Process · CMMC Guide

CMMC Self-Assessment Requirements: What Is Required, What Is Risky

Self-assessment requires the same controls, documentation, and evidence as a C3PAO assessment. The only thing missing is the assessor.

ProcessSelf-Assessment

By Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending
Published May 20, 2026 · 5 min read · CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

Self-assessment sounds easy. It is not. A CMMC self-assessment requires the same control implementation, the same documentation, and the same evidence quality as a C3PAO assessment. The only thing missing is the assessor. Both a Level 2 self-assessment and a Level 2 certification assessment require a MET result on the same 110 requirements, scored the same way (32 CFR 170.16, 170.17, 170.24). The affirmation entered in the Supplier Performance Risk System (SPRS) is made by a named Affirming Official and states that your organization has implemented, and will maintain, all applicable CMMC security requirements (32 CFR 170.22(a)(2)). Here is what self-assessment actually requires, and what gets contractors in trouble. (We are a readiness Agent-as-a-Service (AaaS) provider; we are not a C3PAO and do not issue certifications.)

When self-assessment is allowed

Level 1, which covers Federal Contract Information, is a self-assessment performed annually, with an affirmation at completion and annually thereafter (32 CFR 170.15(a), 170.22(b)(1)). At Level 2, which involves CUI, the solicitation names the assessment type: Level 2 (Self) or Level 2 (C3PAO). On July 13, 2026 the Department of War suspended the CMMC phased implementation schedule, including the November 2026 Phase 2 transition. While the suspension lasts, requiring activities may designate only Level 1 (Self) or Level 2 (Self), and existing Level 2 (C3PAO) requirements are to be removed by solicitation amendment or contract modification (DoW CMMC Procedures memo, Attachment 1, July 13, 2026). Read the contract. Do not infer the assessment type from the level alone.

What a CMMC self-assessment must produce

Four artifacts at Level 2. Three are required every time; the POA&M applies only if you use one to reach Conditional status. None of them are easier because you are doing the assessment yourself.

System Security Plan

At Level 2, the SSP is itself a requirement (NIST SP 800-171 3.12.4), and it is one of six requirements that may never be on a POA&M (32 CFR 170.21(a)(2)(iii)). Under 3.12.4 the SSP describes system boundaries, environments of operation, how each requirement is implemented, and connections to other systems. It is not a checklist. A self-assessment SSP needs to be the document an outside reviewer could use to predict what they would see in your environment.

Evidence for every control

Self-assessment does not mean self-attestation without proof. A requirement is MET only when evidence shows it, and that evidence must be in final form, not draft (32 CFR 170.24(b)(1)). You need it for yourself, for the executive who is about to sign the affirmation, and for any later review, including a DCMA DIBCAC assessment, which DoD reserves the right to conduct (32 CFR 170.16(a)(1)(iv)). Evidence quality is what separates a self-assessment that holds up from one that does not.

POA&M, where permitted

Some requirements can sit on a Plan of Action and Milestones with a closure timeline. Not every requirement is POA&M-eligible: only 1-point requirements qualify (with one encryption exception), six named requirements never do, the score must be at least 88 of 110, and items must be closed out within 180 days (32 CFR 170.21). No POA&M is permitted at Level 1. Treat the POA&M as a debt schedule with a hard due date, not as a parking lot.

Executive affirmation in SPRS

Your Affirming Official, the senior representative responsible for your CMMC compliance, affirms in SPRS that your organization has implemented and will maintain the applicable requirements, at completion of the assessment and annually after that (32 CFR 170.22). It is a formal statement to the Government, made by a named person. Affirmations are not paperwork. They are decisions.

Before an executive signs anything, get an honest read on your control status. The free 10-question gap check is a directional self-assessment, not an official SPRS score, but it shows where the gaps are. Run the free gap check →

Five self-assessment failure patterns

Self-assessment vs C3PAO assessment

A C3PAO assessment costs more. The DoD's own estimates in the final rule put the three-year cost of a Level 2 self-assessment with its affirmations at $37,196 for a small entity and $48,827 for an other-than-small entity, and a Level 2 certification assessment at $104,670 and $117,768 (89 FR 83092, at 83182-83185). Those estimates assume the NIST SP 800-171 requirements are already implemented, so they leave out the cost of implementing them. The choice is usually not yours: the solicitation names the assessment type, and during the Phase 2 suspension requiring activities may designate only Level 2 (Self). A self-assessment carries no third-party finding, only your own, and a senior official's name on the affirmation. For the full path either way, see our CMMC certification process timeline.

What the affirmation commits you to

The Affirming Official who submits the SPRS affirmation states, by name, that the applicable requirements are implemented and will be maintained (32 CFR 170.22(a)(2)). In the final rule, DoD noted that it cannot change the False Claims Act, a Federal law that imposes liability on persons and companies who knowingly submit false claims to the government (89 FR 83109). This is not legal advice, and you should talk to your counsel, but no senior official should sign an affirmation they have not personally been walked through. The brief is the discipline that documents what the affirmation rests on.

How Agent-as-a-Service keeps self-assessment evidence current

The hardest part of self-assessment is keeping yourself honest. Agent-as-a-Service helps, not because the AI judges you, but because it records and time-stamps what was measured whether or not anyone remembers to. Connected sources are re-scanned about every seven days, and the Level 2 package is rebuilt on your tier's cycle. The SSP is built from measured findings where a connected source can show them; elsewhere it uses your team's attestations, and a requirement with no evidence on file is scored not met. When the executive sits down to sign the affirmation, the brief is real: the record shows what was measured, when, and what your team substantiated, so the basis and timing of what the executive affirms are documented. The executive still owns the decision. The system gives the team the leverage to make it a decision based on facts. If you are not sure yet whether you even qualify for self-assessment, start with the CMMC assessment readiness checklist.

Know where you stand before you spend a dollar on remediation

The free gap check gives you a directional read from 10 questions. The CMMC Level 2 Readiness Snapshot checks your intake, and the read-only configuration of any cloud you connect, against the 110-requirement NIST SP 800-171 Rev. 2 baseline; it measures only the requirements a connected source can show, and returns a PDF of your top gaps within minutes of intake, for $999 one time. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2. Readiness subscriptions are billed annually, with a month-to-month option on every tier.

Run the free 10-question gap check See the $999 Level 2 Readiness Snapshot
CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

Disclaimer. This article is general information about CMMC, not legal, compliance, financial, or assessment advice, and it does not create any advisory or contractual relationship. CMMC regulations and figures change; nothing here is a representation, warranty, or guarantee of any outcome, score, cost, timeline, or certification. Verify current requirements with your own qualified counsel and an authorized C3PAO before making decisions. Dollar figures attributed to the DoD are its published estimates from the CMMC Program Regulatory Impact Analysis, not quotes or predictions of your cost.

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. We do not issue, grant, or guarantee any CMMC status or certification. A Level 2 certification assessment is conducted by an authorized or accredited C3PAO (32 CFR 170.17). The free gap check is a directional self-assessment and is not an official SPRS score. Patent Pending. ElasticD3M, LLC, Texas. All third-party names and frameworks are referenced for identification only and remain the property of their respective owners.