Skip to main content
Truvisory
Federal

SPRS Score Submission, Step by Step: Entering Your CMMC Level 1 Self-Assessment

Tony Adams11 min read

The SPRS entry is the step where a CMMC Level 1 self-assessment becomes real. Until your results are in SPRS and affirmed, you don’t have a CMMC status — you have a binder. And because the government’s own guides are screenshot-heavy PDFs that occasionally disagree with their own prose, this walkthrough sticks to the labels that actually appear on screen, verified against the SPRS Quick Entry Guide (V4.0) and the February 2025 SPRS/PIEE briefing.

One disambiguation first, because the phrase “SPRS score” means two different things and conflating them causes real confusion in proposal rooms.

Two records, one system: the 800-171 score vs. the CMMC Level 1 entry

SPRS Cyber Reports holds two things a defense contractor cares about:

The NIST SP 800-171 Basic Assessment score. Required by DFARS 252.204-7019/-7020 since November 2020, independent of CMMC. It’s a number produced under the DoD Assessment Methodology — perfect implementation of NIST SP 800-171 scores 110, and deductions for missing controls can push a score all the way down to −203. This is what people usually mean by “SPRS score,” and if your contracts carry the 7019/7020 clauses, it still has to be current no matter what happens with CMMC.

The CMMC assessment entry. New with the CMMC program rule. At Level 1 there is no score of any kind: 32 CFR § 170.15(a)(1) requires every one of the 15 CMMC Level 1 requirements — the safeguards of FAR 52.204-21 — to be MET, and SPRS asks you to attest that compliance as a literal Yes/No. Yes is required to achieve a “Final Level 1 Self-Assessment.”

The rest of this article is about the second record. (Worth noting for context: since the CMMC Phase II suspension of July 13, 2026, self-assessment entries — Level 1 (Self) and Level 2 (Self) — are the only CMMC postures a contracting officer may currently designate, which makes getting this entry right more consequential, not less.)

Before you start: the role chain

The prerequisite chain runs SAM → PIEE → SPRS, and it’s where most first-time submitters lose a week:

  1. SAM.gov — your entity registration is the root: UEI, CAGE code, and your CAGE hierarchy (which SPRS imports directly from SAM).
  2. PIEE — the Procurement Integrated Enterprise Environment at piee.eb.mil. Your company establishes a vendor group and designates a Contractor Administrator (CAM).
  3. The role — the CAM approves your request for the “SPRS Cyber Vendor User” role, which is what permits adding, editing, deleting, and affirming cyber assessments. The “SPRS Contractor/Vendor (Support Role)” is view-only — fine for the proposal team, useless for submission.

The diagnostic is blunt and reliable: if you’re in SPRS and the Add New CMMC Level 1 Self-Assessment button isn’t on your screen, you don’t have the Cyber Vendor User role. Fix the role; don’t hunt the menus.

The walkthrough

  1. Log in through PIEE and open Cyber Reports

    From the PIEE landing page (piee.eb.mil), click LOG IN, select SPRS, then select Cyber Reports. There is no separate SPRS login — PIEE is the front door.

  2. Select your hierarchy

    Choose the desired hierarchy, identified by the Highest Level Owner (HLO), from the drop-down. An asterisk next to an entry means you hold the SPRS Cyber Vendor User role for it — access to add, edit, and delete.

  3. Open the CMMC Assessments tab and add the assessment

    Within the CMMC Assessments tab, click Add New CMMC Level 1 Self-Assessment. (Both official guides’ screenshots agree on that button label, even where the Quick Entry Guide’s own prose transposes it.)

  4. Enter the assessment details

    Five fields do the work: the assessment date (the date the self-assessment was conducted — not necessarily today); the assessing scope (Enterprise or Enclave); the employee count — scoped to the organization the self-assessment applies to, not necessarily total headcount; the included CAGE code(s), comma-delimited if you’re entering more than one, with an Open CAGE Hierarchy picker (the hierarchy imports from SAM); and the Yes/No question — are you compliant with each of the security requirements specified in FAR clause 52.204-21? Yes is required to achieve a “Final Level 1 Self-Assessment.”

  5. Continue to Affirmation — or Transfer to AO

    Click Continue to Affirmation. If you are not the Affirming Official, enter the AO’s email and select Transfer to AO. The record sits at “Pending Affirmation” until the AO acts — and a pending record is not an eligible one.

  6. The Affirming Official affirms

    The AO — under 32 CFR § 170.22(a)(1), the senior level representative from within the Organization Seeking Assessment (OSA) who is responsible for ensuring compliance with the CMMC Program requirements and has the authority to affirm the OSA’s continuing compliance — opens the pending record, verifies their personal information and authority, optionally adds points of contact for contracting officers, checks the “I certify that I have read the above statement” box, and clicks Affirm. Read that affirmation statement before certifying: it warns that misrepresentation can bring criminal prosecution under 18 U.S.C. § 1001, civil liability under the False Claims Act, and contract remedies.

  7. Confirm the final record

    The affirmed record receives a CMMC Unique Identifier (UID) — the value you’ll be asked to quote — and the status becomes “Final Level 1 Self-Assessment.” That’s the SPRS UI label; the regulation names the same status “Final Level 1 (Self)” (32 CFR § 170.15(a)). It is also the only Level 1 status type visible to Government personnel.

Expiry, the annual cycle, and the six-year rule

Three dates govern the record after you close the browser tab:

One year out. In SPRS, a “Final Level 1 Self-Assessment” automatically becomes “No CMMC Status (Expired Assessment)” after 1 year. That flip is SPRS behavior — the rule behind it is 32 CFR § 170.15(a)(1)’s requirement for an annual self-assessment, with results submitted in SPRS, to maintain the status, paired with § 170.22’s annual affirmation. Either way, the operational consequence is identical: calendar the re-assessment, because the expired status is a visible row, not a quiet lapse.

Before award. Under 32 CFR § 170.15(b), eligibility takes both the Final Level 1 (Self) status and the submitted affirmation. Transfer-to-AO on proposal-due day is how contractors miss this one.

Six years back. 32 CFR § 170.15(c)(2) requires the artifacts used as assessment evidence to be retained for six years from the CMMC Status Date — which § 170.4 defines as the date the results are submitted to SPRS, not the affirmation date. Screenshots, exports, policies, logs: keep them, dated, where you can find them.

The part before SPRS

Everything above assumes the self-assessment itself is done honestly — 15 requirements, 59 assessment objectives, every finding MET or NOT APPLICABLE, evidence in final form. That’s the actual work, and it’s the part a Yes/No radio button can’t do for you. If you haven’t run it yet, our free CMMC Level 1 self-assessment tool walks you through every objective in plain language and generates the document package and SPRS-ready worksheet this walkthrough assumes you’re holding. And if your contracts involve CUI rather than just Federal Contract Information (FCI), the level you should be reading about is CMMC Level 2.

Frequently asked

What is an SPRS score?
Usually it means the NIST SP 800-171 Basic Assessment score required by DFARS 252.204-7019/-7020 — a number computed under the DoD Assessment Methodology, topping out at 110 with deductions that can drive it negative (the floor is −203). It is separate from a CMMC Level 1 entry, which records compliance as Yes/No with no numeric score at all. Both live in the same SPRS Cyber Reports module.
Is there a numeric score for CMMC Level 1?
No. A Level 1 self-assessment is all-or-nothing: every one of the 15 FAR 52.204-21 requirements must be MET (or NOT APPLICABLE, which counts as MET). In SPRS you answer a Yes/No question about FAR 52.204-21 compliance — Yes is required to achieve a "Final Level 1 Self-Assessment."
What role do I need to enter a CMMC assessment in SPRS?
The "SPRS Cyber Vendor User" role, requested through PIEE and approved by your company's Contractor Administrator. The view-only "SPRS Contractor/Vendor (Support Role)" cannot add, edit, or affirm assessments. The tell that you lack the role: the "Add New CMMC Level 1 Self-Assessment" button simply is not there.
How long is a CMMC Level 1 self-assessment good for?
In SPRS, a "Final Level 1 Self-Assessment" automatically becomes "No CMMC Status (Expired Assessment)" after 1 year. Behind that behavior sits the rule: 32 CFR § 170.15(a)(1) requires an annual self-assessment (with results submitted in SPRS) to maintain the Final Level 1 (Self) status, and § 170.22 requires an annual affirmation.
Who is the Affirming Official?
Under 32 CFR § 170.22(a)(1), the Affirming Official is the senior level representative from within each Organization Seeking Assessment (OSA) who is responsible for ensuring the OSA's compliance with the CMMC Program requirements and has the authority to affirm the OSA's continuing compliance with the specified security requirements. Every CMMC assessment needs one — Level 1 included.
Do I need both the SPRS entry and the affirmation before award?
Yes. Under 32 CFR § 170.15(b), eligibility for a contract carrying a Level 1 requirement takes both the Final Level 1 (Self) CMMC status and the affirmation submitted in SPRS. An entry sitting at "Pending Affirmation" does not qualify.
§ Field notes — monthly

One email a month. Not a vendor blog.

// Signing up gets you the AI pilot go/no-go checklist + one field-note a month — no drip, one-click unsub