CMMC Compliance Checkby Agent Trust Cloud

SPRS score: how the CMMC Level 2 score is calculated

A Level 2 self-assessment produces a score that goes into the Supplier Performance Risk System (SPRS). The method is the CMMC Scoring Methodology in 32 CFR 170.24, CMMC Scoring Methodology.

The method

  1. Start at 110, one point per requirement.
  2. For each requirement not met, subtract its value. Not applicable counts as met.
  3. The result can be negative. With nothing met it is -203.

Point values

ValueRequirementsWhich
5 points423.1.1, 3.1.2, 3.1.12, 3.1.13, 3.1.16, 3.1.17, 3.1.18, 3.2.1, 3.2.2, 3.3.1, 3.3.5, 3.4.1, 3.4.2, 3.4.5, 3.4.6, 3.4.7, 3.4.8, 3.5.1, 3.5.2, 3.5.10, 3.6.1, 3.6.2, 3.7.2, 3.7.5, 3.8.3, 3.8.7, 3.9.2, 3.10.1, 3.10.2, 3.11.2, 3.12.1, 3.12.3, 3.13.1, 3.13.2, 3.13.5, 3.13.6, 3.13.15, 3.14.1, 3.14.2, 3.14.3, 3.14.4, 3.14.6
3 or 5 points (partial credit)23.5.3 (MFA only for remote and privileged users: 3); 3.13.11 (encryption used, but not FIPS-validated: 3)
3 points143.1.5, 3.1.19, 3.3.2, 3.7.1, 3.7.4, 3.8.1, 3.8.2, 3.8.8, 3.9.1, 3.11.1, 3.12.2, 3.13.8, 3.14.5, 3.14.7
1 point51Every other requirement
No value, but required13.12.4 (System Security Plan): without it the assessment can't be completed

Worked examples

What the score is not

The score counts requirements, not risk, and it is only as good as the assessment behind it. The DoD can check a self-assessment with a DCMA DIBCAC assessment, and those results take precedence (32 CFR 170.16, Level 2 self-assessment).

Calculate your score

Sources