Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
CMMC Level 2 Self-Assessment Requirements
Updated July 2026: This article used to explain when the DoD allowed Level 2 self-assessment instead of a third-party audit. As of July 13, 2026, that question answered itself: C3PAO certification assessments are suspended, and Level 2 (Self) is the only Level 2 designation contracts may include. Self-assessment isn’t the budget option anymore — it’s the system. Full context: CMMC Phase 2 Is Suspended. Your Compliance Obligations Are Not.
CMMC Level 2 self-assessment means your organization evaluates its own compliance with all 110 NIST SP 800-171 requirements, scores the result, submits it to SPRS, and has a senior official affirm it annually — without a third-party assessor involved.
Before July 13, 2026, this was the path for a subset of lower-sensitivity contracts. Today it’s the path for everyone at Level 2, and that promotion comes with a catch worth understanding before you start: the auditor who would have caught your mistakes is gone, but the legal weight of your score is not. This guide walks through the requirements, the process, the conditional-status rules (including the number most articles get wrong), and how to self-assess in a way you can defend.
Self-assessment means your organization evaluates its own compliance rather than hiring a C3PAO — a Certified Third-Party Assessment Organization — to assess you.
NIST SP 800-171 is the federal standard specifying 110 security requirements for protecting Controlled Unclassified Information (CUI). It’s made contractually binding by DFARS clause 252.204-7012, which the suspension did not touch.
Who Self-Assesses Now (Everyone) — and What the Old Split Was
The current rule, per the July 13 implementing memo: contracting officers may only include CMMC Level 1 (Self) or Level 2 (Self) in solicitations and contracts. Level 2 (C3PAO) and Level 3 (DIBCAC) designations are prohibited during the CMMC reform review, and existing contracts containing them are being amended to remove them. You don’t request this — it’s happening government-wide.
The old split, for context (and because some version of it may return after the review): the program divided Level 2 contracts by CUI sensitivity — self-assessment for lower-sensitivity programs, C3PAO certification for higher-sensitivity and national-security-critical ones, with the contract dictating which. If the reform task force brings back a third-party layer, expect it to be narrower than the old universal-audit plan; the Department’s own review mandate calls for replacing “prohibitive third-party compliance models with scalable, realistic security measures.”
Two things that continue regardless:
- Select government-led assessments. The Department explicitly reserved the right to conduct these during the review. DIBCAC can still show up — self-assessed doesn’t mean never-checked.
- Prime contractor scrutiny. Primes own their supply-chain risk under DFARS 7012 flowdown, and with government verification suspended, many are leaning harder on their own supplier reviews, not lighter.
What You Assess: All 110 Requirements, at the Objective Level
Level 2 self-assessment covers the full NIST SP 800-171 Rev 2 control set across 14 families:
Access Control (22), Awareness and Training (3), Audit and Accountability (9), Configuration Management (9), Identification and Authentication (11), Incident Response (3), Maintenance (6), Media Protection (9), Personnel Security (2), Physical Protection (6), Risk Assessment (3), Security Assessment (4), System and Communications Protection (16), and System and Information Integrity (7).
But the real unit of assessment isn’t the control — it’s the assessment objective. NIST SP 800-171A breaks the 110 controls into roughly 320 specific, checkable statements, and a control only counts as implemented when every objective behind it is met. “We have MFA” is a control-level claim; 800-171A asks whether it covers local access, network access, and privileged accounts separately. Self-assessments that stop at the control level systematically overstate scores — which, in the current enforcement environment, is precisely the mistake to avoid.
The Self-Assessment Process
Step 1: Define Your CUI Boundary
Identify every system that stores, processes, or transmits CUI: workstations and servers, network infrastructure connecting them, cloud services, mobile devices, backup systems. Document what’s in scope and what’s excluded, and why. Scope is also your biggest cost lever — a contained CUI boundary means fewer systems assessed against those ~320 objectives (our scope-reduction guide covers this in depth).
Step 2: Confirm Your SSP Exists and Is Current
This deserves its own step because the methodology makes it a gate: security requirement 3.12.4 (the System Security Plan) has no point value, and the absence of an SSP means an assessment cannot be completed at all — no valid score exists without one. If your SSP is missing or describes an environment you no longer run, fix that before scoring anything.
An SSP is a System Security Plan — the document describing how your environment implements each requirement. A POA&M is a Plan of Action and Milestones — your tracked list of gaps and remediation plans.
Step 3: Assess Each Requirement Against 800-171A
For each requirement, work through its assessment objectives and determine status: implemented (every objective met, operating today — not just written in a policy), not implemented, or — rarely, and with documented justification — not applicable.
Step 4: Calculate Your Score
Use the DoD Assessment Methodology: start at 110 and subtract the point value (1, 3, or 5) of each unimplemented requirement. Scores run from 110 down to -203. Two details most self-assessments miss:
- Partial credit exists for exactly two controls: 3.5.3 (MFA) and 3.13.11 (FIPS-validated cryptography) can deduct 3 points instead of 5 in defined partial-implementation cases. Everything else is all-or-nothing.
- Getting these rules right matters in both directions — misapplying partial credit inflates your score (legal risk); missing it where it legitimately applies understates it (competitive cost).
Full walkthrough with examples: How to Calculate Your SPRS Score.
Step 5: Document Everything
Your assessment package: the SSP, your methodology, evidence supporting every implemented determination (organized control by control), and a POA&M for every gap. This documentation is what separates a defensible self-assessment from a hopeful one — it’s what a government-led assessment would examine, what a prime’s supplier review would request, and what protects the person who signs in Step 6.
Step 6: Senior Official Affirmation
A senior company official affirms the assessment was conducted properly, the results are accurate, and compliance will be maintained. This is a personal attestation to the federal government in connection with contract awards — squarely inside the False Claims Act, with treble damages and a DOJ Civil Cyber-Fraud Initiative that has already settled multimillion-dollar cases over inflated scores. Post-suspension, this signature carries the weight the audit used to: brief your Affirming Official accordingly, and have them review the evidence, not just the number.
Step 7: Submit to SPRS
Enter your results — assessment date, score, POA&M completion date if applicable, CMMC status, and affirming official information — via the PIEE portal using the SPRS Cyber Vendor role. Your assessment must be current within three years. Step-by-step: How to Submit Your SPRS Score.
POA&M and Conditional Status: The 88-Point Rule
Unlike Level 1, Level 2 self-assessment allows a conditional status with open POA&M items — within strict limits set by 32 CFR Part 170:
- Minimum score of 88 out of 110. This is 80% of the total points, and 80% of 110 is 88 — not 80. The “score of 80” figure that circulates in many guides is simply wrong, and it’s a seven-point difference that matters.
- Not everything can be POA&M’d. Certain critical requirements — generally the highest-weighted controls — must be implemented outright; a gap there can’t ride on a plan.
- 180 days to close. All POA&M items must be remediated within 180 days of the assessment. Miss the window and the conditional status expires.
- Full status requires all 110 implemented, a score of 110, and no open POA&M items.
The design logic is worth internalizing: the system rewards accuracy, not perfection. An honest 91 with a real POA&M is a legitimate, defensible conditional status. An inflated 110 is a liability with your Affirming Official’s name on it.
Annual Affirmation and Reassessment
- Every 12 months, the senior official re-affirms continued compliance and POA&M progress. Calendar it at submission — a lapsed affirmation is visible to contracting officers.
- Reassess fully when your CUI environment changes significantly, after security incidents, and at least every three years to keep your score current.
- Correct promptly if you discover your posted score overstates reality. An honest downward correction with a POA&M is a defensible position; a known-inflated score left standing while being affirmed annually is the exact fact pattern False Claims Act cases are built on.
Self-Assessment vs. Certification Assessment (Current State)
| Aspect | Self-Assessment | C3PAO Certification |
|---|---|---|
| Status | ✅ The only Level 2 path contracts may currently require | ⛔ Suspended as of July 13, 2026, pending the CMMC review |
| Who assesses | Your organization (or an independent firm you engage) | Accredited third-party assessor |
| Cost | Internal effort, or a fixed-fee independent assessment ($7,500–$15,000 at Greypike) | Was typically $35,000–$100,000+, paid to the assessor |
| Verification | Your evidence + your affirmation; select government-led assessments continue | Independent verification |
| Legal surface | Annual affirmation under the False Claims Act | Assessor findings preceded government reliance |
Common Level 2 Self-Assessment Mistakes
Mistake 1: Treating self-assessed as unverified. Government-led assessments continue, primes are checking harder, and whistleblowers don’t need an audit regime. Assess as if someone will look, because someone can.
Mistake 2: Scoring at the control level. Skipping the 800-171A objectives is the single biggest source of inflated scores. The bar is every objective met, not “we have something like that.”
Mistake 3: Missing the two partial-credit rules — or inventing others. Only 3.5.3 and 3.13.11 score partially. Applying partial credit anywhere else overstates; missing it there understates.
Mistake 4: Using 80 as the conditional threshold. It’s 88. Building a remediation plan to reach 80 leaves you seven points short of a valid conditional status.
Mistake 5: Ignoring the 180-day clock. Conditional isn’t a resting state. Sequence the POA&M by SPRS impact and calendar the deadline on day one.
Mistake 6: An unbriefed affirmation. The senior official signing should have reviewed the evidence, not just received the score. Post-suspension, their signature is where the entire program’s legal weight sits.
Key Takeaways
During the CMMC suspension, Level 2 self-assessment is the only Level 2 path contracts may require — the old sensitivity-based split between self-assessment and C3PAO certification is on hold pending the 60-day reform review. The work: assess all 110 NIST 800-171 requirements at the ~320-objective level, calculate your score per the DoD methodology (including the two partial-credit rules), document evidence, and have a senior official affirm annually.
Conditional status requires a minimum score of 88 (not 80), a compliant POA&M, and closure within 180 days — and certain critical controls can’t be POA&M’d at all. With no auditor between your score and government reliance on it, accuracy is the whole game: an honest score with a real plan is defensible; an inflated one is False Claims Act exposure with a name attached.
Related Articles:
- How to Calculate Your SPRS Score
- How to Submit Your SPRS Score
- CMMC Scope Reduction: Cutting Compliance Costs by 40%+
- How to Define Your CMMC Level 2 Assessment Boundary
- CMMC Phase 2 Is Suspended. Your Compliance Obligations Are Not.
Official Sources: 32 CFR §§ 170.16 and 170.21 (Level 2 self-assessment and CMMC status requirements), NIST SP 800-171 Revision 2, NIST SP 800-171A, the NIST SP 800-171 DoD Assessment Methodology (v1.2.1), and the July 13, 2026 Department of War memoranda (publication case 26-P-1023).
Self-assessing doesn’t have to mean assessing alone. Greypike’s fixed-fee Roadmap — the same engagement we call SPRS Attestation Assurance — is an independent assessment of all ~320 objectives with corrected scoring and evidence your Affirming Official can actually sign behind, at $7,500–$15,000 flat. Or run this guide yourself and calculate your score with our free tool.