Free Tool
SPRS Score Calculator
Estimate your Supplier Performance Risk System (SPRS) score for a NIST SP 800-171 Rev 2 self-assessment. Toggle each control that is NOT fully implemented; we apply the DoD Assessment Methodology weights (-1, -3, or -5) and update your score live.
A perfect score is +110. Most DoD primes accept 88 or higher; anything below 80 typically requires a POA&M and a closure plan. Negative scores indicate significant gaps and disqualify most contracts.
- -53.1.1Limit system access to authorized users
- -53.1.2Limit system access to permitted transactions and functions
- -13.1.3Control the flow of CUI
- -13.1.4Separate duties of individuals
- -33.1.5Employ least privilege
- -13.1.6Use non-privileged accounts for non-security functions
- -13.1.7Prevent non-privileged users from executing privileged functions
- -13.1.8Limit unsuccessful logon attempts
- -13.1.9Provide privacy and security notices
- -13.1.10Use session lock with pattern-hiding displays
- -13.1.11Terminate user session after defined condition
- -53.1.12Monitor and control remote access sessions
- -53.1.13Employ cryptographic mechanisms for remote access
- -13.1.14Route remote access via managed access control points
- -13.1.15Authorize remote execution of privileged commands
- -53.1.16Authorize wireless access prior to allowing connections
- -53.1.17Protect wireless access using authentication and encryption
- -53.1.18Control connection of mobile devices
- -53.1.19Encrypt CUI on mobile devices and mobile computing platforms
- -13.1.20Verify and control external system connections
- -13.1.21Limit use of portable storage devices on external systems
- -13.1.22Control CUI posted or processed on publicly accessible systems
- -53.2.1Ensure managers and users are aware of security risks
- -53.2.2Ensure personnel are trained to carry out assigned duties
- -13.2.3Provide insider threat awareness training
- -53.3.1Create and retain system audit logs
- -33.3.2Ensure actions of individual users can be uniquely traced
- -13.3.3Review and update logged events
- -13.3.4Alert in the event of an audit logging process failure
- -53.3.5Correlate audit record review and reporting processes
- -13.3.6Provide audit record reduction and report generation
- -13.3.7Provide a system capability that compares and synchronizes internal clocks
- -13.3.8Protect audit information and audit logging tools
- -13.3.9Limit management of audit logging functionality to a subset of users
- -53.4.1Establish and maintain baseline configurations and inventories
- -53.4.2Establish and enforce security configuration settings
- -13.4.3Track, review, approve, and log changes to systems
- -13.4.4Analyze the security impact of changes prior to implementation
- -13.4.5Define, document, approve, and enforce physical and logical access restrictions
- -53.4.6Employ principle of least functionality
- -53.4.7Restrict, disable, or prevent nonessential programs and services
- -53.4.8Apply deny-by-exception or permit-by-exception for software execution
- -13.4.9Control and monitor user-installed software
- -53.5.1Identify system users, processes acting on behalf of users, and devices
- -53.5.2Authenticate users, processes, or devices before allowing access
- -53.5.3Use MFA for privileged accounts and for network access to non-privileged accounts
- -53.5.4Employ replay-resistant authentication mechanisms
- -13.5.5Prevent reuse of identifiers for a defined period
- -13.5.6Disable identifiers after a defined period of inactivity
- -13.5.7Enforce a minimum password complexity
- -13.5.8Prohibit password reuse for a defined number of generations
- -13.5.9Allow temporary passwords with immediate change requirement
- -53.5.10Store and transmit only cryptographically protected passwords
- -13.5.11Obscure feedback of authentication information
- -53.6.1Establish an operational incident-handling capability
- -53.6.2Track, document, and report incidents to designated officials
- -13.6.3Test the organizational incident response capability
- -13.7.1Perform maintenance on organizational systems
- -13.7.2Provide controls on tools, techniques, mechanisms, and personnel used for maintenance
- -13.7.3Ensure equipment removed for off-site maintenance is sanitized of CUI
- -53.7.4Check media containing diagnostic and test programs for malicious code
- -53.7.5Require MFA to establish nonlocal maintenance sessions
- -13.7.6Supervise the maintenance activities of maintenance personnel without required access
- -33.8.1Protect (physically control and securely store) media containing CUI
- -33.8.2Limit access to CUI on system media to authorized users
- -33.8.3Sanitize or destroy media containing CUI before disposal or reuse
- -13.8.4Mark media with necessary CUI markings and distribution limitations
- -13.8.5Control access to media containing CUI and maintain accountability during transport
- -53.8.6Implement cryptographic mechanisms to protect confidentiality of CUI on digital media during transport
- -53.8.7Control the use of removable media on system components
- -33.8.8Prohibit use of portable storage devices when such devices have no identifiable owner
- -13.8.9Protect the confidentiality of backup CUI at storage locations
- -33.9.1Screen individuals prior to authorizing access to systems containing CUI
- -33.9.2Ensure CUI is protected during and after personnel actions
- -53.10.1Limit physical access to systems, equipment, and operating environments
- -53.10.2Protect and monitor the physical facility and support infrastructure
- -13.10.3Escort visitors and monitor visitor activity
- -13.10.4Maintain audit logs of physical access
- -13.10.5Control and manage physical access devices
- -13.10.6Enforce safeguarding measures for CUI at alternate work sites
- -33.11.1Periodically assess the risk to organizational operations
- -53.11.2Scan for vulnerabilities in organizational systems and applications periodically
- -13.11.3Remediate vulnerabilities in accordance with risk assessments
- -53.12.1Periodically assess the security controls in organizational systems
- -33.12.2Develop and implement plans of action designed to correct deficiencies
- -53.12.3Monitor security controls on an ongoing basis
- -33.12.4Develop, document, and periodically update system security plans
- -53.13.1Monitor, control, and protect communications at system boundaries
- -53.13.2Employ architectural designs, software development techniques promoting security
- -13.13.3Separate user functionality from system management functionality
- -13.13.4Prevent unauthorized and unintended information transfer via shared resources
- -53.13.5Implement subnetworks for publicly accessible system components
- -53.13.6Deny network communications traffic by default and allow by exception
- -53.13.7Prevent remote devices from split tunneling
- -53.13.8Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI in transit
- -13.13.9Terminate network connections at the end of the sessions or after inactivity
- -53.13.10Establish and manage cryptographic keys for cryptography employed
- -53.13.11Employ FIPS-validated cryptography when used to protect CUI
- -13.13.12Prohibit remote activation of collaborative computing devices
- -13.13.13Control and monitor the use of mobile code
- -13.13.14Control and monitor the use of Voice over Internet Protocol
- -53.13.15Protect the authenticity of communications sessions
- -33.13.16Protect the confidentiality of CUI at rest
- -53.14.1Identify, report, and correct system flaws in a timely manner
- -53.14.2Provide protection from malicious code at designated locations
- -53.14.3Monitor system security alerts and advisories and take action
- -53.14.4Update malicious code protection mechanisms when new releases are available
- -33.14.5Perform periodic scans of the system and real-time scans of files from external sources
- -53.14.6Monitor systems including inbound and outbound communications traffic
- -33.14.7Identify unauthorized use of organizational systems
Get the branded PDF
Enter your email and we'll open a printable, branded version of this scorecard with your family-level breakdown. We'll also send you a copy for the record.
Ready to close these gaps?
Symbiosis pre-loads all 110 controls, generates your SSP and POA&M, and produces a C3PAO-ready evidence package. Flat $2,500 for the readiness engagement.
See the CMMC L2 package