What is the Supplier Performance Risk System?
The Supplier Performance Risk System is the Department of War’s internal record of what it knows about the companies that supply it. It aggregates delivery performance, quality history, and — most relevant to technology companies — the cybersecurity assessment scores that defense contractors are required to post about their own implementation of federal security requirements.
It is a government-only system. Contracting officers use it during source selection. Contractors can see their own record through the government’s authenticated procurement portal. Nobody else sees anything, and the data is not released to the public in any form.
That single fact is why this entry exists, and it is worth stating plainly before anything else: this platform does not contain this data, cannot obtain it, and does not estimate it. The Federal Readiness Score is computed from publicly observable federal sources. A non-public government risk record is not one of them.
What it holds
Two broad categories of information, from a contractor’s perspective:
- Performance and risk history — delivery and quality signals drawn from government systems, summarized into risk indicators a contracting officer can reference during source selection.
- Cybersecurity assessment results — the self-assessment scores contractors post under the defense clauses that accompany DFARS 252.204-7012, reflecting how completely they have implemented NIST SP 800-171.
The second is the one with an immediate eligibility consequence.
The assessment score, and how the arithmetic works
The self-assessment score is not a percentage and not a grade. It starts from a maximum of 110 — one point for each requirement in the standard — and subtracts for every requirement that is not implemented. The subtractions are not uniform: requirements whose absence creates the greatest exposure cost more than the others.
The consequence surprises people the first time they compute it. A company that has implemented most of the requirement set but missed several of the heavily weighted ones can land well below zero. A negative number is not an error; it is the model telling you that what is missing matters more than what is present.
Why a posted assessment is an eligibility question
Where the applicable defense clauses are in a solicitation, the contracting officer needs a current assessment on file for the offeror before proceeding. The posting is administrative — it takes far less time than the underlying security work — but its absence stops a bid as effectively as a technical disqualification.
This is one of the most common avoidable losses in defense contracting: a capable company with a genuinely decent security program that never posted, and therefore never got read. Post the assessment you actually have, keep it current, and improve the underlying implementation on its own timeline.
Being honest about what is not knowable
Public federal data supports a great deal. It supports knowing what a company has been awarded, which agencies bought from it, which vehicles it holds, what its registration status is, and what its published compliance authorizations are. It does not support knowing what a government-only risk system says about it.
Anyone selling you a “risk score” for a competitor or supplier that claims to reflect this system is either describing something else or modelling a guess. The honest answer is the one this platform gives on its methodology page: here is what public data can show, here is what it cannot, and we do not paper over the difference.
Classified awards are the other example — exempt from public reporting under federal acquisition rules, and therefore absent from every commercial dataset built on public sources, including this one.