DFARS Readiness Checklists and guides for DFARS readiness.

Guides / October 05, 2026

What Is SPRS and How Do I Post My Score There?

A defense contract asks for your cybersecurity score in the Supplier Performance Risk System, or SPRS.

What is SPRS?

SPRS is the database run by the Department of Defense, or DoD. It stores cybersecurity assessment scores for defense contractors. Contracting officers check it before they award a contract (DFARS 252.204-7019). They need to see a current score for your company. If it is missing or too old, you can lose the award (DFARS 252.204-7019).

SPRS does not grade your systems. You do the assessment first, then you post only the summary score.

Who has to post a score?

DFARS stands for the Defense Federal Acquisition Regulation Supplement. Clause 252.204-7019 says offerors need a current NIST 800-171 score in SPRS to be considered for award (DFARS 252.204-7019). NIST is the National Institute of Standards and Technology. The score must not be more than three years old (DFARS 252.204-7019). Clause 252.204-7020 adds the same duty for subcontractors on covered systems (DFARS 252.204-7020).

What are Basic, Medium, and High assessments?

The DoD assessment method defines three levels (DFARS 252.204-7020).

A Basic assessment is your own self-assessment. It must follow the official DoD scoring method (DoD Assessment Methodology). It earns Low confidence because you score it yourself.

A Medium assessment is done by DoD staff. They review your Basic assessment and your documents, then discuss questions with you. It earns Medium confidence.

A High assessment is also done by DoD staff. They verify your systems on site or in a virtual session. It earns High confidence.

Most companies only ever complete a Basic assessment. The Government starts Medium and High assessments itself. You get 14 business days to rebut findings from a Medium or High assessment (DFARS 252.204-7020).

How do I post my Basic score, step by step?

Follow these steps in order.

  1. Write a System Security Plan, called an SSP, that covers all 110 NIST SP 800-171 requirements (DoD Assessment Methodology).
  2. Mark each requirement as met or not met.
  3. Start at 110 and subtract points for each unmet requirement.
  4. Some requirements cost 5 points, others 3 or 1 (DoD Assessment Methodology).
  5. The final number is your summary-level score.
  6. Post only this single number, not one number per requirement (DFARS 252.204-7020).
  7. For each unmet requirement, write a Plan of Action and Milestones, or POA&M.
  8. Pick the date when every requirement will be met.
  9. Log in through the Procurement Integrated Enterprise Environment, known as PIEE.
  10. Get the SPRS Cyber Vendor User role to add an assessment (SPRS entry tutorial).
  11. Choose your scope: Enterprise, Enclave, or Contract (SPRS entry tutorial).
  12. Enter the assessment date, score, SSP name, and POA&M date.
  13. If the score is under 110, the POA&M date is required (SPRS entry tutorial).
  14. Save the entry, and SPRS assigns a unique record ID (SPRS entry tutorial).
  15. As an alternative, email the details encrypted to [email protected] (DFARS 252.204-7020).

What mistakes cause trouble?

SPRS shows scores older than three years in red (SPRS entry tutorial). A red score is too old to count.

Common mistakes include bad math on the score. Ask a second person to check the subtraction.

Missing the POA&M date when the score is under 110 is another common one. SPRS will not accept the entry without it.

Posting one number per requirement instead of a single summary score causes problems too (DFARS 252.204-7020). The clause asks for the summary score only.

Confirm your company profile in SPRS is correct before you post. Fixing it after the fact takes extra time.

Make the evidence part easy

Doing this by hand works, but evidence collection is the hard part. PolicyCortex reads live Azure configuration and checks it against NIST 800-53 and NIST 800-171. It re-verifies after fixes and builds your SSP, Security Assessment Report (SAR), and POA&M from real evidence. See how it works here.

Sources