Self-assessment

CMMC Self Assessment Guide: Requirements, Steps, & Attestation Readiness

MNS Group
MNS Group Jul 21, 2026 3:24:02 PM 2 min read
CMMC Self Assessment Guide

The Department of War may have paused CMMC Phase 2, but contractors are still required to self-attest. The stakes are high, and many businesses are going through the process for the first time.

We've pulled together a quick guide to help you execute a successful CMMC self-assessment.

CMMC Self Assessment 101

Much of the information below can be found in the official CMMC Resources & Documentation. If you need help or feel stuck, reach out to our team to get answers to your questions.

Step 1: Define Your System Security Scope

Invest the time to fully map where FCI or CUI enters, travels, is stored, and leaves your environment. Identify every endpoint, server, network boundary, cloud service, and team member interacting with covered data.

Step 2: Gather Evidence and Evaluate Controls

The practices differ for Level 1 and Level 2. For every required practice, collect objective evidence demonstrating control implementation.

  • Level 1
    • 15 practices
    • Verify basic cyber hygiene like access limits, media sanitization, and endpoint protection.
  • Level 2
    • 110 practices
    • Evaluate policies, procedures, System Security Plans (SSPs), and technical controls across all 14 NIST control families.

Step 3: Calculate Your SPRS Assessment Score

Using the DoW Assessment Methodology, calculate your score starting from a maximum of 110 points (Level 2). Unmet controls deduct weighted points (1, 3, or 5 points).

Step 4: Address Deficiencies (POA&M)

For Level 2 self-assessments, certain unmet requirements can be placed on a Plan of Action and Milestones (POA&M). Note that high-weight controls cannot be placed on a POA&M, and all items must be resolved within 180 days. (POA&Ms are not permitted for Level 1).

Step 5: Submit Assessment and Corporate Attestation

Upload your self-assessment score, System Security Plan (SSP) details, and CMMC status to the Supplier Performance Risk System (SPRS). A senior corporate official must affirm the results within SPRS under the penalty of law.

The Danger of Submitting an Unverified Attestation

Affirming CMMC compliance is a legal submission under the False Claims Act (FCA). Submitting inaccurate scores, overestimating control implementation, or signing an attestation without verifiable objective evidence introduces severe financial, operational, and legal risks.

Common pitfalls are:

  • Misinterpreting scope: Missing secondary devices or remote workers handling CUI.
  • Lack of evidence: Assuming written policies equal operational reality without technical testing.
  • Insufficient artifact mapping: Lacking proof when auditors or DoW representatives request evidence.

Submitting unverified or inaccurate CMMC self-assessments exposes contractors to severe legal penalties, including treble damages, statutory fines exceeding $28,000 per false claim, whistleblower bounties, jail time, and debarment from federal contracting.

Need A Second Set of Eyes?

Ready to Attest™ is a service we offer that gives your organization an independent evidence review before you formally affirm. Our expert C3PAOs will provide:

Independent evidence review

Gap analysis led by CMMC experts

Remediation guidance

Updated SPRS score

Confidence to self-attest

It's an opportunity to identify gaps, strengthen your evidence, and reduce risk before it matters most.

 

Reach out to our team today to learn more.

Don't forget to share this post!

Related posts

CMMC CMMC Assessment

"It's ONLY a Self-Assessment..."

Sep 9, 2025 5:24:09 PM
MNS Group
CMMC Drones

From World War II to Unmanned Warfare: Forging a Resilient Defense Supply Chain Together

Jun 1, 2026 9:35:40 AM
Laura
CMMC

Northrop Grumman Signals a New Era of Cyber Requirements

Dec 5, 2025 8:28:27 AM
MNS Group