Free CMMC Readiness Check

Answer 24 questions about your environment and get an instant estimated SPRS score — weighted with the same DoD Assessment Methodology point values an assessor uses. No email required. About 5 minutes.

Before the questions: one gate

The DoD Assessment Methodology has one requirement with no point value, because without it a score cannot be submitted to SPRS at all: a System Security Plan (NIST SP 800-171 § 3.12.4).

Do you have a current System Security Plan (SSP) describing your CUI environment?

How SPRS scoring actually works

Every requirement in NIST SP 800-171 carries a weight in the DoD Assessment Methodology. Not implementing a requirement subtracts 1, 3, or 5 points from a starting score of 110 — so the scale runs from 110 down to −203. Forty-two requirements are worth 5 points each; miss even a handful and a score collapses fast. Two requirements score on a sliding scale: MFA (3.5.3) costs 5 points with no MFA or 3 points if general users are uncovered, and cryptography (3.13.11) costs 5 points unencrypted or 3 points when encryption is not FIPS-validated.

The number that matters for certification is 88: at or above it, with every open item POA&M-eligible, conditional CMMC Level 2 certification is possible. Below it — or with any high-weight gap open — remediation comes first. The median defense contractor’s first honest self-assessment lands well below zero, which is why the checker above reports a range and treats “not sure” as not implemented: that is how an assessor will treat it too.

Frequently asked questions

What is an SPRS score?

The Supplier Performance Risk System (SPRS) score is the DoD's measure of how completely a contractor has implemented the 110 security requirements of NIST SP 800-171. Scoring follows the DoD Assessment Methodology: you start at 110 and subtract weighted points (1, 3, or 5) for each requirement not implemented, down to a floor of −203. Contractors handling CUI must have a current score posted in SPRS to be eligible for DoD awards under DFARS 252.204-7019/7020.

What SPRS score do I need for CMMC Level 2?

Full certification requires all 110 requirements implemented — a score of 110. A conditional Level 2 certification is possible at 88 or above, but only when every open item is eligible for a Plan of Action & Milestones (POA&M). The highest-weighted requirements — such as multifactor authentication and FIPS-validated encryption — are not POA&M-eligible, so gaps there block even conditional certification regardless of your total.

How accurate is this free readiness check?

It assesses 23 of the 110 requirements directly — skewed toward the 5-point items that dominate the score — using the exact DoD Assessment Methodology weights, then extrapolates the remainder from your weighted implementation rate. It returns a range, not a certainty: a real gap assessment reviews evidence for all 110 requirements and commonly moves self-reported scores down, because assessors credit only what can be proven.

Why does the check ask about a System Security Plan first?

NIST SP 800-171 § 3.12.4 (the SSP) carries no point value in the DoD methodology for a reason: without one, an assessment cannot be conducted and a score cannot be submitted to SPRS at all. If you have no current SSP, that is step one — before remediating any technical gap.

Is a self-assessed SPRS score enough, or do I need a C3PAO?

It depends on the contract. Self-assessment satisfies CMMC Level 1 and a small set of Level 2 contracts, but most Level 2 work involving CUI requires third-party certification by a C3PAO every three years, with an annual executive affirmation in between. A realistic self-assessed score is still the essential starting point — it tells you whether you can schedule an assessment or need remediation first.

What happens if my SPRS score is wrong?

An inflated score is a False Claims Act risk — DOJ's Civil Cyber-Fraud Initiative has settled cases against contractors that misrepresented their cybersecurity posture. Score honestly, document your basis for each requirement, and update SPRS as your posture changes.

Using Claude or another AI assistant for compliance work? Our free CMMC MCP server gives it the full 800-171 control catalog and exact SPRS scoring.

MacTech Solutions is an SDVOSB that builds CUI enclaves and takes defense contractors from first SSP to C3PAO-ready. See the CMMC offerings or start a verified readiness scan.