SPRS score: how the CMMC Level 2 score is calculated
A Level 2 self-assessment produces a score that goes into the Supplier Performance Risk System (SPRS). The method is the CMMC Scoring Methodology in 32 CFR 170.24, CMMC Scoring Methodology.
The method
- Start at 110, one point per requirement.
- For each requirement not met, subtract its value. Not applicable counts as met.
- The result can be negative. With nothing met it is -203.
Point values
| Value | Requirements | Which |
|---|---|---|
| 5 points | 42 | 3.1.1, 3.1.2, 3.1.12, 3.1.13, 3.1.16, 3.1.17, 3.1.18, 3.2.1, 3.2.2, 3.3.1, 3.3.5, 3.4.1, 3.4.2, 3.4.5, 3.4.6, 3.4.7, 3.4.8, 3.5.1, 3.5.2, 3.5.10, 3.6.1, 3.6.2, 3.7.2, 3.7.5, 3.8.3, 3.8.7, 3.9.2, 3.10.1, 3.10.2, 3.11.2, 3.12.1, 3.12.3, 3.13.1, 3.13.2, 3.13.5, 3.13.6, 3.13.15, 3.14.1, 3.14.2, 3.14.3, 3.14.4, 3.14.6 |
| 3 or 5 points (partial credit) | 2 | 3.5.3 (MFA only for remote and privileged users: 3); 3.13.11 (encryption used, but not FIPS-validated: 3) |
| 3 points | 14 | 3.1.5, 3.1.19, 3.3.2, 3.7.1, 3.7.4, 3.8.1, 3.8.2, 3.8.8, 3.9.1, 3.11.1, 3.12.2, 3.13.8, 3.14.5, 3.14.7 |
| 1 point | 51 | Every other requirement |
| No value, but required | 1 | 3.12.4 (System Security Plan): without it the assessment can't be completed |
Worked examples
- Every requirement met or not applicable: 110.
- Nothing met: -203.
- The example on this site's self-check: 3.14.6 not met (-5), 3.5.3 partly done (-3), 3.13.11 partly done (-3), 3.1.4 not met (-1), 3.3.4 not met (-1), and 3.13.5 not applicable. Score: 97. It is above 88, but 3.14.6 and 3.5.3 can't go on a POA&M, so no Conditional status is possible until they are fixed.
What the score is not
The score counts requirements, not risk, and it is only as good as the assessment behind it. The DoD can check a self-assessment with a DCMA DIBCAC assessment, and those results take precedence (32 CFR 170.16, Level 2 self-assessment).