Your SPRS Score Is Not Your CMMC Readiness
By Christina Sentry · 2026-07-02
A high self-assessment score feels safe until a C3PAO starts asking for evidence. Here is why scores inflate and how to pressure test yours before it counts.
A high self-assessment score feels safe until a C3PAO starts asking for evidence. Contractors who submitted confident SPRS scores in 2023 and 2024 are now discovering — during readiness assessments or actual CMMC audits — that their scores reflected optimism more than implementation.
This gap between self-reported score and actual readiness is one of the most consistent patterns we see in pre-assessment work. Understanding why it happens, and how to test your own score before it matters, is the difference between a smooth C3PAO engagement and an expensive remediation sprint.
What the SPRS Score Actually Measures
The Supplier Performance Risk System (SPRS) score is a self-assessment of your organization's implementation of NIST SP 800-171. You score each of the 110 practices as implemented (0 point deduction), not implemented, or partially implemented — with partial and non-implementation carrying specific point deductions that reduce from a maximum score of 110.
The critical word is self-assessment. The score is calculated by you, submitted by you, and stored in SPRS with no third-party verification. Until CMMC Level 2 certification becomes contractually required, your contracting officer has no independent way to verify whether a score of 88 reflects 88 points' worth of implemented controls or 88 points' worth of good intentions.
Why Scores Inflate
Aspirational scoring is the most common driver. A contractor reviews a practice, recognizes that they're working toward it — a policy is drafted, a tool is being configured — and scores it as implemented. The NIST assessment guide is clear: a practice is implemented when it is fully operational and producing the expected security outcome, not when it is in progress. "We have a policy that says we do this" is not the same as "we do this."
Misunderstanding scope compounds the problem. A contractor may correctly implement a control in their primary office but fail to apply it to remote workers, a second facility, or a cloud environment where CUI also lives. The control gets marked implemented because it's implemented somewhere, when CMMC requires it to be implemented across the entire assessment scope.
Evidence decay is a subtler issue. A contractor implements a control correctly, scores it accordingly, and then infrastructure changes — a cloud migration, a staff departure, a software update — leave the control no longer functioning as documented. The SPRS score isn't updated because no one noticed the control broke. By the time a C3PAO arrives, the evidence doesn't match the score.
"Organizational" controls scored without records is common in the Awareness and Training and Risk Assessment families. A contractor knows they do security training, so they score the AT practices as implemented. But when an assessor asks for training completion records for the past twelve months, the records don't exist or are incomplete. Knowing you do something and being able to demonstrate that you do it are two different things under CMMC.
The Gap in Practice
We routinely see contractors with self-submitted SPRS scores in the 90–105 range enter readiness assessments and discover actual scores in the 60–80 range. The practices most commonly overstated:
- AC.1.001 and AC.1.002 (access control to CUI): Often scored implemented based on having Active Directory or an identity provider, without evaluating whether CUI-bearing systems are actually restricted and whether user access is reviewed periodically.
- AT.2.056 and AT.2.057 (security awareness training): Scored based on having done training at some point, without records to demonstrate recency or completion for all in-scope personnel.
- CM.2.061 through CM.2.064 (configuration management): Scored based on having a configuration policy, without evidence of a maintained baseline or documented change approval process.
- IR.2.092 and IR.2.093 (incident response): Scored based on having an incident response plan, without evidence the plan has been tested or that staff know how to execute it.
How to Pressure-Test Your Score
Before your C3PAO engagement — ideally 60–90 days before — conduct a rigorous internal review using the CMMC Assessment Guide (CAG), not just your SSP. The CAG specifies the objective evidence an assessor will look for per practice. For each practice you've scored as implemented, ask:
Can I produce the specific evidence the CAG identifies for this practice? If the CAG asks for access control lists, system-generated reports, or configuration screenshots, do those artifacts exist and reflect current configuration?
Does the evidence cover the full scope of my assessment boundary? A control implemented at headquarters but not at a satellite office, or in your on-premises environment but not in your cloud tenant, is a partial implementation.
Is the evidence dated within a reasonable operational window? Evidence of training from 18 months ago doesn't demonstrate a current, sustained training program.
Would someone unfamiliar with my organization understand what they're looking at? Assessors encounter dozens of organizations. Clear, labeled, organized evidence packages score better than accurate-but-opaque ones.
For practices where you can't produce clean evidence, reclassify the practice on your internal scoring sheet. The resulting number is your real readiness score — and it's the number you should be working toward before submitting to SPRS again.
What a Realistic Score Means for Your Timeline
If your internal pressure test reveals a significant gap — say, a score of 70 when you submitted 95 — don't panic, but do move quickly. A score in the 70s typically requires 90–120 days of focused remediation before a C3PAO assessment. Most of that time is spent building evidence: implementing controls is often faster than creating the documentation and records that prove they're implemented.
The contractors who struggle most are those who discover the gap two weeks before an assessment that's already scheduled with a C3PAO. At that point, your options are to proceed and accept a lower score, or reschedule at significant cost. Neither is good.
The contractors who succeed are those who treat the SPRS score as a hypothesis to be tested, not a conclusion to be submitted. Run the pressure test early. Fix what you find. Then submit a score that will hold up when it counts.
If you'd like an independent assessment of your SPRS score's accuracy, Cipher Sentinel's gap assessment service is designed exactly for this situation — evaluating your current implementation against CMMC requirements and giving you a realistic readiness picture before your C3PAO engagement begins.