How Your SPRS Score Is Calculated: the 110-Point Math

Published October 5, 2026

A CMMC Level 2 self-assessment score is simple arithmetic once you know the rules. You start at 110, one point for each of the 110 NIST SP 800-171 Rev 2 requirements, and subtract a fixed value for every requirement that is not met. The values are 5, 3 or 1. The result is the number that goes into SPRS, the Supplier Performance Risk System.

Start at 110

The maximum score equals the total number of Level 2 security requirements. If every requirement is met, you get the maximum. For each requirement not met, its value is subtracted, "which may result in a negative score." (Source: 32 CFR 170.24, CMMC scoring methodology, (c)(2).) There is no partial credit for a requirement that is half done, with two exceptions covered below. (Source: 32 CFR 170.24, CMMC scoring methodology, (a) and (c)(2)(i)(B)(4).) A POA&M does not change this: a requirement that is not implemented is scored NOT MET whether or not it is on a POA&M. (Source: 32 CFR 170.24, CMMC scoring methodology, (c)(2)(i)(B)(6).)

The 5, 3 and 1 point weights

The rule lists the 5-point and 3-point requirements by number. Every other derived requirement is worth 1. (Source: 32 CFR 170.24, CMMC scoring methodology, (c)(2)(i)(B)(1) to (3).)

ValueWhyRequirements
5 pointsIf not implemented, could lead to significant exploitation of the network or exfiltration of CUI.Basic: 3.1.1, 3.1.2, 3.2.1, 3.2.2, 3.3.1, 3.4.1, 3.4.2, 3.5.1, 3.5.2, 3.6.1, 3.6.2, 3.7.2, 3.8.3, 3.9.2, 3.10.1, 3.10.2, 3.12.1, 3.12.3, 3.13.1, 3.13.2, 3.14.1, 3.14.2, 3.14.3. Derived: 3.1.12, 3.1.13, 3.1.16, 3.1.17, 3.1.18, 3.3.5, 3.4.5, 3.4.6, 3.4.7, 3.4.8, 3.5.10, 3.7.5, 3.8.7, 3.11.2, 3.13.5, 3.13.6, 3.13.15, 3.14.4, 3.14.6.
3 pointsIf not implemented, has a specific and confined effect on the security of the network and its data.Basic: 3.3.2, 3.7.1, 3.8.1, 3.8.2, 3.9.1, 3.11.1, 3.12.2. Derived: 3.1.5, 3.1.19, 3.7.4, 3.8.8, 3.13.8, 3.14.5, 3.14.7.
1 pointIf not implemented, has a limited or indirect effect on the security of the network and its data.All remaining derived requirements.
3 or 5 pointsCan be partially effective.3.5.3 (multifactor authentication) and 3.13.11 (FIPS-validated encryption).

That is 42 requirements at 5 points and 14 at 3 points, counted from the lists in the rule.

Partial credit: MFA and encryption

Only two requirements can score in between: (Source: 32 CFR 170.24, CMMC scoring methodology, (c)(2)(i)(B)(4).)

  • 3.5.3, multifactor authentication. Subtract 3 if MFA is implemented only for remote and privileged users. Subtract 5 if it is not implemented for any users.
  • 3.13.11, FIPS-validated encryption of CUI. Subtract 3 if encryption is used but is not FIPS-validated. Subtract 5 if encryption is not used.

N/A counts as met

A requirement or objective can be Not Applicable when it does not apply at the time of the assessment. The rule's example is 3.13.5, public-access system separation, which might be N/A if there are no publicly accessible systems in scope. An objective assessed as N/A "is equivalent to the same assessment objective being assessed as MET," so it costs no points. (Source: 32 CFR 170.24, CMMC scoring methodology, (b)(3).) Two other things also score as met: enduring exceptions described in the system security plan with their mitigations, and temporary deficiencies addressed in operational plans of action that show progress. (Source: 32 CFR 170.24, CMMC scoring methodology, (b)(1)(i) and (ii).) A requirement for which the DoD CIO has adjudicated an alternative measure as equally effective is met if the environment has not changed, provided the adjudication is in the SSP. (Source: 32 CFR 170.24, CMMC scoring methodology, (c)(2)(i)(B)(8).)

The SSP is not a deduction

CA.L2-3.12.4, the system security plan, does not appear in any of the point lists. Instead, you must have an SSP at the time of the assessment, and without an up to date one the result is that the assessment could not be completed. (Source: 32 CFR 170.24, CMMC scoring methodology, (c)(2)(i)(B)(5).) No SSP means no score, not a lower score.

The floor: -203

The rule does not print a minimum, but the lists fix it. If nothing is met: 42 requirements at 5 points is 210, the two partial-credit requirements at their full 5 points is 10, 14 requirements at 3 points is 42, and the remaining 51 requirements at 1 point is 51 (110 requirements, less 42, 14, the two partial ones and the SSP). That is 313 points of deductions, and 110 minus 313 is -203. It is the arithmetic of the lists in 170.24, not a separate rule. (Source: 32 CFR 170.24, CMMC scoring methodology, (c)(2)(i)(B).)

A worked example

Suppose a self-assessment finds four gaps, with everything else met or N/A:

Requirement not metValue in 170.24Running score
Start110
3.1.1, limit system access to authorized users5105
3.3.2, trace actions to individual users3102
3.1.8, limit unsuccessful logon attempts1 (a remaining derived requirement)101
3.5.3, MFA in place for remote and privileged users only3 (partial)98

The score to post is 98 out of 110. Whether a score like this can carry a POA&M is a separate question with its own rules: here it cannot, because 3.1.1, 3.3.2 and the partial 3.5.3 are each worth more than 1 point. (Source: 32 CFR 170.21, plan of action and milestones requirements, (a)(2)(ii).) See the POA&M rules.

What goes into SPRS with the score

The self-assessment results in SPRS must include at least the CMMC level, the CMMC Status Date, the assessment scope, every CAGE code tied to the systems in scope, the overall score (the rule's example is "105 out of 110"), and POA&M usage and compliance status if there is one. (Source: 32 CFR 170.16, CMMC Level 2 self-assessment and affirmation requirements, (a)(1)(i).) An affirmation is required at the time of each assessment and annually after that, and the self-assessment is repeated every three years. (Source: 32 CFR 170.16, CMMC Level 2 self-assessment and affirmation requirements, (a)(1) and (a)(2).)

Check the score before it goes into SPRS. The CMMC Self-Assessment Score Validator recomputes a Level 2 score from your per-requirement results with the 32 CFR 170.24 point values, flags a claimed score that does not match, checks POA&M eligibility against 170.21, and checks the SPRS details and the annual affirmation. $25.00 per completed verification, with free sample runs on the page. Verify a score

A matching score is not a CMMC assessment and not a guarantee of contract eligibility. It is not legal advice.

Related

Sources

Read October 5, 2026. SpreadRun is not affiliated with or endorsed by the Department of Defense. This is general information, not legal advice. Where this page and the law differ, the law controls.