How to Submit Your SPRS Score: PIEE Registration and the CMMC Level 2 Self-Assessment, Step by Step
The complete path from zero to a submitted SPRS score: SAM.gov and your CAGE code, PIEE vendor registration, the SPRS Cyber Vendor User role, running the 110-requirement NIST SP 800-171 self-assessment, and exactly what to enter in the portal.
Why this matters now
If your company holds — or wants — DoD contracts that involve Controlled Unclassified Information (CUI), DFARS 252.204-7019 and 7020 require a current NIST SP 800-171 self-assessment score in SPRS (the Supplier Performance Risk System). Contracting officers check it before award. Primes check it before adding you to a team. And with CMMC Phase 2 suspended, the self-assessment score in SPRS is — right now — the only cyber number the government sees about you.
Most small contractors hit the same two walls: they don't know their score, and they don't know the bureaucratic path to submit it. This guide walks the whole thing, in order.
Part 1: Know your score before you touch a government portal
Submitting a score you haven't actually calculated is the fastest route to a False Claims Act problem — the score you affirm is a legal representation. So the sequence matters: assess first, register second, submit third.
The DoD Assessment Methodology scores all 110 NIST SP 800-171 Rev 2 requirements on the official scale of −203 to +110. You start at 110 and subtract points for every requirement you haven't implemented — most are worth 1, 3, or 5 points. Two requirements (multi-factor authentication and FIPS-validated cryptography) allow partial credit; a missing System Security Plan means the assessment can't be conducted at all.
You can do this on a spreadsheet — or run it in CyberPolicify: the platform walks you through all 110 requirements in plain English and calculates your estimated SPRS score live, using the official weights, partial-credit rules, and the POA&M-eligibility threshold (score ≥ 88), so you know exactly where you stand before anything gets affirmed. It also flags which open items are blocking you and what each is worth, so you fix the 5-pointers first.
Part 2: The registration chain — SAM.gov → CAGE → PIEE → SPRS
Step 1: Verify your SAM.gov registration
Your company needs an active SAM.gov registration with a CAGE code (Commercial and Government Entity code — assigned automatically during SAM registration) and a designated Electronic Business Point of Contact (EB POC). If you already do federal work, you have all three; confirm they're current, because an expired SAM registration blocks everything downstream.
Step 2: Register on PIEE
Go to the Procurement Integrated Enterprise Environment — piee.eb.mil — click Register, accept the terms, and choose Vendor as your user type. Use your company email; the account is tied to your CAGE code.
Step 3: Request the "SPRS Cyber Vendor User" role
During (or after) PIEE registration, add the SPRS application to your account and request the role named SPRS Cyber Vendor User — this is the specific role that lets you enter and edit your company's NIST SP 800-171 self-assessment score. Enter your CAGE code when prompted. (The read-only "SPRS" role exists too; you want the Cyber Vendor one.)
Step 4: Get approved internally
Your company's Contractor Account Administrator (CAM) — usually the EB POC, or whoever first set up PIEE for your company — must approve the role request inside PIEE. In a five-person shop this may be you approving yourself with a second account role; in a larger company, find the CAM before you start so the request doesn't sit in a queue.
Part 3: What you actually enter in SPRS
Once the role is active, log into PIEE, open SPRS, and add a new NIST SP 800-171 assessment record. Have these ready:
- Your summary score (−203 to 110) — from your completed self-assessment
- Assessment date — the date you completed it
- Assessment scope — a short description of the system boundary the assessment covered (which systems/enclaves handle CUI)
- CAGE code(s) covered by the assessment
- Plan of action completion date — if you scored below 110, the date by which open items will be closed
That's the whole submission — it's a form, not an upload. One thing to be clear-eyed about: no tool or consultant can submit to SPRS for you. DoD requires you to log into PIEE with your own credentials, and anyone offering to "submit on your behalf" is asking for a government login you should never share. What a platform can do — and what CyberPolicify does — is get you to the portal with a defensible score behind you and every field already on your clipboard: score, date, scope, CAGE. The typing takes about two minutes. The work is everything before it: an honest 110-requirement assessment, a System Security Plan, and a realistic plan of action for what's open.
Scores are good for three years, but you must re-submit whenever your posture materially changes — and under CMMC Level 2 self-assessment rules, affirmation is annual.
The order of operations, one more time
- Run the full 110-requirement self-assessment and get your real score.
- Write down your scope statement and gather your CAGE code.
- SAM.gov current → PIEE vendor account → SPRS Cyber Vendor User role → CAM approval.
- Enter score, date, scope, CAGE, and POA&M date in SPRS.
- Calendar the annual re-affirmation.
The portals are free. The score is the product of real security work — and knowing your number before you're asked for it is the difference between bidding with confidence and scrambling under a deadline.
Generate documentation mapped to frameworks
Generate policies, procedures, and gaps you can act on—without consultant-heavy overhead.