What Happens When Your SPRS Score Is Too Low to Win a Contract?
Most contractors treat their SPRS score like a formality: fill it out once, upload it, move on. Then a contracting officer pulls it during source selection, or a prime asks for it before adding you to a subcontract, and the number turns out to matter a great deal more than anyone expected. There is no published cutoff that fails a bid outright, and that ambiguity is exactly what causes the trouble.
The stakes cut both ways. Score too low, or let the score go stale, and you can lose a competitive evaluation you never knew you were losing, or get quietly dropped from a prime’s supplier list. Score higher than your actual control environment supports, and you are looking at False Claims Act exposure the Department of Justice has already used against other contractors. Either way, the SPRS score has become a live input into who gets DoD work, not a compliance checkbox filed away and forgotten.
This post covers what the score actually measures, what happens in practice when it is too low, and where the underlying requirement sits now that the DFARS 252.204-7019 clause that used to house it has been folded into the CMMC framework.
What the SPRS Score Actually Measures
The Supplier Performance Risk System score is a self-assessment against the 110 security requirements in NIST SP 800-171, the control set for protecting Controlled Unclassified Information on contractor systems. Every contractor handling CUI under DFARS 252.204-7012 has to score their own environment, control by control, and submit the result through the Procurement Integrated Enterprise Environment.
The math starts at 110, a perfect score representing full implementation of every requirement. Each unimplemented control subtracts its assigned weight, and the total point value across all 110 requirements is 313, which means a company with none of the controls in place scores as low as -203. Contracting officers, primes with flowdown obligations, and DoD acquisition staff can all look the number up. It is not a private number.
There Is No Hard Minimum, but There Is a Real Floor
This is the part that catches manufacturers off guard. DoD has never published a minimum passing score for contract award. A contracting officer has discretion to weigh the number however the solicitation allows, which means the same score can be a non-issue on one contract and a disqualifying red flag on another.
In practice, a floor exists anyway. Primes evaluating you as a subcontractor commonly want to see scores well into the 80s or higher before they will flow work down to you, since your posture becomes part of their own risk picture. Scores that are negative, missing, or older than the required assessment window draw scrutiny in source selection even without a stated threshold. The absence of an official number does not mean the absence of a real one, it just means the number is set by whoever is evaluating you, contract by contract.
What Actually Happens When Your Score Is Too Low
A low SPRS score rarely produces a single dramatic rejection letter. It shows up as a series of quieter losses. You lose points in a competitive best-value evaluation against a competitor with a stronger score. A prime doing supplier due diligence for a new subcontract passes you over without explanation. A contracting officer flags your accounting or security posture for closer review during an otherwise routine award decision.
The more procedural failure mode is simpler: no current score on file means no eligibility at all. If your contract requires implementation of NIST SP 800-171, and it has no current, accurate score behind it, that alone can keep you out of the award regardless of how good your actual security posture is. A Plan of Action and Milestones can bridge specific unimplemented controls while remediation is underway, but a POA&M is a supplement to a submitted score, not a substitute for having one.
The Clause Moved. The Obligation Did Not.
If you have heard that DFARS 252.204-7019 and 252.204-7020 are gone, that is accurate as far as it goes. Under the Revolutionary FAR Overhaul, DoD consolidated cybersecurity and supply chain requirements into a restructured FAR Part 40 and DFARS Part 240, and the standalone self-assessment clauses that used to require the SPRS submission were retired as separate provisions.
What did not change is the underlying obligation. If your contract carries DFARS 252.204-7012, you still implement the 110 controls, you still self-assess, and you still report a score in SPRS. That requirement now lives under the CMMC clause, DFARS 252.204-7021, which is also the clause that will require a C3PAO-verified assessment rather than a self-assessment for contracts specifying a CMMC level. The renumbering is housekeeping. The scrutiny on the number itself is going up, not down, as CMMC’s phased rollout continues.
Where Manufacturers Get This Wrong
Treating the score as a cybersecurity-only problem. The SPRS score gets filed with IT and forgotten by everyone else, when in practice it is read by contracting officers and primes right alongside your delivery and quality performance data in the same system. It is part of your overall risk profile, not a siloed technical artifact.
Letting the score go stale. A self-assessment more than three years old is treated as effectively non-compliant, and a score that has not been touched since a rushed submission years ago rarely reflects the environment DoD or a prime is actually evaluating. Systems change, contracts change, and the score on file needs to keep up.
Inflating the number to look competitive. A score that does not match a defensible System Security Plan and control implementation is a False Claims Act problem waiting to surface, and DOJ’s Civil Cyber-Fraud Initiative has already brought settlements built on exactly this gap. A lower, accurate score beats a higher, indefensible one every time.
Assuming a good FAR and DFARS compliance record offsets a weak cyber posture. It does not. A contracting officer or prime weighing your SPRS score is not going to average it against how clean your incurred cost submissions are. The two are evaluated on separate tracks, and a weakness in one does not get forgiven by strength in the other.
Where GovComply Fits
GovComply does not run your NIST SP 800-171 self-assessment or manage your SPRS score. That is a distinct workstream, usually owned by IT or a dedicated cybersecurity partner, and we are not going to pretend otherwise just to fit it into a product pitch.
What GovComply does is keep the rest of your contract compliance picture in a defensible state, so a low or under-review SPRS score is not compounded by gaps a contracting officer or prime finds elsewhere. Flowdown obligations tracked and evidenced, CPSR readiness maintained, supplier quality documentation current, audit records assembled before the request comes in rather than scrambled together after. When your cyber score draws a second look, you want the rest of the file to hold up without a scramble.
If you are not sure whether your current SPRS score, or the documentation behind it, would survive a contracting officer’s or prime’s closer look, that is worth a conversation before it becomes a live issue on a bid.
GovComply.ai is compliance software built for defense and aerospace manufacturers holding government contracts.