Meet Your DFARS SPRS Requirements
Have you received letters from the DoD or your prime contractor asking about your compliance status with DFARS 252.204-7012 • DFARS 252.204-7019 • DFARS 252.204-7020 (The Supplier Performance Risk System SPRS)? Then it’s likely that you handle Controlled Unclassified Information (CUI) and are NOW required to perform your NIST 800-171 self-assessment and submit its score with summary-level POA&M remediation plan information.
Haven’t submitted your SPRS yet?
If you haven’t made your SPRS submission, we have a cost-effective solution for you! Within 4 weeks, we’ll help you develop all the required information and provide the guidance you need to make your DoD SPRS submission.
Submitted to SPRS but lack confidence?
You’re not alone. According to the DoD Inspector Generals’ 2019 report, many companies lack the expertise to perform an accurate NIST 800-171 self-assessment. We will review your self-assessment to rebuild the foundation of your compliance program.
Call for a Complimentary Consultation at 617.314.9721 x158
SPRS Consulting: Here’s How We Work Together
- We conduct Zoom calls to analyze how your business operates.
- Discern the CUI information you handle.
- Use our proprietary “CUI Data Lifecycle” methodology to scope your CUI boundary, minimize its footprint and reduce your CMMC compliance cost.
1 Input & Creation of CUI
Review and document how it’s received and created.
2 Storage of CUI
Evaluate, inspect, and document processes and mechanisms.
3 Use of CUI
Examine who, what, where, why, and how of usage.
4 Share of CUI
How shared with prime contractors,
subcontractors and DoD.
5 Archive of CUI
Analyze methods and processes of archival and encryption.
6 Disposal of CUI
Evaluate contract requirements with
practices and processes.
SPRS DFARS 252.204-7020 Compliance Package
Let us help you report “In Compliance” to the DoD and your prime contractors.
Here’s the documentation package we prepare for you:
- SSP documentation of existing NIST 800-171 baseline practices
- POA&M (Plan Of Action & Milestones) for missing practices
- Summary Assessment level score with worksheet
- Debrief call to review our work and answer your questions
Prices start at $11,900 and vary by your in-scope factors, including the numbers of:
- Physical locations and cage codes
- Employees and citizenship
- Systems, Devices, and applications
Now you’re ready to submit and report “In Compliance”
Video: The DoD’s SPRS and your DFARS 252.204-7020 requirements
[Paul] Today, we will talk about the DoD’s Supplier Performance Risk System SPRS reporting requirement. Kyle, what is it? Can you give a high-level explanation of what the DoDs SPRS is, please?
[Kyle] SPRS is a system hosted by the DoD ….
The Next Step is to Remediate POAM Deficiences and Prepare for CMMC
Do You Sell Commercial Off The Shelf (COTS)?
If so, NIST 800-171 and CMMC Level 3 don’t apply. If you believe that what you sell to the DoD is COTS, we can help you prove it.
“Do you have a Negative Score on Your
NIST 800-171 Self-Assessment?” [Psst…we can help!]
Contact Us to Schedule a Consultation at No Cost!
We meet you where you’re at and bring you to ‘CMMC assessment ready’
with as much or as little help as you need
"*" indicates required fields