Federal Contractor Readiness Guide
How to Complete SPRS
Enter NIST SP 800-171 basic assessment scores and related metadata in the Supplier Performance Risk System (SPRS) through PIEE after completing your self-assessment.
What it is
SPRS is DoD's authoritative repository for supplier performance and cyber assessment data, including NIST SP 800-171 basic assessment scores required by DFARS 252.204-7019 for covered contractors.
Who needs it
Defense contractors handling covered defense information who must report NIST SP 800-171 assessment summary results—or CMMC status when applicable—to the government via SPRS.
Prerequisites
- Completed NIST SP 800-171 basic assessment methodology (SPRS stores results; it does not perform the assessment)
- PIEE account with SPRS Cyber Vendor User role
- Active SAM.gov CAGE hierarchy accurate for your organization
Step-by-step process
- 1. Complete the NIST SP 800-171 basic assessment
Use the assessment methodology published by DoD Pricing and Contracting before entering summary scores. SPRS only stores assessment results.
- 2. Obtain PIEE access with SPRS Cyber Vendor User role
Register or update your PIEE account and request the SPRS Cyber Vendor User role following DISA SPRS access instructions.
- 3. Open SPRS Cyber Reports in PIEE
Log in at PIEE, select SPRS, then Cyber Reports. Choose the hierarchy location (CAGE) you are authorized to edit.
- 4. Enter NIST SP 800-171 assessment summary data
On the NIST SP 800-171 Assessments tab, add a new basic assessment with score, assessment date, scope CAGE codes, SSP metadata, and POA&M completion date as required.
- 5. Maintain and update records
Edit assessments when your security posture changes. SPRS assigns a DoD UID for each saved basic assessment; updates should reflect current implementation status.
Information and documents you need
- NIST SP 800-171 basic assessment score
- Assessment date and scope CAGE codes
- System Security Plan name, version, and date
- Plan of Action completion date when applicable
- Completed System Security Plan and assessment methodology worksheets (retain internally; SPRS stores summary fields)
Cost
There is no federal fee to access SPRS through PIEE for vendor cyber reporting roles described in official SPRS access materials.
Typical processing time
SAM.gov CAGE hierarchy updates typically flow to SPRS within about 48 hours per SPRS NIST guidance; assessment entry is immediate once PIEE roles are approved.
Common mistakes
- Attempting to perform the assessment inside SPRS instead of beforehand
- Entering scores before the SPRS Cyber Vendor User role is approved
- Using CAGE codes that are not in the SAM-imported hierarchy
What happens after approval / completion
Government acquisition personnel can view basic assessment scores for source selection and oversight. Update SPRS whenever your score or POA&M status changes and align with CMMC reporting when contract clauses require it.
Official sources
- SPRS — NIST SP 800-171 (primary)
- SPRS — User Access (primary)
- PIEE (supporting)