GSA Ready Now
Contracting officer reviewing a posted SPRS Score of Record alongside civilian agency CUI clauses and the proposed FAR CUI rule
Back to Blog
Compliance Aug 31, 2026 10 min read

What Your Score of Record Tells a Contracting Officer

Focus keyword: score of record

Your Score of Record is a single number, a date and a scope, and a contracting officer can absorb all three in about ten seconds. What that number communicates has less to do with your security posture than most contractors assume, and more to do with whether you look like a company that manages its own paperwork.

This matters right now because the line between defense obligations and civilian obligations is being actively redrawn, and a lot of contractors are reading defense signals into civilian contracts where they do not yet apply.

What Exactly Is a Score of Record?

The term comes from the Supplier Performance Risk System (SPRS), the Department of War's repository for contractor risk data. Under DFARS 252.204-7019 and 252.204-7020, defense contractors whose contracts include the safeguarding clause must conduct a self-assessment against NIST SP 800-171 and post a summary level score.

The scoring method is the NIST SP 800-171 DoD Assessment Methodology. It starts at 110, one point per control, and subtracts weighted values (5, 3 or 1) for each control not fully implemented. The weighting reflects how much risk the government associates with that particular gap, which is why a perfect looking spreadsheet can still produce a low number.

Your Score of Record is the assessment currently on file for a given scope. Assessments come in three confidence levels: Basic (you assess yourself), Medium and High (the government assesses you). A government conducted assessment carries more weight than a self-assessment, and assessments have a shelf life, generally three years.

What Does a Contracting Officer Actually Read Into Your Score?

Not what you might think. A contracting officer is usually not evaluating whether 88 is meaningfully safer than 76. They are checking four things, roughly in this order.

  1. 1

    Is there a score at all.

    On the defense side, a current posted assessment is a condition of eligibility for award under the relevant clauses. A missing score is not a low score, it is a blocked action, and it lands on the CO's desk as a problem to solve before the clock runs out.

  2. 2

    Is it current.

    A score posted years ago against a system that has since moved to a different cloud environment tells the CO that nobody has revisited it. Staleness reads as inattention.

  3. 3

    Does the scope match the work.

    Scores are posted against CAGE codes and a described system boundary. If the score covers your corporate CAGE but the work will be performed by a subsidiary or in a separate enclave, the CO now has a scoping question, and scoping questions delay awards.

  4. 4

    Is the number plausible for a company your size.

    A 110 from a twelve person firm with no dedicated security staff invites more scrutiny, not less. So does a score that jumped forty points in a quarter with no corresponding change in infrastructure.

The honest summary: the score is a screening artifact, not a security rating. It tells the officer whether you are administratively reliable and whether awarding to you creates work for them.

Does Any of This Apply If I Only Sell to Civilian Agencies?

This is where careful reading matters, and where a great deal of vendor marketing gets sloppy.

SPRS scoring under DFARS 252.204-7019 and 7020 is a defense contract obligation. It flows from a Department of War acquisition regulation supplement. If you hold a GSA Schedule and sell exclusively to civilian agencies under civilian funded orders, that clause is not what obligates you.

CMMC is likewise a Department of War program. The CMMC acquisition rule took effect in late 2025 and is phasing into defense solicitations over a multi year schedule. It is not a governmentwide requirement, and there is no civilian equivalent certification today.

That said, "no SPRS requirement" is not the same as "no CUI requirement." Civilian agencies have been imposing safeguarding obligations for years through their own supplements and contract terms. DHS has long used its own CUI safeguarding clauses in the HSAR. GSA has its own information technology security requirements in the GSAR. Individual solicitations frequently reference NIST SP 800-171 directly. The result is a patchwork: the obligation is real, but it arrives contract by contract rather than through one governmentwide mechanism.

So the practical answer for a civilian focused schedule holder is: you probably do not have a Score of Record, you may still have substantive 800-171 obligations, and you should be reading your clause list rather than your peers' LinkedIn posts.

What Would the Proposed FAR CUI Rule Change?

The FAR Council has a proposed rule that would establish governmentwide requirements for identifying, marking, safeguarding and reporting on Controlled Unclassified Information. It is FAR Case 2017-016. It was published for comment and, as of this writing, it is proposed. It is not final and it is not in force.

That distinction is the whole point. A proposed rule tells you what the government is thinking about. It does not create an obligation, it does not create a compliance deadline, and anyone selling you a "FAR CUI rule readiness certification" is selling you something that does not exist.

What the proposal signals, if it is finalized in something close to its current form:

  • A common process for how CUI is identified and handed to contractors, replacing part of the current agency by agency patchwork.
  • Safeguarding expectations anchored to NIST SP 800-171 for contractor systems that process covered information.
  • An incident reporting obligation with a defined window. The specific timing is one of the details that can move between proposal and final rule, so treat any number you see quoted as provisional.

What the proposal does not do, as drafted: it does not create a civilian certification body, it does not extend CMMC to civilian agencies, and it does not stand up a civilian version of SPRS scoring. There is no civilian Score of Record on the horizon in this rule. If a final rule lands, expect the mechanism to look like contract clauses and representations, not like a score you post to a portal.

How Do I Make My Score of Record Defensible?

If you do have a score, defensible means you could explain it to an auditor, a prime, or a Department of Justice attorney without changing your story.

  1. 1

    Write the System Security Plan first, score second.

    The score is derived from an assessment of a defined system. If the boundary is not written down, the number is arbitrary.

  2. 2

    Keep the arithmetic.

    Retain the control by control worksheet showing which requirements were scored as not implemented and what point value was deducted. Reconstructing this two years later is miserable.

  3. 3

    Treat plans of action as dated commitments, not decoration.

    If you scored partial credit on the strength of a remediation plan, the plan needs owners and dates, and someone needs to check it.

  4. 4

    Do not round up.

    The Department of Justice has an active Civil Cyber Fraud Initiative that has pursued contractors over inaccurate cybersecurity representations, including assessment scores. Overstating a score is a representation to the government. That is a different category of risk than being behind on remediation, and it is the one that ends careers.

  5. 5

    Refresh on infrastructure change, not just on the calendar.

    A tenant migration, a new managed service provider, or a shift in where CUI actually lives should trigger a reassessment regardless of how recent the posted score is.

What Should a GSA Schedule Holder Do This Quarter?

Something modest and useful, rather than something expensive and premature.

Start by determining whether you actually receive CUI. A surprising number of contractors assume they do because a customer used the phrase loosely, or assume they do not because nobody ever marked anything. Neither assumption survives contact with the actual contract file.

Then read your clauses. Pull the solicitation and contract terms for your current work and identify what safeguarding language is already in there. This is the only reliable way to know what binds you today.

Then do a gap assessment against NIST SP 800-171, honestly and without posting anything anywhere. The value here is not the number. It is knowing where you stand before a rule finalizes, a prime flows something down, or a civilian agency adds a clause to your next order. Preparation that would be useful under a final rule is largely the same preparation that is useful under today's agency specific clauses, which makes it a reasonable investment even while the FAR proposal sits unresolved.

What not to do: do not buy a certification that does not exist on the civilian side, and do not restructure your entire environment around a rule that has not been finalized.

Frequently Asked Questions

What is a Score of Record in SPRS?

A Score of Record is the NIST SP 800-171 assessment score currently on file in the Supplier Performance Risk System for a defined scope, usually tied to CAGE codes and a described system boundary. It is calculated using the DoD Assessment Methodology, starting at 110 and deducting weighted points for requirements that are not fully implemented. Scores come with an assessment date and a confidence level of Basic, Medium or High.

Do civilian agency contractors need an SPRS score?

Generally no. SPRS score posting is required by DFARS clauses 252.204-7019 and 252.204-7020, which are Department of War acquisition supplement clauses that appear in defense contracts. Contractors working exclusively on civilian agency contracts are typically not subject to those clauses, though they may still have CUI safeguarding obligations through agency specific clauses or individual solicitation terms.

Is the FAR CUI rule in effect?

No. The FAR CUI rule (FAR Case 2017-016) is a proposed rule. It has been published for public comment but has not been finalized, and it does not currently impose obligations on contractors. Any compliance deadline attributed to it is speculative until a final rule is published.

Does CMMC apply to civilian agencies?

CMMC is a Department of War program and applies through defense contracts. It is not a governmentwide requirement and there is no civilian agency equivalent certification. Civilian CUI obligations, where they exist, currently arrive through agency supplements and contract clauses rather than a certification program.

Can a low Score of Record disqualify me from an award?

On the defense side, the more common problem is a missing or expired score rather than a low one, because a current assessment can be a condition of eligibility under the applicable clauses. A low score does not automatically disqualify you, but it invites scrutiny and can weigh against you where a solicitation makes cybersecurity an evaluation factor. Accuracy matters more than the number, since misrepresenting a score carries legal exposure that being behind on remediation does not.

How often should I redo my assessment?

Assessments under the DoD methodology are generally treated as valid for three years, but the calendar is the floor, not the standard. Reassess whenever your system boundary materially changes, such as a cloud migration, a new managed service provider, or a shift in where CUI is stored or processed.

If you are unsure whether your current contracts already obligate you on CUI, start with a clause review of the work you hold today.

Run the Gap Assessment

Find Out If You're Ready for a GSA Contract

Take the free 19-question GSA readiness assessment and get a personalized score with a clear action plan — in minutes.

Start Free Assessment