CMMC · SPRS
How to raise your SPRS score while CMMC Phase 2 is paused
With no third-party assessor coming for now, your SPRS score is the one number DoW sees, and it's the one you signed. Here's how to raise it with work that holds up, in the order that moves it most.
Published September 30, 2026 · Cyberuptive, Honolulu
The short answer
Raise it by closing 5-point requirements first, fixing multifactor authentication and FIPS-validated encryption for partial credit, and making sure every "implemented" answer has evidence behind it. Don't raise it by re-reading requirements more generously. With third-party assessments paused, the government is leaning harder on self-assessments and its own spot checks, so your score is doing more work than it used to.
What the pause did and didn't change
On July 13, 2026, the Department of War suspended CMMC Phase 2. Contracting officers can still require Level 1 (Self) or Level 2 (Self), but can't require Level 2 (C3PAO) or Level 3 (DIBCAC) (Morgan Lewis). DoW has said it will keep enforcing the underlying requirements through self-assessments and selected DoW-led assessments, and offerors generally still need a current status and affirmation in SPRS to be eligible for award (Inside Government Contracts).
As of late September 2026, the Reform Task Force's recommendations hadn't been made public and no Phase 2 restart date had been set. Separately, DFARS Class Deviation 2026-O0025, Revision 3, signed September 3, tells contracting officers to remove or revise CMMC requirements in solicitations and contracts, and moves the NIST SP 800-171 DoD assessment clause into a new DFARS Part 240 as 252.240-7997 (Vigilant Cybersecurity). Check which clauses your contracts actually carry. Where they include Level 1 or Level 2 (Self), you still post a current self-assessment in SPRS.
How the score works
The NIST SP 800-171 DoD Assessment Methodology is simple arithmetic:
- Start at 110, one point per requirement.
- Subtract 5 for each unmet requirement that "could lead to significant exploitation of the network, or exfiltration of DoD CUI."
- Subtract 3 for requirements with "a specific and confined effect."
- Subtract 1 for the rest.
- The score "may result in a negative score."
Two partial-credit rules matter. For MFA (3.5.3), you lose 3 points instead of 5 if MFA covers remote and privileged users but not everyone. For encryption (3.13.11), you lose 3 instead of 5 if you encrypt CUI but not with FIPS-validated cryptography.
Two rules catch people out. First, a plan of action doesn't earn points: "Security requirements not implemented, whether a plan of action is in place or not, will be assessed as 'not implemented.'" A 75 percent MFA rollout counts as not implemented. Second, if you have no system security plan (3.12.4), the methodology says an assessment "could not be completed." No SSP, no score.
Where the points are
The methodology assigns 5 points to 42 requirements, plus up to 5 each for MFA and encryption. The ones we most often see unmet in small and mid-sized contractors:
| Requirement | What it covers | Points |
|---|---|---|
| 3.5.3 | Multifactor authentication | 5, or 3 if only remote and privileged users |
| 3.13.11 | FIPS-validated encryption of CUI | 5, or 3 if encrypted but not FIPS-validated |
| 3.3.1 | Create and retain audit logs | 5 |
| 3.3.5 | Correlate audit review and reporting | 5 |
| 3.6.1 / 3.6.2 | Incident handling capability and reporting | 5 each |
| 3.11.2 | Vulnerability scanning | 5 |
| 3.12.1 / 3.12.3 | Periodic security assessments and continuous monitoring | 5 each |
| 3.14.1 / 3.14.2 / 3.14.3 | Flaw remediation, malicious code protection, security alerts | 5 each |
| 3.14.6 | Monitor systems to detect attacks | 5 |
| 3.1.12 / 3.1.13 | Monitor and encrypt remote access | 5 each |
Point values per the DoD Assessment Methodology.
Notice how many of those are monitoring and response. A managed SOC with proper logging, correlation, and an incident response plan can close several 5-point gaps at once: audit logging, correlation, incident handling, attack monitoring, and security alerts. That's often the fastest honest route from the 70s into the 90s.
The number that matters for CMMC later
If Phase 2 comes back in any form, the conditional status rules in 32 CFR 170.21 likely still apply. To get Conditional Level 2 status with a POA&M, you need a score of at least 0.8 of the total (88 of 110), no POA&M items worth more than 1 point except 3.13.11 at 3 points, and none of six specific requirements on the POA&M, including the SSP (3.12.4) and physical access controls. The POA&M must be closed within 180 days. In practice, every 5-point and 3-point gap has to be closed before an assessment, not after.
Second opinion
Get an independent SPRS score check
We'll re-score your current self-assessment against the DoD Assessment Methodology and show which 5-point gaps to close first, and where your posted score may be too high.
- Line-by-line score recalculation
- 5-point gap list in fix order
- POA&M eligibility check
- Affirmation risk notes
A 90-day plan
- Weeks 1 to 2: re-score honestly. Walk all 110 requirements with evidence in hand. Anything "mostly done" is not implemented. Compare the result with what's in SPRS.
- Weeks 1 to 2: fix the SSP. If it's thin or out of date, nothing else counts.
- Weeks 2 to 6: MFA and encryption. Extend MFA to all users. Confirm FIPS-validated modules for CUI at rest and in transit.
- Weeks 3 to 8: logging and monitoring. Centralize audit logs, turn on correlation, set up 24/7 monitoring and an incident response plan. See SOC as a Service and our incident response retainer.
- Weeks 6 to 10: vulnerability management. Regular authenticated scanning and a tracked remediation process. See vulnerability scanning.
- Weeks 10 to 12: re-score and update SPRS. Post the corrected score, whether it went up or down, and have the affirming official sign off knowing what's behind it.
If your posted score was too high
Correct it. An inaccurate SPRS score or affirmation creates exposure under the Department of Justice Civil Cyber-Fraud Initiative, which uses the False Claims Act and isn't affected by the CMMC pause (Morgan Lewis). A lower number you can defend beats a higher one you can't. Talk to counsel about how to handle the correction.
Frequently asked questions
Do I still need to post an SPRS score during the CMMC Phase 2 pause?
Yes, wherever your contracts require it. The July 13, 2026 suspension stopped Level 2 (C3PAO) and Level 3 requirements, but contracting officers can still require Level 1 (Self) and Level 2 (Self), and those require a current self-assessment and affirmation in SPRS.
How is an SPRS score calculated?
Under the NIST SP 800-171 DoD Assessment Methodology, you start at 110 and subtract 5, 3, or 1 point for each requirement not implemented. The score can go negative. Partial credit exists only for multifactor authentication (3.5.3) and FIPS-validated encryption (3.13.11).
Does a POA&M raise my SPRS score?
No. The methodology says plans of action are not a substitute for a completed requirement; an unimplemented requirement counts as not implemented with or without a plan. Not having a plan at all also fails requirement 3.12.2.
What SPRS score do I need for CMMC Level 2?
To get Conditional Level 2 status with a POA&M, 32 CFR 170.21 requires a score of at least 80 percent of the requirements (88 of 110), no POA&M items worth more than 1 point except 3.13.11 at 3 points, none of six listed requirements on the POA&M, and closeout within 180 days. Final status requires all requirements met.
What are the fastest ways to raise an SPRS score?
Close 5-point gaps first, such as MFA for all users (3.5.3), FIPS-validated encryption for CUI (3.13.11), audit logging (3.3.1), malicious code protection (3.14.2), and security assessments (3.12.1). Make sure your SSP (3.12.4) exists, since without it no score can be calculated.
Can my SPRS score be too high?
Yes, and that's the bigger risk. An inaccurate score or affirmation can create False Claims Act exposure under the Department of Justice Civil Cyber-Fraud Initiative, which the CMMC pause doesn't affect. If your score was optimistic, correct it.