The Four CMMC Self-Assessment Activities

Understanding the CMMC Level 2 (Self) Assessment, the NIST SP 800‑171 Basic Assessment, the CMMC Security Control Assessment (CA.L2‑3.12.1), and the Annual Affirmation

  • Ryan Heidorn

    Chief Technology Officer

Four CMMC assessmentrelated activities are frequently treated as if they were the same thing:  

  • CMMC Level 2 (Self) assessment defined in 32 CFR § 170.16 
  • NIST SP 800171 Basic Assessment required under DFARS 252.2047019 / 7020  
  • The security control assessment requirement found in CMMC (CA.L23.12.1) 
  • The annual affirmation required by 32 CFR § 170.22. 

Each has its own scope, methodology, and division of responsibility between C3 and your team. This article walks through what each activity requires, how they connect, and which parts your organization owns. 

At a Glance 

The CMMC Level 2 (Self) Assessment is a methodology-driven evaluation against all 320 NIST SP 800171A assessment objectives. The NIST SP 800171 Basic Assessment is the predecessor to the CMMC Level 2 self-assessment, still in force under many contracts. CA.L23.12.1 is a CMMC practice requiring periodic assessment of security controls, and the Annual Affirmation is a yearly attestation affirming continued compliance submitted to the United States Government by your Affirming Official. 

Comparing the Four Assessment-Related Activities  

Activity Requirements
CMMC Level 2 (Self) Assessment Per 32 CFR § 170.16, your organization conducts a self‑assessment against all 110 CMMC Level 2 practices, evaluated at the level of all 320 assessment objectives in NIST SP 800‑171A, using the examine, interview, and test methods. Results are scored, posted to SPRS, and support a Final or Conditional Level 2 (Self) status on a triennial cycle.
NIST SP 800-171 Basic Assessment Per DFARS 252.204‑7019 and ‑7020, the contractor scores its implementation of NIST SP 800‑171 Rev. 2 using the DoD Assessment Methodology and posts a summary‑level score to SPRS on a triennial cycle. Under Class Deviation 2026‑O0025 (effective February 1, 2026), ‑7019 and ‑7020 are not prescribed in new solicitations. Contracts issued prior to the class deviation retain the legacy obligation.
Security Control Assessment (CA.L2-3.12.1) Per the CMMC Assessment Guide and NIST SP 800‑171 Rev. 2: “Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.”
Annual Affirmation Per 32 CFR § 170.22, your Affirming Official submits an annual affirmation in SPRS attesting that your organization has implemented and will maintain implementation of all applicable CMMC security requirements within the relevant Assessment Scope. Applies to Level 1 (Self), Level 2 (Self), and Level 2 (C3PAO) on an annual cadence following the Final CMMC Status Date.

The Level 2 (Self) Assessment 

A CMMC Level 2 (Self) assessment is a defined, documented evaluation of your information system against all 110 NIST SP 800171 Rev. 2 security requirements, evaluated at the level of all 320 assessment objectives in NIST SP 800171A. The organization applies the examine, interview, and test methods to reach a MET, NOT MET, or NOT APPLICABLE determination for each objective. 

The CMMC Assessment Guide – Level 2 is explicit on this point: “The security requirements for a Level 2 selfassessment and a Level 2 certification assessment are the same, the only difference in these assessments is whether it is conducted by the OSA or by an independent C3PAO.” The methodology your team applies to a selfassessment is the same methodology a C3PAO would apply to a certification assessment. 

How C3 supports a Level 2 (Self) assessment 

C3 supports your Level 2 (Self) assessment through a PreAssessment Readiness Review, a separately scoped project that prepares your team to execute the selfassessment with confidence. 

  • What it includes: evidence gathering and organization, and a tabletop exercise walking each Level 2 assessment objective with the examine, interview, and test methods. 
  • Preconditions: the same preconditions as the selfassessment itself. The CMMC Assessment Scope is defined and documented, the information system is implemented and operational (generally 60+ days of operational evidence), and all documentation is final. 
  • Independence: C3 does not perform formal assessments of systems C3 has implemented or operates. A PreAssessment Readiness Review is a support engagement that helps your team prepare for and execute the selfassessment. 

C3 does not provide an attestation of compliance. Your organization remains accountable for every MET / NOT MET determination, the SPRS submission, and the Affirming Official attestation. 

A note on “SPRS score” as a phrase 

Needing to “enter an SPRS score” is a phrase that comes up regularly for defense contractors. That phrase maps to one of two distinct regulatory regimes, and the right path forward depends on which one applies to your contract: 

  • NIST SP 800171 Basic Assessment under DFARS 252.2047019 / 7020 (preCMMC): Your organization scores its implementation of NIST SP 800‑171 Rev. 2 using the DoD Assessment Methodology and posts a summarylevel score to the NIST SP 800171 Assessments module in SPRS. Under Class Deviation 2026O0025 (effective February 1, 2026), DFARS 252.2047019 and 252.2047020 are no longer prescribed in new solicitations. Existing contracts awarded before February 1, 2026 that already contain 7019 / 7020 retain those obligations, and flowdowns from primes operating under those legacy clauses can still reach a subcontractor today. 
  • CMMC Level 2 (Self) Assessment under 32 CFR § 170.16: Your organization assesses against all 110 requirements at the level of 320 assessment objectives using the NIST SP 800‑171A methodology, and posts the result to the CMMC module of SPRS. Required under DFARS 252.2047021 when the contracting officer specifies a CMMC level in the solicitation. 

The two are scored using substantively the same methodology, but they are different SPRS records supporting different contractual bases. C3’s support is the same in either case: a PreAssessment Readiness Review. Your organization conducts and owns the assessment, the SPRS submission, and the Affirming Official attestation (for CMMC) or the contractor’s certification of the score (for DFARS -7019/-7020). 

CA.L23.12.1: The Annual Security Control Assessment 

The CMMC practice CA.L23.12.1 requires your organization to “periodically assess the security controls in organizational systems to determine if the controls are effective in their application.” 

The CMMC Assessment Guide provides the following illustrative example, which is the operative reference for what this practice asks for: 

“Taking the requirements outlined in your SSP as a guide, you conduct annual written reviews of the security controls to ensure they meet your organization’s needs. When you find controls that do not meet requirements, you propose updated or new controls, develop a written implementation plan, document new risks, and execute the changes.”  CMMC Assessment Guide – Level 2, p. 201 

CA.L23.12.1 is not necessarily asking your organization to apply the full NIST SP 800171A assessment methodology against every assessment objective. It is asking your organization to define an assessment frequency and to conduct a review at that frequency. 

How C3 conducts this review 

C3’s Managed Compliance team performs this review annually in collaboration with your team, typically during the Operational Maintenance phase of service delivery, after initial implementation is complete. 

  • Methodology under 3.12.1[b]: we work through the SSP and assess, at the security requirement level, whether each requirement is implemented, partially implemented, or not implemented. Where a requirement is partial or not implemented, we document the finding and route it into your POA&M for tracking and remediation. A written report is generated as a deliverable. 
  • What this is not: a Level 2 (Self) assessment, an application of the NIST SP 800171A assessment methodology to all 320 objectives, or an attestation of compliance. 

The Annual Affirmation 

32 CFR § 170.22(a) requires your organization to “affirm continuing compliance with the appropriate level selfassessment or certification assessment.” Under § 170.22(a)(2)(ii), the affirmation is an “Affirmation statement attesting that the OSA has implemented and will maintain implementation of all applicable CMMC security requirements to their CMMC Status for all information systems within the relevant CMMC Assessment Scope.” 

The preamble to the CMMC Final Rule clarifies the purpose: “Annual affirmations ensure OSAs conduct periodic checks and verify to the Department that changes to their networks have not taken them out of compliance during the certification period.” The rule further confirms: “No supporting evidence is required for an annual affirmation.” Annual affirmation applies to Level 1 (Self), Level 2 (Self), and Level 2 (C3PAO) statuses, in each case following the Final CMMC Status Date. 

Important: Your organization owns full responsibility and accountability for what your Affirming Official affirms. The affirmation is a personal attestation submitted to the United States Government and carries legal weight under the False Claims Act. C3 supports the decision; C3 does not own and cannot own the affirmation. 

How C3 thinks about the evidentiary basis 

C3’s position: the affirmation can be reasonably supported by the completion of a security control assessment under CA.L23.12.1. The CMMC regulatory text does not prescribe the evidentiary basis for the annual affirmation and does not require a full Level 2 (Self) assessment to be conducted in support of it. The triennial reassessment cycle established in § 170.16 is the mechanism by which the full selfassessment methodology is reapplied; the annual affirmation is a separate, lighterweight attestation in the intervening years. 

Learn More 

For a deeper walkthrough of the Level 2 (Self) assessment, see The CMMC Level 2 Self-Assessment: A Practical Guide for DIB Contractors. 

Authoritative Sources 

CMMC Self-Assessment Frequently Asked Questions

What is a CMMC Level 2 self-assessment? 

A CMMC Level 2 self-assessment is a documented evaluation of your information system against all 110 NIST SP 800-171 Rev. 2 security requirements, evaluated at the level of all 320 assessment objectives in NIST SP 800-171A. The organization applies the examine, interview, and test methods to reach a MET, NOT MET, or NOT APPLICABLE determination for each objective. Results are scored, posted to SPRS, and support a Final or Conditional Level 2 (Self) status on a triennial (three-year) cycle. 

What are the four CMMC Level 2 assessment-related activities? 

The four activities are the CMMC Level 2 (Self) assessment (32 CFR § 170.16), the NIST SP 800-171 Basic Assessment (DFARS 252.204-7019/-7020), the security control assessment practice CA.L2-3.12.1, and the annual affirmation (32 CFR § 170.22). They are frequently confused, but each has its own scope, methodology, and division of responsibility. The Level 2 self-assessment and Basic Assessment are triennial scoring exercises posted to SPRS; CA.L2-3.12.1 is an annual review of control effectiveness; and the annual affirmation is a yearly attestation of continued compliance. 

What is the difference between the CMMC Level 2 self-assessment and the NIST SP 800-171 Basic Assessment? 

The two use substantively the same scoring methodology but support different contractual bases and live in different SPRS modules. The NIST SP 800-171 Basic Assessment is the predecessor requirement under DFARS 252.204-7019/-7020, scored with the DoD Assessment Methodology and posted to the NIST SP 800-171 Assessments module in SPRS. The CMMC Level 2 (Self) assessment is required under 32 CFR § 170.16 and DFARS 252.204-7021, and is posted to the CMMC module in SPRS. Under Class Deviation 2026-O0025 (effective February 1, 2026), -7019 and -7020 are no longer prescribed in new solicitations, but contracts awarded before that date retain the legacy obligation. 

What is CA.L2-3.12.1 in CMMC? 

CA.L2-3.12.1 is the CMMC security control assessment practice that requires you to “periodically assess the security controls in organizational systems to determine if the controls are effective in their application.” The CMMC Assessment Guide illustrates this as an annual written review of the security controls in your System Security Plan (SSP) to confirm they still meet requirements. It is not the full NIST SP 800-171A methodology applied to all 320 objectives, and it is not a Level 2 (Self) assessment — it asks you to define an assessment frequency and conduct a review at that frequency. 

What is the CMMC annual affirmation? 

The CMMC annual affirmation is a yearly attestation, submitted in SPRS by your Affirming Official, stating that your organization has implemented and will maintain all applicable CMMC security requirements within the relevant Assessment Scope. It is required under 32 CFR § 170.22 and applies to Level 1 (Self), Level 2 (Self), and Level 2 (C3PAO) statuses, on an annual cadence following the Final CMMC Status Date. Its purpose is to verify that network changes have not taken you out of compliance between assessments. No supporting evidence is submitted with the affirmation itself. 

Who is the Affirming Official for a CMMC affirmation? 

The Affirming Official is the individual in your organization who submits the annual affirmation to the U.S. Government in SPRS and is accountable for its accuracy. The affirmation is a personal attestation that carries legal weight under the False Claims Act, so your organization owns full responsibility for what the Affirming Official affirms. A support partner such as C3 can help inform the decision to affirm, but cannot own or submit the affirmation on your behalf. 

How often is a CMMC Level 2 self-assessment required? 

A CMMC Level 2 (Self) assessment is required on a triennial (three-year) cycle under 32 CFR § 170.16, with an annual affirmation submitted in each intervening year. The full 320-objective NIST SP 800-171A methodology is re-applied at the triennial reassessment; the annual affirmation is a separate, lighter-weight attestation in the years between. A CA.L2-3.12.1 security control assessment is typically performed annually to support each affirmation. 

What is an SPRS score and how do I enter one? 

An SPRS score is the compliance score a defense contractor posts to the Supplier Performance Risk System (SPRS), and “entering an SPRS score” maps to one of two distinct regimes. Under the legacy NIST SP 800-171 Basic Assessment (DFARS 252.204-7019/-7020), you score your NIST SP 800-171 Rev. 2 implementation with the DoD Assessment Methodology and post a summary-level score to the NIST SP 800-171 Assessments module. Under the CMMC Level 2 (Self) assessment (32 CFR § 170.16), you assess all 110 requirements at the level of 320 objectives and post the result to the CMMC module. The right path depends on which clause your contract carries. 

Does a security control assessment under CA.L2-3.12.1 satisfy the annual affirmation? 

An annual affirmation can be reasonably supported by a security control assessment performed under CA.L2-3.12.1, in C3’s view, when that review is completed within 60 days of the affirmation date. The CMMC regulation does not prescribe the evidentiary basis for the annual affirmation and does not require a full Level 2 (Self) assessment to support it. The triennial reassessment cycle is the mechanism for re-applying the full methodology; the annual affirmation is the lighter-weight attestation used in the intervening years. If no qualifying review has been performed within that window, C3 will conduct the 3.12.1[b] review ahead of the affirmation date. 

Does C3 attest to my CMMC compliance or submit my assessment? 

No — C3 does not assess its own work, does not attest to compliance, and does not own your affirmation. Your organization conducts and owns the self-assessment, the SPRS submission, and the Affirming Official attestation. C3 supports a Level 2 (Self) or Basic Assessment through a separately scoped Pre-Assessment Readiness Review, and performs the annual CA.L2-3.12.1 security control review through its Managed Compliance team. This division reflects the Cyber AB Code of Professional Conduct, under which C3 does not perform formal assessments of systems it has implemented or operates. 

What is a Pre-Assessment Readiness Review? 

A Pre-Assessment Readiness Review is a separately scoped C3 engagement that prepares your team to execute a CMMC Level 2 (Self) assessment or NIST SP 800-171 Basic Assessment with confidence. It walks your team through the 800-171A methodology, gathers and organizes evidence, and runs a tabletop exercise against each Level 2 assessment objective using the examine, interview, and test methods. It requires the same preconditions as the assessment itself: a defined and documented CMMC Assessment Scope, an operational information system (generally 60+ days of operational evidence), and final documentation. It is a support engagement, not an attestation of compliance. 

Are DFARS 252.204-7019 and -7020 still required in 2026? 

DFARS 252.204-7019 and -7020 are no longer prescribed in new solicitations as of February 1, 2026, under Class Deviation 2026-O0025, but existing contracts retain the obligation. Contracts awarded before February 1, 2026 that already contain -7019/-7020 keep those requirements, and flowdowns from primes operating under those legacy clauses can still reach a subcontractor today. The class deviation introduces DFARS 252.240-7997 in lieu of -7019/-7020 for new solicitations. 

Meet the Author

Ryan Heidorn

Chief Technology Officer