Understanding CMMC Level 2 Self-Assessments
An in-depth breakdown of the CMMC Level 2 Self-Assessment process and how to factor the requirements into your larger compliance strategy.
Understanding CMMC Level 2 Self-Assessments
With the CMMC Final Rule now in effect and requirements appearing in active solicitations, defense contractors are under growing pressure to demonstrate compliance. While CMMC Level 2 certification requirements will continue to expand in November 2026, many organizations are already encountering Level 2 self-assessment requirements as contracts begin to flow down.
These self-assessments are not new or informal. They represent the next evolution of long-standing DFARS obligations for safeguarding Controlled Unclassified Information (CUI) and carry the same expectations for rigor, accuracy, and accountability.
What is a CMMC Level 2 Self-Assessment?
The CMMC Level 2 self-assessment is one of the four CMMC assessment statuses that a Contracting Officer may require in contracts governed by DFARS 252.204-7021 (CMMC awards) or DFARS 252.204-7025 (notice in solicitations). Within Level 2, there are two distinct paths: self-assessment and certification.
During Phase 1 of CMMC implementation, which took effect in November 2025, many CMMC requirements appearing in contracts are for Level 2 (Self). This requirement applies whenever CUI is involved.
Which Level 2 path applies depends on the type of CUI involved. The DoW’s January 2025 implementation guidance establishes that CUI categories within the Defense Organizational Index Grouping of the CUI Registry – which includes categories like Controlled Technical Information, Naval Nuclear Propulsion Information, and Unclassified Controlled Nuclear Information – require Level 2 Certification conducted by a C3PAO. CUI categories outside that grouping require a Level 2 Self-Assessment.
Who Needs a Level 2 Self-Assessment?
As the CMMC rollout progresses, many organizations are encountering Level 2 Self-Assessment requirements in current contracts. While some of these contracts may transition to Level 2 (C3PAO) requirements beginning in Phase 2 (November 2026), there is no way to know if a requirement initially designated as Level 2 (Self) will remain so in future phases. Contractors should plan accordingly and avoid treating Level 2 self-assessments as a short-term or temporary obligation.
A persistent misconception is that Level 2 self-assessments will disappear as CMMC matures. This is not the case. Level 2 self-assessments will continue to exist in Phases 2 through 4 and beyond, depending on the type of CUI involved. For example, a contractor handling non-Defense-Index CUI such as tax information, archaeological data, or VA PII or health records may only ever see a Level 2 (Self) requirement.
However, a contractor designing weapons systems, maintaining defense infrastructure, providing logistics support, or doing any of the core work of the DIB is likely handling Defense Organizational Index CUI almost by definition. Contractors evaluating their long-term compliance posture may find that pursuing Level 2 (C3PAO) certification offers broader business flexibility. Certification can support a wider range of future contract opportunities and reduce uncertainty as requirements evolve. The decision between self-assessment and certification should be driven by overall business strategy, not just immediate contract needs.
The CMMC Level 2 Self-Assessment Process
Organizations conducting a CMMC Level 2 self-assessment are responsible for evaluating, documenting, and reporting that all applicable security requirements are “MET.” This includes performing a formal self-assessment against each of 320 assessment objectives in accordance with NIST SP 800-171A (June 2018), which results in an overall compliance score of up to 110.
Once the assessment is complete, the Organization Seeking Assessment (OSA) must determine whether the results support a Conditional or Final Level 2 self-assessment status based on the presence or absence of unmet requirements and applicable Plans of Action and Milestones (POA&Ms).
To formally report the assessment, the OSA must enter the following information into the Supplier Performance Risk System (SPRS):
- CMMC Level (Level 2 self-assessment)
- CMMC Status Date
- Assessment Scope (Enterprise or Enclave)
- All industry CAGE codes associated with the in-scope systems
- Overall Level 2 self-assessment score
In addition to submitting the assessment results, organizations are required to complete an affirmation of accuracy:
- At the time the assessment is submitted, and
- Annually thereafter for as long as the assessment remains active
To support this effort, we strongly recommend using a structured assessment workbook or tracking document to capture evidence, implementation details, and assessor notes for each individual requirement. Proper documentation not only helps ensure accuracy and consistency but is critical for demonstrating due diligence if the assessment is ever reviewed.
Evidence and Artifact Retention: What Counts and Why It Matters
CMMC Level 2 self-assessments must be conducted in accordance with NIST SP 800-171A (June 2018). When this process is followed as intended, evidence and assessment artifacts are produced naturally as part of the evaluation. Organizations conducting a Level 2 self-assessment are required to retain this evidence for six years from the CMMC Status Date.
The OSA has discretion in how evidence and artifacts are stored and maintained, provided they can be made available throughout the full retention period. Unlike certification assessments conducted by C3PAOs or DCMA DIBCAC, self‑assessments do not require evidence hashing.
It is important to understand that a Level 2 self-assessment is not a simplified or informal version of a Level 2 certification assessment. The required assessment methodology is fundamentally the same – the only difference is that it is performed by the OSA rather than a C3PAO.
Organizations should also be aware that self-assessments are not risk-free. The Department of War (DoW) reserves the right to conduct a DCMA DIBCAC assessment at its discretion, and any unsupported or inaccurate assertions may carry contractual, financial, or legal consequences.
Strategic Considerations for Long-Term CMMC Planning
If your organization is pursuing CMMC Level 2 (Self), it’s critical to evaluate the decision through the lens of long-term business strategy, not just immediate contract needs. CMMC compliance is designed to support eligibility across multiple contracts, not a single award in isolation. Focusing too narrowly on one opportunity can limit future flexibility and create unnecessary rework.
Organizations should also be cautious about scope decisions made early in the process. Attempting to add CAGE codes after an assessment may be considered a “significant change” and could trigger a required reassessment. Similarly, developing contract-specific Level 2 enclaves may satisfy a short-term requirement but leave gaps for other DoW work down the road.
It’s also important to understand how Level 2 self-assessment aligns with Level 2 certification. A Level 2 assessment conducted by a C3PAO fully satisfies the requirements of Level 2 self-assessment—but only for the same defined scope. Certification does not automatically extend to unrelated systems supporting other contracts or departments.
Taking the time to align scope, CAGE codes, and business objectives up front can reduce compliance risk, avoid costly reassessments, and position your organization for sustained success as CMMC requirements continue to evolve.
Final Thoughts
CMMC Level 2 self-assessments are no less rigorous, formal, or consequential than certification. They demand advance planning, disciplined execution, and comprehensive evidence collection and retention. Treating a self-assessment as a minimum-effort exercise can introduce avoidable risk, both operational and contractual.
When deciding between Level 2 self-assessment and Level 2 certification, organizations should look beyond immediate contract requirements and consider their broader business strategy, future bidding opportunities, and long-term compliance posture.
If you’re preparing for a Level 2 self-assessment, our evidence collection workbook can help you document implementation, organize artifacts, and maintain consistency throughout the assessment process. You can also find more information in our comprehensive eBook, The CMMC Level 2 Self-Assessment.
And if you’d like expert guidance evaluating your contract requirements or broader CMMC strategy, schedule a consultation with us to ensure you’re positioned for success.