What's your real SPRS score?
Primes are asking for it, and guessing is how contractors end up in False Claims Act territory. Check off what you have actually implemented and this page does the DoD math for you: all 110 NIST 800-171 requirements, the exact point values, the two partial-credit rules, the negative floor. Nothing you enter leaves your browser.
STEP 0 Do you have a current System Security Plan?
This is requirement 3.12.4 and it works differently from the other 109. It has no point value because it is the prerequisite: no current SSP, no assessment, no score in SPRS. If you answer no, the calculator still tracks your gaps, it just can't give you a number yet.
How the scoring works
Every contractor starts at 110. Each requirement you haven't implemented subtracts its weight (5, 3, or 1 point), and the floor is −203. There is no partial credit, with exactly two exceptions: multifactor authentication (3.5.3) and FIPS-validated cryptography (3.13.11) can subtract 3 instead of 5 when partially in place. Be honest here, this number goes into a federal system with your company's name on it.
Gap report as of
Print this page to get a clean PDF of the report (the checklist is left out of the printed version).
A negative score is fixable
Most of the missing points come back from documentation you can write yourself: the SSP, the policies, a POA&M with dates on it. I put together Cleared2, a complete CMMC Level 2 kit for small defense contractors, with an SSP scaffold for all 110 requirements, 14 policies, a POA&M tracker, and the same auto-scoring workbook this calculator is built on. The worked sample is free, so you can judge the quality before spending anything.