Supplier Performance Risk System (SPRS)
SPRS is the DoD's authoritative database for supplier performance and risk information. For cybersecurity, SPRS is where NIST SP 800-171 self-assessment scores live. Contracting officers look at these scores when evaluating proposals. A low score can lose you the award. A knowingly inflated score can land you in False Claims Act litigation. Scores are submitted through the PIEE portal.
- glossary
- What SPRS Stores
What SPRS Stores
- NIST SP 800-171 Basic Assessment scores, from -203 to 110.
- Assessment date and the expected date to reach a score of 110.
- CMMC Level 1 self-assessment affirmations.
- DIBCAC Medium and High assessment results.
- Supplier quality and delivery performance metrics.
- Counterfeit part reports and other supply chain indicators.
How Scores Get Calculated
The DoD Assessment Methodology (Version 1.2.1) drives scoring. You start at 110. Each of the 110 NIST 800-171 requirements deducts 1, 3, or 5 points if not fully implemented, depending on security impact. Partial credit applies in a limited set of cases. The math can push you below zero, down to -203, if enough high-weight controls are missing.
Submitting Your Score
Access SPRS through PIEE (piee.eb.mil). Authorized company representatives (typically someone with the Contractor Approver role) enter the score along with assessment date and scope. You need to submit before a contract with DFARS 252.204-7019 is awarded. DIBCAC-conducted Medium or High assessments update your SPRS record directly without contractor action.
Score Maintenance
Scores expire after three years. Re-assess earlier if you've remediated significant gaps or made major environment changes. Holding an outdated low score while actively improving doesn't help you win contracts. Update the score when you can credibly claim improvement and have the evidence to back it up.
Who Sees Your Score
Contracting officers across DoD have SPRS access. Prime contractors can request SPRS data for their subcontractors (with the subcontractor's consent in some cases). The score is not fully public, but assume any DoD procurement professional evaluating your company can see it.
Inflated Scores and the Civil Cyber-Fraud Initiative
The DOJ's Civil Cyber-Fraud Initiative, launched October 2021, targets contractors who misrepresent cybersecurity compliance. SPRS score inflation is a prime target. Settlements have ranged from $300k to $11.3M, often triggered by whistleblower qui tam actions. The DOJ doesn't need to prove a breach happened; it only needs to prove that the score or attestation was false when submitted.