DFARS 252.204-7020: Assessment Levels, SPRS Scoring, and Flowdown

DFARS 252.204-7020 requires defense contractors that handle controlled unclassified information to score their systems against the 110 security requirements in NIST SP 800-171, post that score in a Department of Defense database, and keep it current before the DoD will award or renew a contract. The clause also obligates prime contractors to confirm that their subcontractors have done the same before any subcontract involving CUI is signed.1eCFR. 48 CFR 252.204-7020 – NIST SP 800-171 DoD Assessment Requirements The score you post is visible to every contracting officer evaluating your bids, and it is treated as a formal representation to the federal government.

When the Clause Applies to Your Contract

The clause is included in any DoD solicitation or contract where the contractor’s systems must comply with NIST SP 800-171 under the companion clause DFARS 252.204-7012.1eCFR. 48 CFR 252.204-7020 – NIST SP 800-171 DoD Assessment Requirements In practice, if the work touches CUI, expect the clause. That includes acquisitions for commercial products and services.

Two carve-outs exist. Solicitations solely for commercially available off-the-shelf items are excluded, and so are micro-purchases. COTS products are standardized goods sold in substantial quantities to the general public without modification, so they generally don’t involve the data exchange that creates CUI exposure.

There is no single passing score written into the rule. The DoD Assessment Methodology states that it does not add substantive requirements beyond NIST SP 800-171 itself.2Department of Defense. NIST SP 800-171 DoD Assessment Methodology Individual contracting officers can set score thresholds in a solicitation, and many do for sensitive programs. A low score with no credible plan to reach 110 will make you uncompetitive on any serious opportunity.

The Three Assessment Levels

The clause recognizes three tiers of assessment. Each produces a different confidence level attached to your posted score.

Basic Assessment

A Basic assessment is a self-evaluation. You review your own system security plan against the 110 requirements, score yourself using the DoD methodology, and post the result. Because nothing has been verified by the government, the score carries a Low confidence rating.1eCFR. 48 CFR 252.204-7020 – NIST SP 800-171 DoD Assessment Requirements This is the baseline requirement, and it is the most common assessment type in the defense industrial base.

Medium Assessment

A Medium assessment is run by the government. Assessors from the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), part of the Defense Contract Management Agency, review your Basic assessment, examine documentation, and hold discussions with you to clarify how each control is implemented.3Defense Contract Management Agency. Defense Industrial Base Cybersecurity Assessment Center It doesn’t necessarily involve on-site verification of technical controls, but it goes well beyond taking your word for it. The result carries a Medium confidence rating.

High Assessment

A High assessment is the most rigorous tier. DIBCAC assessors work from NIST SP 800-171A, the companion assessment guide, to verify that controls are not just documented but actually working. That means technical demonstrations and in-depth discussions in addition to the documentation review.1eCFR. 48 CFR 252.204-7020 – NIST SP 800-171 DoD Assessment Requirements High assessments are typically reserved for contractors on sensitive programs. The result carries a High confidence rating.

How the Score Is Calculated

Every assessment produces a summary score out of 110. The methodology starts you at 110 and subtracts points for each requirement that is not fully implemented. Deductions are weighted by how critical the missing control is to protecting CUI, so not every gap costs the same.2Department of Defense. NIST SP 800-171 DoD Assessment Methodology

The heaviest deductions are worth 5 points each and cover foundational controls: limiting system access to authorized users, multifactor authentication, FIPS-validated encryption for CUI, baseline system configurations, periodic vulnerability scans, and current malware protections, among roughly two dozen top-tier requirements. Missing a handful of these can drop a score sharply. Lower-weighted requirements carry deductions of 3 or 1 points. Use the published methodology during your self-assessment rather than estimating. You submit only the summary score; the per-requirement point values are not reported.4Acquisition.GOV. DFARS 252.204-7020 – NIST SP 800-171 DoD Assessment Requirements

Posting Your Score in SPRS

Assessment results go into the Supplier Performance Risk System (SPRS), which contractors reach through the DoD Procurement Integrated Enterprise Environment (PIEE) portal.5Supplier Performance Risk System. SPRS – Frequently Asked Questions To enter or edit a score, a user needs the SPRS Cyber Vendor User role in PIEE. Your organization’s administrator assigns it, and provisioning can take several days, so set up access before you need it.6Supplier Performance Risk System. NIST SP 800-171 Information

The NIST SP 800-171 Assessments module collects several pieces of information:

  • Your numeric score out of 110.
  • The date the assessment was completed.
  • The CAGE codes for each business unit covered by the assessment.
  • The name, version, and date of your System Security Plan.
  • The scope of covered contractor information systems included.
  • The date you expect to close all gaps in your Plan of Action and Milestones, if your score is below 110.
  • The confidence level (Low, Medium, or High) tied to the assessment tier.

A posted assessment stays current for three years unless the solicitation specifies a shorter window.1eCFR. 48 CFR 252.204-7020 – NIST SP 800-171 DoD Assessment Requirements If your score ages out before an award, reassess and repost before you bid. What you enter here is a representation to the federal government, so treat accuracy as a compliance obligation, not a formatting task.

What You Owe Your Subcontractors

Paragraph (g) of the clause extends the obligation down the supply chain. As a prime, you must flow the substance of DFARS 252.204-7020 into every subcontract involving CUI, including subcontracts for commercial products and services, subject to the same COTS carve-out.1eCFR. 48 CFR 252.204-7020 – NIST SP 800-171 DoD Assessment Requirements

You cannot award a subcontract to a company that will handle CUI unless that subcontractor has completed at least a Basic assessment within the prior three years and has a current score posted in SPRS. If a subcontractor lacks a score, it can perform a Basic assessment and submit results by email for posting, but that must happen before the subcontract is signed.

If a later audit shows a subcontractor never completed an assessment or posted a score, the prime carries the contractual exposure. Consequences can include negative performance evaluations, withheld payments, or termination. Verify each subcontractor’s SPRS score as a procurement gate, before the award, not after.

False Claims Act Exposure for Inflated Scores

The score you post is a statement to the government. If it does not reflect reality, the Department of Justice can pursue you under the False Claims Act (31 U.S.C. ยง 3729), which reaches knowingly false statements made to obtain federal payments. The DOJ launched its Civil Cyber-Fraud Initiative in 2021 to target contractors who misrepresent cybersecurity compliance, and enforcement has continued to escalate. Pennsylvania State University paid $1.25 million to resolve allegations that it failed to meet cybersecurity requirements across fifteen DoD and NASA contracts.7U.S. Department of Justice. Pennsylvania State University Agrees to Pay 1.25M to Resolve False Claims Act Allegations Other settlements have reached as high as $11 million.

Many of these cases start as qui tam suits filed by insiders who know the posted score does not match the actual security posture. Whistleblowers keep a share of any recovery, which creates a real incentive to report inflated numbers. Posting a 95 while knowing you have serious unaddressed gaps is not just a procurement risk; it puts a litigation target on the company. The safer path is an honest score paired with a realistic Plan of Action and Milestones.

What Changes Under CMMC 2.0

DFARS 252.204-7020 is being layered under the Cybersecurity Maturity Model Certification (CMMC) program, codified at 32 CFR Part 170. The CMMC rollout runs in four phases, each keyed to the effective date of the companion 48 CFR Part 204 CMMC Acquisition rule:8eCFR. 32 CFR Part 170 – Cybersecurity Maturity Model Certification

  • Phase 1 begins when the acquisition rule takes effect. DoD requires CMMC Level 1 (Self) or Level 2 (Self) for applicable contracts, and can require Level 2 (C3PAO), a third-party assessment, in place of self-assessment at its discretion.
  • Phase 2 begins one year later. Third-party certification by an accredited C3PAO becomes the default for Level 2 contracts, and DoD can begin requiring Level 3 (DIBCAC) assessments for the most sensitive programs.
  • Phase 3 begins one year after Phase 2. Level 2 (C3PAO) becomes mandatory for all applicable contracts and option periods, and Level 3 (DIBCAC) becomes the default where applicable.
  • Phase 4 is full implementation, applying CMMC requirements to all applicable solicitations, contracts, and option periods, including those awarded earlier.

Assessments under both the current DFARS framework and CMMC are measured against NIST SP 800-171 Revision 2. DoD has said it will adopt Revision 3 through future rulemaking, but Rev 2 remains the standard until that rulemaking is complete.9Department of Defense Chief Information Officer. CMMC Alignment to NIST Standards

CMMC allows a Conditional status for contractors who do not achieve a perfect score, but the thresholds are strict. Your assessment score divided by the total number of requirements must be at least 0.80, no individual gap can be worth more than 1 point (with one limited exception for certain encryption requirements), and specific critical requirements cannot appear on a Plan of Action and Milestones at all.10eCFR. 32 CFR 170.21 – Plan of Action and Milestones Requirements Any POA&M gaps must be closed within 180 days and confirmed by a closeout assessment. Miss that window and the Conditional status expires, taking your eligibility with it.

For contractors currently operating on Basic self-assessments, the move to third-party verification is the practical shift to prepare for. A self-scored 110 that has never been pressure-tested will face real scrutiny from a C3PAO. If a later DIBCAC assessment finds you have not maintained the required CMMC status, the DIBCAC result overrides anything previously recorded in SPRS, and standard contractual remedies apply. Get your actual security posture aligned with your reported score before that verification arrives.