The Gap Assessment evaluates your organisation's current implementation status against all CMMC practices for your target level. It produces a domain-by-domain breakdown and calculates your SPRS (Supplier Performance Risk System) score, which is required for DoD contract eligibility.

SPRS Score Calculation

  • Start at 110 points (perfect score = all 110 NIST SP 800-171 requirements fully implemented)
  • Each unimplemented requirement deducts a weighted value (1, 3, or 5 points)
  • The minimum possible score is -203
  • Requirements on a POA&M still count as deductions until fully implemented

Score Interpretation

110Full implementation of all requirements
90-109Strong posture; likely assessment-ready
70-89Good progress; focused remediation needed
40-69Moderate; significant work required
Below 40Early stages; major remediation needed

Requirement Weights

WeightDeductionExamples
5 pointsCriticalMFA, CUI encryption, audit logging
3 pointsSignificantConfig baselines, IR plans, risk assessments
1 pointStandardContent reviews, maintenance tools, visitor records