NIST SP 800-171 · DoD Assessment Methodology · DFARS 252.204-7019 / 7020
All 110 requirements, scored exactly the way DoD scores them: start at 110, subtract 5, 3, or 1 for each requirement not met. The number updates as you go. Nothing leaves your browser until you ask for your results package.
For any company holding, or bidding on, a contract with DFARS 252.204-7012 in it — primes and subs alike — and for any business that wants to be measured against a real standard.
How DoD scores it
110 to start. Every requirement not implemented subtracts its value: 5 for the ones whose absence leaves the network exposed, 3 for partial exposure, 1 for the rest. Lowest possible score is −203.
Two partial credits only. MFA (3.5.3) covering privileged and remote users but not everyone: −3 instead of −5. Encryption in place but not FIPS-validated (3.13.11): −3 instead of −5. Nothing else is partial.
A plan is not a point. A requirement on a POA&M still deducts its full value until it is done. And with no system security plan (3.12.4) the methodology says the assessment cannot be completed at all.
Policy — a formal, approved, written policy says you do it. Approved means signed or otherwise adopted by someone who can bind the company.
Tested SOP — a written procedure implements the policy, and it has been run and shown to work, not just written.
Evidence — you can produce the logs, screenshots, tickets, or records that prove the procedure runs. A requirement is Met only when all three are yes. Anything less is the full deduction; the DoD methodology has no half-credit for good intentions.
Your result
Answer the requirements above. The score, the deductions that drive it, and your plan of action appear here.
Read this before anyone posts a score. A score in SPRS is a representation to the United States government about the state of your systems. Under 32 CFR Part 170 a senior official of the company affirms it, and affirms it again every year. A score that is knowingly wrong is a False Claims Act matter — for the company, and personally for the official who affirmed it. The Department of Justice's Civil Cyber-Fraud Initiative has already settled cases on exactly this: Aerojet Rocketdyne, Penn State, Georgia Tech.
The score above is self-reported and unvalidated. It is an input to that affirmation, not a substitute for it.
Every requirement scored Not met or Partial, ranked by what it costs you. Work it top-down; the five-pointers are also the ones an assessor checks first.
| Points | Req. | Requirement | Missing |
|---|
Assessment date, scope (system boundary / enclave), SSP date, and the date all requirements are expected to be implemented are what SPRS asks for alongside the score. Fill them from your SSP; do not post a score for a system that has no SSP.
Validated and signed is a different document. A Monadnock Cyber CISO reviews the evidence behind every one of the 110 requirements, corrects the score where the evidence does not support it, writes the POA&M with dates the company can defend, and signs an attestation that the evidence supports the score — on behalf of your affirming official, who still makes the affirmation. Fixed price, from $8,500, typically two working days on site or remote.
Jeff Stutzman · former CISO, Northrop Grumman Electronics Sector · Monadnock Cyber LLC, Amherst, New Hampshire · blackbook@monadnockcyber.ai · 1-888-299-6615