Skip to main content

CMMC Pause: What DoW & Primes Still Require

  • blog
  • CMMC Phase 1 Self-Assessment Guide: Level 1 and Level 2 Requirements

CMMC Phase 1 Self-Assessment Guide: Level 1 and Level 2 Requirements

  • July 16, 2026
Author

Anna Fitzgerald

Senior Content Marketing Manager

While the transition to Phase 2 requirements was paused as of July 13, 2026, CMMC Phase 1 requirements are still firmly in place.

That means contractors and subcontractors in the Defense Industrial Base still must comply with CMMC Level 1 or Level 2 self-assessment requirements and submit their results and score along with an executive affirmation in SPRS before contract award.

This guide walks through who needs one, what each level requires, and how to complete it.

What is a CMMC self-assessment?

A CMMC self-assessment is an internal evaluation where an organization assesses its own information systems against CMMC Level 1 or Level 2 practices.

This is different from a certification assessment, which is conducted by a CMMC Third-Party Assessment Organization (C3PAO) on behalf of the organization. (Note that this requirement was paused as of July 13, 2026 and assessment types may change after the 60-day review). 

To complete the self-assessment process and achieve a current CMMC status, organizations must document and report their results, along with an executive affirmation of compliance, in the Supplier Performance Risk System (SPRS).

The Department of Defense (DoD) can then verify that suppliers have a passing score in SPRS and are capable of protecting sensitive unclassified information, including Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), before awarding or renewing a contract. Prime contractors can do the same by asking for a screenshot of their supplier’s SPRS score and status.

A note on naming: The Department is now commonly referred to by its official secondary title, the Department of War (DoW). Because existing CMMC rules, contract clauses, and source documents still read "Department of Defense (DoD)," we continue to use this statutory name or "the Department.”

Recommended reading

Everything You Need To Know About CMMC: Requirements, Assessments, And Costs

Who needs to meet CMMC Phase 1 self-assessment requirements?

CMMC Phase 1 took effect on November 10, 2025 and remains in force today. These Phase 1 requirements break down by level and apply to:

Originally, CMMC Level 2 was split by assessment requirement. Originally, self-assessments only applied to a small percentage of contractors handling less sensitive CUI and Security Protection Data (SPD), estimated to be about 2% of the DIB. The other contractors handling CUI (an estimated 35% of the DIB) would have to complete a certification assessment conducted by a C3PAO. 

While the DoD had the discretion to roll out CMMC Level 2 (C3PAO) requirements during Phase 1 and many primes began asking for proof of certification or readiness from suppliers before that, Phase 2 was going to expand the rollout to most applicable contracts and option periods starting on November 10, 2026.

CMMC Phased Rollout as of July 13, 2026 pause

With the transition to Phase 2 requirements on pause, the CMMC Level 2 self-assessment requirement effectively applies to all contractors handling CUI. An implementation memo directed DoD program managers to amend or remove C3PAO requirements from existing contracts, and only include the CMMC Level 1 (Self) or Level 2 (Self) assessment requirement, stating:

“During this suspension the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select government-led assessments.”

Let’s break down what these CMMC self-assessment requirements are at each level.

Level 1 self-assessment Level 2 self-assessment
Data scope FCI only, including supplier information and technical specification CUI, including export controlled information
Security requirements 15 requirements from FAR 52.204-21, including 58 assessment objectives 110 requirements from NIST SP 800-171, including 320 assessment objectives
SPRS reporting requirements Self-assessment results with score of MET or NOT MET, and executive affirmation submitted in SPRS every year Self-assessment results with maximum score of 110* submitted in SPRS every three years (*Minimum score of at least 88 allowed for conditional status for limited time)
Affirmation requirements Affirmation signed by name senior executive submitted in SPRS annually Affirmation signed by name senior executive submitted in SPRS annually
POA&Ms Not permitted Permitted if minimum score achieved (88 to 109) and certain requirements aren’t on the POA&M

What are CMMC Level 1 self-assessment requirements?

Specified in 32 CFR § 170.15, Level 1 self-assessment requirements include:

  • Achieving a MET result for all 15 safeguarding requirements in FAR Clause 52.204-21 (which has been renumbered to FAR 52.240-93)*
  • Scoring the self-assessment as MET or NOT MET in its entirety
  • Submitting results and score to SPRS
  • Providing an affirmation of compliance signed by a named senior executive in SPRS
  • Submitting assessment and affirmation annually to maintain status
  • No Plan of Action and Milestones (POA&M) is permitted at this level

What are the security requirements being assessed?

Note that CMMC Level 1 is made up of 15 security requirements from FAR Clause 52.204-21 (now FAR 52.240-93) and 58 assessment objectives. These requirements and assessment objectives are a subset of NIST 800-171 Rev 2.

Because these are basic safeguarding requirements, such as using antivirus software, restricting physical access to systems, and ensuring employees use strong passwords, CMMC Level 1 is critical for strengthening defense contractor’s baseline cybersecurity posture.

CMMC Level 1 Compliance Checklist

Download this checklist to guide and assess your implementation of all 15 requirements and 58 assessment objectives required at this level before enforcement begins.

What are CMMC Level 2 self-assessment requirements?

Level 2 self-assessment requirements are more complex than Level 1 because there are two potential CMMC statuses that indicate compliance:

  • CMMC L2 Final Self-Assessment indicates full compliance
  • CMMC L2 Conditional Self-Assessment indicates compliance with most requirements

Specified in 32 CFR § 170.16, Level 2 self-assessment requirements to achieve a Final status include:

  • Achieving a MET result for all security requirements in NIST SP 800-171 Rev 2
  • Scoring the self-assessment until the maximum score of 110 is achieved
  • Submitting self-assessment results and score into the SPRS
  • Submitting an executive affirmation of compliance in SPRS
  • Submitting assessment every three years and affirmation every year to maintain status

Unlike Level 1, Level 2 entities can achieve a Conditional status if they meet the following requirements:

  • Implement enough security requirements in NIST SP 800-171 Rev 2 to achieve a minimum score of 88
  • Document any unmet requirements in a POA&M
  • Do not include any of the requirements listed in 32 CFR 170.21(a)(2)(iii) in the POA&M
  • Remediate all NOT MET requirements and perform a POA&M closeout self-assessment within 180 days (6 months) of the Conditional CMMC Status Date

If they do not close out the POA&M within the 180-day timeframe, their conditional status will expire and the OSA will be ineligible for additional awards with a Level 2 (Self) requirement. If they do close it out within the timeframe, then they will achieve the CMMC Status of Final Level 2 (Self).

What are the security requirements being assessed?

Because this contractual requirement applies to organizations handling more sensitive unclassified information, like controlled technical information, export controlled information, and critical infrastructure data, Level 2 (self) involves more rigorous self-assessment requirements and security requirements than Level 1.

Level 2 adds 95 requirements on top of the 15 requirements for Level 1. It totals 110 requirements and 320 assessment objectives that align fully with NIST SP 800-171 Rev 2, which was already required for the protection of CUI by DFARS clause 252.204-7012.

CMMC Level 2 Compliance Checklist

Download this checklist to guide and assess your implementation of all 110 NIST 800-171 requirements required at this level before enforcement begins.

How to conduct a CMMC self-assessment

A self-assessment doesn’t have to be overwhelming. Here’s a step-by-step breakdown of the self-assessment process, using guidance from the DoD’s CMMC Level 1 Self-Assessment Guide​ and CMMC Level 2 Self-Assessment Guide​.

1. Identify the correct assessment level

Start by confirming which level applies:

  • If you only handle FCI, complete a CMMC Level 1 self-assessment.
  • If you handle CUI or SPD, complete a CMMC Level 2 self-assessment.

2. Review the security requirements

Level 1 includes 15 basic safeguarding requirements and 58 assessment objectives. To demonstrate Level 1 compliance, the OSA will need a finding of MET or NOT APPLICABLE on all Level 1 security requirements.

Level 2 maps to the 110 controls in NIST SP 800-171 and 320 assessment objectives. To demonstrate final Level 2 compliance, the OSA will need a finding of MET or NOT APPLICABLE on all Level 2 security requirements.

3. Specify scope

Next, define scope. The CMMC Self-Assessment Scope identifies which assets within the contractor’s environment will be assessed and the details of the self-assessment.

For a CMMC Level 1 self-assessment, the assets that process, store, or transmit FCI are considered in scope and should be assessed against the CMMC Level 1 practices.

For a CMMC Level 2 self-assessment, the assets that process, store, or transmit CUI and assets that provide security protections for these assets are considered in scope and should be assessed against the CMMC Level 2 practices. These fall into one of four asset categories defined in 32 CFR § 170.19(c)(1). You can read more about them in our guide to scoping.

4. Perform a gap analysis

Now, you’re ready to perform a gap analysis and build your remediation plan. If you’re taking a manual approach, you can use the official DoD self-assessment guides for Level 1 and 2 to determine whether each practice is MET (or NOT APPLICABLE). 

For Level 1, you must achieve MET/NA across all requirements since POA&Ms aren’t allowed so you have to close all gaps before moving forward.

For Level 2, you must achieve MET/NA across all requirements to achieve a final certification, but there is opportunity for a conditional status. 

If you identify gaps when assessing your implementation of all NIST SP 800-171 requirements, you can put certain ones on a POA&M with clear owners and dates to achieve a conditional status and remediate them within 180 days from your status date. Or you may choose to remediate all gaps before submitting your assessment results in SPRS to achieve a final CMMC status.

Performing this gap analysis, compiling all the evidence, and managing remediation efforts manually can feel like playing a game of whack-a-mole. A CMMC automation tool can simplify this step for you. It can collect all evidence for you and map controls along with its assessment objectives, implementation status, and evidence to requirements so you can see exactly where you stand in terms of CMMC readiness.

5. Score your implementation

Once your assessment is complete, you’ll need to score your results. For Level 1, there is no numerical value. You score your assessment as MET if all 15 requirements and assessment objectives are fully implemented, or NOT MET if they aren’t.

For Level 2, assessment results are given a numerical score. You are given one, three, or five points based on the NIST 800-171 requirements you have fully implemented. This produces your SPRS score, which must be submitted in the SPRS.

Image source: CMMC.com Requirement Explorer

6. Document UNMET requirements in POA&M (Level 2 only)

If your CMMC Level 2 self-assessment doesn’t achieve the maximum score of 110, record every NOT MET requirement in a POA&M. For each item, note the requirement ID, gap description, affected assets, interim/compensating measures, discrete remediation tasks, owners, resources, and target dates.

To move forward, you must ensure you achieve a minimum score of 88 that’s required for Conditional Level 2 (Self) status and remember that certain requirements cannot be placed on a POA&M. You must update your SSP to reflect both current and planned implementation status of all requirements, then track remediation to completion.

Plan to complete the POA&M closeout self-assessment within 180 days of the conditional status date to convert to Final Level 2 (Self).

7. Submit your results in SPRS

You must submit your self-assessment results and scores in SPRS. You must do so annually to maintain Level 1 certification. To maintain Level 2 (Self), you must submit results and a score at least every three years.

SPRS final score example

8. Submit your annual affirmation in SPRS

In addition to your self-assessment results, an Affirming Official (AO) must submit a signed affirmation indicating that the organization has achieved and intends to maintain compliance with the CMMC level requirements. This AO is the senior executive inside your organization responsible for ensuring your organization’s CMMC compliance and holding the authority to affirm its continuous compliance.

As specified in 32 CFR 170.22, an affirmation must include:

  • The Affirming Official's name, title, and contact information
  • A statement attesting that your organization has implemented, and will maintain implementation of, all applicable CMMC security requirements for every information system in your assessment scope
SPRS affirmation screen

The AO is required to submit an affirmation in each of the following instances:

  • When you achieve Conditional CMMC Status
  • When you achieve Final CMMC Status
  • Annually after your Final CMMC Status Date
  • After a POA&M closeout assessment

Once affirmations are entered electronically in SPRS, the Department verifies this submission as well as a passing score of a current self-assessment to confirm your eligibility for a solicitation or contract with CMMC requirements pre-award.

Why must CMMC self-assessments be submitted to SPRS?

To achieve a valid CMMC status that will make your organization eligible for contract awards with a Level 1 (Self) or Level 2 (Self) requirement, you must complete a self-assessment, submit your results every year for Level 1 or three years for Level 2, and affirm compliance every year in the SPRS.

This submission in SPRS provides the DoD as well as primes with increased assurance and confidence that the contractor actually meets CMMC Level 1 or 2 practices at the time of award and for the duration of the contract period. This is critical for them to make informed, risk-based decisions when acquiring or maintaining relationships with suppliers.

While only the DoD has access to an organization's self-assessment information in SPRS, primes are responsible for flowing down requirements and verifying that subcontractors have a current CMMC status in SPRS. Many ask for screenshots, but they're allowed to pick their own verification process.

The affirmation piece is what sets CMMC apart from previous self-attestation regulations. Your results and score reflect your cybersecurity posture at the time of the self-assessment. Your affirmation attests that you have actually implemented, and are maintaining your implementation of, those cybersecurity requirements. The 32 CFR rule explains that the purpose of the affirmation is to “validate to the DoD that the contractor is actively maintaining its CMMC level status, which is more than a checkbox exercise.”

That is why affirmations are required annually, regardless of CMMC level. Affirming Officials must reaffirm compliance with CMMC Level 2 requirements in SPRS annually, but the organization need only conduct a new assessment every three years. By requiring annual affirmations instead of annual assessments for Level 2, the DoD “limits the burden of compliance” while having a verification mechanism in place that your status remains valid in the two years between assessments. Miss it and your assessment lapses.

That is also why affirmations carry legal weight. An affirmation means a named executive is signing a formal representation to the federal government every year that their organization achieved and intends to maintain compliance with the applicable DoD cybersecurity requirements. An inaccurate or unsupported affirmation opens the executive and organization up to False Claims Act exposure.

SPRS affirmation FCA warning

Note that while only the DoD has access to an organization's self-assessment information in SPRS, primes are responsible for flowing down requirements and verifying that subcontractors have a current CMMC status in SPRS. Many ask for screenshots, but they’re allowed to pick their own verification process. 

Recommended reading

SPRS and CMMC: How to Get a Current CMMC Status to Stay Eligible for DoD Contracts

Using a CMMC self-assessment tool to streamline requirements

The affirmation you submit to SPRS is a formal attestation, signed by a named senior executive, that your self-assessment results are complete and accurate. Without an assessor reviewing your work before it reaches the government, the accuracy of your self-assessment rests entirely on you. That increases the risk of a cyber incident or False Claims Act settlement exposing a score that misrepresents your cybersecurity posture.

That’s what happened most recently to LOGZONE: they self-reported a perfect score of 110 to SPRS when a later DCMA assessment scored it −170 and ended up paying $500K to resolve False Claims Act liability.

This makes the case for tooling. While a third-party assessment was designed to provide a level of assurance, an automation tool can check and verify your work before you certify it on an ongoing basis, providing:

  • Gap assessment and requirement mapping
  • Real-time implementation tracking
  • SPRS score monitoring, so the number you attest to reflects your environment today
  • Automated evidence collection through integrations
  • SSP, POA&M, and documentation management
  • Continuous control monitoring
  • Multi-framework compliance mapping

The result is a supported self-assessment, less manual effort, and an affirmation your executive can sign with confidence.

How Secureframe Defense simplifies CMMC self-assessment requirements

The DoD has paused the rollout and initiated a review of the CMMC program due to its cost and complexity, which is the exact problem Secureframe Defense was built to solve.

Contractors and subcontractors are still challenged with implementing 110 requirements, keeping evidence current, maintaining a current SSP and POA&M, and producing an accurate score and affirmation every year.

Secureframe Defense automates and simplifies this process so you have a defensible self-assessment, every time. It provides:

  • Gap analysis: Real-time visibility into Level 1 and 2 readiness with prioritized remediation
  • Automated evidence collection: Deep integrations with key tools in your tech stack, like Microsoft GCC High, pull required control evidence automatically
  • Real-time SPRS scoring: Continuous tracking of implementation status and automatic score generation, so your affirmation reflects your actual posture
  • Documentation management: Integrated SSP, POA&M, and policy generation mapped to requirements
  • Continuous monitoring: Real-time visibility into your compliance status and any CMMC-specific drift detected through integrations, alerts, and dashboards
  • Asset and vendor management: Automatic in-scope asset discovery and vendor tracking for CUI and security functions
  • Trust Center: Customizable compliance showcase for stakeholder transparency
  • In-platform training: Role-based and security awareness training with completion tracking
  • Multi-framework mapping: CMMC controls map to NIST 800-53, FedRAMP, NIST CSF, TX-RAMP, and CJIS to reduce rework

Talk to our team about how Secureframe Defense can reduce the cost and complexity of preparing for and completing CMMC self-assessments.

This post was originally published in May 2025 and has been updated for accuracy and comprehensiveness.

One platform. Complete CMMC readiness.

Request a demo

FAQs

What does self-assessment mean for CMMC?

It is an internal evaluation where an organization assesses its systems against CMMC Level 1 or Level 2 requirements without hiring an external certified assessor. Results and an executive affirmation are submitted to SPRS.

What are CMMC Phase 1 requirements?

Phase 1 requires applicable contractors to meet CMMC Level 1 (Self) or Level 2 (Self) before award: complete the self-assessment for your level, submit results in SPRS, and have a named senior official affirm continuous compliance. As of July 13, 2026, new DoW solicitations can designate only these Phase 1 requirements, not Level 2 (C3PAO) or Level 3 (DIBCAC), while Phase 2 is on hold and the program is under a 60-day review.

Does the July 2026 Phase 2 announcement change self-assessment requirements?

No. The announcement pauses the Phase 2 transition to third-party (C3PAO) assessment requirements for Level 2 and opens a 60-day program review. Phase 1 self-assessment requirements, NIST SP 800-171 Revision 2, and DFARS 252.204-7012 remain fully in effect. If your contract requires a Level 1 or Level 2 self-assessment, you still need to complete and affirm it.

How do Level 1 and Level 2 self-assessment requirements compare?

Level 1 requires a MET result on all 15 requirements with no POA&M allowed. Level 2 assesses 110 NIST SP 800-171 requirements and produces a scored result (-203 to 110), with a conditional POA&M option down to a minimum score of 88.

Can a third party assist in a CMMC self-assessment?

Yes, the DoD’s CMMC Assessment Level 1 Guide v2.13 says an organization can hire a third-party to assist and the result is still a self-assessment, not a certification assessment. 

How do I submit a CMMC Level 1 self-assessment?

Log into SPRS with the Cyber Vendor User role, go to Cyber Reports then CMMC Assessments, select "Add New Level 1 CMMC Self-Assessment," enter the details, and transfer to the Affirming Official for review and affirmation. Level 1 self-assessments expire after one year.

Do subcontractors have to meet Phase 1 self-assessment requirements?

Yes, when they handle FCI or CUI under a DoW prime or higher-tier subcontract that flows down CMMC Level 1 (Self) or Level 2 (Self) requirements. Primes must verify suppliers have a current CMMC status before award. To do so, they may ask for screenshots of their status in SPRS, readiness evidence or questionnaires submitted in their own tracking systems, or voluntary C3PAO certification, depending on their risk tolerance.

Can I still pursue a C3PAO assessment during Phase 1?

Yes, voluntarily, or if a prime still requires it for its own supply-chain risk reasons. During the Phase 2 pause, DoW program managers may not designate Level 2 (C3PAO) in new solicitations, and C3PAO language is being removed from active solicitations and contracts. However, this delay in the government rollout may not impact prime's own deadlines for Level 2. Confirm with your buyer before scheduling or canceling an assessment.

Anna Fitzgerald

Senior Content Marketing Manager

Anna Fitzgerald is a digital and product marketing professional with nearly a decade of experience delivering high-quality content across highly regulated and technical industries, including healthcare, web development, and cybersecurity compliance. At Secureframe, she specializes in translating complex regulatory frameworks—such as CMMC, FedRAMP, NIST, and SOC 2—into practical resources that help organizations of all sizes and maturity levels meet evolving compliance requirements and improve their overall risk management strategy.