Self-assessment sounds easy. It is not. A CMMC self-assessment requires the same control implementation, the same documentation, and the same evidence quality as a C3PAO assessment. The only thing missing is the assessor. Both a Level 2 self-assessment and a Level 2 certification assessment require a MET result on the same 110 requirements, scored the same way (32 CFR 170.16, 170.17, 170.24). The affirmation entered in the Supplier Performance Risk System (SPRS) is made by a named Affirming Official and states that your organization has implemented, and will maintain, all applicable CMMC security requirements (32 CFR 170.22(a)(2)). Here is what self-assessment actually requires, and what gets contractors in trouble. (We are a readiness Agent-as-a-Service (AaaS) provider; we are not a C3PAO and do not issue certifications.)
When self-assessment is allowed
Level 1, which covers Federal Contract Information, is a self-assessment performed annually, with an affirmation at completion and annually thereafter (32 CFR 170.15(a), 170.22(b)(1)). At Level 2, which involves CUI, the solicitation names the assessment type: Level 2 (Self) or Level 2 (C3PAO). On July 13, 2026 the Department of War suspended the CMMC phased implementation schedule, including the November 2026 Phase 2 transition. While the suspension lasts, requiring activities may designate only Level 1 (Self) or Level 2 (Self), and existing Level 2 (C3PAO) requirements are to be removed by solicitation amendment or contract modification (DoW CMMC Procedures memo, Attachment 1, July 13, 2026). Read the contract. Do not infer the assessment type from the level alone.
What a CMMC self-assessment must produce
Four artifacts at Level 2. Three are required every time; the POA&M applies only if you use one to reach Conditional status. None of them are easier because you are doing the assessment yourself.
System Security Plan
At Level 2, the SSP is itself a requirement (NIST SP 800-171 3.12.4), and it is one of six requirements that may never be on a POA&M (32 CFR 170.21(a)(2)(iii)). Under 3.12.4 the SSP describes system boundaries, environments of operation, how each requirement is implemented, and connections to other systems. It is not a checklist. A self-assessment SSP needs to be the document an outside reviewer could use to predict what they would see in your environment.
Evidence for every control
Self-assessment does not mean self-attestation without proof. A requirement is MET only when evidence shows it, and that evidence must be in final form, not draft (32 CFR 170.24(b)(1)). You need it for yourself, for the executive who is about to sign the affirmation, and for any later review, including a DCMA DIBCAC assessment, which DoD reserves the right to conduct (32 CFR 170.16(a)(1)(iv)). Evidence quality is what separates a self-assessment that holds up from one that does not.
POA&M, where permitted
Some requirements can sit on a Plan of Action and Milestones with a closure timeline. Not every requirement is POA&M-eligible: only 1-point requirements qualify (with one encryption exception), six named requirements never do, the score must be at least 88 of 110, and items must be closed out within 180 days (32 CFR 170.21). No POA&M is permitted at Level 1. Treat the POA&M as a debt schedule with a hard due date, not as a parking lot.
Executive affirmation in SPRS
Your Affirming Official, the senior representative responsible for your CMMC compliance, affirms in SPRS that your organization has implemented and will maintain the applicable requirements, at completion of the assessment and annually after that (32 CFR 170.22). It is a formal statement to the Government, made by a named person. Affirmations are not paperwork. They are decisions.
Before an executive signs anything, get an honest read on your control status. The free 10-question gap check is a directional self-assessment, not an official SPRS score, but it shows where the gaps are. Run the free gap check →
Five self-assessment failure patterns
- Scoring with optimism instead of evidence.
- SSPs that describe a future state rather than the present state.
- MFA gaps on accounts the contractor forgot existed: service accounts, vendor accounts, legacy admin.
- No evidence pipeline, so the answer to "can you show me" is always "give me a week."
- An executive affirmation signed without an honest brief. The person who signs needs to understand what they are signing.
Self-assessment vs C3PAO assessment
A C3PAO assessment costs more. The DoD's own estimates in the final rule put the three-year cost of a Level 2 self-assessment with its affirmations at $37,196 for a small entity and $48,827 for an other-than-small entity, and a Level 2 certification assessment at $104,670 and $117,768 (89 FR 83092, at 83182-83185). Those estimates assume the NIST SP 800-171 requirements are already implemented, so they leave out the cost of implementing them. The choice is usually not yours: the solicitation names the assessment type, and during the Phase 2 suspension requiring activities may designate only Level 2 (Self). A self-assessment carries no third-party finding, only your own, and a senior official's name on the affirmation. For the full path either way, see our CMMC certification process timeline.
What the affirmation commits you to
The Affirming Official who submits the SPRS affirmation states, by name, that the applicable requirements are implemented and will be maintained (32 CFR 170.22(a)(2)). In the final rule, DoD noted that it cannot change the False Claims Act, a Federal law that imposes liability on persons and companies who knowingly submit false claims to the government (89 FR 83109). This is not legal advice, and you should talk to your counsel, but no senior official should sign an affirmation they have not personally been walked through. The brief is the discipline that documents what the affirmation rests on.
How Agent-as-a-Service keeps self-assessment evidence current
The hardest part of self-assessment is keeping yourself honest. Agent-as-a-Service helps, not because the AI judges you, but because it records and time-stamps what was measured whether or not anyone remembers to. Connected sources are re-scanned about every seven days, and the Level 2 package is rebuilt on your tier's cycle. The SSP is built from measured findings where a connected source can show them; elsewhere it uses your team's attestations, and a requirement with no evidence on file is scored not met. When the executive sits down to sign the affirmation, the brief is real: the record shows what was measured, when, and what your team substantiated, so the basis and timing of what the executive affirms are documented. The executive still owns the decision. The system gives the team the leverage to make it a decision based on facts. If you are not sure yet whether you even qualify for self-assessment, start with the CMMC assessment readiness checklist.