Every defense contractor handling Controlled Unclassified Information has, somewhere in the Supplier Performance Risk System (SPRS), a number between -203 and 110. Most executives couldn't tell you what theirs is. Fewer could tell you how it was calculated. And almost none have considered what that number actually is from a legal standpoint: a representation to the United States government that the Department of Justice can — and does — test against reality.
In this post, we'll walk through how the scoring methodology actually works, the mistakes we see most often when we re-score environments, and what it takes to submit a number you'd be comfortable defending.
How the NIST 800-171 Scoring Methodology Works
The DoD Assessment Methodology starts every organization at a perfect 110 — one point available for each NIST SP 800-171 control — and subtracts points for every control not fully implemented. But the subtraction isn't uniform:
- 5-point deductions: The controls DoD considers most critical — things like multifactor authentication, FIPS-validated encryption, and system boundary protections. Miss a handful of these and your score falls fast.
- 3-point deductions: Significant controls whose absence materially weakens your posture.
- 1-point deductions: The remainder — still required, but weighted lower.
Because of the weighting, two contractors can each be "missing ten controls" and sit forty points apart. The floor is -203, and yes, real environments score negative on first assessment more often than anyone likes to admit.
Key Takeaway: "Partially implemented" scores the same as "not implemented." The methodology is binary per control — you either meet the full requirement, including documentation, or you take the deduction.
Where DFARS 7019 and 7020 Come In
DFARS 252.204-7019 requires you to have a current NIST 800-171 self-assessment score (no more than three years old) posted in SPRS to be considered for award. DFARS 252.204-7020 requires you to give the government access to your facilities and records to verify that score through a higher-level assessment — and to flow the requirement down to subcontractors handling CUI.
Read those two clauses together and the picture is clear: the score isn't a formality to unlock bidding. It's a standing claim the government reserves the right to audit, with contract remedies and legal exposure attached if the claim doesn't hold.
The False Claims Act Dimension
The Department of Justice's Civil Cyber-Fraud Initiative exists specifically to pursue contractors who misrepresent their cybersecurity posture. Settlements to date have involved companies that certified compliance they didn't have — and whistleblower provisions mean the person who reports an inflated score often works in your own IT department.
An honest low score is a compliance posture with a plan. An inflated high score is a liability sitting in a federal database with an executive's name attached. If your score was produced by optimistic self-grading — "we mostly do that" counted as done — it's the second kind.
The Five Scoring Mistakes We See Most
1. Counting policy as implementation
A written policy requiring MFA is not MFA. Assessors — government or third-party — test what's actually enforced, on every in-scope system, including the legacy server everyone forgot.
2. Ignoring the documentation half of the control
Many controls are two-part: do the thing, and document the thing. A firewall configured correctly with no documented baseline still fails.
3. Scoping too narrowly
If CUI touches a laptop, a file share, or a cloud tenant, that asset is in scope. Contractors routinely score only their "main" environment and miss half their actual boundary.
4. Treating POA&Ms as credit
A Plan of Action and Milestones documents a gap — it doesn't close one. Controls on a POA&M still take their full deduction until remediated.
5. Letting the score age
Environments drift. A 100 scored two years ago, before a merger, a cloud migration, and staff turnover, may describe a company that no longer exists.
Making Your Score Defensible
A defensible score has three properties:
- It was produced against the assessment methodology, control by control, objective by objective — not by gut feel.
- Every point is backed by evidence you could hand an assessor tomorrow: configurations, screenshots, policies, logs.
- It's current — re-validated after significant changes to systems, people, or scope.
That's precisely what a properly run gap assessment produces: a score you can submit with your executive's signature on it and sleep that night. Whatever direction CMMC enforcement takes, the self-assessment obligation is already in your contracts today — and it's the foundation everything else gets built on.