Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

CMMC Level 2 Certification an RFP Wants? Bid Anyway

An RFP you want to win says the offeror must hold CMMC Level 2 certification. You do not have it, and neither, at the moment, does anyone else who did not already hold a certificate. Before you write this one off, read the requirement word for word, because solicitations use three different terms as if they meant the same thing and they do not.

The difference between them is the difference between a bid you cannot make and a bid you can make this week. This article is part of Something Just Happened and You Need CMMC: A Triage Guide.

Three requirements that all get written as CMMC Level 2 certification

What the solicitation saysWhat it meansCan you satisfy it now
“A current NIST SP 800-171 assessment posted in SPRS” A self assessment score, dated within three years, on record Yes. This is achievable in days once you have PIEE access.
“CMMC Level 2 self assessment” You score yourself against all 110 requirements and affirm the result Yes, with the work described below.
“CMMC Level 2 certification” or “certified by a C3PAO” A third party assessment resulting in a certificate Not currently. Phase 2 certification assessments were suspended on July 13, 2026.

Find which of these your solicitation actually requires. Then look for a minimum score, because some solicitations set one, and a threshold changes the calculation entirely. For a fuller comparison of what each clause triggers, see DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers.

Use the question period. It is there for exactly this.

Most solicitations have a window for written questions, and this is the highest value hour you will spend on the pursuit. Ask plainly:

  1. Given that CMMC Phase 2 certification assessments are currently suspended, will the government accept a current self assessment posted in SPRS in satisfaction of the cybersecurity requirement?
  2. Is a minimum SPRS score required for eligibility, and if so, what is it?
  3. Must the requirement be met at time of proposal submission, at time of award, or during performance?
  4. Will controlled unclassified information be provided under this contract, and if so, how will it be transmitted?

Two things happen when you ask. You get an answer you can plan around, and the answer is published to all offerors as an amendment, which means the requirement stops being ambiguous for everyone. Contracting officers generally appreciate the question because unclear cybersecurity language creates protest exposure they would rather avoid.

Deciding whether to bid without CMMC Level 2 certification

Treat this as a normal capture decision with one extra variable, rather than as a compliance question. Four things determine the answer.

What is actually required. If the answer from the question period is a current self assessment, the barrier is administrative and you should bid. If it is a certificate, and the government confirms it, then no compliant offeror exists in your position and the requirement will probably be amended or the procurement delayed.

Where your score would land. An honest self assessment produces a number. Under 32 CFR 170.21 a conditional Level 2 status requires a score of at least 88 of 110 with the remaining items on a Plan of Action and Milestones, which is explained in Achieving Conditional CMMC Level 2 Certification with POA&M. That threshold is a useful yardstick even outside the certification process, because it tells you how a knowledgeable evaluator will read your number.

Time to award. If award is ninety days out, you have room to post a score and close gaps. If it is three weeks, your position on the day of submission is your position.

Whether the work is worth the program. If winning obligates you to hold controlled information for the first time, the true cost of this bid includes a compliance program, not just performance. Price it that way.

What to do in the two weeks you have

Assuming you decide to pursue it, the order matters more than the effort.

  • Confirm PIEE access with the SPRS Cyber Vendor role. Start today. Provisioning is the step that misses deadlines, and it has nothing to do with how hard your team works. If your posted assessment is also out of date, your SPRS score expired and a bid is due covers that sequence.
  • Confirm a System Security Plan exists and describes the environment you run now. Without it there is no valid assessment at all, because requirement 3.12.4 carries no point value and its absence stops the assessment rather than reducing the score.
  • Score all 110 requirements honestly and take the number you get. The mechanics are in How to Calculate Your SPRS Score.
  • Close the quick technical gaps in the remaining days. Multifactor authentication, removing shared administrator accounts, and turning on audit logging are usually available inside a week and usually worth points.
  • Post the score and get it affirmed by a senior official who understands what they are signing.

How to write it in the proposal

Say what is true, in specific terms, and let the evaluator see that you understand the requirement. Something close to this, adjusted to your facts:

The company maintains a current self assessment against NIST SP 800-171 posted in the Supplier Performance Risk System, with an assessment date of [date] and a score of [score], affirmed by [title]. A System Security Plan covering the assessed boundary and a Plan of Action and Milestones with assigned owners and completion dates are maintained and available for government review. The company will pursue CMMC Level 2 certification when third party assessments resume, and will maintain compliance with DFARS 252.204-7012 and the annual affirmation requirement throughout performance.

If you win and only then discover the clause in the executed contract, you won an award and then found the 7021 clause picks up from there.

That paragraph does three things. It states a verifiable fact, it demonstrates that you know certification is currently unavailable rather than that you failed to obtain it, and it commits to the obligations that are actually in force. Vague language about being committed to cybersecurity does none of that.

What not to write

Do not claim a certification you do not hold. Do not describe yourself as CMMC compliant without saying at what level and by what method. Do not state a score you have not posted and cannot evidence. A proposal statement about cybersecurity posture is a representation made to the government in connection with an award, and the Department of Justice has settled multiple cases under the Civil Cyber-Fraud Initiative involving exactly that kind of statement.

A score of 55 with a real plan will lose you very few competitions. A 110 you cannot support is a different category of problem and it follows the company for years.

Frequently asked

Questions about this topic

Can we bid on an RFP without CMMC Level 2 certification?
Usually yes, because most solicitations that use the phrase are asking for a current self assessment posted in SPRS rather than a third party certificate. Read the exact wording and submit a written question during the question period if it is ambiguous. The answer is published as an amendment and binds the evaluation.
Is anyone able to obtain Level 2 certification right now?
CMMC Phase 2 certification assessments were suspended on July 13, 2026, so new certificates are not currently being issued. Contractors who were already certified retain what they hold. Everyone else is in the same position you are.
What score do we need?
The clause requires a current assessment, not a threshold, unless the solicitation sets one. As a reference point, 32 CFR 170.21 sets 88 of 110 as the minimum for conditional Level 2 status with remaining items on a Plan of Action and Milestones. Read your solicitation for any stated minimum, since that governs.
Can we post a score during the proposal period?
Yes, and you should if yours is missing or expired. The submission itself takes under an hour once you have PIEE access and a completed assessment. The parts that take real time are the access request and the System Security Plan the assessment depends on.
Should we disclose a low score in the proposal?
State the score, the assessment date and the existence of a Plan of Action and Milestones. Evaluators can see your SPRS record, so there is nothing to gain by omission and real credibility to gain by addressing it directly.
What if we win and cannot meet the requirement during performance?
Raise it with the contracting officer in writing as soon as you know, and propose a compliance schedule. Contracting officers work with contractors on realistic timelines regularly. What they cannot work with is a gap they learn about from somebody else.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Table of Contents