Free · no sign-in · in your browser
SPRS score calculator
What a result proves: the number a prime or contracting officer sees in SPRS, and whether it is a usable one. Not sure about a requirement? Each ID links to its reference page with the assessment objectives an assessor checks.
3.1Access Control
- 3.1.1Authorized access control5 pts
- 3.1.2Transaction and function control5 pts
- 3.1.3Control CUI flow1 pt
- 3.1.4Separation of duties1 pt
- 3.1.5Least privilege3 pts
- 3.1.6Non-privileged accounts for non-security functions1 pt
- 3.1.7Prevent and log privileged functions1 pt
- 3.1.8Limit unsuccessful logon attempts1 pt
- 3.1.9Privacy and security notices1 pt
- 3.1.10Session lock1 pt
- 3.1.11Session termination1 pt
- 3.1.12Monitor remote access5 pts
- 3.1.13Encrypt remote access5 pts
- 3.1.14Managed remote access points1 pt
- 3.1.15Authorize remote privileged commands1 pt
- 3.1.16Authorize wireless access5 pts
- 3.1.17Protect wireless access5 pts
- 3.1.18Control mobile device connections5 pts
- 3.1.19Encrypt CUI on mobile devices3 pts
- 3.1.20External connections1 pt
- 3.1.21Portable storage on external systems1 pt
- 3.1.22CUI on public systems1 pt
3.2Awareness & Training
3.3Audit & Accountability
- 3.3.1System audit logs5 pts
- 3.3.2User accountability in audit records3 pts
- 3.3.3Review and update logged events1 pt
- 3.3.4Alert on audit logging failure1 pt
- 3.3.5Correlate audit review and reporting5 pts
- 3.3.6Audit reduction and report generation1 pt
- 3.3.7Synchronized system clocks1 pt
- 3.3.8Protect audit information1 pt
- 3.3.9Limit audit management to privileged users1 pt
3.4Configuration Management
- 3.4.1Baseline configuration5 pts
- 3.4.2Security configuration enforcement5 pts
- 3.4.3Change control1 pt
- 3.4.4Security impact analysis of changes1 pt
- 3.4.5Access restrictions for change5 pts
- 3.4.6Least functionality5 pts
- 3.4.7Restrict nonessential programs and services5 pts
- 3.4.8Deny-by-exception software policy5 pts
- 3.4.9Control user-installed software1 pt
3.5Identification & Authentication
- 3.5.1Identify users, processes and devices5 pts
- 3.5.2Authenticate users, processes and devices5 pts
- 3.5.3Multifactor authentication5 pts
- 3.5.4Replay-resistant authentication1 pt
- 3.5.5Prevent identifier reuse1 pt
- 3.5.6Disable inactive identifiers1 pt
- 3.5.7Password complexity1 pt
- 3.5.8Prohibit password reuse1 pt
- 3.5.9Temporary passwords1 pt
- 3.5.10Cryptographically protected passwords5 pts
- 3.5.11Obscure authentication feedback1 pt
3.6Incident Response
3.7Maintenance
3.8Media Protection
- 3.8.1Protect media containing CUI3 pts
- 3.8.2Limit access to CUI on media3 pts
- 3.8.3Media sanitization5 pts
- 3.8.4Mark media with CUI markings1 pt
- 3.8.5Control media during transport1 pt
- 3.8.6Encrypt CUI on media in transport1 pt
- 3.8.7Control removable media5 pts
- 3.8.8Prohibit portable storage with no owner3 pts
- 3.8.9Protect backup CUI1 pt
3.9Personnel Security
3.10Physical Protection
3.11Risk Assessment
3.12Security Assessment
3.13System & Communications Protection
- 3.13.1Boundary protection5 pts
- 3.13.2Security engineering principles5 pts
- 3.13.3Separate user and management functions1 pt
- 3.13.4Prevent transfer via shared resources1 pt
- 3.13.5Subnetworks for public components5 pts
- 3.13.6Deny by default, allow by exception5 pts
- 3.13.7Prevent split tunneling1 pt
- 3.13.8Encrypt CUI in transit3 pts
- 3.13.9Terminate network connections1 pt
- 3.13.10Cryptographic key management1 pt
- 3.13.11FIPS-validated cryptography5 pts
- 3.13.12Collaborative computing devices1 pt
- 3.13.13Control mobile code1 pt
- 3.13.14Control VoIP1 pt
- 3.13.15Protect session authenticity5 pts
- 3.13.16Encrypt CUI at rest1 pt
3.14System & Information Integrity
Check the arithmetic
The same calculation, from the MCP server
The calculator above and the CMMC MCP server apply one dataset. Ask your assistant the same question and it will answer with these deductions.
What this proves: Every deduction is the Annex A point value, the two sliding-scale requirements score their partial value, and the answer is a number a contracting officer can check.
$ calculate_sprs_score not_implemented=[3.11.2, 3.14.1, 3.1.12, 3.3.1] partially_implemented=[3.5.3, 3.13.11] summing Annex A deductions … done 3.11.2 vulnerability scanning -5 3.14.1 flaw remediation -5 3.1.12 monitor remote access -5 3.3.1 system audit logs -5 3.5.3 multifactor authentication -3 (privileged and remote only) 3.13.11 FIPS-validated cryptography -3 (encryption in place, not validated) sprs_score: 84 of 110 (26 deducted; floor -203) meets_conditional_level_2_threshold: false — 88 needed
How the score works
- How is an SPRS score calculated?
- Start at 110 and subtract the Annex A point value of every requirement that is not implemented: 5, 3 or 1 point each, from the DoD Assessment Methodology. The deduction pool totals 313, so the floor is -203. Two requirements score on a sliding scale: 3.5.3 (multifactor authentication) deducts 3 instead of 5 when MFA covers privileged and remote access only, and 3.13.11 deducts 3 instead of 5 when encryption is in place but not FIPS-validated.
- What score do I need for CMMC Level 2?
- A final CMMC Level 2 status needs every requirement met. Conditional status is possible at 88 or above, provided every open requirement is POA&M-eligible under 32 CFR 170.21, with one 180-day closeout window.
- Why does 3.12.4 have no points?
- The system security plan is not scored because without one there is no assessment to score. The methodology treats a missing SSP as a reason no score can be submitted to SPRS at all.
- Is this the official DoD calculation?
- It applies the published Annex A point values and the two documented partial cases exactly as the DoD Assessment Methodology states them. It is your self-assessment, not a Basic, Medium or High assessment by DCMA DIBCAC, and an assessor tests each requirement objective by objective.
Prefer to answer questions than mark 110 rows? The readiness check estimates the same score from 24 questions. Want it verified against evidence? Start the readiness assessment.