Skip to main content

CMMC Pause: What DoW & Primes Still Require

  • blog
  • SPRS Scoring: How to Get a Current CMMC Status and Stay Eligible for Defense Contracts

SPRS Scoring: How to Get a Current CMMC Status and Stay Eligible for Defense Contracts

  • July 30, 2026
Author

Anna Fitzgerald

Senior Content Marketing Manager

Reviewer

Rob Gutierrez

Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP

Editor’s note: The DoW paused the transition to CMMC Phase 2 on July 13, 2026 while a Reform Task Force reviews the program, so Program Managers can designate only CMMC Level 1 (Self) or CMMC Level 2 (Self) in new solicitations at this time. That makes self-assessment and SPRS reporting the operative path for more contracts, not fewer. See our Phase 2 pause update for what changed and what did not.

SPRS is the only place your CMMC status officially exists. In the current Phase 1 of enforcement, DoW contracting officers check it before award. Primes ask for it before they subcontract. And the senior official who signs the affirmation attached to it is putting their name on your cybersecurity posture, not just your paperwork.

That makes your SPRS score the most consequential number in your cybersecurity program. It is also the number contractors most often get wrong or are unable to defend.

This guide explains what the SPRS is and how it fits into the current CMMC program, what score you need at each level, how to submit your assessment results and score step by step, and how to keep the number accurate once it is on record.

What is the Supplier Performance Risk System (SPRS)?

The Supplier Performance Risk System (SPRS) is a web-based application the Department of Defense (DoD) uses to collect and evaluate supplier performance and risk data. It serves as a centralized database for:

  • Price, item and supplier risk assessments and ratings
  • Supplier performance data, including on-time delivery scores
  • Cyber reports, including CMMC and NIST SP 800-171 assessment results

SPRS predates CMMC. It was an existing DoD database before the program was introduced, and the 32 CFR CMMC Program rule expanded its use to include CMMC status, assessment scores, and annual affirmations.

Here’s why it matters:

  • SPRS is the system of record for supplier and product assessments that Department contracting officers check before award (and that primes most often ask screenshots of before award).
  • It operates independently of the government’s CMMC rollout schedule. It was collecting cyber reports before CMMC existed, and any phase changes do not take it offline, suspend submission requirements, or invalidate scores already posted.

In short, SPRS is not a CMMC-specific requirement that comes and goes with the rollout calendar. It is the DoD's standing procurement system, and your cyber reports and affirmations must live inside it now.

A note on naming: The Department of Defense is now commonly referred to by its official secondary title, the Department of War (DoW). Because existing CMMC rules, contract clauses, and source documents still read "Department of Defense (DoD)," this post uses both or “the Department.”

Why is SPRS key to the CMMC program?

The purpose of CMMC is to give the Department increased assurance that contractors and subcontractors are meeting the cybersecurity requirements for protecting sensitive unclassified information, including Federal Contract Information (FCI) and CUI.

SPRS provides that assurance by giving contractors a “location” to certify CMMC Level 1 and 2 compliance and the Department a centralized view of that cybersecurity data alongside performance data.

This visibility benefits:

  • The Department, by supporting better decisions about which vendors and suppliers can be trusted with sensitive unclassified information.
  • Contractors, subcontractors, and the wider defense supply chain by ensuring their CMMC and NIST 800-171 compliance is documented and visible. This helps them achieve and maintain eligibility for DoD contracts and foster trust with federal agencies, primes, and other stakeholders.

That is why the CMMC program requires contractors to submit self-assessment results, scores, and affirmations of compliance to SPRS in the first place. Let’s dive into these SPRS requirements, and their purpose, next.

If you’re new to CMMC, check out our pocket guide to CMMC that explains why this assessment framework was created, who it applies to, and exactly what it requires.

Are SPRS scores mandatory for CMMC?

Short answer: yes.

The longer answer is that an organization must have a current CMMC status in SPRS, based on its assessment score and its affirmation of compliance, to be eligible for contract awards that carry CMMC requirements.

Even for CMMC self-assessments, this introduces a layer of verification that didn't exist in previous self-attestation models of security under regulations like DFARS 7012. Three verification pieces that CMMC adds or builds on that hinge on the SPRS:

1. A verifiable metric that must be checked before award.

Prior to CMMC, by signing contracts with DFARS 7012 or other safeguarding requirements for federal data, organizations effectively self-attested that they met those requirements. There wasn't a reliable or scalable way to check whether companies were actually implementing those controls. Often, verification only came after the award, when there was a cyber incident or False Claims Act settlement.

CMMC provided an actual metric, the SPRS score, that has to be verified before DoW program managers can award or renew contracts and before primes flow down sensitive information and purchase orders.

2. An affirmation that makes it a continuing statement.

Your score describes your posture on the date you assessed. Your annual affirmation attests that you are still maintaining it. That means an accurate score can become an inaccurate one without you touching SPRS at all, simply by letting your environment drift.

3. A government right to test your number.

DFARS 252.240-7997 (formerly 252.204-7020) authorizes Department-led Medium and High assessments using NIST SP 800-171A procedures. A self-assessed score is a claim, and the Department can check it against your actual environment whenever program criticality or data sensitivity warrants. A gap between a self-attested score and a government-assessed one is a common source of False Claims Act exposure.

The direction of the program reinforces this verification layer rather than softening it. The DoW's request for information for the CMMC Reform Task Force asks industry specifically about "leveraging and optimizing self-attestation capabilities." Whatever shape the reformed program takes, self-assessment and SPRS reporting are the floor beneath it.

Here are the SPRS requirements in place now, regardless of the rollout schedule:

What SPRS requiresWhy it holds
A current CMMC status posted before awardDFARS 252.204-7021 (the CMMC clause) conditions eligibility on it. Contracting officers check SPRS directly.
A status your prime can verify, usually by screenshotPrimes cannot see your SPRS entry, so they ask for it. Prime deadlines are supply chain risk decisions set independently of the Department's calendar.
Level 1 scored MET or NOT MET, Level 2 scored against the 110 NIST SP 800-171 Rev 2 requirementsThe scoring methodology is codified in the CMMC Program rule at 32 CFR § 170.24, and is unaffected by the phased rollout schedule.
An annual affirmation signed by a named senior officialThe affirmation attests you are maintaining implementation, not that you passed once. That is why it is annual at every level.
A score that matches your actual postureYour entry is a representation to the government. If a later government assessment finds a materially different posture, the gap becomes the evidence in a False Claims Act suit.

Takeaway: Self-assessment does not lower the bar. It removes the second set of eyes and leaves your signature on the record.

Recommended reading

CMMC Self-Assessment Guide: Level 1 and Level 2 Process

A brief history on SPRS requirements and current state

CMMC was not the first program to put cybersecurity requirements in defense contracts. Since DFARS 252.204-7012 took effect in 2017, organizations in the Defense Industrial Base (DIB) have been required to provide adequate security for covered defense information and to flow that clause down to subcontractors.

But 7012 had no verification mechanism. Many contractors fell short of the safeguards, which left the Department exposed to risks that adversaries could exploit.

The 2020 DFARS Interim Rule added three clauses to strengthen 7012, and the February 1, 2026 Revolutionary FAR Overhaul reorganized them. Here is where the SPRS obligation stands today:

ClauseStatus as of February 1, 2026What it means for SPRS
DFARS 252.204-7012UnchangedRequires NIST SP 800-171 Rev 2 implementation, an SSP, and 72-hour incident reporting. No SPRS submission of its own.
DFARS 252.204-7019EliminatedThe standalone "Basic" self-assessment and SPRS submission requirement no longer exists as a separate provision, since it’s redundant of the DFARS 7021 (CMMC) clause.
DFARS 252.204-7020Renumbered to 252.240-7997 and revisedReferences to "Basic" assessments removed. Now defines only government-performed Medium and High assessments.
DFARS 252.204-7021UnchangedThe CMMC clause. This is where the assessment and SPRS submission obligation now lives.

This overhaul is not a reduction in assessment and reporting obligations. It simply consolidated them under the CMMC framework, not removed. If your contract requires CMMC Level 1 (Self) or Level 2 (Self), you still complete the assessment and your results still go into SPRS.

In other words, your SPRS obligation did not disappear when DFARS 7019 did. It moved to DFARS 252.204-7021.

Note: Solicitations issued after February 1, 2026 use the new numbering (FAR 52.240-93 and DFARS 252.240-7997), while older contracts still reference the legacy numbers (FAR 52.204-21 and DFARS 252.204-7020). Both are circulating right now. Read the clause text, not just the citation.

Recommended reading

A Guide to the DFARS Clauses Behind CMMC & How They've Changed in 2026

Are CMMC SPRS requirements being enforced by the DoW and primes?

Yes. CMMC SPRS requirements took effect November 10, 2025 with Phase 1 and have applied to new solicitations ever since. Changes to the rollout schedule since then, including the July 2026 pause of the Phase 2 transition, have not changed them.

Department contracting officers are required to check SPRS and withhold award from an offeror that does not have a current CMMC status posted at the level the solicitation requires, or higher. Primes must confirm subcontractors have a valid CMMC status in SPRS before awarding subcontracts.

What primes require is a separate question from what the Department requires, and it has not slowed down. Prime deadlines are business decisions driven by supply chain risk, set independently of the Department's rollout calendar. Nothing in a change to the Department's schedule directs a prime to drop a requirement it set for its own reasons.

Elbit America's July 2026 supplier letter put it directly, urging suppliers to keep maturing their programs while the Phase 2 transition is on hold: "This pause is an opportunity to strengthen your program, not a reason to delay it."

CMMC 2.0 Timeline as of July 13, 2026 pause

Practically, the answer to "do I still need a current SPRS score" is yes on three separate tracks:

  1. Department contracts. A current CMMC status is a condition of award under DFARS 252.204-7021.
  2. Prime subcontracts. Primes verify supplier status before award, and many set their own deadlines ahead of the Department's.
  3. Your own exposure. Your score is a representation to the government that the government can test later, under the Medium and High assessment authority in DFARS 252.240-7997 and the safeguarding obligations in DFARS 252.204-7012.

Takeaway: No change to the rollout calendar has ever moved the SPRS requirement. Enter or refresh your score now.

Recommended reading

Which Prime Contractors Have Begun Enforcing CMMC in Their Supply Chains? A List + The Actual Supplier Notices

What are SPRS requirements for each CMMC level?

CMMC sets different SPRS reporting requirements by level and assessment type. The table below shows what each level requires and whether it can currently be designated in a new solicitation.

Level and typeWho submitsCadenceAvailable in new solicitations today?
Level 1 (Self)You, in SPRSAnnuallyYes
Level 2 (Self)You, in SPRSEvery 3 years, with annual affirmationYes
Level 2 (C3PAO)Your C3PAO, via eMASS to SPRSEvery 3 years, with annual affirmationNot by DoW program managers while the Phase 2 transition is on hold
Level 3 (DIBCAC)Department assessor, via eMASS to SPRSEvery 3 years, with annual affirmationNot by DoW program managers while the Phase 2 transition is on hold

Important nuance on the last two rows: the hold applies to what Department program managers can require, not to what SPRS and eMASS can process.

During the most recent July Town Hall, the Cyber AB confirmed that Level 2 (C3PAO) certification assessments are continuing and that eMASS and SPRS remain fully operational to record them. If you already hold a Level 2 (C3PAO) certification or have one in progress, it still posts and it still counts.

CMMC Level 1 (Self)

All Level 1 contractors and subcontractors that handle FCI must complete an annual self-assessment and submit the results, plus an affirmation of compliance signed by a senior official (the Affirming Official, or AO), in SPRS themselves.

When submitting Level 1 results, they must include at minimum(1)(i)):

  • CMMC Level
  • CMMC Status Date
  • CMMC Assessment Scope
  • All industry CAGE codes associated with the information systems in scope
  • Compliance result

CMMC Level 2 (Self)

Currently, all Level 2 contractors and subcontractors handling CUI must complete a self-assessment and submit the results plus an AO affirmation in SPRS themselves. The assessment must be submitted every three years and the affirmation every year.

While this path was originally limited to contracts involving CUI that was not critical to national security, it is currently the only path available for Level 2 requirements put in new solicitations by DoW Program Managers.

Level 2 submissions include the same information as Level 1(1)(i)) with two differences. Instead of "Compliance Result," they include:

  • Overall Level 2 self-assessment score (out of 110)
  • POA&M usage and compliance status, if applicable (for example, a score between 88 and 109)

Scoring is covered in detail below.

CMMC Level 2 (C3PAO)

Level 2 contractors handling CUI critical to national security were slated to undergo a triennial assessment by a CMMC Third-Party Assessment Organization (C3PAO). Program managers cannot designate this requirement in new solicitations while Phase 2 is paused.

Where an assessment does happen, the C3PAO enters results into the CMMC Enterprise Mission Assurance Support Service (eMASS), which transmits them to SPRS. The minimum eMASS inputs are specified in 32 CFR § 170.17(1)(i)), but contractors do not enter this information themselves.

The AO must still affirm continuing compliance after every assessment and annually thereafter, entered electronically in SPRS.

CMMC Level 3 (DIBCAC)

Level 3 follows the same mechanics as Level 2 (C3PAO), except the assessment is government-led by DIBCAC and the Department assessor enters results into eMASS. Minimum inputs are specified in 32 CFR § 170.18(1)(i)). An AO must submit an annual affirmation in SPRS.

Level 3 designations are also paused. This level is unlikely to apply to subcontractors, although primes may flow down Level 3 requirements if the information they share requires that level of protection.

What SPRS score do you need for CMMC?

The score you need depends on the CMMC level and status you are seeking. For Level 2, a score of 110 is required for a Final status. A score of 88 to 109 can support a Conditional status with a POA&M.

The scoring methodology applies to all levels. As described in 32 CFR § 170.24, each security requirement evaluated during a CMMC assessment results in one of three findings:

  • MET: All applicable objectives for the requirement are satisfied based on evidence.
  • NOT MET: One or more applicable objectives is not satisfied.
  • NOT APPLICABLE (N/A): The requirement or objective does not apply at the time of assessment.

Levels 2 and 3 are both scored numerically based on MET and NOT MET requirements, but the point values and maximums differ. Level 1 is scored differently. Here is each.

You can also explore the requirements for each level and how they factor into your SPRS score in the Requirement Explorer tool on CMMC.com.

CMMC Level 1 scoring

Level 1 contractors must fully implement all 15 basic safeguarding requirements in FAR 52.240-93 (formerly FAR 52.204-21(1)(i))). None of the 15 can be unmet or placed on a Plan of Action and Milestones (POA&M) for later remediation.

Because all 15 must be implemented in full, Level 1 results are scored MET or NOT MET in their entirety rather than with a number. That is why there is no score column for Level 1 in the Requirement Explorer tool.

Think of Level 1 as pass or fail, and Levels 2 and 3 as scored.

CMMC Level 2 scoring

Level 2 contractors receive a numerical score and can carry some NOT MET requirements on a POA&M.

Level 2 scoring ranges from ‑203 to 110. The negative floor exists because each of the 110 NIST SP 800-171 Rev 2 requirements is weighted at one, three, or five points rather than one point each.

The weights reflect the potential adverse effect of not meeting the requirement:

  • 5 points if it could lead to significant exploitation of the network or exfiltration of CUI
  • 3 points if it would have a specific and confined effect on the security of the network and its data
  • 1 point if it would have a limited or indirect effect

So an organization starts at 110 and subtracts one, three, or five points for every requirement assessed as NOT MET, which can produce a negative final score.

A maximum score of 110 indicates full compliance with NIST SP 800-171, meaning every requirement was assessed as MET or NOT APPLICABLE. It is the only score that produces a Final Level 2 (Self) or Final Level 2 (C3PAO) status.

An organization below 110 can still achieve a Conditional status if it:

  • Scores no lower than 88
  • Documents unmet requirements in a POA&M
  • Does not include any of the requirements listed in 32 CFR § 170.21(a)(2)(iii)(2)(iii)) in the POA&M

POA&M items must be remediated no later than 180 days after the Conditional status was issued to reach Final status.

Bottom line: A score below 110 does not automatically disqualify you, and a strong SSP, POA&M, and documentation set still demonstrate your cybersecurity posture. But the score exists to help the Department and primes gauge risk, and the closer you are to 110, the better positioned you are for awards and renewals.

CMMC Level 3 scoring

Level 3 contractors also receive a numerical score and can carry POA&M items, but Level 3 does not use weighted scoring. Each MET requirement is worth one point and each NOT MET requirement subtracts one.

Level 3 requirements are a subset of 24 NIST SP 800-172 requirements. All 24 must be implemented for a Final Level 3 (DIBCAC) status.

A Conditional Level 3 (DIBCAC) status requires:

  • Implementing at least 20 of the 24 requirements, for a score of at least 80%
  • Documenting unmet requirements in a POA&M
  • Excluding any requirement listed in 32 CFR § 170.21(a)(3)(ii)(3)(ii)) from the POA&M

As with Level 2, POA&M items must be remediated within 180 days. An organization is only eligible to initiate a Level 3 assessment after achieving a maximum score on Level 2.

Plan of Action & Milestones (POA&M) Template

The POA&M is the document you use to identify and track the actions required to close the gaps found in an assessment. Use this template to document remediation and demonstrate ongoing progress toward a Final CMMC status.

What happens if your SPRS score is wrong?

An inaccurate SPRS score is a representation to the government, and the government can test it later. When the tested score does not match the reported one, the gap itself becomes the evidence of false claims.

The clearest recent example is LOGZONE, Inc., a Huntsville, Alabama defense contractor. In October 2021, LOGZONE posted a self-assessed score of 110 to SPRS under two Navy contracts. In 2024, a DIBCAC assessment found the actual score was ‑170, near the bottom of the ‑203 to 110 range. On June 18, 2026, the Department of Justice announced that LOGZONE agreed to pay $507,144, including $253,572 in restitution, to resolve False Claims Act allegations.

Two details make LOGZONE worth studying rather than just citing:

  • There was no breach. The liability came from the score and the years of billing on contracts that required it, not from an attacker getting in.
  • There was no whistleblower. Unlike most cases in this line, LOGZONE came out of a government assessment and referral. You cannot manage this risk by trusting that no insider will report you.

LOGZONE is part of a consistent pattern under the DOJ's Civil Cyber-Fraud Initiative:

OrganizationAnnouncedAmountThe gap
Penn StateOct 2024$1.25MInflated SPRS scores across 15 DoD and NASA contracts
MORSE CorpMar 2025$4.6MReported 104 in Jan 2021; a gap analysis later found ‑142, not updated until Jun 2023
Raytheon / RTX / NightwingMay 2025$8.5MNo NIST 800-171 compliant SSP across 29 contracts
Georgia Tech Research CorpOct 2025$875KScore submitted for an environment that did not correspond to a covered system
LOGZONEJun 2026$507KReported 110; DIBCAC assessed ‑170

However, it's important to understand that the risk of legal enforcement is real, but rare. Cybersecurity False Claims Act settlements number in the single digits every year against a DIB of roughly 200,000 to 300,000 organizations. This should not be the reason you get your score right. The reason is that the score is supposed to reflect your actual ability to protect defense information and provide real assurance to the DoW and primes when deciding who to partner with. These cases are simply what happens when that score does not.

What they point to operationally is straightforward: treat your SPRS score as a legal record, not a compliance checkbox. That means assessing against all objectives in NIST SP 800-171A rather than the 110 high-level requirements alone, keeping evidence behind every MET finding, and updating the score when your environment changes rather than waiting for the next assessment cycle.

Takeaway: During the pause, nothing sits between your claim and the record. Make the claim defensible.

Recommended reading

CMMC Cybersecurity Misrepresentation: The False Claims Act Cases DIB Contractors Should Know

How to enter a CMMC self-assessment into the SPRS

If you are ready to enter Level 1 or Level 2 self-assessment results, follow the steps below.

To access SPRS, you first need access to the Procurement Integrated Enterprise Environment (PIEE) portal. If you do not have it, start at step 1A. If you do, skip to step 1B.

Step 1A: Register as a PIEE user and add the "SPRS Cyber Vendor User" role

Navigate to the PIEE portal and click "New User." Complete the steps in the PIEE Vendors Getting Started Help guide, including:

Then complete registration:

  • Click "Register," read the Privacy Statement, and click "Agree."
  • Select user type "Vendor" and select your authentication method.
  • Complete the "User Profile" and "Supervisor / Agency" information.
  • Select "SPRS Supplier Performance Risk System" from the application list.
  • Select the "SPRS Cyber Vendor User" role from the User Roles list and click "Add Roles."

Step 1B: Access SPRS through PIEE as an existing user

  • Navigate to the PIEE landing page and click "Log In."
  • Select SPRS.
  • Select Cyber Reports (CMMC & NIST) from the Compliance Reports menu. Older guidance calls this module simply "Cyber Reports."

Step 2: Select your company hierarchy

  • Use the Company Hierarchy drop-down to select your company's hierarchy, identified by its Highest-Level Owner (HLO). The CAGE codes associated with your profile will appear.
  • Select the appropriate CAGE and hierarchy combination and click "Run Cyber Reports."
  • An asterisk next to a CAGE indicates you hold the SPRS Cyber Vendor User role for it, which is what grants add, edit, and delete access.

Step 3: Add a new CMMC Level 1 or Level 2 self-assessment

  • Navigate to the CMMC Assessments tab, then select the sub-tab for the level you are entering: CMMC Level 1 (Self) or CMMC Level 2 (Self).
  • Click "Add New CMMC Level 1 Self-Assessment" or "Add New CMMC Level 2 Self-Assessment." Only users with the privileged SPRS Cyber Vendor User role will see this button.

Step 4: Enter your CMMC assessment details

For Level 1 self-assessments:

  • Enter the Assessment Date in MM/DD/YYYY format.
  • Select the Assessing Scope: "Enterprise" or "Enclave." Enterprise refers to an organization with a defined mission and boundary that uses information systems to execute that mission and manages its own risk. Enclave refers to a set of system resources operating in the same security domain that share a single, common, continuous security perimeter.
  • Provide the total number of employees applicable to the assessment.
  • Answer "Yes" to confirm compliance with the security requirements in the referenced FAR clause. Note that the SPRS screen and the DoD quick entry guide still label this FAR 52.204-21, the pre-February 2026 number for what is now FAR 52.240-93. Confirming compliance is required to reach a Final Level 1 Self-Assessment.
  • Use the Open CAGE Hierarchy button to add relevant CAGE codes, or paste a comma-delimited list.
  • Click "Continue to Affirmation."

For Level 2 self-assessments:

The Level 2 flow runs through a progress bar with a stage for each of the 14 requirement families, followed by Review, CAGEs, Score, and Affirm.

  • Mark Met, Not Met, or N/A for all 110 NIST SP 800-171 Rev 2 requirements, working family by family from Access Control (AC). Select "Save and Continue" to move to the next family.
  • Before marking a requirement, open the Requirement Objectives button next to it. SPRS lists the underlying assessment objectives, and the screen states the rule directly: every objective must be met for the requirement to be Met.
  • At the Review stage, SPRS shows all 110 answers in one table and blocks you from continuing until every requirement is answered. Use the Export button here to pull your answers into a file before you affirm. That export is the cleanest record of what you attested to and on what date.
  • At the CAGEs stage, add your Assessing Scope, employee count, and included CAGE codes. You cannot add CAGEs outside your company hierarchy, since that data comes from SAM.
  • At the Score stage, your final score and CMMC Status Type appear. Only a Conditional score of 88 to 109 or a Final score of 110 can be affirmed.
  • If a requirement marked "Not Met" is one that cannot be placed on a POA&M, your Status Type becomes No CMMC Status regardless of your score. A 109 with an ineligible requirement unmet gets you nothing.

A note on the marking step: assess against the NIST SP 800-171A objectives, not the requirement statements alone. Level 2 has 110 requirements and 320 assessment objectives beneath them, and most overstated scores come from marking a requirement MET when only some of its objectives are actually satisfied. SPRS now surfaces those objectives in the interface, so there is no longer any gap between what the form asks and what the standard requires.

Step 5: Confirm or transfer to the Affirming Official (AO)

  • If you are the AO, select "Continue to Affirmation."
  • If you are not, enter the AO's email address and select "Transfer to AO."

Step 6: Affirm the assessment

  • Review the assessment details. Until it is affirmed, the record carries an "Unaffirmed" prefix on its status, for example Unaffirmed CMMC L2 Conditional Self-Assessment.
  • Check the box certifying you have read the affirmation statement, then select "Affirm."
  • After affirmation, a Cyber Vendor User can edit, cancel, or delete certain records. Cancelling an affirmed Level 2 record marks it "Retracted by Vendor" rather than removing it.

Read the affirmation statement before you check that box. It is not boilerplate. It states that misrepresenting your CMMC compliance status to the government may lead to criminal prosecution under 18 U.S.C. § 1001, civil liability under the False Claims Act, and contract remedies at the contracting officer's discretion. Every settlement in the table above began with someone checking that box.

The affirmation is also what distinguishes CMMC from earlier self-attestation regimes. Your score reflects your posture on the date of assessment. Your affirmation attests that you have implemented and are maintaining those requirements. The 32 CFR rule states the purpose plainly: the affirmation validates that the contractor is actively maintaining its CMMC status, which is more than a checkbox exercise. That is why it is required annually at every level.

Level 1 CMMC Status Types:

  • Final Level 1 Self-Assessment: Indicates compliance. This is the only Level 1 status type visible to government personnel, so anything short of it reads to a contracting officer as no status at all.
  • Pending Affirmation: Awaiting AO approval.
  • Incomplete: Assessment information only partially completed.
  • No CMMC Status (Expired Assessment): A Final Level 1 Self-Assessment converts to this automatically one year after the assessment date, with no action or warning on your part.

Level 2 CMMC Status Types:

  • CMMC L2 Final Self-Assessment: Score of 110. Valid for 3 years with annual affirmations.
  • CMMC L2 Conditional Self-Assessment: Score of 88 to 109. Valid for 180 days.
  • Pending Affirmation: Awaiting AO approval.
  • Incomplete: Assessment information only partially completed.
  • Retracted by Vendor: An affirmed record you subsequently cancelled.
  • No CMMC Status: Your Final Self-Assessment expired, or a requirement marked "Not Met" cannot be placed on a POA&M.

CMMC Level 2 compliance checklist

Working through the 110 requirements before you enter a score is the difference between a defensible submission and a guess. This checklist walks through each requirement and what evidence supports it.

Who can see your SPRS score and CMMC status?

Only you and the Department can see your CMMC certificate or self-assessment information, including your score, in SPRS.

That raises an obvious question: how are primes expected to verify CMMC status among their subcontractors? This came up repeatedly in the 48 CFR rulemaking comments. In the final rule, the Department responded that contractors can only access their own CMMC certificate or self-assessment information, that it has no tool for sharing subcontractor information with primes electronically, and that primes are expected to work with their suppliers to conduct verifications as they would for any other flowed-down clause requirement.

The response noted that SPRS lets subcontractors print or screenshot their own status and affirmation information and share it with their primes if they choose. Subcontractors can also voluntarily provide copies of their SPRS reports for Level 2 (C3PAO) and Level 3 (DIBCAC).

For example, here is what Secureframe's own report looks like, showing our latest assessment and current CMMC status. We went through the Level 2 (C3PAO) process ourselves, and that status still posts and still counts while the Phase 2 transition is on hold.

This matters more during the pause than before it. With C3PAO certificates off the table as a contractual requirement in new solicitations, the SPRS screenshot is often the only artifact a supplier has to hand a prime. Whether you share it is up to you and your prime. The Department is not dictating a method.

Takeaway: Your score is private to the Department by default and public to your prime by choice. Assume you will be asked for it.

Recommended reading

Elbit America Tells Suppliers to Stay the Course: Why the CMMC Pause Doesn't Change Prime Flowdown Requirements

How Secureframe helps you get and keep a valid CMMC status in SPRS

The readiness gap that made CMMC necessary has not closed. An October 2025 CyberSheath report found that only 1% of DIB organizations felt fully prepared for CMMC assessments, fewer than half had completed foundational documentation like an SSP or POA&M, and the average SPRS score sat at 60 against a required 110.

The pause of third-party assessment requirements does not close that readiness gap. It removes the deadline, and shifts the entire burden of accuracy onto the organization signing the affirmation. Secureframe Defense is an end-to-end cybersecurity platform purpose-built to help the DIB carry that burden and reduce the true cost and complexity drivers behind CMMC: the implementation and maintenance of NIST 800-171.

Whether you need a Level 1 or Level 2 self-assessment or you are maintaining a Level 2 certification, Secureframe Defense helps you get there faster and stay there:

  • Live SPRS score tracking. See how your implementation status translates into a live SPRS score, mapped directly to the 110 NIST 800-171 requirements. Spot what is missing and close gaps before they cost you a contract, or before they show up in a government assessment.
  • A provisioned CUI enclave and government cloud licensing. Auto-provision a CUI enclave in Microsoft GCC High or Google Workspace, preconfigured with the access control, audit and accountability, identification and authentication, and system and communications protection controls required to safeguard CUI. You can even purchase GCC High licenses directly in Secureframe as an authorized AOS-G reseller. Browse GCC High licensing on our Marketplace.
  • Control-by-control implementation tracking. View the status of all 110 Level 2 controls and 320 assessment objectives, with evidence, attachments, comments, and POA&M items behind each objective. This is the layer that keeps a MET finding defensible.
  • SSP and POA&M automation. Generate your System Security Plan from control, policy, and vendor data in your Secureframe instance, and link POA&M items to unmet requirements. Assign owners, track due dates, and show progress.
  • Automated evidence collection from federal systems. Connect Microsoft GCC High, Google Workspace, AWS GovCloud, Azure Government, and over 300 tools to collect and validate evidence continuously.
  • Continuous monitoring and drift detection. Your environment changes between assessments. Continuous control testing means your SPRS score reflects your posture today, and the executive signing the annual affirmation has a record behind the signature rather than a memory of last year's assessment.
  • Expert guidance. Federal compliance experts with CMMC audit experience, and first-hand experience preparing for and undergoing a Level 2 assessment, help you navigate requirements before, during, and after.

If you need help scoping, self-assessing, or scoring your DIB cybersecurity program, talk to our team.

One platform. Complete CMMC readiness.

Request a demo

This post was originally published in January 2025 and has been updated for accuracy and comprehensiveness, most recently for the July 13, 2026 pause of the CMMC Phase 2 transition and the February 2026 FAR and DFARS clause renumbering.

FAQs

Why is SPRS relevant for CMMC?

SPRS is the designated system for reporting CMMC assessment results, scores, and executive affirmations of compliance. Department contracting officers check it before award, and a current CMMC status in SPRS is a condition of eligibility.

Is my SPRS score still required during the CMMC Phase 2 pause?

Yes. Under DFARS 252.204-7021, the CMMC clause, you still need a current self-assessment score in SPRS and an annual affirmation of continuous compliance. The DoW's July 13, 2026 announcement paused the transition to Phase 2 and the designation of Level 2 (C3PAO) and Level 3 requirements. It did not change the SPRS requirement. See the CMMC FAQ on CMMC.com for more on what the pause did and did not change.

Can I still submit a Level 2 (C3PAO) assessment to SPRS during the pause?

Yes. SPRS and eMASS remain fully operational and C3PAO assessments are continuing. What is paused is the Department's ability to require a C3PAO assessment in new solicitations. Existing certifications remain valid and still post to SPRS.

What is the CMMC score in SPRS?

The CMMC score in SPRS reflects your compliance with FAR 52.240-93 (formerly 52.204-21) for Level 1, NIST SP 800-171 for Level 2, and NIST SP 800-172 for Level 3.

  • Level 1 is not numerical. It is MET if all 15 requirements are fully implemented and NOT MET if any are not.
  • The maximum for Level 2 is 110, indicating full compliance with the 110 NIST SP 800-171 requirements. A score of 88 to 109 supports a Conditional Level 2 status.
  • The maximum for Level 3 is 24. At least 20 of 24 requirements, or 80%, is the minimum for a Conditional Level 3 status. Organizations must achieve 110 and Final Level 2 status to be eligible for Level 3.

How do you calculate your SPRS score?

For Level 2, you calculate it from your implementation of the 110 NIST SP 800-171 requirements. Each requirement is weighted at 1, 3, or 5 points based on the risk if it is not implemented. You start at a baseline of ‑203 and gain points for each requirement marked MET. The final score ranges from ‑203 to 110, with 110 indicating full compliance.

What is a good SPRS score?

110 is the maximum for Level 2 and 24 for Level 3. A lower score can be acceptable if unmet requirements are documented in a POA&M with remediation plans, and POA&M items are closed within 180 days of the conditional status date. A higher score positions you better for award, since the Department and primes both use it to gauge risk.

How often do I need to update my SPRS score?

Level 1 self-assessments are annual. Level 2 assessments are triennial with an annual affirmation. Beyond that cadence, update your score whenever your environment changes materially enough to affect it. A score that no longer reflects your posture is the pattern behind most of the False Claims Act settlements in this space.

What happens if my SPRS score is inaccurate?

An inaccurate score is a representation to the government. If a government assessment later finds a materially different posture, the gap can support False Claims Act liability. In June 2026, LOGZONE, Inc. agreed to pay $507,144 to resolve allegations after reporting a score of 110 that a DIBCAC assessment scored at ‑170. That case originated from a government assessment rather than a whistleblower.

What CMMC Status Types could you see after submitting your self-assessment in SPRS?

  • CMMC L2 Final Self-Assessment: Compliance with all 110 Level 2 requirements.
  • CMMC L2 Conditional Self-Assessment: Compliance with 88 to 109 requirements.
  • Final Level 1 Self-Assessment: Compliance with Level 1 requirements.
  • Pending Affirmation: Awaiting AO approval.
  • Incomplete: Assessment information only partially completed.
  • No CMMC Status: Your previous self-assessment report has expired.

Anna Fitzgerald

Senior Content Marketing Manager

Anna Fitzgerald is a digital and product marketing professional with nearly a decade of experience delivering high-quality content across highly regulated and technical industries, including healthcare, web development, and cybersecurity compliance. At Secureframe, she specializes in translating complex regulatory frameworks—such as CMMC, FedRAMP, NIST, and SOC 2—into practical resources that help organizations of all sizes and maturity levels meet evolving compliance requirements and improve their overall risk management strategy.

Rob Gutierrez

Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP

Rob Gutierrez is an information security leader with nearly a decade of experience in GRC, IT audit, cybersecurity, FedRAMP, cloud, and supply chain assessments. As a former auditor and security consultant, Rob performed and managed CMMC, FedRAMP, FISMA, and other security and regulatory audits. At Secureframe, he’s helped hundreds of customers achieve compliance with federal and commercial frameworks, including NIST 800-171, NIST 800-53, FedRAMP, CMMC, SOC 2, and ISO 27001.