A: Before you enter SPRS you should have completed your NIST SP 800-171 assessment, identified your score, and completed a System Security Plan (SSP) for your company. Below are resources to support these tasks.
NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1, June 24, 2020. Page 12 is where the assessment score card begins.
www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf
or
Small Businesses Project Spectrum:
https://projectspectrum.io/#!/
SSP Guide & Template:
https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
(assist with creation of your company System Security Plan - required by the program)
For specific questions about conducting the assessment please contact your Program Office or Contracts representative or the Defense Contract Management Agency (DCMA) help desk,
DCMA_7012_Assessment_Inquiry@mail.mil for assistance.
NIST SP 800-171 assessment scores (cyber scores) are considered Controlled Unclassified Information (CUI) for federal government employees. SPRS data is UNCLASSIFIED for companies viewing their own information. Access is controlled by the company Contractor Account Administrator (CAM). Apply for SPRS access through the Procurement Integrated Enterprise Environment (PIEE). Access instructions available
SPRS Access Cyber Reports.
If the cyber score of a subcontractor is required, contact them directly. SPRS reports are not releasable under the Freedom of Information Act (FOIA).