---
title: "What Is SPRS? CMMC Definition"
description: "SPRS is the DoD system where contractors post their NIST 800-171 self-assessment score and, under CMMC, their certification status and affirmations."
url: https://policycortex.com/cmmc/glossary/sprs
sealed: 2026-07-02
amended: 2026-07-13
register: cmmc/glossary/sprs
records: 3
digest: sha3:0f3d869a4c3473f08e854b0d4411c9a6a33c26230241109139ba3befd3c032c3
---

# What is SPRS?

Register / Glossary

SPRS is the DoD system where contractors post their NIST 800-171 self-assessment score and, under CMMC, their certification status and affirmations.

Sealed 2026-07-02 · Amended 2026-07-13

SPRS stands for Supplier Performance Risk System.

The Supplier Performance Risk System (SPRS) is the government database contracting officers check to confirm a contractor's cybersecurity posture. A NIST 800-171 self-assessment score has been required in SPRS since DFARS 252.204-7019/7020 took effect in November 2020.

Under CMMC, SPRS also holds certification status and affirmations. The planned November 10, 2026 Phase II transition was suspended on July 13, 2026; Phase I self-assessment requirements remain in place during the reform review.

A SPRS score is a signed federal representation. The 2026 LOGZONE False Claims Act settlement — a self-reported 110 against a DIBCAC-assessed −170 — established that an inflated SPRS score can be treated as fraud, even without a breach.

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

### Related terms and reading

| Entry |
|---|
| [NIST SP 800-171](https://policycortex.com/cmmc/glossary/nist-800-171): NIST SP 800-171 is the federal standard of 110 security controls for protecting CUI in non-federal systems: the technical basis of CMMC Level 2. |
| [POA&M: Plan of Action and Milestones](https://policycortex.com/cmmc/glossary/poam): A POA&M is a tracked plan for remediating security controls that are not yet fully implemented, with owners and target dates. |
| [DFARS 252.204-7012](https://policycortex.com/cmmc/glossary/dfars-7012): DFARS 7012 is the long-standing clause requiring contractors to safeguard covered defense information per NIST 800-171 and report cyber incidents within 72 hours. |
| [The $507K LOGZONE Settlement: SPRS Score Liability](https://policycortex.com/blog/logzone-false-claims-act-sprs-score) |

Know the term. Then see the record behind it. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Dates of record

- **Sealed**: 2026-07-02
- **Last amended**: 2026-07-13
- **Record**: https://policycortex.com/cmmc/glossary/sprs

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | 544ce54b8a0f | e2e50b3d548e |
| REC 0001 | DEFINITION | 530a9ded7a79 | 544ce54b8a0f |
| REC 0002 | RELATED RECORDS | 0f3d869a4c34 | 530a9ded7a79 |

Head sha3:0f3d869a4c3473f08e854b0d4411c9a6a33c26230241109139ba3befd3c032c3. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
