An SPRS score can be present and still be the wrong score for a proposal. Currency under the NIST SP 800-171 DoD Assessment rules is primarily a date question, but usefulness is also a scope question: does that assessment describe the covered contractor information system that will perform the work now?
For most procurements using the standard DFARS timing, a current assessment is no more than three years old unless the solicitation requires a shorter period. The safest operational habit is to track both the formal date and the architectural assumptions behind the score.
Step 1: read the assessment date and the solicitation
Start with the completion date of the assessment shown in the relevant records. Then read the solicitation for any shorter required period. The DFARS policy expressly allows a lesser time to be specified, so a three-year-old rule of thumb should never override procurement-specific language.
Put the resulting 'usable through' date in an internal register, but label it as a planning date rather than a guarantee. Contract amendments, changed requirements, or system changes can affect whether the score is still the right record even before the date arrives.
Step 2: identify which SSP and system the score covers
A Basic Assessment is associated with an SSP and system architecture. Match the SPRS entry to the internal SSP name, CAGE code or codes, and boundary description. If the company has multiple enclaves, avoid guessing from a similar name. Proposal staff should be able to point to one system record and say why it supports this opportunity.
Normalize names across the SSP, asset inventory, SPRS register, and proposal templates. Small naming differences such as 'CUI Enclave,' 'Secure Engineering,' and 'GovCloud Tenant' may refer to the same system, but they create confusion when ownership changes or a contracting officer asks for clarification.
Step 3: test whether the environment materially changed
Review major changes since the assessment: identity and access design, network segmentation, cloud tenancy, endpoint management, managed service providers, backup architecture, remote access, mergers, and acquisitions. The question is whether the assessment assumptions and score calculation still describe the environment relevant to the contract.
Do not automatically recalculate a score for every routine patch or hardware replacement. Use a documented material-change threshold. The threshold should focus on changes that affect the boundary, implementation of scored requirements, or the systems supporting contract performance.
Step 4: verify the live SPRS record
Check the live record rather than an exported screenshot from last quarter. Confirm assessment date, score, system description, and other identifying information that your process relies on. If the internal assessment workbook and SPRS disagree, treat the discrepancy as an issue to resolve before proposal submission, not as an administrative detail for later.
Keep evidence of the check, but keep SPRS as the government-facing source of truth. A PDF export can help reconstruct what was seen on a particular date; it should not become the master record that employees keep copying into new bids after the live entry changes.
Step 5: plan reassessment with business lead time
Working backward from formal expiration is better than waiting for it. Estimate how long your team needs to refresh the SSP, re-run the assessment, remediate score-impacting gaps, obtain management review, and update the government record. Then add proposal lead time. For many small firms, starting several months ahead is more realistic than a 30-day reminder.
Use the same calendar for contract options and extensions. Even when no new competitive proposal is involved, a contract action can prompt another currency check. A recurring control catches these events more reliably than depending on one employee to remember the original assessment date.
What to hand the proposal manager
Provide a short readiness card: system name, SPRS assessment date, score, planning expiration date, CAGE mapping, SSP owner, last material-change review, and the person who verified the record. Add a note if the solicitation imposes a shorter validity period. This gives the business team the facts it needs without distributing the whole security package.
The card should also say what it does not prove. A current Basic Assessment is not automatically a CMMC Level 2 status, a blanket statement about every company system, or evidence that no security changes are needed. Clear boundaries make the information more useful and reduce overclaiming in proposal language.
Three dates that teams often confuse
Keep three dates separate in the readiness register: the Basic Assessment completion date, any planning expiration date derived from the applicable DFARS rule or solicitation, and the date the team last verified the live SPRS record. They answer different questions. A record can be formally current but not recently verified, or recently verified but too old for a solicitation with a shorter validity period.
If CMMC status is also tracked, give it its own fields. A CMMC assessment date, annual affirmation date, and conditional closeout deadline should not be compressed into the same 'cyber expiration' column as the Basic Assessment. Shared dashboards are useful only when the labels remain precise.
Add a 'material change reviewed' date. This tells the proposal team when security last checked whether the scored system still matches the present architecture. It also gives the compliance owner a natural trigger for reviewing changes that may not justify immediate reassessment but should not remain undocumented.
Finally, record the person who verified each date and the source used. That creates accountability without turning the register into a certification document. The next bid team needs to understand what the date means, not merely see a green cell and assume it is safe.
If several opportunities share the same system, use the earliest meaningful procurement date as the planning constraint. This avoids a common scheduling trap in which security plans around the formal three-year deadline while sales is preparing a bid that will require a current record months earlier. Review the calendar at pipeline meetings so assessment currency is visible before an RFP becomes urgent.
Use the register in contract reviews, not only in security meetings. When a capture team opens a new opportunity, the assessment date and system mapping should be checked alongside CAGE data, registrations, and facility requirements. That makes currency a routine commercial input instead of a cybersecurity fact discovered at the end of proposal production.
If several business units share one SPRS administrator, give each assessed system a named business owner as well. The administrator can see the record; the business owner knows whether that system is still the one being offered. This pairing catches a common failure mode in growing companies: the score is technically current, but the proposal moved to a new tenant or acquired environment that the score never covered. Currency and applicability need to be checked together.
Before the proposal moves
- ✓Record every relevant SPRS assessment date
- ✓Map each record to a named system boundary
- ✓Add 180-day and 90-day pre-expiration reminders
- ✓Review solicitation-specific timing
- ✓Reconcile score with the latest SSP
- ✓Assign one owner for SPRS data quality
Common questions
Does SPRS automatically mean my score is valid for this proposal?
No. Verify which SPRS record the solicitation relies on, its date or status, the system it describes, and any shorter validity period written into the procurement.
Is the three-year Basic Assessment window the same as a CMMC annual affirmation?
No. A NIST SP 800-171 DoD Basic Assessment normally uses a three-year currency rule unless the solicitation shortens it, while CMMC affirmation has its own schedule. Track them as separate dates.
What should happen if the architecture changed after the score was posted?
Review whether the recorded assessment still represents the system that will perform the work. A date can still be within its nominal window while the underlying scope no longer matches reality.
Official sources used for this guide
Open the primary source before making a contract-specific decision. Regulations and program implementation can change.


