CMMC Self-Attestation: What It Is and How to Get It Right
Table of Contents
- TL;DR
- What Is CMMC Self-Attestation?
- Self-Attestation vs Third-Party Assessment
- Who Can Self-Attest? CMMC Levels and Eligibility
- The CMMC Self-Assessment Process
- Submitting Your Score and Affirmation to SPRS
- What Happens When Your SPRS Score Is Wrong
- Continuous Compliance: How to Build a Defensible Self-Attestation
- Keep Your CMMC Program Audit-Ready With MotherBear
- FAQs About CMMC Self-Attestation
The word "self" does a lot of misleading work in Cybersecurity Maturity Model Certification (CMMC) self-attestation. It suggests a quick form, a box to check, a task your team clears between real projects.
What it actually names is a legal declaration, signed by a senior official, that your organization has fully implemented specific federal cybersecurity requirements.
The stakes just went up, too. On July 13, 2026, the Department of Defense (DoD) suspended the CMMC Phase 2 requirements that would have introduced mandatory third-party assessments.
Phase 1 self-assessments stay in place while a task force reviews the program. For now, self-attestation is the mechanism contract eligibility rests on.
That cuts both ways. Get it right, and you stay eligible with no outside assessor involved. Get it wrong, and the exposure runs from lost DoD contracts to False Claims Act (FCA) liability.
This guide covers what self-attestation actually is, who qualifies for it, the CMMC self-assessment process behind it, and how to submit a score you can defend.
TL;DR
- CMMC self-attestation combines two acts: a self-assessment that scores your control implementation, and a signed affirmation entered into the Supplier Performance Risk System (SPRS). The affirmation is a legal representation to the US government, made by a senior official known as the Affirming Official.
- The data decides your path. Contractors handling only FCI self-assess annually at CMMC Level 1. Handling CUI means Level 2 and all 110 controls from NIST 800-171.
- The DoD suspended Phase 2 and later milestones in July 2026 pending a 60-day review, so self-assessments and select government-led assessments are how compliance gets verified for now. Existing safeguarding obligations under DFARS 252.204-7012 haven't moved.
- Accuracy is the whole game. Inflated scores and unverified affirmations carry False Claims Act exposure, and that risk remains fully in effect during the suspension.
- MotherBear gives contractors and consultants one workspace to keep control status, evidence, documentation, and affirmations connected, so the score you submit is one you can defend.
What Is CMMC Self-Attestation?
Self-attestation under CMMC is the formal declaration that your organization meets its required cybersecurity standards, backed by an assessment you conducted yourself and evidence you can produce on demand.
Two distinct acts hide inside the term, and separating them matters.
The CMMC self-assessment is the evaluation: scoping your environment, measuring control implementation against the requirements, and scoring the results. The attestation is the legal act that follows, an affirmation of those results entered into SPRS.
The affirmation has a named owner. A senior official, designated as the Affirming Official, signs it and takes responsibility for the organization's compliance status.
The role belongs to someone with the authority to answer for the company, not simply whoever manages the systems. That signature is a representation to the United States government, which separates self-attestation from every internal audit your company has ever run.
One more distinction worth holding onto: self-attestation is a verification path, not a lower standard. The security requirements are identical whether you self-assess or face a third-party assessment. What changes is who checks, not what's checked.
Self-Attestation vs Third-Party Assessment
Both paths measure the same thing: whether your organization has implemented the security controls its contracts require. The difference is who does the measuring and how much weight the result carries.
With self-attestation, your own team conducts the assessment, scores it, and a senior official affirms the results. No outside party is involved.
A third-party assessment puts that same evaluation in the hands of a Certified Third-Party Assessment Organization (C3PAO), whose assessors examine your evidence, interview your people, and issue a formal result.
Here's a side-by-side comparison:
|
|
Self-Attestation |
Third-Party Assessment |
|
Who verifies |
Your organization, with an Affirming Official signing off |
An accredited C3PAO |
|
What it involves |
Internal self-assessment, scored against DoD methodology |
Independent examination of evidence, systems, and personnel |
|
Where results go |
Entered into SPRS by your organization |
Assessment results recorded by the C3PAO, affirmed in SPRS |
|
Cadence |
Annual at Level 1; every three years at Level 2, with annual affirmations |
Every three years, with annual affirmations |
|
Cost |
Internal time and preparation |
Assessment fees, typically tens of thousands of dollars |
|
Current status |
In force under Phase 1 |
Requirement suspended as of July 2026 |
The common mistake is treating these as different standards. They aren't. A Level 2 self-assessment and a Level 2 third-party audit measure the same 110 controls with the same scoring methodology.
Self-attestation is not an easier test. It's the same test, graded in-house, with your signature promising the grade is honest.
That framing matters more than ever right now. With third-party requirements suspended, the government's trust, and its enforcement attention, sits on those signatures.
Who Can Self-Attest? CMMC Levels and Eligibility
Eligibility for self-attestation isn't something you choose. The data you handle decides your CMMC level, each solicitation names the required level, and the level determines who verifies your cybersecurity compliance.
Under CMMC 2.0, the answer splits by level, and as of this month, by the state of the program itself.
CMMC Level 1: Always a Self-Assessment
CMMC Level 1 applies to defense contractors handling only Federal Contract Information (FCI), the non-public information provided by or generated for the government under contract.
Level 1 requires 15 basic safeguarding practices, and verification never involves an outside assessor. Contractors complete an annual self-assessment, post the result to SPRS, and affirm it through their Affirming Official.
One rule surprises many contractors: Level 1 is pass/fail. Every one of the 15 requirements must be fully met, with no open gaps and no remediation plans in place of implemented controls.
CMMC Level 2: When Contractors Handling CUI Can Self-Assess
The moment Controlled Unclassified Information (CUI) enters your environment, CMMC Level 2 applies, along with all 110 controls from NIST 800-171.
Level 2 was designed with two verification paths. A minority of contracts involving less sensitive CUI allow a self-assessment every three years, with annual affirmations in between. Contracts involving CUI critical to national security were slated to require third-party certification by a C3PAO.
The DoD's guidance made clear that self-assessment would be the exception. Most defense CUI, including Controlled Technical Information (CTI), pointed to the certification path, and contracting officers had discretion to require it even during Phase 1.
That was the design. What happens next depends on the review now underway.
What the July 2026 Suspension Means for DoD Contractors
CMMC requirements were incorporated into new DoD contracts in November 2025, when the final rule took effect, and Phase 1 began. Phase 2, scheduled for November 10, 2026, would have made third-party assessments a condition of contract award for most contracts involving CUI.
That changed on July 13, 2026. The DoD suspended Phase 2 and all pending and future CMMC milestones, and stood up a task force to review the program, with a report due within 60 days.
Phase 1 self-assessment requirements remain firmly in place.
During the review, compliance runs on self-assessments and select government-led assessments, and the underlying obligation to protect sensitive information under Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 hasn't moved.
The practical takeaway for small and medium contractors: self-attestation is currently how the entire Defense Industrial Base (DIB) demonstrates CMMC compliance and remains eligible for awards.
Whatever the task force recommends, an accurate, defensible self-assessment is the safest position to be waiting in.
The CMMC Self-Assessment Process
Self-assessment follows a defined methodology rather than a questionnaire. The DoD publishes assessment guides for each level, and the CMMC self-assessment process below mirrors how a C3PAO would evaluate you.
Step #1: Define Your Assessment Scope
Map where FCI and CUI enter, move through, and rest in your environment. Every system, person, facility, and service provider that touches the data sits inside your assessment scope.
Include cloud environments, remote work setups, and any external providers with access to your systems. Scoping errors are the most expensive kind, because every step that follows inherits them.
Step #2: Run a Gap Analysis
Measure your current practices against the requirements for your level: 15 safeguarding practices at Level 1 or the 110 controls in NIST 800-171 at Level 2.
The DoD methodology uses three assessment methods: examine documentation, interview the people responsible, and test the technical configurations. A control, like access control, isn't met just because a policy says so. It's met when the settings, logs, and people confirm it.
Step #3: Remediate the Gaps
Close the gap analysis found before you score, not after. At Level 1, this step is non-negotiable, since every requirement must be fully implemented for a passing result.
At Level 2, some deficiencies can go into a Plan of Action and Milestones (POA&M), but the highest-weighted controls generally can't be deferred, and open items run on a 180-day clock.
Step #4: Document Everything in Your SSP
Build the System Security Plan (SSP) that describes how each control is implemented, and keep the supporting evidence organized behind it: configurations, screenshots, logs, and training records.
Under CMMC, documentation is the assessment. An implemented control with no evidence trail scores the same as a missing one when someone asks you to prove it.
Step #5: Score Your Assessment
Level 1 is pass or fail. Level 2 uses the DoD scoring methodology: a maximum of 110 points, with weighted deductions of one, three, or five points for each unmet control.
A perfect 110 means every control is in place. Level 2 self-assessments can earn conditional status at 88 points or higher, provided the remaining gaps are POA&M-eligible and closed within 180 days.
Step #6: Prepare for Submission
Assemble what SPRS will ask for: your score, the scope description, the system name, and the date the assessment was completed. Then get your Affirming Official ready to review what they're about to sign.
Submitting Your Score and Affirmation to SPRS
SPRS is the DoD's system of record for self-assessment scores and CMMC status. If it isn't in SPRS, it doesn't exist as far as contract eligibility is concerned. Here's how the submission works in practice.
Get Access Through PIEE
SPRS sits inside the Procurement Integrated Enterprise Environment (PIEE), the DoD's contracting portal. Your organization needs a PIEE account with the SPRS Cyber Vendor role, tied to the correct Commercial and Government Entity (CAGE) code.
Sorting out account access and CAGE hierarchy is unglamorous work, but it's the step that stalls first-time submissions, so start it before the assessment wraps.
Enter the Assessment Results
The submission includes your CMMC level, assessment type, scope, completion date, and score. Check the CAGE codes covered by the assessment carefully, since that's what contracting officers will look up.
Let the Affirming Official Sign Last
If the person entering the results isn't the Affirming Official, SPRS transfers the assessment to them for review. The status doesn't become effective until that executive affirmation lands.
This ordering is deliberate. The system is built so the accountable executive sees and approves what the organization is claiming, which is exactly what makes the affirmation a legal representation rather than a data entry task.
Reaffirm Every Year
The initial affirmation isn't the last one. Maintaining your CMMC status requires the Affirming Official to reaffirm continued compliance every year, even in years with no new assessment.
A lapsed affirmation can drop your status, and with it, your eligibility. Put the renewal date somewhere it can't be missed.
Once submitted, your compliance status is visible to DoD contracting officers, and primes will ask for it when they verify compliance down their supply chain. Which raises the question of what happens when the score in SPRS and the truth on the ground don't match.
What Happens When Your SPRS Score Is Wrong
An inaccurate self-attestation isn't a paperwork problem. It's a false statement to the federal government, and the enforcement mechanism attached to it is the False Claims Act.
The FCA carries treble damages, meaning three times the government's losses, plus penalties for each false claim. The government doesn't need to prove you intended to deceive anyone. Reckless disregard for whether your score was accurate is enough.
Two features of this exposure catch companies off guard:
- No breach is required: Liability attaches to the false certification itself, not to any incident that follows it. Several settlements under the Department of Justice's Civil Cyber-Fraud Initiative involved no data breach at all, just a gap between what was claimed and what was true.
- The reports usually come from inside: The FCA's whistleblower provisions let employees file suit on the government's behalf and keep a share of the recovery. The people who know your actual cybersecurity posture are the people running it, and ignored internal warnings are how many of these cases start.
The Georgia Tech case shows how it plays out. In September 2025, Georgia Tech Research Corporation agreed to pay $875,000 to resolve allegations that included submitting a score of 98 to SPRS based on what employees described as a fictitious environment, for a campus-wide system that didn't exist as scored.
The case began as a whistleblower complaint from the university's own cybersecurity staff.
The suspension of Phase 2 changes none of this. If anything, it concentrates the risk: with third-party checks on hold, self-attestations are the representations the government relies on, and legal observers expect enforcement attention on false Phase 1 self-assessments to grow.
Falling short has contractual consequences too. Contracting officers can terminate awards, and a status that doesn't hold up puts future contract eligibility at risk. For companies whose business depends on defense work, the inflated score is always the more expensive one.
Continuous Compliance: How to Build a Defensible Self-Attestation
A defensible self-attestation is one where the score in SPRS, the SSP on file, and the reality of your systems all say the same thing, on the day you affirm and every day after.
Certification cycles run in years, but compliance doesn't hold still. Systems change, people leave, controls drift. The organizations that stay safe treat the self-assessment as the start of continuous compliance rather than an annual scramble.
A few practices do most of the work:
- Keep evidence current: Screenshots and configurations from last year's assessment prove last year's compliance. Collect supporting evidence on a schedule, so what's on file matches what's running.
- Track control status in one place: Gaps appear when control ownership, POA&M items, and documentation live in separate spreadsheets. One source of truth means the Affirming Official reviews reality, not a reconstruction.
- Reassess when the environment changes: A new cloud service, an acquisition, or an office move can shift your assessment scope. Catch it when it happens, not at the next annual affirmation.
- Brief the Affirming Official properly: The executive signing should see the score, the open POA&M items, and the evidence behind both. A signature made blind is exactly the exposure the FCA punishes.
This is the operational load that makes contractors and consultants build compliance programs around dedicated tooling rather than folders and spreadsheets.
Keep Your CMMC Program Audit-Ready With MotherBear

MotherBear gives you one workspace to manage the whole program. Control status, evidence, documentation, and affirmations stay connected, so the score you submit is one you can stand behind.
Book a demo and see how MotherBear keeps continuous compliance manageable.
FAQs About CMMC Self-Attestation
Can you self-certify CMMC Level 1?
Yes. Level 1 is always self-assessed, with no outside assessor involved. Contractors handling FCI complete an annual self-assessment against the 15 safeguarding requirements, post the score to SPRS, and affirm the result through their Affirming Official. All 15 must be fully met, since Level 1 allows no POA&Ms.
Can you self-attest CMMC Level 2?
Sometimes. Level 2 was designed so that a minority of contracts involving less sensitive CUI allow self-assessment, while most require third-party assessment. With Phase 2 suspended as of July 2026, self-assessments are being used to verify Level 2 compliance while the program review runs. Check your specific solicitation, as it identifies the applicable requirement.
What are self-attestations?
A self-attestation is a formal declaration that your organization complies with its required cybersecurity standards, based on an assessment you performed yourself. Under CMMC, it combines a scored self-assessment with a legally binding affirmation in SPRS, signed by a senior official. It carries the same accuracy obligations as a third-party assessment.
How do you perform a CMMC self-assessment?
Follow the DoD assessment guide for your level: define the assessment scope, run a gap analysis against the required controls, remediate what falls short, document everything in your SSP, score the results using the DoD methodology, and submit to SPRS. The process section above walks through each step.
How do CMMC assessments work during the Phase 2 suspension?
Self-assessments continue exactly as before, since Phase 1 requirements remain in place. What's suspended is the planned requirement for third-party assessments, along with later program milestones, while a DoD task force reviews the program. Existing safeguarding obligations under DFARS 252.204-7012 are unaffected.
Need to be Prepared for CMMC?
Book a demo of MotherBear to see how we help you simplify CMMC
