
  • 3.3.6Provide audit record reduction and report generation
    -1
  • 3.3.7Provide a system capability that compares and synchronizes internal clocks
    -1
  • 3.3.8Protect audit information and audit logging tools
    -1
  • 3.3.9Limit management of audit logging functionality to a subset of users
    -1
CM
Configuration Management
9 / 9 in place
  • 3.4.1Establish and maintain baseline configurations and inventories
    -5
  • 3.4.2Establish and enforce security configuration settings
    -5
  • 3.4.3Track, review, approve, and log changes to systems
    -1
  • 3.4.4Analyze the security impact of changes prior to implementation
    -1
  • 3.4.5Define, document, approve, and enforce physical and logical access restrictions
    -1
  • 3.4.6Employ principle of least functionality
    -5
  • 3.4.7Restrict, disable, or prevent nonessential programs and services
    -5
  • 3.4.8Apply deny-by-exception or permit-by-exception for software execution
    -5
  • 3.4.9Control and monitor user-installed software
    -1
IA
Identification and Authentication
11 / 11 in place
  • 3.5.1Identify system users, processes acting on behalf of users, and devices
    -5
  • 3.5.2Authenticate users, processes, or devices before allowing access
    -5
  • 3.5.3Use MFA for privileged accounts and for network access to non-privileged accounts
    -5
  • 3.5.4Employ replay-resistant authentication mechanisms
    -5
  • 3.5.5Prevent reuse of identifiers for a defined period
    -1
  • 3.5.6Disable identifiers after a defined period of inactivity
    -1
  • 3.5.7Enforce a minimum password complexity
    -1
  • 3.5.8Prohibit password reuse for a defined number of generations
    -1
  • 3.5.9Allow temporary passwords with immediate change requirement
    -1
  • 3.5.10Store and transmit only cryptographically protected passwords
    -5
  • 3.5.11Obscure feedback of authentication information
    -1
IR
Incident Response
3 / 3 in place
  • 3.6.1Establish an operational incident-handling capability
    -5
  • 3.6.2Track, document, and report incidents to designated officials
    -5
  • 3.6.3Test the organizational incident response capability
    -1
MA
Maintenance
6 / 6 in place
  • 3.7.1Perform maintenance on organizational systems
    -1
  • 3.7.2Provide controls on tools, techniques, mechanisms, and personnel used for maintenance
    -1
  • 3.7.3Ensure equipment removed for off-site maintenance is sanitized of CUI
    -1
  • 3.7.4Check media containing diagnostic and test programs for malicious code
    -5
  • 3.7.5Require MFA to establish nonlocal maintenance sessions
    -5
  • 3.7.6Supervise the maintenance activities of maintenance personnel without required access
    -1
MP
Media Protection
9 / 9 in place
  • 3.8.1Protect (physically control and securely store) media containing CUI
    -3
  • 3.8.2Limit access to CUI on system media to authorized users
    -3
  • 3.8.3Sanitize or destroy media containing CUI before disposal or reuse
    -3
  • 3.8.4Mark media with necessary CUI markings and distribution limitations
    -1
  • 3.8.5Control access to media containing CUI and maintain accountability during transport
    -1
  • 3.8.6Implement cryptographic mechanisms to protect confidentiality of CUI on digital media during transport
    -5
  • 3.8.7Control the use of removable media on system components
    -5
  • 3.8.8Prohibit use of portable storage devices when such devices have no identifiable owner
    -3
  • 3.8.9Protect the confidentiality of backup CUI at storage locations
    -1
PS
Personnel Security
2 / 2 in place
  • 3.9.1Screen individuals prior to authorizing access to systems containing CUI
    -3
  • 3.9.2Ensure CUI is protected during and after personnel actions
    -3
PE
Physical Protection
6 / 6 in place
  • 3.10.1Limit physical access to systems, equipment, and operating environments
    -5
  • 3.10.2Protect and monitor the physical facility and support infrastructure
    -5
  • 3.10.3Escort visitors and monitor visitor activity
    -1
  • 3.10.4Maintain audit logs of physical access
    -1
  • 3.10.5Control and manage physical access devices
    -1
  • 3.10.6Enforce safeguarding measures for CUI at alternate work sites
    -1
RA
Risk Assessment
3 / 3 in place
  • 3.11.1Periodically assess the risk to organizational operations
    -3
  • 3.11.2Scan for vulnerabilities in organizational systems and applications periodically
    -5
  • 3.11.3Remediate vulnerabilities in accordance with risk assessments
    -1
CA
Security Assessment
4 / 4 in place
  • 3.12.1Periodically assess the security controls in organizational systems
    -5
  • 3.12.2Develop and implement plans of action designed to correct deficiencies
    -3
  • 3.12.3Monitor security controls on an ongoing basis
    -5
  • 3.12.4Develop, document, and periodically update system security plans
    -3
SC
System and Communications Protection
16 / 16 in place
  • 3.13.1Monitor, control, and protect communications at system boundaries
    -5
  • 3.13.2Employ architectural designs, software development techniques promoting security
    -5
  • 3.13.3Separate user functionality from system management functionality
    -1
  • 3.13.4Prevent unauthorized and unintended information transfer via shared resources
    -1
  • 3.13.5Implement subnetworks for publicly accessible system components
    -5
  • 3.13.6Deny network communications traffic by default and allow by exception
    -5
  • 3.13.7Prevent remote devices from split tunneling
    -5
  • 3.13.8Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI in transit
    -5
  • 3.13.9Terminate network connections at the end of the sessions or after inactivity
    -1
  • 3.13.10Establish and manage cryptographic keys for cryptography employed
    -5
  • 3.13.11Employ FIPS-validated cryptography when used to protect CUI
    -5
  • 3.13.12Prohibit remote activation of collaborative computing devices
    -1
  • 3.13.13Control and monitor the use of mobile code
    -1
  • 3.13.14Control and monitor the use of Voice over Internet Protocol
    -1
  • 3.13.15Protect the authenticity of communications sessions
    -5
  • 3.13.16Protect the confidentiality of CUI at rest
    -3
SI
System and Information Integrity
7 / 7 in place
  • 3.14.1Identify, report, and correct system flaws in a timely manner
    -5
  • 3.14.2Provide protection from malicious code at designated locations
    -5
  • 3.14.3Monitor system security alerts and advisories and take action
    -5
  • 3.14.4Update malicious code protection mechanisms when new releases are available
    -5
  • 3.14.5Perform periodic scans of the system and real-time scans of files from external sources
    -3
  • 3.14.6Monitor systems including inbound and outbound communications traffic
    -5
  • 3.14.7Identify unauthorized use of organizational systems
    -3

Get the branded PDF

Enter your email and we'll open a printable, branded version of this scorecard with your family-level breakdown. We'll also send you a copy for the record.

Ready to close these gaps?

Symbiosis pre-loads all 110 controls, generates your SSP and POA&M, and produces a C3PAO-ready evidence package. Flat $2,500 for the readiness engagement.

See the CMMC L2 package
Just getting started? The Level 1 self-attestation package starts at $500.