CMMC SPRS Score Calculator
Work through the 110 NIST 800-171 Rev 2 controls and get a live SPRS score against the DoD Assessment Methodology. Mark each control met, not met, partial (where allowed), or N/A. The score, the POA&M-eligible split, and conditional-certification eligibility update as you go. Everything stays on this device — nothing is submitted to SPRS or to us.
110 controls unassessed. If those turn out not implemented, the score drops to -208.
- 3.1.15 ptAuthorized Access Control
- 3.1.25 ptTransaction & Function Control
- 3.1.31 ptCUI Flow Control
- 3.1.41 ptSeparation of Duties
- 3.1.53 ptLeast Privilege
- 3.1.61 ptNon-Privileged Account Use
- 3.1.71 ptPrivileged Function Execution
- 3.1.81 ptUnsuccessful Logon Attempts
- 3.1.91 ptPrivacy & Security Notices
- 3.1.101 ptSession Lock
- 3.1.111 ptSession Termination
- 3.1.125 ptRemote Access Control
- 3.1.135 ptRemote Access Encryption
- 3.1.141 ptManaged Remote Access Routing
- 3.1.151 ptRemote Privileged Commands
- 3.1.165 ptWireless Access Authorization
- 3.1.175 ptWireless Access Protection
- 3.1.185 ptMobile Device Connection
- 3.1.193 ptMobile Device CUI Encryption
- 3.1.201 ptExternal System Connections
- 3.1.211 ptPortable Storage on External Systems
- 3.1.221 ptPublicly Accessible Content
Scores and POA&M eligibility are practitioner estimates per the DoD Assessment Methodology and CMMC scoping rules. Final scoring is determined by your self-assessment and, for Level 2, a C3PAO. This calculator is a planning aid, not a substitute for an assessment, and submits nothing to SPRS. For help getting to a defensible score, see our CMMC practice.
A sub-threshold score with must-fix gaps blocks certification. We close exactly those gaps — and build the SSP and POA&M that hold up to a C3PAO.