How to Calculate Your SPRS Score for CMMC Level 2

    Direct answer: an SPRS score for CMMC Level 2 starts at 110 — one point for each of the 110 NIST SP 800-171 Rev. 2 security requirements — and you subtract a weighted 5, 3, or 1 point for every requirement you have not implemented. The weights reflect risk, not effort, so the scale runs from a maximum of 110 down to a minimum of -203. Two requirements allow partial credit (3.5.3 and 3.13.11), and 3.12.4 gates the assessment entirely. Score all 110 requirements below and download the ledger — free, no sign-up, and nothing you enter leaves your browser.

    Your SPRS score

    0 of 109 scored requirements answered. Unanswered requirements are counted as a full deduction, so the score only improves as you confirm implementation.

    Score all 110 requirements

    • AC.L2-3.1.1
      5-point

      Authorized users/devices

      Status for AC.L2-3.1.1
    • AC.L2-3.1.2
      5-point

      Authorized transactions and functions

      Status for AC.L2-3.1.2
    • AC.L2-3.1.3
      1-point

      Control CUI flow

      Status for AC.L2-3.1.3
    • AC.L2-3.1.4
      1-point

      Separation of duties

      Status for AC.L2-3.1.4
    • AC.L2-3.1.5
      3-point

      Least privilege

      Status for AC.L2-3.1.5
    • AC.L2-3.1.6
      1-point

      Use non-privileged accounts

      Status for AC.L2-3.1.6
    • AC.L2-3.1.7
      1-point

      Prevent non-privileged execution of privileged functions

      Status for AC.L2-3.1.7
    • AC.L2-3.1.8
      1-point

      Limit unsuccessful logon attempts

      Status for AC.L2-3.1.8
    • AC.L2-3.1.9
      1-point

      Privacy and security notices

      Status for AC.L2-3.1.9
    • AC.L2-3.1.10
      1-point

      Session lock

      Status for AC.L2-3.1.10
    • AC.L2-3.1.11
      1-point

      Automatic session termination

      Status for AC.L2-3.1.11
    • AC.L2-3.1.12
      5-point

      Monitor and control remote access sessions

      Status for AC.L2-3.1.12
    • AC.L2-3.1.13
      5-point

      Cryptographic protection for remote access

      Status for AC.L2-3.1.13
    • AC.L2-3.1.14
      1-point

      Route remote access through managed access control points

      Status for AC.L2-3.1.14
    • AC.L2-3.1.15
      1-point

      Authorize remote privileged commands and access

      Status for AC.L2-3.1.15
    • AC.L2-3.1.16
      5-point

      Authorize wireless access

      Status for AC.L2-3.1.16
    • AC.L2-3.1.17
      5-point

      Protect wireless access

      Status for AC.L2-3.1.17
    • AC.L2-3.1.18
      5-point

      Control connection of mobile devices

      Status for AC.L2-3.1.18
    • AC.L2-3.1.19
      3-point

      Encrypt CUI on mobile devices

      Status for AC.L2-3.1.19
    • AC.L2-3.1.20
      1-point

      Verify and control external connections

      Status for AC.L2-3.1.20
    • AC.L2-3.1.21
      1-point

      Limit use of portable storage on external systems

      Status for AC.L2-3.1.21
    • AC.L2-3.1.22
      1-point

      Control publicly accessible CUI

      Status for AC.L2-3.1.22
    • AT.L2-3.2.1
      5-point

      Security awareness for managers/admins/users

      Status for AT.L2-3.2.1
    • AT.L2-3.2.2
      5-point

      Role-based security training

      Status for AT.L2-3.2.2
    • AT.L2-3.2.3
      1-point

      Insider threat awareness training

      Status for AT.L2-3.2.3
    • AU.L2-3.3.1
      5-point

      Create and retain audit logs

      Status for AU.L2-3.3.1
    • AU.L2-3.3.2
      3-point

      Audit record content

      Status for AU.L2-3.3.2
    • AU.L2-3.3.3
      1-point

      Review and update auditable events

      Status for AU.L2-3.3.3
    • AU.L2-3.3.4
      1-point

      Alert on audit logging failure

      Status for AU.L2-3.3.4
    • AU.L2-3.3.5
      5-point

      Correlate audit review/analysis/reporting

      Status for AU.L2-3.3.5
    • AU.L2-3.3.6
      1-point

      Audit reduction and report generation

      Status for AU.L2-3.3.6
    • AU.L2-3.3.7
      1-point

      Time synchronization for audit records

      Status for AU.L2-3.3.7
    • AU.L2-3.3.8
      1-point

      Protect audit information and tools

      Status for AU.L2-3.3.8
    • AU.L2-3.3.9
      1-point

      Limit audit management to privileged users

      Status for AU.L2-3.3.9
    • CM.L2-3.4.1
      5-point

      Baseline configurations and inventories

      Status for CM.L2-3.4.1
    • CM.L2-3.4.2
      5-point

      Enforce security configuration settings

      Status for CM.L2-3.4.2
    • CM.L2-3.4.3
      1-point

      Change control

      Status for CM.L2-3.4.3
    • CM.L2-3.4.4
      1-point

      Security impact analysis for changes

      Status for CM.L2-3.4.4
    • CM.L2-3.4.5
      5-point

      Access restrictions for changes

      Status for CM.L2-3.4.5
    • CM.L2-3.4.6
      5-point

      Least functionality

      Status for CM.L2-3.4.6
    • CM.L2-3.4.7
      5-point

      Restrict nonessential programs/services/ports/protocols

      Status for CM.L2-3.4.7
    • CM.L2-3.4.8
      5-point

      Allow-by-exception or deny-by-exception software control

      Status for CM.L2-3.4.8
    • CM.L2-3.4.9
      1-point

      Control user-installed software

      Status for CM.L2-3.4.9
    • IA.L2-3.5.1
      5-point

      Identify users, processes, and devices

      Status for IA.L2-3.5.1
    • IA.L2-3.5.2
      5-point

      Authenticate identities

      Status for IA.L2-3.5.2
    • IA.L2-3.5.3
      Special 3 / 5

      Multi-factor authentication

      Partial (deduct 3): Multifactor authentication covers remote and privileged users but not general users.

      Status for IA.L2-3.5.3
    • IA.L2-3.5.4
      1-point

      Replay-resistant authentication

      Status for IA.L2-3.5.4
    • IA.L2-3.5.5
      1-point

      Prevent reuse of identifiers

      Status for IA.L2-3.5.5
    • IA.L2-3.5.6
      1-point

      Disable identifiers after inactivity

      Status for IA.L2-3.5.6
    • IA.L2-3.5.7
      1-point

      Password complexity

      Status for IA.L2-3.5.7
    • IA.L2-3.5.8
      1-point

      Password reuse limits

      Status for IA.L2-3.5.8
    • IA.L2-3.5.9
      1-point

      Temporary passwords for immediate change

      Status for IA.L2-3.5.9
    • IA.L2-3.5.10
      5-point

      Cryptographically protected passwords

      Status for IA.L2-3.5.10
    • IA.L2-3.5.11
      1-point

      Obscure authentication feedback

      Status for IA.L2-3.5.11
    • IR.L2-3.6.1
      5-point

      Incident handling capability

      Status for IR.L2-3.6.1
    • IR.L2-3.6.2
      5-point

      Track, document, and report incidents

      Status for IR.L2-3.6.2
    • IR.L2-3.6.3
      1-point

      Test incident response

      Status for IR.L2-3.6.3
    • MA.L2-3.7.1
      3-point

      Perform maintenance

      Status for MA.L2-3.7.1
    • MA.L2-3.7.2
      5-point

      Control maintenance tools, techniques, personnel

      Status for MA.L2-3.7.2
    • MA.L2-3.7.3
      1-point

      Sanitize equipment removed for off-site maintenance

      Status for MA.L2-3.7.3
    • MA.L2-3.7.4
      3-point

      Check maintenance media for malicious code

      Status for MA.L2-3.7.4
    • MA.L2-3.7.5
      5-point

      MFA for nonlocal maintenance sessions

      Status for MA.L2-3.7.5
    • MA.L2-3.7.6
      1-point

      Supervise maintenance personnel without authorization

      Status for MA.L2-3.7.6
    • MP.L2-3.8.1
      3-point

      Protect system media

      Status for MP.L2-3.8.1
    • MP.L2-3.8.2
      3-point

      Limit access to media

      Status for MP.L2-3.8.2
    • MP.L2-3.8.3
      5-point

      Sanitize or destroy media before disposal/reuse

      Status for MP.L2-3.8.3
    • MP.L2-3.8.4
      1-point

      Mark media with CUI markings

      Status for MP.L2-3.8.4
    • MP.L2-3.8.5
      1-point

      Protect media during transport

      Status for MP.L2-3.8.5
    • MP.L2-3.8.6
      1-point

      Cryptographic protection for digital media in transport

      Status for MP.L2-3.8.6
    • MP.L2-3.8.7
      5-point

      Control removable media

      Status for MP.L2-3.8.7
    • MP.L2-3.8.8
      3-point

      Prohibit portable storage with no identifiable owner

      Status for MP.L2-3.8.8
    • MP.L2-3.8.9
      1-point

      Protect backup CUI at storage locations

      Status for MP.L2-3.8.9
    • PS.L2-3.9.1
      3-point

      Screen individuals before authorizing access

      Status for PS.L2-3.9.1
    • PS.L2-3.9.2
      5-point

      Protect CUI during personnel actions

      Status for PS.L2-3.9.2
    • PE.L2-3.10.1
      5-point

      Limit physical access to systems/facilities

      Status for PE.L2-3.10.1
    • PE.L2-3.10.2
      5-point

      Protect and monitor physical access

      Status for PE.L2-3.10.2
    • PE.L2-3.10.3
      1-point

      Escort visitors and monitor visitor activity

      Status for PE.L2-3.10.3
    • PE.L2-3.10.4
      1-point

      Maintain physical access audit logs

      Status for PE.L2-3.10.4
    • PE.L2-3.10.5
      1-point

      Manage and protect physical access devices

      Status for PE.L2-3.10.5
    • PE.L2-3.10.6
      1-point

      Protect transmission lines and output devices

      Status for PE.L2-3.10.6
    • RA.L2-3.11.1
      3-point

      Periodic risk assessments

      Status for RA.L2-3.11.1
    • RA.L2-3.11.2
      5-point

      Vulnerability scanning

      Status for RA.L2-3.11.2
    • RA.L2-3.11.3
      1-point

      Remediate vulnerabilities

      Status for RA.L2-3.11.3
    • CA.L2-3.12.1
      5-point

      Periodic security assessments

      Status for CA.L2-3.12.1
    • CA.L2-3.12.2
      3-point

      Develop and implement POA&Ms

      Status for CA.L2-3.12.2
    • CA.L2-3.12.3
      5-point

      Continuous monitoring

      Status for CA.L2-3.12.3
    • CA.L2-3.12.4
      Assessment blocker · no point value

      System Security Plan (SSP)

      Without an SSP there is no assessable system description, so no valid score can be produced at all.

      Status for CA.L2-3.12.4
    • SC.L2-3.13.1
      5-point

      Boundary protection

      Status for SC.L2-3.13.1
    • SC.L2-3.13.2
      5-point

      Secure architecture and engineering principles

      Status for SC.L2-3.13.2
    • SC.L2-3.13.3
      1-point

      Separate user and system management functionality

      Status for SC.L2-3.13.3
    • SC.L2-3.13.4
      1-point

      Prevent transfer via shared system resources

      Status for SC.L2-3.13.4
    • SC.L2-3.13.5
      5-point

      Public system separation/subnetworks

      Status for SC.L2-3.13.5
    • SC.L2-3.13.6
      5-point

      Deny network traffic by default; allow by exception

      Status for SC.L2-3.13.6
    • SC.L2-3.13.7
      1-point

      Prevent split tunneling

      Status for SC.L2-3.13.7
    • SC.L2-3.13.8
      3-point

      Protect CUI in transit

      Status for SC.L2-3.13.8
    • SC.L2-3.13.9
      1-point

      Terminate network connections

      Status for SC.L2-3.13.9
    • SC.L2-3.13.10
      1-point

      Cryptographic key management

      Status for SC.L2-3.13.10
    • SC.L2-3.13.11
      Special 3 / 5

      FIPS-validated cryptography

      Partial (deduct 3): Cryptography is used to protect CUI but the modules are not FIPS validated.

      Status for SC.L2-3.13.11
    • SC.L2-3.13.12
      1-point

      Collaborative computing device control

      Status for SC.L2-3.13.12
    • SC.L2-3.13.13
      1-point

      Control and monitor mobile code

      Status for SC.L2-3.13.13
    • SC.L2-3.13.14
      1-point

      Control and monitor VoIP

      Status for SC.L2-3.13.14
    • SC.L2-3.13.15
      5-point

      Protect communications session authenticity

      Status for SC.L2-3.13.15
    • SC.L2-3.13.16
      1-point

      Protect CUI at rest

      Status for SC.L2-3.13.16
    • SI.L2-3.14.1
      5-point

      Identify, report, and correct flaws

      Status for SI.L2-3.14.1
    • SI.L2-3.14.2
      5-point

      Malicious code protection

      Status for SI.L2-3.14.2
    • SI.L2-3.14.3
      5-point

      Security alerts and advisories

      Status for SI.L2-3.14.3
    • SI.L2-3.14.4
      5-point

      Update malicious code protection

      Status for SI.L2-3.14.4
    • SI.L2-3.14.5
      3-point

      Perform periodic and real-time scans

      Status for SI.L2-3.14.5
    • SI.L2-3.14.6
      5-point

      Monitor inbound/outbound traffic and detect attacks

      Status for SI.L2-3.14.6
    • SI.L2-3.14.7
      3-point

      Identify unauthorized system use

      Status for SI.L2-3.14.7

    Sanitized example

    Fictional contractor "Northgate Precision LLC". No real system names, hostnames, IPs, or findings — deliberately generic so it is safe to share.

    Northgate Precision answers Met on 106 of the 110 practices, including CA.L2-3.12.4 (System Security Plan), so a valid score can be reported. The four remaining answers are named exactly:

    • IA.L2-3.5.3 — Partial: deduct 3. MFA covers remote and privileged users, but not general users on local access.
    • SC.L2-3.13.11 — Partial: deduct 3. Cryptography protects CUI, but the modules are not FIPS-validated.
    • SI.L2-3.14.7 — Not Met: deduct 3. No documented method identifies unauthorized system use.
    • RA.L2-3.11.2 — Not Met: deduct 5. Vulnerability scanning is ad hoc, with no defined periodic scan.

    Total deductions = 14 (3 + 3 + 3 + 5). Score = 110 − 14 = 96 out of 110. Their fix-first item is RA.L2-3.11.2, because it recovers 5 points — more than any other open item here.

    One path forward

    Free result → $129 CMMC Survival Report → Athena workspace

    1. Free, right now: keep the result and downloads from this tool. No account, no e-mail required.
    2. $129 CMMC Survival Report: an objective-level readiness snapshot with your weakest practices, prioritized remediation order, and an assessor-facing narrative.
    3. Athena workspace / evidence sprint: continuous objective-level tracking, evidence defensibility scoring, and assessor-ready artifacts.

    Athena works at the assessment-objective level, keeps a provenance trail for every artifact, and scores how defensible your evidence is. We do not guarantee a certification outcome — no tool or consultant can.

    The other free CMMC tools

    Met / Not Met / N/A across 110 requirements with a gap report.
    Every NIST SP 800-171A Rev. 2 objective with evidence planning.
    Categorize assets and define your assessment boundary.
    Build a DoD-oriented POA&M with eligibility warnings.
    Day-one evidence list, mock intake, and readiness verdict.

    Educational readiness aid. This is not legal advice, not an official assessment, not a certification, and not a submitted SPRS score. Your assessment results and any affirmation remain your organization's responsibility.

    Share or keep this:The shared link carries no answers or score. The reference contains methodology and blank fields only.

    What the SPRS score is

    SPRS is the Supplier Performance Risk System. For CMMC Level 2, your SPRS score is a single number representing how completely you have implemented the 110 security requirements in NIST SP 800-171 Rev. 2. You start at a perfect 110 and lose weighted points for every requirement not fully met.

    The 110-point scale and the weighted deductions

    It is not one point per requirement. Under the DoD Assessment Methodology, each unimplemented requirement costs 5, 3, or 1 point according to its risk to the confidentiality of CUI, so the scale runs from 110 down to -203. Every requirement is scored all-or-nothing — you earn the point only when every applicable assessment objective is satisfied — with two documented exceptions:

    • 3.5.3 (multifactor authentication) carries a 5-point weight. When MFA is implemented for remote and privileged users but not for general users on local access, 3 points are deducted instead of 5.
    • 3.13.11 (FIPS-validated cryptography) carries a 5-point weight. When cryptography is employed to protect CUI but the modules are not FIPS-validated, 3 points are deducted instead of 5.

    The 3.12.4 gate. Requirement 3.12.4 requires a system security plan. Without one there is no assessment to score, so the calculator treats 3.12.4 as a gate rather than as one more point: mark it Not Met and the result is not a defensible score.

    SPRS score bands and their validity
    SPRS scoreMeaningValidity
    110All requirements met — supports Final status3 years + annual affirmation
    88–109Minor gaps with a valid POA&M — Conditional180 days to close the POA&M
    Below 88No CMMC status — affects eligibility—

    A worked example, verified exactly

    Take an organization with 106 of the 110 requirements Met — including 3.12.4, which must be Met for the score to mean anything — and exactly these four exceptions:

    The four non-Met requirements in the worked example
    RequirementStateDeductionWhy
    3.5.3 (IA.L2-3.5.3)Partially Met−3MFA covers remote and privileged users, but not general users on local access.
    3.13.11 (SC.L2-3.13.11)Partially Met−3Cryptography protects CUI, but the modules are not FIPS-validated.
    3.14.7 (SI.L2-3.14.7)Not Met−3No documented method identifies unauthorized system use.
    3.11.2 (RA.L2-3.11.2)Not Met−5Vulnerability scanning is ad hoc, with no defined periodic scan.

    Total deductions: 3 + 3 + 3 + 5 = 14. Score: 110 − 14 = 96. Note that you cannot derive this from counts alone: four unimplemented requirements produce a deduction of 14, not 4, because the weights and the two partial-credit rules decide the arithmetic.

    Which assessment are we talking about?

    Four different things get called "the assessment," and they are not interchangeable:

    • SPRS Basic Assessment. Your own self-assessment of the 110 NIST SP 800-171 requirements, scored with the DoD Assessment Methodology and reported in SPRS under DFARS 252.204-7019/7020. This calculator computes that score.
    • CMMC Level 2 self-assessment. An assessment against the CMMC Level 2 practices and their assessment objectives, affirmed by a senior official. Related to, but not the same as, the SPRS Basic Assessment score.
    • DIBCAC assessment. A government-conducted assessment by the Defense Industrial Base Cybersecurity Assessment Center. Not something you self-report.
    • C3PAO assessment. A CMMC Level 2 certification assessment conducted by an authorized third-party assessment organization. Only a C3PAO (through the accreditation body) can produce a CMMC certification.

    Nothing on this page produces a certification, an official score, or a submitted SPRS entry. It is a readiness aid.

    How to calculate it, step by step

    1. Confirm your scope. Identify the assets that store, process, or transmit CUI. Scoping errors are the most common reason a score has to be redone — the CUI scoping check walks the categories.
    2. Assess all 110 requirements against their assessment objectives with the Level 2 self-assessment checklist. A requirement is Met only when every applicable objective is satisfied.
    3. Prove each objective with the artifacts an assessor will examine — the 320-objective evidence checklist lists them.
    4. Apply the weighted deductions (5/3/1) and the two partial-credit rules, then subtract from 110.
    5. Build your POA&M for the gaps with the POA&M builder — not every requirement is eligible.
    6. Submit in SPRS with your assessment date and scope, then use the C3PAO preparation checklist before a certification assessment.

    One caution: submitted scores are spot-checked against system security plans. A number you cannot defend with evidence is a liability, not an asset.

    Official sources

    Point values on this page follow the NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 (24 June 2020), scored against NIST SP 800-171 Rev. 2 (110 requirements). Athena last verified this is the current edition on 9 September 2026. Verify against the DoD source before submitting a score to SPRS.

    Turning the number into something defensible

    Hand-scoring 110 weighted requirements is the easy part. The hard part is the evidence behind each of the 320 assessment objectives, and the POA&M that closes the gaps in an order an assessor will accept. That is what Athena does with the score you just produced.

    Turn this score into an assessor-ready remediation plan →

    FAQ

    What is a passing SPRS score?

    110 means every requirement is met; 88 or above with a valid POA&M supports Conditional status; below 88 is no CMMC status.

    What is the lowest possible score?

    -203 — because unimplemented requirements carry weighted 3- and 5-point deductions.

    Can every requirement be placed on a POA&M?

    No — higher-weighted practices are not eligible, a minimum score is required to use one, and scoring is all-or-nothing apart from 3.5.3 and 3.13.11.

    Related: 3.5.3 MFA evidence · Level 2 self-assessment · Evidence checklist