Free quick reference + estimator · no signup
SPRS Score Calculator
This SPRS score calculator is free and ungated — no signup — and built on the DoD Assessment Methodology v1.2.1. Start at 110, check off each unimplemented NIST SP 800-171 requirement, and watch your score update; the partial-credit rules for 3.5.3 (MFA) and 3.13.11 (CUI encryption) are applied automatically. Scores run from 110 to a floor of −203 across 109 scored requirements.
Estimate your score in two minutes
Everything starts as implemented (110). Check each requirement you have not implemented and watch the deductions land. These are the actual Annex A point values from the DoD Assessment Methodology, family by family.
AC · Access Control22 requirements
AT · Awareness and Training3 requirements
AU · Audit and Accountability9 requirements
CM · Configuration Management9 requirements
IA · Identification and Authentication11 requirements
IR · Incident Response3 requirements
MA · Maintenance6 requirements
MP · Media Protection9 requirements
PS · Personnel Security2 requirements
PE · Physical Protection6 requirements
RA · Risk Assessment3 requirements
CA · Security Assessment4 requirements
SC · System and Communications Protection16 requirements
SI · System and Information Integrity7 requirements
At or above the 88-point conditional threshold. Conditional status also requires every open gap to be POA&M-eligible, which this quick estimator doesn't check.
Partial credit: the only two exceptions
Only two requirements earn a reduced deduction under the DoD methodology:
- 3.5.3 (multifactor authentication): deduct 3 instead of 5 when MFA covers remote access and privileged accounts but not yet general users.
- 3.13.11 (CUI encryption): deduct 3 instead of 5 when encryption is deployed but not FIPS-validated.
Everything else is all-or-nothing: "partially implemented" takes the full deduction. This estimator treats every checked item as a full deduction; the full assessment captures both partial-credit cases.
The 3.12.4 gate: unscored, but existential
The System Security Plan requirement (3.12.4) carries no point value because it's more serious than points: without a current SSP, no CMMC assessment can be completed at all, and 3.12.4 may never sit on a POA&M. A 110 without an SSP is a number you can't take to an assessor. If your SSP is the gap, start there: the full assessment drafts one from your answers.
The 88-point conditional threshold
CMMC Level 2 allows conditional status when an assessment scores at least 88 of 110 and every open gap is POA&M-eligible. That generally means the 1-point items, with 3.13.11 allowed only in its 3-point partial case, and six requirements never eligible at all (3.1.20, 3.1.22, 3.12.4, 3.10.3, 3.10.4, 3.10.5). Open POA&M items must close within 180 daysof the conditional status date or the status lapses (32 CFR 170.21). A score of 88 with the wrong kind of gap still fails, which is why the full assessment classifies every gap as POA&M-eligible or must-fix.
Wondering what closing those gaps costs? The price bands for self-serve, consultant-led, and enclave routes, plus the separate C3PAO fee, are in the CMMC Level 2 cost guide.
Minimum SPRS score for CMMC Level 2
The minimum SPRS score for CMMC Level 2 conditional certification is 88 of 110. To receive a Conditional status, every open gap must also be POA&M-eligible — generally 1-point items only (see the six requirements that are never eligible). All POA&M items must close within 180 days of the conditional status date (32 CFR 170.21). There is no separate minimum score just to post a self-assessment and bid — that requires a current, honest assessment, not a particular number.
The full eligibility rules — the never-eligible six, the 3.13.11 exception, and the 180-day clock — are in the POA&M template guide.
Stop estimating. Know your number.
The free full assessment walks all 110 requirements, applies the partial-credit rules, separates POA&M-eligible gaps from must-fix gaps, and drafts the SSP that opens the assessment gate.
Get your free Muster Score