How the score works
Under the DoD Assessment Methodology for NIST SP 800-171, a fully compliant assessment scores 110 — one point of credit per requirement. Each unimplemented requirement subtracts a weighted value (1, 3, or 5 points depending on the control's importance), so scores range from −203 to 110. A handful of controls have defined partial-credit values in the methodology, and the app applies those too.
The desktop app shows your score as a live tile: every status change updates it immediately, so you always know where you stand and can see exactly how much a given remediation is worth.
The estimated Rev 3 score
When you switch to Rev 3, the app estimates a Rev 3 score by mapping the point values of withdrawn Rev 2 controls into their Rev 3 replacements. DoD has not published a final Rev 3 scoring methodology, so treat this as a planning estimate — its value is showing you which of your existing gaps carry forward and roughly what they'll cost.
Level 1 and the free version
CMMC Level 1 has no SPRS scoring — it's a basic-safeguarding self-assessment against 17 practices. Accordingly, the free browser version's tile shows Level 1 progress ("X of N implemented") rather than an SPRS score. The full SPRS calculation across all 110 requirements is part of the licensed desktop app.
Submitting to SPRS
The app computes your score; submitting it is a separate step you perform in the Supplier Performance Risk System with your PIEE account. Contractors handling CUI under DFARS 252.204-7019/7020 must have a current NIST SP 800-171 self-assessment score on file in SPRS. If you're unsure what to submit or want your self-assessment sanity-checked first, a gap analysis or mock assessment can validate your numbers before they go on the record.