If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
CMMC Level 2 Certification an RFP Wants? Bid Anyway
An RFP you want to win says the offeror must hold CMMC Level 2 certification. You do not have it, and neither, at the moment, does anyone else who did not already hold a certificate. Before you write this one off, read the requirement word for word, because solicitations use three different terms as if they meant the same thing and they do not.
The difference between them is the difference between a bid you cannot make and a bid you can make this week. This article is part of Something Just Happened and You Need CMMC: A Triage Guide.
Three requirements that all get written as CMMC Level 2 certification
| What the solicitation says | What it means | Can you satisfy it now |
|---|---|---|
| “A current NIST SP 800-171 assessment posted in SPRS” | A self assessment score, dated within three years, on record | Yes. This is achievable in days once you have PIEE access. |
| “CMMC Level 2 self assessment” | You score yourself against all 110 requirements and affirm the result | Yes, with the work described below. |
| “CMMC Level 2 certification” or “certified by a C3PAO” | A third party assessment resulting in a certificate | Not currently. Phase 2 certification assessments were suspended on July 13, 2026. |
Find which of these your solicitation actually requires. Then look for a minimum score, because some solicitations set one, and a threshold changes the calculation entirely. For a fuller comparison of what each clause triggers, see DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers.
Use the question period. It is there for exactly this.
Most solicitations have a window for written questions, and this is the highest value hour you will spend on the pursuit. Ask plainly:
- Given that CMMC Phase 2 certification assessments are currently suspended, will the government accept a current self assessment posted in SPRS in satisfaction of the cybersecurity requirement?
- Is a minimum SPRS score required for eligibility, and if so, what is it?
- Must the requirement be met at time of proposal submission, at time of award, or during performance?
- Will controlled unclassified information be provided under this contract, and if so, how will it be transmitted?
Two things happen when you ask. You get an answer you can plan around, and the answer is published to all offerors as an amendment, which means the requirement stops being ambiguous for everyone. Contracting officers generally appreciate the question because unclear cybersecurity language creates protest exposure they would rather avoid.
Deciding whether to bid without CMMC Level 2 certification
Treat this as a normal capture decision with one extra variable, rather than as a compliance question. Four things determine the answer.
What is actually required. If the answer from the question period is a current self assessment, the barrier is administrative and you should bid. If it is a certificate, and the government confirms it, then no compliant offeror exists in your position and the requirement will probably be amended or the procurement delayed.
Where your score would land. An honest self assessment produces a number. Under 32 CFR 170.21 a conditional Level 2 status requires a score of at least 88 of 110 with the remaining items on a Plan of Action and Milestones, which is explained in Achieving Conditional CMMC Level 2 Certification with POA&M. That threshold is a useful yardstick even outside the certification process, because it tells you how a knowledgeable evaluator will read your number.
Time to award. If award is ninety days out, you have room to post a score and close gaps. If it is three weeks, your position on the day of submission is your position.
Whether the work is worth the program. If winning obligates you to hold controlled information for the first time, the true cost of this bid includes a compliance program, not just performance. Price it that way.
What to do in the two weeks you have
Assuming you decide to pursue it, the order matters more than the effort.
- Confirm PIEE access with the SPRS Cyber Vendor role. Start today. Provisioning is the step that misses deadlines, and it has nothing to do with how hard your team works. If your posted assessment is also out of date, your SPRS score expired and a bid is due covers that sequence.
- Confirm a System Security Plan exists and describes the environment you run now. Without it there is no valid assessment at all, because requirement 3.12.4 carries no point value and its absence stops the assessment rather than reducing the score.
- Score all 110 requirements honestly and take the number you get. The mechanics are in How to Calculate Your SPRS Score.
- Close the quick technical gaps in the remaining days. Multifactor authentication, removing shared administrator accounts, and turning on audit logging are usually available inside a week and usually worth points.
- Post the score and get it affirmed by a senior official who understands what they are signing.
How to write it in the proposal
Say what is true, in specific terms, and let the evaluator see that you understand the requirement. Something close to this, adjusted to your facts:
The company maintains a current self assessment against NIST SP 800-171 posted in the Supplier Performance Risk System, with an assessment date of [date] and a score of [score], affirmed by [title]. A System Security Plan covering the assessed boundary and a Plan of Action and Milestones with assigned owners and completion dates are maintained and available for government review. The company will pursue CMMC Level 2 certification when third party assessments resume, and will maintain compliance with DFARS 252.204-7012 and the annual affirmation requirement throughout performance.
If you win and only then discover the clause in the executed contract, you won an award and then found the 7021 clause picks up from there.
That paragraph does three things. It states a verifiable fact, it demonstrates that you know certification is currently unavailable rather than that you failed to obtain it, and it commits to the obligations that are actually in force. Vague language about being committed to cybersecurity does none of that.
What not to write
Do not claim a certification you do not hold. Do not describe yourself as CMMC compliant without saying at what level and by what method. Do not state a score you have not posted and cannot evidence. A proposal statement about cybersecurity posture is a representation made to the government in connection with an award, and the Department of Justice has settled multiple cases under the Civil Cyber-Fraud Initiative involving exactly that kind of statement.
A score of 55 with a real plan will lose you very few competitions. A 110 you cannot support is a different category of problem and it follows the company for years.
Frequently asked
Questions about this topic
Can we bid on an RFP without CMMC Level 2 certification?
Is anyone able to obtain Level 2 certification right now?
What score do we need?
Can we post a score during the proposal period?
Should we disclose a low score in the proposal?
What if we win and cannot meet the requirement during performance?
Keep reading
More in Trigger Events & Urgent Situations
- 90 Days to CMMC Compliance: What Is Really Possible →
- CMMC Compliant MSP? How to Verify What Yours Claims →
- CMMC Trigger Events: A Triage Guide for Contractors →
- CUI in Commercial Microsoft 365: What to Do Now →
- CUI Marked Drawings You Were Not Expecting? Do This →
- Cybersecurity Questionnaire From Your Prime? Do This →
- DFARS 7021 Clause Found After Award? Read This First →
- Dropped Without CMMC? What a Prime Can Actually Do →
- Expired SPRS Score and a Bid Due? Fix It This Week →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5