How to Submit Your SPRS Score: PIEE Registration and the CMMC Level 2 Self-Assessment, Step by Step
The complete path from zero to a submitted SPRS score: SAM.gov and your CAGE code, PIEE vendor registration, the SPRS Cyber Vendor User role, running the 110-requirement NIST SP 800-171 self-assessment, and exactly what to enter in the portal.
Why this matters now
If your company holds — or wants — DoD contracts that involve Controlled Unclassified Information (CUI), DFARS 252.204-7019 and 7020 require a current NIST SP 800-171 self-assessment score in SPRS (the Supplier Performance Risk System). Contracting officers check it before award. Primes check it before adding you to a team. And with CMMC Phase 2 suspended, the self-assessment score in SPRS is — right now — the only cyber number the government sees about you.
Most small contractors hit the same two walls: they don't know their score, and they don't know the bureaucratic path to submit it. This guide walks the whole thing, in order.
Part 1: Know your score before you touch a government portal
Submitting a score you haven't actually calculated is the fastest route to a False Claims Act problem — the score you affirm is a legal representation. So the sequence matters: assess first, register second, submit third.
The DoD Assessment Methodology scores all 110 NIST SP 800-171 Rev 2 requirements on the official scale of −203 to +110. You start at 110 and subtract points for every requirement you haven't implemented — most are worth 1, 3, or 5 points. Two requirements (multi-factor authentication and FIPS-validated cryptography) allow partial credit; a missing System Security Plan means the assessment can't be conducted at all.
You can do this on a spreadsheet — or run it in CyberPolicify: the platform walks you through all 110 requirements in plain English and calculates your estimated SPRS score live, using the official weights, partial-credit rules, and the POA&M-eligibility threshold (score ≥ 88), so you know exactly where you stand before anything gets affirmed. It also flags which open items are blocking you and what each is worth, so you fix the 5-pointers first.
Part 2: The registration chain — SAM.gov → CAGE → PIEE → SPRS
Step 1: Verify your SAM.gov registration
Your company needs an active SAM.gov registration with a CAGE code (Commercial and Government Entity code — assigned automatically during SAM registration) and a designated Electronic Business Point of Contact (EB POC). If you already do federal work, you have all three; confirm they're current, because an expired SAM registration blocks everything downstream.
Step 2: Register on PIEE
Go to the Procurement Integrated Enterprise Environment — piee.eb.mil — click Register, accept the terms, and choose Vendor as your user type. Use your company email; the account is tied to your CAGE code.
Step 3: Request the "SPRS Cyber Vendor User" role
During (or after) PIEE registration, add the SPRS application to your account and request the role named SPRS Cyber Vendor User — this is the specific role that lets you enter and edit your company's NIST SP 800-171 self-assessment score. Enter your CAGE code when prompted. (The read-only "SPRS" role exists too; you want the Cyber Vendor one.)
Step 4: Get approved internally
Your company's Contractor Account Administrator (CAM) — usually the EB POC, or whoever first set up PIEE for your company — must approve the role request inside PIEE. In a five-person shop this may be you approving yourself with a second account role; in a larger company, find the CAM before you start so the request doesn't sit in a queue.
Part 3: What you actually enter in SPRS
Once the role is active, log into PIEE, open SPRS, and add a new NIST SP 800-171 assessment record. Have these ready:
- Your summary score (−203 to 110) — from your completed self-assessment
- Assessment date — the date you completed it
- Assessment scope — a short description of the system boundary the assessment covered (which systems/enclaves handle CUI)
- CAGE code(s) covered by the assessment
- Plan of action completion date — if you scored below 110, the date by which open items will be closed
That's the whole submission — it's a form, not an upload. The work is everything before it: an honest 110-requirement assessment, a System Security Plan, and a realistic plan of action for what's open.
Scores are good for three years, but you must re-submit whenever your posture materially changes — and under CMMC Level 2 self-assessment rules, affirmation is annual.
The order of operations, one more time
- Run the full 110-requirement self-assessment and get your real score.
- Write down your scope statement and gather your CAGE code.
- SAM.gov current → PIEE vendor account → SPRS Cyber Vendor User role → CAM approval.
- Enter score, date, scope, CAGE, and POA&M date in SPRS.
- Calendar the annual re-affirmation.
The portals are free. The score is the product of real security work — and knowing your number before you're asked for it is the difference between bidding with confidence and scrambling under a deadline.
Generate documentation mapped to frameworks
Generate policies, procedures, and gaps you can act on—without consultant-heavy overhead.