Skip to main content
Guide

How to Improve an SPRS Score: Risk-Based Prioritization Strategies

A planning guide to SPRS deductions, requirement prioritization, implementation validation, and remediation sequencing without a promised timeline or result.

CMMC Command Team
Compliance Engineering
Feb 20, 20268 min read
Table of Contents(16 sections)

Your SPRS Score Is Negative. Now What?

A negative estimated SPRS score indicates that the entered NOT MET requirements produce deductions greater than the 110-point starting value. It is not evidence of how peer contractors score and does not by itself determine CMMC status.

The Weight-Based Prioritization Strategy

The DoD Assessment Methodology assigns deductions of 1, 3, or 5 points. Use score impact as one prioritization input alongside security risk, dependencies, contractual obligations, POA&M eligibility, and implementation validation.

The Impact Matrix

Plot your unimplemented controls on two axes: DOD weight (impact on score) and implementation difficulty (time/cost to implement).

PriorityWeightDifficultyAction
1 (Review First)5LowValidate implementation and dependencies
2 (Prioritize)5MediumAssign an owner and justified target date
3 (Plan For)5HighScope the work and budget
4 (Batch)3LowBatch together for efficiency
5 (Schedule)3Medium-HighScheduled remediation
6 (Last)1AnyAddress after higher weights

Candidate High-Impact Requirements

Implementation effort varies by environment. Validate each requirement and all applicable assessment objectives before estimating effort or score impact.

3.5.3 Use multifactor authentication (Weight 5) MFA capabilities may already exist in the identity environment, but coverage, privileged access, remote access, authenticator strength, exceptions, and evidence still require validation.

3.1.1 Limit system access to authorized users (Weight 5) Review your user accounts. Remove inactive accounts. Document who has access to what. This is often already partially done.

3.1.2 Limit system access to transaction types (Weight 5) Implement role-based access control. Users should only have permissions for their job function.

3.13.8 Implement cryptographic mechanisms for CUI in transit (Weight 5) Select and validate cryptographic mechanisms appropriate to the CUI data flows and applicable requirements; a generic "enable HTTPS" statement is not sufficient.

3.14.2 Provide protection from malicious code (Weight 5) Validate malicious-code protection coverage, configuration, updates, scans, and evidence across the assessed environment.

Medium Effort, High Impact (Weight 5)

3.3.1 Create and retain system audit logs (Weight 5) Enable and retain the required audit records across the assessed environment. Establish the implementation target from architecture, retention, integration, staffing, and validation dependencies.

3.4.1 Establish and maintain baseline configurations (Weight 5) Document your current system configurations. This is labor-intensive but straightforward.

3.13.1 Monitor communications at external boundaries (Weight 5) Deploy or configure boundary firewalls with logging. Many organizations have firewalls but aren't monitoring them effectively.

An Illustrative Improvement Sequence

This is not a promised 60-day plan or score gain. Use it only as a sequencing example after validating scope and current implementation.

Baseline Assessment and Authentication Review

  • Complete full 110-control assessment
  • Validate MFA coverage against the assessed environment and applicable requirements
  • Review high-impact requirements alongside security risk and implementation dependencies
  • Document existing controls that are implemented but not documented

Access Control Review

  • Audit all user accounts and remove unused accounts
  • Implement RBAC with documented access matrices
  • Configure session timeouts and lockouts
  • Document remote access procedures

Logging and Monitoring

  • Enable audit logging on all CUI systems
  • Configure log retention based on contractual, operational, and assessment needs
  • Set up basic log review process
  • Enable endpoint protection reporting

Documentation and Evidence Review

  • Generate a structured SSP draft from your preparation platform for owner and qualified review
  • Create the policies and procedures needed to describe and govern the organization’s actual implementation
  • Build POA&M for remaining gaps
  • Collect evidence for implemented controls

SPRS improvement depends on which requirements are actually implemented and assessed as MET. Documentation by itself does not earn points for an unmet technical or procedural requirement.

The POA&M Strategy

For requirements that are not yet implemented, create POA&M entries when permitted and appropriate. A POA&M documents remediation, but the requirement remains NOT MET and is deducted from the SPRS score.

POA&M entries require careful owner and qualified review. A practical planning entry includes:

  • Specific finding description
  • Remediation milestones with dates
  • Responsible party
  • Resource requirements
  • Realistic target completion date

Common Score Killers

1. Ignoring Access Control

AC has 22 requirements, more than any other Rev 2 family, and includes multiple five-point deductions. Calculate the exact score effect from the requirements assessed NOT MET rather than assigning a generic family penalty.

2. No Audit Logging

The AU family is weight-5 heavy. If you're not logging, you're hemorrhaging points.

3. Treating Documentation as Optional

Implementation, the SSP, and assessment evidence must be consistent. Missing or inaccurate documentation can prevent a reviewer from validating a MET result, but the applicable objectives and examine, interview, and test evidence determine the result; documentation alone is not the implementation.

Tracking Your Progress

Your SPRS score should be a living metric that updates as you implement controls. Use a platform that:

  • Estimates your score from entered statuses using published DoD assessment weights
  • Shows trending over time
  • Identifies which controls will have the most score impact
  • Supports review and export of the underlying data before any required manual submission

Estimate your SPRS score now. Free, based on entered statuses and published DoD assessment weights, with an impact simulator.

SPRSScore ImprovementPrioritizationImplementation Planning

Organize your CMMC preparation

Review all 110 requirements and see an estimated SPRS score based on the statuses you enter. Completion time varies. Free, no credit card.