SPRS Score & POA&M Report
Globe-America Consulting · NIST SP 800-171 Rev 2 DoD Assessment Methodology
This calculator generates a DFARS 252.204-7019 / 7020 Basic Assessment score. Under CMMC 2.0, that score is required in SPRS for every contractor handling CUI — but the majority of L2 contracts require a C3PAO-conducted certification assessment, not just self-assessment. Verify your required path in your contract or DD-254 before submitting. POA&M caveats: controls weighted at 5 points are generally NOT POA&M-eligible and must be fully met; POA&M items must be closed within 180 days for conditional certification. Annual senior official affirmation is also required in SPRS regardless of which path applies.
Generated from your control responses using DoD Assessment Methodology v1.2.1. Review carefully before submitting to SPRS. Inaccurate scores may expose your organization to False Claims Act liability. After reviewing, switch to the POA&M Builder tab to document remediation plans for all gaps.
| Domain | Implemented | Not Implemented | N/A | Points Deducted | Domain Health |
|---|
Ensure Your SSP is Current
Your System Security Plan must be complete and accurately reflect how your organization implements each of the 110 controls before you submit.
Document POA&Ms for All Gaps
Switch to the POA&M Builder tab to complete your Plan of Action & Milestones. Required for every unimplemented control per NIST 800-171 requirement 3.12.2.
Access the PIEE Portal
Go to piee.eb.mil, log in with your credentials, navigate to SPRS, and select the Cyber vendor role.
Submit Your Assessment
Enter your summary score, NIST SP 800-171 Rev 2 standard version, CAGE code(s), assessment date, and expected full compliance date. Score is valid for 3 years per DFARS 7019, but CMMC 2.0 requires an annual senior official affirmation in SPRS regardless.
Work Your POA&M and Reassess
As you implement controls, update your score in SPRS. Globe-America assists with POA&M management and quarterly score reviews.
Switch to the SPRS Score Calculator tab and mark any controls as Not Implemented or Partial. Your POA&M will auto-populate from those responses.