A Supplier Performance Risk System (SPRS) score of 88 can sound reassuring. But it is not a universal pass.
In a Cybersecurity Maturity Model Certification (CMMC) Level 2 context, an 88 only works when controls that cannot be deferred to a Plan of Action and Milestones (POA&M) are already complete and defensible.
That nuance is often missed, and across the Defense Industrial Base (DIB), it is quietly costing government contractors real revenue.
Prime contractors are no longer treating SPRS as a pass-fail metric. They are using it as a risk signal. And in competitive bids, an 88 increasingly reads as “not ready.”
As CMMC enforcement expands, SPRS scores are becoming an early filter. Contractors with marginal scores are being asked harder questions, pushed to the side, or excluded entirely.
Dig deeper below to understand why meeting the minimum SPRS threshold is no longer enough to stay competitive in today’s defense supply chain.
On paper, an 88 suggests progress.
In practice, it often signals Conditional Level 2 status under CMMC, and that comes with strict regulatory limits.
Under 32 Code of Federal Regulations (CFR) § 170.21, an Organization Seeking Assessment (OSA) may only achieve Conditional CMMC Level 2 if:
Those prohibited controls include:
There is one narrow exception. Encryption of CUI that is not validated under Federal Information Processing Standards (FIPS) may appear on a POA&M, even though it carries three points.
That means an 88 only works if the remaining gaps are limited, low-weighted, and not tied to any prohibited requirements.
And even then, the clock starts.
Conditional status requires all POA&Ms to be closed within 180days of the Conditional CMMC Status date.
Closure is not informal. It requires a POA&M closeout assessment:
If remediation is not completed and confirmed within 180 days, the Conditional status expires.
As Darryl Jones, Information Technology (IT) Compliance Manager at ISI, explains:
“Although a CMMC Conditional Certification enables contractors to be awarded DoD contracts with CMMC Level 2 (C3PAO) requirements, it is critical to maintain focus on remediation. As with most businesses, 180 days, when competing with changing priorities, can approach quicker than expected.”
For prime contractors, that matters.
An 88 can represent:
For multi-year programs, that is not a minor variable. It is measurable risk.
SPRS was designed as a Department of Defense (DoD) (also known as the Department of War) risk indicator. The supply chain has taken that idea further.
Today, primes use SPRS scores to:
An 88 might keep you eligible. It does not keep you competitive.
We are seeing real scenarios where:
Some of this scrutiny now appears directly in solicitations and sources sought, while the rest happens during evaluation, vetting, and prime-led risk reviews.
CMMC has changed expectations.
Under CMMC Level 2, the end state is full implementation of all 110 NIST SP 800-171 controls. SPRS scores are now being viewed through that lens.
An 88 suggests:
For primes planning multi-year programs, that gap matters.
They are not just buying a product or service. They are inheriting risk.
This is not about chasing a higher number. It is about addressing the specific control gaps that signal risk to prime contractors and undermine CMMC Level 2 readiness.
Strong next steps include:
In today’s market, credibility is proven through implementation, evidence, and readiness, not by meeting the minimum.
An SPRS score of 88 may meet the minimum DoD requirement in some cases, but acceptability is no longer the same as competitiveness. Prime contractors increasingly expect higher scores that demonstrate stronger implementation and lower risk. An 88 often triggers follow-up questions, additional scrutiny, or quiet exclusion in competitive bids.
Prime contractors are accountable for the security of their supply chain. SPRS scores provide a fast way to assess subcontractor risk against NIST SP 800-171 requirements. A lower score suggests potential delays, audit issues, or remediation timelines that could impact contract performance and compliance obligations.
Waiting creates risk. SPRS scores are already influencing award decisions, even before full CMMC enforcement. Improving your score now strengthens trust with primes, reduces future remediation pressure, and positions your organization for smoother CMMC assessments.