Federal Contractor Readiness Guide

How to Complete SPRS

Enter NIST SP 800-171 basic assessment scores and related metadata in the Supplier Performance Risk System (SPRS) through PIEE after completing your self-assessment.

Cybersecurity & Compliance

What it is

SPRS is DoD's authoritative repository for supplier performance and cyber assessment data, including NIST SP 800-171 basic assessment scores required by DFARS 252.204-7019 for covered contractors.

Who needs it

Defense contractors handling covered defense information who must report NIST SP 800-171 assessment summary results—or CMMC status when applicable—to the government via SPRS.

Prerequisites

  • Completed NIST SP 800-171 basic assessment methodology (SPRS stores results; it does not perform the assessment)
  • PIEE account with SPRS Cyber Vendor User role
  • Active SAM.gov CAGE hierarchy accurate for your organization

Step-by-step process

  1. 1. Complete the NIST SP 800-171 basic assessment

    Use the assessment methodology published by DoD Pricing and Contracting before entering summary scores. SPRS only stores assessment results.

    Official reference: https://www.sprs.csd.disa.mil/nistsp.htm

  2. 2. Obtain PIEE access with SPRS Cyber Vendor User role

    Register or update your PIEE account and request the SPRS Cyber Vendor User role following DISA SPRS access instructions.

    Official reference: https://www.sprs.csd.disa.mil/access.htm

  3. 3. Open SPRS Cyber Reports in PIEE

    Log in at PIEE, select SPRS, then Cyber Reports. Choose the hierarchy location (CAGE) you are authorized to edit.

    Official reference: https://piee.eb.mil/

  4. 4. Enter NIST SP 800-171 assessment summary data

    On the NIST SP 800-171 Assessments tab, add a new basic assessment with score, assessment date, scope CAGE codes, SSP metadata, and POA&M completion date as required.

    Official reference: https://www.sprs.csd.disa.mil/nistsp.htm

  5. 5. Maintain and update records

    Edit assessments when your security posture changes. SPRS assigns a DoD UID for each saved basic assessment; updates should reflect current implementation status.

    Official reference: https://www.sprs.csd.disa.mil/nistsp.htm

Information and documents you need

  • NIST SP 800-171 basic assessment score
  • Assessment date and scope CAGE codes
  • System Security Plan name, version, and date
  • Plan of Action completion date when applicable
  • Completed System Security Plan and assessment methodology worksheets (retain internally; SPRS stores summary fields)

Cost

There is no federal fee to access SPRS through PIEE for vendor cyber reporting roles described in official SPRS access materials.

Typical processing time

SAM.gov CAGE hierarchy updates typically flow to SPRS within about 48 hours per SPRS NIST guidance; assessment entry is immediate once PIEE roles are approved.

Common mistakes

  • Attempting to perform the assessment inside SPRS instead of beforehand
  • Entering scores before the SPRS Cyber Vendor User role is approved
  • Using CAGE codes that are not in the SAM-imported hierarchy

What happens after approval / completion

Government acquisition personnel can view basic assessment scores for source selection and oversight. Update SPRS whenever your score or POA&M status changes and align with CMMC reporting when contract clauses require it.

Official sources

Related acronyms

Related guides

Related federal market intelligence

Last reviewed / updated: September 20, 2026