ScopeHunter · From the build log
15 to 43: scoring ourselves, honestly
Our own SPRS self-assessment score, with every point accounted for. Published because a compliance product that hides its own number is asking you to trust something it will not do itself.
The number today
43 out of 110 (NIST SP 800-171 DoD Assessment Methodology, scored 2026-09-06 by the same engine our customers use). 67 points still deducted — every one of them named in our POA&M, most with a target date. 76 controls met, 16 partial, 3 known gaps, 13 recorded not applicable (only five of those are the Annex A waivers; the rest still deduct and are queued for honest reclassification), 2 not yet assessed.
That is not a marketing number. The methodology starts everyone at 110 and subtracts weighted deductions for anything not fully implemented — a requirement nobody has examined costs the same as a known failure. Scores below zero are common for first assessments. Ours started at 15.
How it moved
| Date | Score | What actually happened |
|---|---|---|
| Aug 22 | 15 | First honest baseline after we stopped counting policy documents as implementation. A painful number we chose to keep, because the alternative was lying to ourselves with our own product. |
| Sep 2 | 33 | Accepted provider inheritance from Google Cloud under its FedRAMP High authorization — through a proposal flow that showed every control delta before one click applied it. Physical and environmental controls we genuinely do not operate moved to met-inherited, each citing the authorization relied upon. |
| Sep 5–6 | 43 | The scoping pass: environmental facts (no wireless in the boundary, no mobile devices touching it, no VPN to split-tunnel) recorded as the Annex A methodology actually scores them — five requirements as conditional N/A, the rest as met-by-prohibition, because N/A on a non-waived requirement deducts the same as unimplemented. Plus live evidence flipping controls the automation could finally prove. |
What stands behind it
The score is derived, not declared. Behind it, on this production system, as of this writing:
- 761 control-status transitions since August 9, every one logged with what changed it — a human, a host report, an accepted proposal. The trail an assessor asks for first.
- 137 distinct automated checks reporting from the OS-hardening formula, the cloud integration, and the platform''s own org-evidence runs. A machine-written status is never overwritten by hand silently, and a hand-written one is never overwritten by a machine — the transition log holds both sides honest.
- 143,000+ vendor security advisories mirrored nightly and correlated against what is actually installed — findings say "patch these two, reboot for that kernel," and since September, every remediation writes a receipt: what was exposed, for how long, resolved how.
- 56 controls carrying inheritance from Google Cloud — labeled inherited, never blended into our own count, because an assessor will ask which is which.
Why 43 is worth publishing
Because the failure mode of this industry is the confident number. A score of 110 on day one means someone answered a questionnaire optimistically; ours moved only when evidence or an accountable human moved it, and the 67 missing points are a work list, not a secret. When CMMC Phase II assessments resume, the contractors in trouble will be the ones whose SPRS submission and reality diverge — the False Claims Act does not care which questionnaire you used.
If you want your own honest number: the same engine, checks, and proposal flows that produced ours are the product. It will probably tell you something lower than you hoped. That is the point.
How the host evidence is automated · The build log · Compliance FAQ
All figures queried from our production database on the date shown; this page is updated when the number moves materially, in either direction.