How to Calculate Your SPRS Score for CMMC Level 2
Direct answer: an SPRS score for CMMC Level 2 starts at 110 — one point for each of the 110 NIST SP 800-171 Rev. 2 security requirements — and you subtract a weighted 5, 3, or 1 point for every requirement you have not implemented. The weights reflect risk, not effort, so the scale runs from a maximum of 110 down to a minimum of -203. Two requirements allow partial credit (3.5.3 and 3.13.11), and 3.12.4 gates the assessment entirely. Score all 110 requirements below and download the ledger — free, no sign-up, and nothing you enter leaves your browser.
Current CMMC status — as of 8 September 2026
This tool runs entirely in your browser
Your SPRS score
- Document the system boundary, all in-scope assets, and how each of the 110 requirements is implemented.
- Have the SSP reviewed and approved by the person accountable for the environment, and record the approval date.
- Put the SSP under version control with a defined review cadence, then re-run this calculator.
For planning only, your answers currently deduct 313 points (a would-be score of -203). That figure is not a valid SPRS score and must not be reported.
0 of 109 scored requirements answered. Unanswered requirements are counted as a full deduction, so the score only improves as you confirm implementation.
Score all 110 requirements
- AC.L2-3.1.15-point
Authorized users/devices
- AC.L2-3.1.25-point
Authorized transactions and functions
- AC.L2-3.1.31-point
Control CUI flow
- AC.L2-3.1.41-point
Separation of duties
- AC.L2-3.1.53-point
Least privilege
- AC.L2-3.1.61-point
Use non-privileged accounts
- AC.L2-3.1.71-point
Prevent non-privileged execution of privileged functions
- AC.L2-3.1.81-point
Limit unsuccessful logon attempts
- AC.L2-3.1.91-point
Privacy and security notices
- AC.L2-3.1.101-point
Session lock
- AC.L2-3.1.111-point
Automatic session termination
- AC.L2-3.1.125-point
Monitor and control remote access sessions
- AC.L2-3.1.135-point
Cryptographic protection for remote access
- AC.L2-3.1.141-point
Route remote access through managed access control points
- AC.L2-3.1.151-point
Authorize remote privileged commands and access
- AC.L2-3.1.165-point
Authorize wireless access
- AC.L2-3.1.175-point
Protect wireless access
- AC.L2-3.1.185-point
Control connection of mobile devices
- AC.L2-3.1.193-point
Encrypt CUI on mobile devices
- AC.L2-3.1.201-point
Verify and control external connections
- AC.L2-3.1.211-point
Limit use of portable storage on external systems
- AC.L2-3.1.221-point
Control publicly accessible CUI
- AT.L2-3.2.15-point
Security awareness for managers/admins/users
- AT.L2-3.2.25-point
Role-based security training
- AT.L2-3.2.31-point
Insider threat awareness training
- AU.L2-3.3.15-point
Create and retain audit logs
- AU.L2-3.3.23-point
Audit record content
- AU.L2-3.3.31-point
Review and update auditable events
- AU.L2-3.3.41-point
Alert on audit logging failure
- AU.L2-3.3.55-point
Correlate audit review/analysis/reporting
- AU.L2-3.3.61-point
Audit reduction and report generation
- AU.L2-3.3.71-point
Time synchronization for audit records
- AU.L2-3.3.81-point
Protect audit information and tools
- AU.L2-3.3.91-point
Limit audit management to privileged users
- CM.L2-3.4.15-point
Baseline configurations and inventories
- CM.L2-3.4.25-point
Enforce security configuration settings
- CM.L2-3.4.31-point
Change control
- CM.L2-3.4.41-point
Security impact analysis for changes
- CM.L2-3.4.55-point
Access restrictions for changes
- CM.L2-3.4.65-point
Least functionality
- CM.L2-3.4.75-point
Restrict nonessential programs/services/ports/protocols
- CM.L2-3.4.85-point
Allow-by-exception or deny-by-exception software control
- CM.L2-3.4.91-point
Control user-installed software
- IA.L2-3.5.15-point
Identify users, processes, and devices
- IA.L2-3.5.25-point
Authenticate identities
- IA.L2-3.5.3Special 3 / 5
Multi-factor authentication
Partial (deduct 3): Multifactor authentication covers remote and privileged users but not general users.
- IA.L2-3.5.41-point
Replay-resistant authentication
- IA.L2-3.5.51-point
Prevent reuse of identifiers
- IA.L2-3.5.61-point
Disable identifiers after inactivity
- IA.L2-3.5.71-point
Password complexity
- IA.L2-3.5.81-point
Password reuse limits
- IA.L2-3.5.91-point
Temporary passwords for immediate change
- IA.L2-3.5.105-point
Cryptographically protected passwords
- IA.L2-3.5.111-point
Obscure authentication feedback
- IR.L2-3.6.15-point
Incident handling capability
- IR.L2-3.6.25-point
Track, document, and report incidents
- IR.L2-3.6.31-point
Test incident response
- MA.L2-3.7.13-point
Perform maintenance
- MA.L2-3.7.25-point
Control maintenance tools, techniques, personnel
- MA.L2-3.7.31-point
Sanitize equipment removed for off-site maintenance
- MA.L2-3.7.43-point
Check maintenance media for malicious code
- MA.L2-3.7.55-point
MFA for nonlocal maintenance sessions
- MA.L2-3.7.61-point
Supervise maintenance personnel without authorization
- MP.L2-3.8.13-point
Protect system media
- MP.L2-3.8.23-point
Limit access to media
- MP.L2-3.8.35-point
Sanitize or destroy media before disposal/reuse
- MP.L2-3.8.41-point
Mark media with CUI markings
- MP.L2-3.8.51-point
Protect media during transport
- MP.L2-3.8.61-point
Cryptographic protection for digital media in transport
- MP.L2-3.8.75-point
Control removable media
- MP.L2-3.8.83-point
Prohibit portable storage with no identifiable owner
- MP.L2-3.8.91-point
Protect backup CUI at storage locations
- PS.L2-3.9.13-point
Screen individuals before authorizing access
- PS.L2-3.9.25-point
Protect CUI during personnel actions
- PE.L2-3.10.15-point
Limit physical access to systems/facilities
- PE.L2-3.10.25-point
Protect and monitor physical access
- PE.L2-3.10.31-point
Escort visitors and monitor visitor activity
- PE.L2-3.10.41-point
Maintain physical access audit logs
- PE.L2-3.10.51-point
Manage and protect physical access devices
- PE.L2-3.10.61-point
Protect transmission lines and output devices
- RA.L2-3.11.13-point
Periodic risk assessments
- RA.L2-3.11.25-point
Vulnerability scanning
- RA.L2-3.11.31-point
Remediate vulnerabilities
- CA.L2-3.12.15-point
Periodic security assessments
- CA.L2-3.12.23-point
Develop and implement POA&Ms
- CA.L2-3.12.35-point
Continuous monitoring
- CA.L2-3.12.4Assessment blocker · no point value
System Security Plan (SSP)
Without an SSP there is no assessable system description, so no valid score can be produced at all.
- SC.L2-3.13.15-point
Boundary protection
- SC.L2-3.13.25-point
Secure architecture and engineering principles
- SC.L2-3.13.31-point
Separate user and system management functionality
- SC.L2-3.13.41-point
Prevent transfer via shared system resources
- SC.L2-3.13.55-point
Public system separation/subnetworks
- SC.L2-3.13.65-point
Deny network traffic by default; allow by exception
- SC.L2-3.13.71-point
Prevent split tunneling
- SC.L2-3.13.83-point
Protect CUI in transit
- SC.L2-3.13.91-point
Terminate network connections
- SC.L2-3.13.101-point
Cryptographic key management
- SC.L2-3.13.11Special 3 / 5
FIPS-validated cryptography
Partial (deduct 3): Cryptography is used to protect CUI but the modules are not FIPS validated.
- SC.L2-3.13.121-point
Collaborative computing device control
- SC.L2-3.13.131-point
Control and monitor mobile code
- SC.L2-3.13.141-point
Control and monitor VoIP
- SC.L2-3.13.155-point
Protect communications session authenticity
- SC.L2-3.13.161-point
Protect CUI at rest
- SI.L2-3.14.15-point
Identify, report, and correct flaws
- SI.L2-3.14.25-point
Malicious code protection
- SI.L2-3.14.35-point
Security alerts and advisories
- SI.L2-3.14.45-point
Update malicious code protection
- SI.L2-3.14.53-point
Perform periodic and real-time scans
- SI.L2-3.14.65-point
Monitor inbound/outbound traffic and detect attacks
- SI.L2-3.14.73-point
Identify unauthorized system use
Sanitized example
Fictional contractor "Northgate Precision LLC". No real system names, hostnames, IPs, or findings — deliberately generic so it is safe to share.
Northgate Precision answers Met on 106 of the 110 practices, including CA.L2-3.12.4 (System Security Plan), so a valid score can be reported. The four remaining answers are named exactly:
- IA.L2-3.5.3 — Partial: deduct 3. MFA covers remote and privileged users, but not general users on local access.
- SC.L2-3.13.11 — Partial: deduct 3. Cryptography protects CUI, but the modules are not FIPS-validated.
- SI.L2-3.14.7 — Not Met: deduct 3. No documented method identifies unauthorized system use.
- RA.L2-3.11.2 — Not Met: deduct 5. Vulnerability scanning is ad hoc, with no defined periodic scan.
Total deductions = 14 (3 + 3 + 3 + 5). Score = 110 − 14 = 96 out of 110. Their fix-first item is RA.L2-3.11.2, because it recovers 5 points — more than any other open item here.
Free result → $129 CMMC Survival Report → Athena workspace
- Free, right now: keep the result and downloads from this tool. No account, no e-mail required.
- $129 CMMC Survival Report: an objective-level readiness snapshot with your weakest practices, prioritized remediation order, and an assessor-facing narrative.
- Athena workspace / evidence sprint: continuous objective-level tracking, evidence defensibility scoring, and assessor-ready artifacts.
Athena works at the assessment-objective level, keeps a provenance trail for every artifact, and scores how defensible your evidence is. We do not guarantee a certification outcome — no tool or consultant can.
Official primary references
- DoD Assessment Methodology, NIST SP 800-171, Version 1.2.1
- NIST SP 800-171 Rev. 2 (security requirements)
- NIST SP 800-171A Rev. 2 (assessment objectives)
- CMMC Assessment Guide — Level 2, Version 2.13
- CMMC Scoping Guide — Level 2
- 32 CFR Part 170 (Subchapter G) — CMMC Program
- DFARS 252.204-7012 — Safeguarding covered defense information
- DFARS 252.204-7019 — Notice of NIST SP 800-171 assessment requirements
- DFARS 252.204-7020 — NIST SP 800-171 DoD assessment requirements
- DoD CIO — official CMMC program status
The other free CMMC tools
Educational readiness aid. This is not legal advice, not an official assessment, not a certification, and not a submitted SPRS score. Your assessment results and any affirmation remain your organization's responsibility.
What the SPRS score is
SPRS is the Supplier Performance Risk System. For CMMC Level 2, your SPRS score is a single number representing how completely you have implemented the 110 security requirements in NIST SP 800-171 Rev. 2. You start at a perfect 110 and lose weighted points for every requirement not fully met.
The 110-point scale and the weighted deductions
It is not one point per requirement. Under the DoD Assessment Methodology, each unimplemented requirement costs 5, 3, or 1 point according to its risk to the confidentiality of CUI, so the scale runs from 110 down to -203. Every requirement is scored all-or-nothing — you earn the point only when every applicable assessment objective is satisfied — with two documented exceptions:
- 3.5.3 (multifactor authentication) carries a 5-point weight. When MFA is implemented for remote and privileged users but not for general users on local access, 3 points are deducted instead of 5.
- 3.13.11 (FIPS-validated cryptography) carries a 5-point weight. When cryptography is employed to protect CUI but the modules are not FIPS-validated, 3 points are deducted instead of 5.
The 3.12.4 gate. Requirement 3.12.4 requires a system security plan. Without one there is no assessment to score, so the calculator treats 3.12.4 as a gate rather than as one more point: mark it Not Met and the result is not a defensible score.
| SPRS score | Meaning | Validity |
|---|---|---|
| 110 | All requirements met — supports Final status | 3 years + annual affirmation |
| 88–109 | Minor gaps with a valid POA&M — Conditional | 180 days to close the POA&M |
| Below 88 | No CMMC status — affects eligibility | — |
A worked example, verified exactly
Take an organization with 106 of the 110 requirements Met — including 3.12.4, which must be Met for the score to mean anything — and exactly these four exceptions:
| Requirement | State | Deduction | Why |
|---|---|---|---|
| 3.5.3 (IA.L2-3.5.3) | Partially Met | −3 | MFA covers remote and privileged users, but not general users on local access. |
| 3.13.11 (SC.L2-3.13.11) | Partially Met | −3 | Cryptography protects CUI, but the modules are not FIPS-validated. |
| 3.14.7 (SI.L2-3.14.7) | Not Met | −3 | No documented method identifies unauthorized system use. |
| 3.11.2 (RA.L2-3.11.2) | Not Met | −5 | Vulnerability scanning is ad hoc, with no defined periodic scan. |
Total deductions: 3 + 3 + 3 + 5 = 14. Score: 110 − 14 = 96. Note that you cannot derive this from counts alone: four unimplemented requirements produce a deduction of 14, not 4, because the weights and the two partial-credit rules decide the arithmetic.
Which assessment are we talking about?
Four different things get called "the assessment," and they are not interchangeable:
- SPRS Basic Assessment. Your own self-assessment of the 110 NIST SP 800-171 requirements, scored with the DoD Assessment Methodology and reported in SPRS under DFARS 252.204-7019/7020. This calculator computes that score.
- CMMC Level 2 self-assessment. An assessment against the CMMC Level 2 practices and their assessment objectives, affirmed by a senior official. Related to, but not the same as, the SPRS Basic Assessment score.
- DIBCAC assessment. A government-conducted assessment by the Defense Industrial Base Cybersecurity Assessment Center. Not something you self-report.
- C3PAO assessment. A CMMC Level 2 certification assessment conducted by an authorized third-party assessment organization. Only a C3PAO (through the accreditation body) can produce a CMMC certification.
Nothing on this page produces a certification, an official score, or a submitted SPRS entry. It is a readiness aid.
How to calculate it, step by step
- Confirm your scope. Identify the assets that store, process, or transmit CUI. Scoping errors are the most common reason a score has to be redone — the CUI scoping check walks the categories.
- Assess all 110 requirements against their assessment objectives with the Level 2 self-assessment checklist. A requirement is Met only when every applicable objective is satisfied.
- Prove each objective with the artifacts an assessor will examine — the 320-objective evidence checklist lists them.
- Apply the weighted deductions (5/3/1) and the two partial-credit rules, then subtract from 110.
- Build your POA&M for the gaps with the POA&M builder — not every requirement is eligible.
- Submit in SPRS with your assessment date and scope, then use the C3PAO preparation checklist before a certification assessment.
One caution: submitted scores are spot-checked against system security plans. A number you cannot defend with evidence is a liability, not an asset.
Official sources
- Scoring methodology, weights and the −203 floor — DoD NIST SP 800-171 Assessment Methodology, Version 1.2.1
- The 110 security requirements — NIST SP 800-171 Rev. 2
- The 320 assessment objectives — NIST SP 800-171A
- Reporting obligation — DFARS 252.204-7020 (eCFR)
- Score submission — Supplier Performance Risk System
Point values on this page follow the NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 (24 June 2020), scored against NIST SP 800-171 Rev. 2 (110 requirements). Athena last verified this is the current edition on 9 September 2026. Verify against the DoD source before submitting a score to SPRS.
Turning the number into something defensible
Hand-scoring 110 weighted requirements is the easy part. The hard part is the evidence behind each of the 320 assessment objectives, and the POA&M that closes the gaps in an order an assessor will accept. That is what Athena does with the score you just produced.
Turn this score into an assessor-ready remediation plan →
FAQ
What is a passing SPRS score?
110 means every requirement is met; 88 or above with a valid POA&M supports Conditional status; below 88 is no CMMC status.
What is the lowest possible score?
-203 — because unimplemented requirements carry weighted 3- and 5-point deductions.
Can every requirement be placed on a POA&M?
No — higher-weighted practices are not eligible, a minimum score is required to use one, and scoring is all-or-nothing apart from 3.5.3 and 3.13.11.
Related: 3.5.3 MFA evidence · Level 2 self-assessment · Evidence checklist