SPRSSPRS Score
The Supplier Performance Risk System score (-203 to 110) reflecting a contractor's self-assessed compliance with NIST SP 800-171. Required for DoD contracts involving CUI.
Related Terms
NIST SP 800-171
The NIST standard for protecting CUI in non-federal systems. Revision 2 — the revision DoD assesses — specifies 110 security requirements and forms the basis of CMMC Level 2 and DFARS 252.204-7012 compliance.
CMMC Level 2 (Advanced)
The mid-tier CMMC level requiring all 110 NIST SP 800-171 controls. Third-party (C3PAO) assessment at this level was suspended as an award condition in July 2026 pending review; Level 2 self-assessment remains in force.
POA&M
A document identifying security weaknesses, the planned remediation actions, required resources, and scheduled completion dates for achieving full compliance.
Related Guides
Check Your CMMC Readiness
Run our free compliance tools to see where your organization stands.
Audit Your Tech Stack FreeTurn this gap analysis into a remediation plan
This SPRS Score explainer is the start, not the answer. Book a 25-minute compliance assessment — you leave with a prioritized roadmap and a fixed-fee implementation quote.
Book a 25-min assessmentRelated: how much CMMC certification costs — DoD’s own priced figures