Skip to content

How to Conduct a CMMC Level 2 Self-Assessment

A self-assessment is an event, not an ongoing activity — and not a signature on a form. 32 CFR Part 170 gives it specific rules, and it looks a lot more like what a C3PAO does than most contractors expect. Here is what the rule requires, and the six-step method our Lead Assessors use to run it in a way that survives scrutiny.


What the rule requires

The CMMC Program rule, 32 CFR Part 170 (89 FR 83214, October 15, 2024), sets out in 32 CFR 170.16 exactly what an organization must do to achieve and hold a CMMC Status of Level 2 (Self). Throughout, OSA means Organization Seeking Assessment — that's you. In brief:

  • Assess against the right standard, within the right scope — a self-assessment "in accordance with NIST SP 800-171A Jun2018" and the CMMC Level 2 scoping requirements, for the systems in your CMMC Assessment Scope (32 CFR 170.16(c)(1)). That means all 320 assessment objectives across the 110 requirements, by the examine / interview / test methods; a requirement is MET only when every objective under it is met.
  • Score it under the CMMC Scoring Methodology (32 CFR 170.24): maximum 110; weighted deductions of 5, 3, or 1 point per NOT MET requirement; partial-credit rules for MFA and FIPS-validated encryption; scores run down to −203.
  • Submit the results in SPRS with, at minimum: CMMC Level, CMMC Status Date, CMMC Assessment Scope, all industry CAGE codes for the systems in scope, the overall score, and POA&M usage and compliance status (32 CFR 170.16(a)(1)(i)).
  • Know which status your results produce. A passing score is Final Level 2 (Self) — valid three years with annual affirmation. A score of at least 88 of 110 with only POA&M-eligible items open is Conditional Level 2 (Self) (32 CFR 170.21(a)(2)): only one-point requirements may ride a POA&M (single exception: CUI Encryption employed but not FIPS-validated), and six requirements may never appear on one.
  • Close the POA&M within 180 days or the status expires — "If the POA&M is not successfully closed out within the 180-day timeframe, the Conditional Level 2 (Self) CMMC Status for the information system will expire" (32 CFR 170.16(a)(1)(ii)(B)), with contract-eligibility consequences.
  • Affirm — at the assessment, at closeout, and annually — by your Affirming Official, electronically in SPRS (32 CFR 170.16(a)(2), 170.22).
  • Repeat the self-assessment every three years (32 CFR 170.16(a)(1)).
  • Using a CSP or ESP? A cloud service handling CUI must be FedRAMP Moderate Authorized or meet equivalent security requirements per DoD Policy; a non-CSP external service provider must be documented in your SSP and assessed within your scope; both require the Customer Responsibility Matrix documented or referred to in your SSP (32 CFR 170.16(c)(2)–(3)).
  • Retain the artifacts for six years from the CMMC Status Date (32 CFR 170.16(c)(4)).
  • DoD can check. DCMA DIBCAC may assess you under 48 CFR 252.204-7020, and if its results show the rule's provisions were not achieved or maintained, they take precedence over your self-assessed status (32 CFR 170.16(a)(1)(iv)).
Read the full regulatory text — 32 CFR 170.16, verbatim (click to expand)

Source: eCFR, current as of July 22, 2026. Rule published 89 FR 83214, October 15, 2024. Internal cross-references to other sections of the rule appear in brackets.

32 CFR 170.16 — CMMC Level 2 self-assessment and affirmation requirements.

(a) Level 2 self-assessment. To comply with Level 2 self-assessment requirements, the OSA must meet the requirements detailed in paragraphs (a)(1) and (2) of this section. An OSA conducts a Level 2 self-assessment as detailed in paragraph (c) of this section to achieve a CMMC Status of either Conditional or Final Level 2 (Self). Achieving a CMMC Status of Level 2 (Self) also satisfies the requirements for a CMMC Status of Level 1 (Self) detailed in [170.15] for the same CMMC Assessment Scope.

(1) Level 2 self-assessment requirements. The OSA must complete and achieve a MET result for all security requirements specified in [170.14(c)(3)] to achieve the CMMC Status of Level 2 (Self). The OSA must conduct a self-assessment in accordance with the procedures set forth in paragraph (c)(1) of this section and submit assessment results in Supplier Performance Risk System (SPRS). To maintain compliance with the requirements for a CMMC Status of Level 2 (Self), the OSA must conduct a Level 2 self-assessment every three years and submit the results in SPRS, within three years of the CMMC Status Date associated with the Conditional Level 2 (Self).

(i) Inputs to SPRS. The Level 2 self-assessment results in the SPRS shall include, at minimum, the following information:

(A) CMMC Level.

(B) CMMC Status Date.

(C) CMMC Assessment Scope.

(D) All industry CAGE code(s) associated with the information system(s) addressed by the CMMC Assessment Scope.

(E) Overall Level 2 self-assessment score (e.g., 105 out of 110).

(F) POA&M usage and compliance status, if applicable.

(ii) Conditional Level 2 (Self). The OSA has achieved the CMMC Status of Conditional Level 2 (Self) if the Level 2 self-assessment results in a POA&M and the POA&M meets all the CMMC Level 2 POA&M requirements listed in [170.21(a)(2)].

(A) Plan of Action and Milestones. A Level 2 POA&M is allowed only in accordance with the CMMC POA&M requirements listed in [170.21].

(B) POA&M closeout. The OSA must remediate any NOT MET requirements, must perform a POA&M closeout self-assessment, and must post compliance results to SPRS within 180 days of the CMMC Status Date associated with the Conditional Level 2 (Self). If the POA&M is not successfully closed out within the 180-day timeframe, the Conditional Level 2 (Self) CMMC Status for the information system will expire. If Conditional Level 2 (Self) CMMC Status expires within the period of performance of a contract, standard contractual remedies will apply, and the OSA will be ineligible for additional awards with a requirement for the CMMC Status of Level 2 (Self), or higher requirement, for the information system within the CMMC Assessment Scope until such time as a new CMMC Status is achieved.

(iii) Final Level 2 (Self). The OSA has achieved the CMMC Status of Final Level 2 (Self) if the Level 2 self-assessment results in a passing score as defined in [170.24]. This score may be achieved upon initial self-assessment or as the result of a POA&M closeout self-assessment, as applicable.

(iv) CMMC Status investigation. The DoD reserves the right to conduct a DCMA DIBCAC assessment of the OSA, as provided for under the 48 CFR 252.204-7020. If the investigative results of a subsequent DCMA DIBCAC assessment show that adherence to the provisions of this part have not been achieved or maintained, these DCMA DIBCAC results will take precedence over any pre-existing CMMC Status. At that time, standard contractual remedies will be available and the OSA will be ineligible for additional awards with CMMC Status requirement of Level 2 (Self), or higher requirement, for the information system within the CMMC Assessment Scope until such time as a new CMMC Status is achieved.

(2) Affirmation. Affirmation of the Level 2 (Self) CMMC Status is required for all Level 2 self-assessments at the time of each assessment, and annually thereafter. Affirmation procedures are set forth in [170.22].

(b) Contract eligibility. Prior to award of any contract or subcontract with requirement for CMMC Status of Level 2 (Self), the following two requirements must be met:

(1) The OSA must achieve, as specified in paragraph (a)(1) of this section, a CMMC Status of either Conditional Level 2 (Self) or Final Level 2 (Self).

(2) The OSA must submit an affirmation of compliance into SPRS, as specified in paragraph (a)(2) of this section.

(c) Procedures —

(1) Level 2 self-assessment of the OSA. The OSA must conduct a Level 2 self-assessment in accordance with NIST SP 800-171A Jun2018 (incorporated by reference, see [170.2]) and the CMMC Level 2 scoping requirements set forth in [170.19(a) and (c)] for the information systems within the CMMC Assessment Scope. The Level 2 self-assessment must be scored in accordance with the CMMC Scoring Methodology described in [170.24] and the OSA must upload the results into SPRS. If a POA&M exists, a POA&M closeout self-assessment must be performed by the OSA when all NOT MET requirements have been remediated. The POA&M closeout self-assessment must be performed within 180-days of the Conditional CMMC Status Date. Additional guidance can be found in the guidance document listed in paragraph (c) of appendix A to this part.

(2) Level 2 self-assessment with the use of Cloud Service Provider (CSP). An OSA may use a cloud environment to process, store, or transmit CUI in performance of a contract or subcontract with a requirement for the CMMC Status of Level 2 (Self) under the following circumstances:

(i) The CSP product or service offering is FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline in accordance with the FedRAMP Marketplace; or

(ii) The CSP product or service offering is not FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline but meets security requirements equivalent to those established by the FedRAMP Moderate (or higher) baseline. FedRAMP Moderate or FedRAMP Moderate equivalent is in accordance with DoD Policy.

(iii) In accordance with [170.19(c)(2)], the OSA's on-premises infrastructure connecting to the CSP's product or service offering is part of the CMMC Assessment Scope, which will also be assessed. As such, the security requirements from the Customer Responsibility Matrix (CRM) must be documented or referred to in the OSA's System Security Plan (SSP).

(3) Level 2 self-assessment with the use of an External Service Provider (ESP), not a CSP. An OSA may use an ESP that is not a CSP to process, store, or transmit CUI in performance of a contract or subcontract with a requirement for the CMMC Status of Level 2 (Self) under the following circumstances:

(i) The use of the ESP, its relationship to the OSA, and the services provided are documented in the OSA's SSP and described in the ESP's service description and CRM.

(ii) The ESP services used to meet OSA requirements are assessed within the scope of the OSA's assessment against all Level 2 security requirements.

(iii) In accordance with [170.19(c)(2)], the OSA's on-premises infrastructure connecting to the ESP's product or service offering is part of the CMMC Assessment Scope, which will also be assessed. As such, the security requirements from the CRM must be documented or referred to in the OSA's SSP.

(4) Artifact retention. The artifacts used as evidence for the assessment must be retained by the OSA for six (6) years from the CMMC Status Date.


The method — six steps from the Lead Assessor's chair

The rule tells you what. The assessor's side of the table tells you how. The most common failure mode we see is an OSA that builds its documentation, signs an affirmation, and calls that a self-assessment. It isn't one — and if the score in SPRS ever gets examined, the difference between "we attested after we finished writing" and "we conducted a scheduled assessment event with named assessors, objective-level determinations, and sealed evidence" is the difference between a defensible record and a False Claims Act problem.

Step 1 — Schedule it like an assessment

Put the event on the calendar with a start date, an end date, and a scope freeze before it. Practical anchors: your three-year SPRS cadence, contract award timing, and your annual affirmation date. Block the assessors' and SMEs' time the way you would for a C3PAO visit — because the discipline, not the assessor's employer, is what makes the result defensible.

Step 2 — Stand up an assessment team that isn't grading its own homework

The rule does not require independence. We recommend it anyway, strongly: determinations made by the people who implemented the controls carry a credibility discount, and they miss things familiarity hides. In order of preference:

  1. A separate internal assessment team (compliance, internal audit, or another business unit) that did not implement the controls.
  2. Cross-review — implementers assess each other's domains, never their own.
  3. Where the org is too small for either, engage outside support for the assessment event itself.

Name the assessors in the record. Every determination should carry who made it and on what basis.

Step 3 — Assess to the assessment objective, not the requirement

A requirement is MET only when every one of its 800-171A assessment objectives is met — scoring the 110 requirements as 110 yes/no questions is the most common self-assessment failure there is. Walk all 320 objectives with the examine / interview / test methods, and record for each: the determination (MET / NOT MET / NOT APPLICABLE — NA always with a documented justification), the basis (what was examined, who was interviewed, what was tested), and the assessor's comments.

Pull the evidence before you record the verdict, and ask the two questions an assessor asks of every artifact: is it adequate (does it actually demonstrate this objective?) and is it sufficient (does it cover the whole scope, currently — not last year)? Policy language that says the right words is not evidence that the system does them.

And be honest about your NOT METs — the score is not the point. An inflated self-assessment score is worse than a low honest one: DIBCAC precedence means DoD can replace your score with theirs, and the affirmation carries personal legal exposure for the official who signs it. A defensible 91 beats an indefensible 110 every time.

Step 4 — Findings, POA&M, and the Operational Deficiencies Report

Every NOT MET gets triaged during the event, not after:

  • POA&M-eligible (per 32 CFR 170.21 — limited to specific one-point requirements, with prohibited items excluded): onto the POA&M with an owner, milestones, and a completion date inside the 180-day closeout window.
  • Not POA&M-eligible: it must be remediated before you can claim the status — or it goes into an internal Operational Deficiencies Report with a remediation timetable, and your SPRS score reflects reality in the meantime.
  • Temporary deficiencies with defined remediation underway belong in an operational plan of action consistent with the CMMC Assessment Guide Level 2 v2.13 treatment.

Do the eligibility math before you count on Conditional status: most requirements are not POA&M-eligible, and if a five-point requirement like MFA or FIPS encryption is NOT MET there is no Conditional path through it. Schedule the closeout self-assessment when you open the POA&M — 180 days arrives faster than remediation does, and the clock is terminal.

Hashing your self-assessment artifacts is not required by 32 CFR 170.16 — the six-year retention is. Our recommendation: do voluntarily what 170.17 makes certification assessments do anyway, because unhashed retained evidence proves very little. If your SPRS score is ever questioned — and a self-attested score is exactly the kind of statement the False Claims Act reaches — sealed hashes are what let you prove the evidence behind your score is the evidence you had on assessment day, not something assembled after the fact.

The procedure comes from the DoD CMMC Hashing Guide: assemble the assessment artifacts, generate a SHA-256 hash for every file into an artifact listing (CMMCAssessmentArtifacts.log — algorithm, hash, and full path per artifact), then hash that listing itself into a second file (CMMCAssessmentLogHash.log). Retain the artifact archive and both log files for the full six years — and build the artifact index while you assess, not six years later from memory.

Step 6 — Enter the score in SPRS, then affirm

Your assessment isn't done until it lives in the Supplier Performance Risk System (SPRS) — the DoD system of record where your CMMC status is posted and where contracting officers verify it before award. Two things happen here that catch OSCs off guard, and both are worth walking your team through before assessment day.

First: SPRS makes you record a Compliance Status on all 110 requirements, one at a time. There is no "we're basically compliant" shortcut. In the CMMC Level 2 (Self) entry screen you work family by family (AC, AT, AU, …), and for every requirement you select Met, Not Met, or N/A — with the standing reminder that all objectives must be met for the requirement to be Met. This is why the objective-level worksheet in Step 3 matters: when SPRS asks for 110 answers, you want 110 defensible determinations already in hand, not 110 on-the-spot guesses.

SPRS CMMC Level 2 self-assessment requirement entry — Met / Not Met / N/A per requirement

SPRS scores the entry automatically (110 down to a floor of −203). Only a score of 88–109 (Conditional) or 110 (Final) can be affirmed — and if any Not Met requirement isn't POA&M-eligible, the status becomes No CMMC Status regardless of the number.

Second: the affirmation is a distinct, deliberate act by a named person. Entering the score is data entry; affirming is a legal attestation. If the person entering the assessment isn't your Affirming Official, SPRS transfers the record to the AO by email, and the status stays incomplete until the AO acts. The AO then reviews the full assessment, checks a box certifying they have read the affirmation statement, and clicks Affirm.

Read that statement before you get there — it is the whole reason a self-assessment must be treated as an event. It binds a named official to the compliance claim and names the consequences: "Misrepresentation of this CMMC compliance status to the Government may result in criminal prosecution … civil liability under the False Claims Act, and contract remedies."

SPRS affirmation screen — the Affirming Official certifies the statement (with False Claims Act language) and clicks Affirm

That is the moment the whole discipline of this guide pays off. The AO is not rubber-stamping a document someone built — they are signing their name, under False Claims Act exposure, to determinations that were made deliberately, at the objective level, by an impartial team, on evidence you can still produce years from now.

Then calendar the rhythm. A Conditional status is valid 180 days (close the POA&M inside it). A Final status is valid three years, with an affirmation required at submission and annually thereafter. Put the annual affirmation, the 180-day closeout, and the three-year reassessment on the calendar the day you affirm — a self-assessment program is a rhythm, not a one-time scramble.

SPRS screenshots: DoD SPRS CMMC Level 2 Self-Assessment Quick Entry Guide v4.0 (Feb 2025), a public U.S. Government work.


Doing it with Concura

The Concura Level 2 Self-Assessment runs this entire event as a tool: all 320 objectives with Lead Assessor guidance beside every determination, DoD Assessment Methodology scoring with the POA&M-eligibility rules built in, the 180-day closeout clock, evidence retention with hashing, and an export package built for the SPRS entry.


Sources: 32 CFR 170.16, 170.17, 170.21, 170.22, 170.24 (eCFR, current as of July 22, 2026; rule published 89 FR 83214, October 15, 2024); DoD CMMC Hashing Guide v2.14; CMMC Assessment Guide Level 2 v2.13; NIST SP 800-171 Rev 2; NIST SP 800-171A (June 2018); DoD SPRS CMMC Level 2 Self-Assessment Quick Entry Guide v4.0 (Feb 2025).

Concura.AI — a product of Consultant Works, LLC. This guide is general information, not legal advice. Status: draft — needs Senior Assessor Review.