PAST PERFORMANCE

SPRS

The government-only Department of War system that holds supplier risk and performance data, including the cybersecurity assessment scores defense contractors are required to post.

Also called Supplier Performance Risk System

Last reviewed

What is the Supplier Performance Risk System?

The Supplier Performance Risk System is the Department of War’s internal record of what it knows about the companies that supply it. It aggregates delivery performance, quality history, and — most relevant to technology companies — the cybersecurity assessment scores that defense contractors are required to post about their own implementation of federal security requirements.

It is a government-only system. Contracting officers use it during source selection. Contractors can see their own record through the government’s authenticated procurement portal. Nobody else sees anything, and the data is not released to the public in any form.

That single fact is why this entry exists, and it is worth stating plainly before anything else: this platform does not contain this data, cannot obtain it, and does not estimate it. The Federal Readiness Score is computed from publicly observable federal sources. A non-public government risk record is not one of them.

What it holds

Two broad categories of information, from a contractor’s perspective:

  • Performance and risk history — delivery and quality signals drawn from government systems, summarized into risk indicators a contracting officer can reference during source selection.
  • Cybersecurity assessment results — the self-assessment scores contractors post under the defense clauses that accompany DFARS 252.204-7012, reflecting how completely they have implemented NIST SP 800-171.

The second is the one with an immediate eligibility consequence.

The assessment score, and how the arithmetic works

The self-assessment score is not a percentage and not a grade. It starts from a maximum of 110 — one point for each requirement in the standard — and subtracts for every requirement that is not implemented. The subtractions are not uniform: requirements whose absence creates the greatest exposure cost more than the others.

The consequence surprises people the first time they compute it. A company that has implemented most of the requirement set but missed several of the heavily weighted ones can land well below zero. A negative number is not an error; it is the model telling you that what is missing matters more than what is present.

Why a posted assessment is an eligibility question

Where the applicable defense clauses are in a solicitation, the contracting officer needs a current assessment on file for the offeror before proceeding. The posting is administrative — it takes far less time than the underlying security work — but its absence stops a bid as effectively as a technical disqualification.

This is one of the most common avoidable losses in defense contracting: a capable company with a genuinely decent security program that never posted, and therefore never got read. Post the assessment you actually have, keep it current, and improve the underlying implementation on its own timeline.

Being honest about what is not knowable

Public federal data supports a great deal. It supports knowing what a company has been awarded, which agencies bought from it, which vehicles it holds, what its registration status is, and what its published compliance authorizations are. It does not support knowing what a government-only risk system says about it.

Anyone selling you a “risk score” for a competitor or supplier that claims to reflect this system is either describing something else or modelling a guess. The honest answer is the one this platform gives on its methodology page: here is what public data can show, here is what it cannot, and we do not paper over the difference.

Classified awards are the other example — exempt from public reporting under federal acquisition rules, and therefore absent from every commercial dataset built on public sources, including this one.

COMMON QUESTIONS

Can a company see its own record in this system?

Yes. Contractors access their own supplier record through the government's authenticated procurement portal, using an account tied to their registered entity. What a contractor cannot do is see another company's record, and what a commercial data provider cannot do is obtain the underlying data at all.

Can I buy this data from a market intelligence provider?

No. The system is government-only and its contents are not released to the public, so no commercial platform has it — including this one. Any product implying otherwise is either describing a different dataset or estimating. An estimate of a non-public government risk score is a guess wearing a number.

What is a Basic Assessment score?

A contractor's self-evaluation of its implementation of the NIST SP 800-171 requirement set, expressed as a number and posted to the government system. It starts from a maximum of 110 and subtracts for each unimplemented requirement, with larger subtractions for the requirements that matter most, so the result can fall below zero for a company that has implemented very little.

Why does a posted assessment matter for award eligibility?

Because defense contract clauses make it a condition. Where the applicable clauses are present, a contracting officer needs a current assessment on file for the offeror before proceeding. A missing or stale posting is an administrative reason to be set aside that has nothing to do with the quality of the offer.

HOW GOVEXPRESS SCORES THIS

Past Performance

This is the clearest example of a Past Performance signal that exists but is not public, and because the Federal Readiness Score is computed only from publicly observable federal data, nothing in this platform contains it or estimates it.

One of the 12 categories in the Federal Readiness Score. The methodology is public — including the things this platform will never claim.

SPRS is one signal. See all of them.

Get your free score