Skip to content

Walkthrough

How to run a CMMC self-assessment and submit your score

Nine steps, in order, with the traps flagged. This is the same sequence we follow for clients. The difference when we do it is that nobody is grading their own homework.

Before you start

A self-assessment is a formal exercise with real consequences. The score you produce goes into a federal system and becomes a representation made in connection with government contracts. Treat it accordingly: assess honestly, document the basis for every determination, and keep the working papers.

You will need the requirements themselves (NIST SP 800-171), the assessment procedures that decompose them into objectives (NIST SP 800-171A), the DoD Assessment Methodology for the scoring rules, and access to PIEE with the appropriate SPRS role.

  1. 01

    Confirm which level and which assessment type applies

    Read the clauses in your actual contracts. FAR 52.204-21 alone points to Level 1. DFARS 252.204-7012 plus CUI points to Level 2. Then check whether the solicitation calls for a self-assessment or a certification assessment, because that determines whether this walkthrough is your whole job or just the first half of it.

    Watch out: If you cannot find the clauses, ask your contracts officer for the full clause list. Do not guess based on what a competitor told you.

  2. 02

    Define your scope before you assess anything

    Identify every asset that processes, stores, or transmits CUI, plus the security-protection assets that defend them, plus specialised assets like test equipment and CNC controllers. Categorise each one. Draw the boundary and write down what is deliberately outside it and why.

    Watch out: This step determines everything that follows. Assessing an undefined scope produces a meaningless score.

  3. 03

    Assess against objectives, not requirements

    Work through NIST SP 800-171A, which decomposes the 110 requirements into 320 discrete assessment objectives. For each objective, determine met or not met, and record the evidence that supports your determination. A requirement scores as implemented only when every objective inside it is met.

    Watch out: Be ruthless. "We mostly do this" means not met. The whole value of a self-assessment is that it is honest.

  4. 04

    Calculate your score using the DoD methodology

    Start at 110. Subtract 5 points for each unimplemented high-weighted requirement, 3 for each significant one, and 1 for the rest. Apply the defined partial-credit provisions where they exist. The result, anywhere from 110 down to -203, is your score.

    Watch out: Record the exact deductions, not just the total. You will need them for your POA&M and for the next assessment.

  5. 05

    Write the System Security Plan

    Document the system boundary, the architecture, the asset inventory, and a control-by-control description of how each requirement is implemented in your environment: the specific product, the specific setting, the responsible role.

    Watch out: Write it from the environment outward. An SSP copied from a template and lightly edited is the single most common cause of a failed assessment.

  6. 06

    Build a POA&M that is actually executable

    Every unimplemented requirement gets an entry: what is missing, who owns it, what resources it needs, the milestone date, and what artefact will prove closure. Sequence by point value and by which items can never be deferred.

    Watch out: Under CMMC, a POA&M is only permitted at 88 of 110 or better, only for lower-weighted requirements, and everything must close within 180 days.

  7. 07

    Submit to SPRS

    Post your score in the Supplier Performance Risk System along with the assessment date, the scope description, the CAGE codes covered, and the date by which your plan of action will be complete. You need PIEE access with the correct SPRS role to do this.

    Watch out: Get the PIEE role provisioned early. Access requests are not instant, and this is a common last-minute blocker.

  8. 08

    Complete the annual affirmation

    A senior official at your company affirms continuing compliance in SPRS. That person is personally attesting on behalf of the organisation, so brief them properly on what they are signing and what evidence supports it.

    Watch out: The affirming official must be a company official, not your consultant, not your MSP.

  9. 09

    Keep it alive

    Re-assess when your environment changes materially, close POA&M items on schedule with evidence, and refresh the SSP as you go. A self-assessment is a snapshot; the obligation is continuous.

    Watch out: Diarise the annual affirmation the day you submit. Missed affirmations are an avoidable and entirely visible failure.

The uncomfortable part

A large number of contractors posted a 110 in SPRS years ago because a vendor questionnaire said they could, and have not looked at it since. Those companies are now facing assessments against the same requirements, and the gap between the posted score and the actual environment is about to become visible.

If that describes you, the right move is to reassess honestly and post a corrected score with a genuine POA&M. It feels like a step backwards. It is substantially safer than the alternative, and contracting officers deal with corrected scores routinely.

When to bring someone in

Do it yourself if you have someone internally who genuinely understands the objectives and has the standing to record uncomfortable findings about their own employer’s environment. That combination is rare.

Otherwise, our NIST SP 800-171 assessment and documentation service produces the score, the SSP, and the POA&M, and we will tell you where you actually stand rather than where you would like to.

Straight answers

Self-assessment questions

Ask us something else

Can we do a CMMC self-assessment ourselves?

Legally, yes, that is what a self-assessment is. Practically, most companies who do it unaided score themselves far too generously, because the objectives are precise and the instinct is to give yourself credit for intent. The value of outside help is not access to a secret checklist; it is someone who has no incentive to grade you kindly.

What score do we need?

For a Level 2 certification you need all applicable requirements met, with a limited POA&M permitted only from 88 of 110 upward. For contract eligibility more broadly, a current score has to exist in SPRS. There is no universal pass mark below that. What matters is that the score is accurate and current.

How long does a self-assessment take?

For a small contractor with a defined scope, a careful assessment against 320 objectives is typically two to four weeks of real work, including evidence collection. Companies that finish in two days have not actually assessed anything.

Is it risky to post a low score?

Far less risky than posting a high one you cannot defend. A low score with a credible POA&M shows a company that understands its position. An unsupported 110 is a representation to the government that has already produced False Claims Act settlements in this industry.

Does a self-assessment satisfy our CMMC obligation?

For Level 1 and for those Level 2 contracts designated as self-assessment, yes, combined with the annual affirmation. For Level 2 contracts requiring certification, the self-assessment is preparation, not the finish line: an accredited C3PAO has to assess you.

Next step

Rather have someone score it who has no reason to be generous?

We assess all 320 objectives, produce your SSP and POA&M, and walk you through the SPRS submission, so the number you post is one you can defend.

We reply within one business day.