The Department of War may have paused CMMC Phase 2, but contractors are still required to self-attest. The stakes are high, and many businesses are going through the process for the first time.
We've pulled together a quick guide to help you execute a successful CMMC self-assessment.
Much of the information below can be found in the official CMMC Resources & Documentation. If you need help or feel stuck, reach out to our team to get answers to your questions.
Invest the time to fully map where FCI or CUI enters, travels, is stored, and leaves your environment. Identify every endpoint, server, network boundary, cloud service, and team member interacting with covered data.
The practices differ for Level 1 and Level 2. For every required practice, collect objective evidence demonstrating control implementation.
Using the DoW Assessment Methodology, calculate your score starting from a maximum of 110 points (Level 2). Unmet controls deduct weighted points (1, 3, or 5 points).
For Level 2 self-assessments, certain unmet requirements can be placed on a Plan of Action and Milestones (POA&M). Note that high-weight controls cannot be placed on a POA&M, and all items must be resolved within 180 days. (POA&Ms are not permitted for Level 1).
Upload your self-assessment score, System Security Plan (SSP) details, and CMMC status to the Supplier Performance Risk System (SPRS). A senior corporate official must affirm the results within SPRS under the penalty of law.
Affirming CMMC compliance is a legal submission under the False Claims Act (FCA). Submitting inaccurate scores, overestimating control implementation, or signing an attestation without verifiable objective evidence introduces severe financial, operational, and legal risks.
Common pitfalls are:
Submitting unverified or inaccurate CMMC self-assessments exposes contractors to severe legal penalties, including treble damages, statutory fines exceeding $28,000 per false claim, whistleblower bounties, jail time, and debarment from federal contracting.
Ready to Attest™ is a service we offer that gives your organization an independent evidence review before you formally affirm. Our expert C3PAOs will provide:
✔ Independent evidence review
✔ Gap analysis led by CMMC experts
✔ Remediation guidance
✔ Updated SPRS score
✔ Confidence to self-attest
It's an opportunity to identify gaps, strengthen your evidence, and reduce risk before it matters most.