← All articles

How to Complete a CMMC Level 2 Self-Assessment (Step-by-Step Guide)

How to Complete a CMMC Level 2 Self-Assessment (Step-by-Step Guide)

Author: Adam Rosenman, Lead CMMC Strategist · August 1, 2026

Defense contractors face a new reality following the July 13, 2026, decision by the Department of War to suspend CMMC Phase 2 third-party assessments for a 60-day review. While this pause delays the requirement for external C3PAO audits, the mandate to protect Controlled Unclassified Information (CUI) remains fully active through self-attestations. Contractors must still complete a comprehensive internal review to remain eligible for upcoming solicitations. This guide provides the tactical roadmap you need to navigate the 110 controls of Level 2 and secure your standing in the defense industrial base.

Key Takeaways

  • Level 2 self-assessments cover 110 NIST SP 800-171 controls (Department of Defense, 2024).
  • The triennial cost for a small business self-assessment averages $37,196 (DoD, 2024).
  • SPRS scores start at 110 and deduct weighted points for every unmet requirement.
  • Annual affirmations by a senior official are mandatory even during the CMMC Phase 2 pause.

What Is a CMMC Level 2 Self-Assessment?

A CMMC Level 2 self-assessment is an internal verification of compliance with 110 NIST SP 800-171 controls (NIST, 2024). It is a mandatory requirement for contractors handling non-prioritized CUI. You must document your security practices in a System Security Plan (SSP) and submit a calculated score to the DoD's Supplier Performance Risk System (SPRS). This process requires a detailed review of policies, technical configurations, and physical security measures to ensure CUI is protected against unauthorized access.

Does the Recent CMMC Suspension Affect Your Self-Assessment?

No, the July 13, 2026, suspension of third-party audits does not waive the requirement for self-assessment. While external C3PAO certifications are on a 60-day pause, self-attestations under DFARS 252.204-7019 remain mandatory for contract awards (Department of Defense, 2026). For contractors, this means the pressure has shifted from passing an external audit to ensuring their internal affirmation is legally defensible under the False Claims Act.

Step 1: Define Your CUI Scoping Boundary

Scoping is the most critical factor in cost control, as small firms spend an average of $37,196 over three years on assessment activities (DoD, 2024). You must identify every system, employee, and facility that processes or transmits Controlled Unclassified Information (CUI). In our experience, contractors often over-scope their environments by including guest networks or non-defense departments. Drawing a hard line between your corporate environment and your CUI enclave can save hundreds of hours in remediation and evidence collection.

Step 2: Conduct a Gap Analysis Against NIST 800-171

A gap analysis evaluates your network against all 110 requirements of NIST SP 800-171 (NIST, 2024). Using the NIST SP 800-171A assessment methodology, you must verify that every control objective is met through specific artifacts. You cannot simply state that a control is met. You must identify evidence such as logs, policy documents, or screenshots that prove the control is functioning as intended. Any requirement that cannot be verified must be marked as a gap for Step 4.

Step 3: Calculate Your SPRS Score Correctly

Your SPRS scores start at a baseline of 110 and deduct weighted points for every unmet control (DoD, 2024). Deductions are typically 1, 3, or 5 points depending on the criticality of the requirement. Note that only two requirements, Multi-Factor Authentication (MFA) and FIPS-validated cryptography, allow for partial credit. Most others are all or nothing, meaning a single missing sub-objective can result in a 5-point penalty that lowers your ranking in competitive bid evaluations.

Step 4: Develop Your System Security Plan (SSP)

The System Security Plan (SSP) is a foundational document that describes how each of the 110 controls is implemented (DoD, 2024). Without a completed SSP, any submitted SPRS score is considered invalid by contracting officers. If you have unmet requirements, you must also create a Plan of Action and Milestones (POA&M). This document lists each deficiency, the planned remediation actions, and the expected completion date. Under CMMC rules, any gaps on a POA&M must be closed within 180 days to maintain conditional compliance status.

Step 5: Submit and Affirm Your Results in SPRS

After calculating your score, you must record it in the Supplier Performance Risk System (SPRS) via the PIEE portal. Following the CMMC program pause, the annual affirmation by a senior official has become the primary legal enforcement mechanism. By signing this affirmation, the executive is personally certifying that the submitted score accurately reflects the company's security posture. Errors or exaggerations at this stage can lead to significant legal exposure if a security incident later reveals the controls were not actually in place.

How Often Do You Need to Renew Your CMMC Self-Assessment?

CMMC Level 2 self-assessments follow a triennial full cycle, but the senior-level affirmation must be renewed annually (DoD, 2024). You are also required to update your SPRS entry whenever there is a significant change to your network architecture or security posture. Maintaining a living SSP ensures that you are always ready for a contract option year or a sudden request from a prime contractor for an updated score. Continuous monitoring is the best defense against a score that grows stale and inaccurate over time.

FAQ

What is a passing SPRS score for CMMC Level 2? There is no single passing score for all contracts, but most prime contractors require a score of at least 88 for conditional eligibility (PreVeil, 2026). A perfect score of 110 is required for final certification, though certain POA&M items are allowed for a 180-day remediation period.

Can I use a POA&M for a Level 2 self-assessment? Yes, certain unmet requirements can be placed on a Plan of Action and Milestones for Level 2 self-assessments (DoD, 2024). However, high-weight 5-point controls generally cannot be placed on a POA&M if you are seeking a conditional award. All gaps must be remediated within 180 days.

Is a C3PAO required for all Level 2 contracts? No, the DoD originally estimated that only about 6,000 of the 125,000 Level 2 contractors would rely solely on self-assessments (DoD, 2024). However, with the current Phase 2 suspension, all Level 2 contracts are temporarily relying on self-assessments until the 60-day program review concludes.

About the Author

Adam Rosenman is a Lead CMMC Strategist with over 10 years of experience in defense cybersecurity. A CISSP-certified professional, He has guided dozens of contractors through NIST SP 800-171 implementation and SPRS score reporting. Adam specializes in creating defensible compliance documentation that survives regulatory scrutiny and contracting officer reviews.

Conclusion

Completing a CMMC Level 2 self-assessment is an essential step for any defense contractor handling CUI in 2026. By following this 5-step process from boundary scoping to SPRS affirmation, you can build a resilient security posture that withstands both regulatory scrutiny and evolving cyber threats. For more information on maintaining your status, visit our compliance resources or contact our specialists for a detailed readiness review.

Frequently asked questions

What is a passing SPRS score for CMMC Level 2?

While there is no universal minimum, many prime contractors demand an SPRS score of at least 88 for conditional eligibility (PreVeil, 2026). Achieving a perfect score of 110 is the ultimate goal, as unmet controls can result in point deductions that lower your ranking in competitive bid evaluations.

Can I use a POA&M for a Level 2 self-assessment?

Yes, Level 2 self-assessments allow for a Plan of Action and Milestones (POA&M) to track unmet requirements (DoD, 2024). However, high-weight 5-point controls often cannot be deferred, and all items listed on a POA&M must be remediated within 180 days of the assessment date to maintain status.

Is a C3PAO required for all Level 2 contracts?

Currently, all Level 2 third-party assessments are suspended for a 60-day review as of July 13, 2026. This means self-assessments are the primary requirement for all contractors today. Before the suspension, the DoD estimated only 6,000 contractors would be eligible for self-assessment only (DoD, 2024).