Every CMMC status ends with a signature. Somebody at your company has to go into the Supplier Performance Risk System (SPRS) and attest, under their own name and title, that the company has implemented every applicable security requirement and will keep them implemented. That person is the CMMC affirming official: a senior person from inside your own company with responsibility for compliance and the authority to attest to it. Not your managed service provider (MSP), not your consultant, not your prime.
For a 5 to 50 person shop that usually means the owner, president or general manager. This post is about that person: what the affirmation says, when they sign, and why the civil False Claims Act makes it something to prepare for rather than click through. The yearly calendar has its own post, the CMMC annual affirmation requirement.
The short version. Under 32 CFR 170.22 the affirming official enters their name, title and contact information in SPRS with a statement that the organization has implemented and will maintain all applicable CMMC security requirements for every system in the assessment scope. That statement is a condition of contract eligibility, and the False Claims Act at 31 U.S.C. 3729 covers false statements made to get federal money.
Who can be the CMMC affirming official
The definition in 32 CFR 170.4 has three parts, and all three have to be true of the same person. They must be senior level. They must be from within the Organization Seeking Assessment (OSA), which is the rule's name for your company. And they must both be responsible for the company's compliance with the CMMC Program requirements and have the authority to affirm its continuing compliance.
| Person | Can they be the affirming official? | Why |
|---|---|---|
| Owner, president, CEO, general manager | Yes, and usually the right choice | Senior, inside the company, able to commit it |
| Operations or compliance lead reporting to the owner | Possibly | Only if genuinely senior and given the authority in writing |
| Internal IT manager | Usually not | Closest to the evidence, rarely senior enough to commit the company |
| Managed service provider | No | Not from within the OSA |
| Outside consultant or registered practitioner | No | Not from within the OSA |
| Someone at your prime | No | 170.22(a) says each OSA, prime or subcontractor, affirms for itself |
The mechanics follow the definition. The SPRS Affirming Official tutorial says the affirming official needs their own Procurement Integrated Enterprise Environment (PIEE) account with the SPRS Cyber Vendor User role. Someone else can key in the assessment and use the Transfer to AO function to send it over, per the SPRS Level 2 Quick Entry Guide. The affirming official's name, title and contact details are pulled from their PIEE registration, they check a box to certify they reviewed the statement, and they click Affirm. SPRS then assigns the CMMC Unique Identifier (UID).
What the affirmation actually attests to
32 CFR 170.22(a)(2) sets the content: the affirming official's name, title and contact information, and a statement attesting that the OSA has implemented and will maintain implementation of all applicable CMMC security requirements to their CMMC Status for all information systems within the relevant CMMC Assessment Scope.
- Has implemented. Past tense, all applicable requirements. Under 32 CFR 170.24 a requirement is MET only when every applicable objective is satisfied by evidence in final form, not draft. A policy that exists only as a template is not implementation.
- Will maintain. The statement is forward looking, and DFARS 252.204-7021 defines a current status as one with no changes in compliance since the status date. A new cloud service, a new MSP, or a laptop outside the boundary changes what you signed.
- All information systems within the CMMC Assessment Scope. The statement covers the boundary you declared. If the scope was drawn wrong, the affirmation is wrong. See our scoping guide.
- To their CMMC Status. Level 1 (Self) attests to the 15 requirements of FAR 52.204-21. Level 2 (Self) attests to all 110 requirements of NIST SP 800-171 Revision 2.
The plan of action closeout is its own affirmation
If your Level 2 self-assessment scored between 88 and 109 and everything left open was eligible for a plan of action and milestones (POA&M), you hold a Conditional status, and 32 CFR 170.21 gives you 180 days from the Conditional status date to close it with a POA&M closeout self-assessment. The affirming official affirms at that closeout too. That second signature says the items you deferred are now MET, with evidence. See CMMC POA&M explained for how a closeout works.
When the affirming official signs
170.22(a)(3) lists four moments. From the signer's side of the desk:
| Trigger | What the affirming official is saying |
|---|---|
| Conditional CMMC Status achieved | The score is real, every open item is POA&M eligible, and closeout will happen within 180 days |
| Final CMMC Status achieved | Every applicable requirement is MET with final-form evidence |
| Annually after the Final CMMC Status Date | Nothing has slipped in the past year |
| After a POA&M closeout assessment | The deferred items are now MET |
The contract clause repeats the rule. DFARS 252.204-7021 (November 2025 text) requires the contractor to complete on an annual basis, and maintain as current, an affirmation by the affirming official in SPRS for each CMMC UID used on the contract, and requires primes to ensure subcontractors have an affirmation in place before subcontract award. Under 32 CFR 170.16(b) a Level 2 (Self) contractor is not eligible for award until both the assessment results and the affirmation are in SPRS. For certified assessments, the SPRS tutorial says the annual Affirm button opens 60 days before the expiration date.
The False Claims Act exposure
This is explanatory content, not legal advice. The statute, your contract and your own counsel govern. The civil False Claims Act, 31 U.S.C. 3729 through 3733, makes any person liable who knowingly presents a false claim for payment, or knowingly makes or uses a false record or statement material to a false claim. Three features matter to an affirming official.
- Knowingly is broader than lying. The statute defines it to include deliberate ignorance and reckless disregard of the truth, and says no specific intent to defraud is required. Signing without looking is the fact pattern that definition was written for.
- The numbers. A civil penalty per violation plus three times the damages the government sustains. For penalties assessed after July 3, 2025, the Department of Justice table at 28 CFR 85.5 sets the penalty at $14,308 to $28,619 per violation.
- Whistleblowers. Private parties can sue on the government's behalf and share in the recovery. In both settlements below, the whistleblowers came from inside the contractor's own IT organization.
DOJ made cybersecurity an explicit target on October 6, 2021, when it announced the Civil Cyber-Fraud Initiative, which uses the False Claims Act against contractors that knowingly misrepresent their cybersecurity practices, provide deficient cybersecurity products or services, or fail to report incidents. The announcement says it will hold accountable entities or individuals.
Two settlements show what that looks like in a NIST SP 800-171 context. Both were allegations only, with no determination of liability, and both predate CMMC affirmations. They turned on SPRS scores, which live in the same system the affirmation does.
| Settlement | Date and amount | What the government alleged |
|---|---|---|
| Pennsylvania State University | October 22, 2024; $1,250,000 | Across 15 DoD and NASA contracts or subcontracts from 2018 to 2023, submitted scores showing controls were not implemented but misrepresented the dates by which they would be, and did not pursue the plans of action. The whistleblower, a former lab chief information officer, received $250,000. |
| Georgia Tech Research Corporation | September 30, 2025; $875,000 | Submitted a campus-wide score of 98 in December 2020 premised on a fictitious environment, and had no system security plan for the lab until at least February 2020. Two former cybersecurity team members shared $201,250. |
What changes with an affirmation. A SPRS score is a number posted by an account. A CMMC affirmation is a named senior person attesting, in their own name, that the company has implemented and will maintain every requirement. The statute reaches any person who knowingly makes a false statement material to a claim, and the plans of action that were never worked in the Penn State matter are the same kind of POA&M the affirming official now signs off on at closeout. The signature is no longer anonymous.
How an owner should prepare before signing
Treat the affirmation like a loan covenant: something you verify before you sign, with a file that shows you verified it.
- Evidence in final form for every requirement in scope: approved, dated, versioned. No drafts, no folder called Templates.
- The system security plan (SSP) current as of the signing date, with the scope diagram matching the systems in use today.
- Every POA&M item marked closed has closeout evidence, and the closeout self-assessment is posted in SPRS inside the 180 days.
- A signed internal attestation from whoever runs the systems, your IT lead or your MSP, listing what they checked and the date. The MSP cannot be the affirming official, but their written statement is what the affirming official relies on.
- The SPRS record matches reality: level, status date, scope description, Commercial and Government Entity (CAGE) codes, and score.
- A memo to file naming who reviewed what, dated the same week as the affirmation.
- A calendar reminder in the affirming official's own calendar, set today, for 60 days before the next affirmation is due.
What to do this week
- Name the affirming official in writing. One dated sentence from the owner saying who it is and that they have the authority to affirm. If it is the owner, write it anyway.
- Get them the PIEE account and the SPRS Cyber Vendor User role now. Account setup takes days.
- Ask IT or the MSP for a change list since the last assessment. New services, new devices, departed staff, anything that touches the boundary.
- Walk the POA&M with the evidence open. Anything marked closed without an artifact goes back to open.
- Put the next date in the calendar and write down where the affirmation record is kept, separate from SPRS.
CMMC Map, CMMC compliance software for small defense contractors, keeps an evidence pointer next to each of the 110 requirements, so the affirming official can see what is really MET. The assessment and the live SPRS score are free forever. The generated system security plan, plan of action, policies and readiness report are the one paid plan at $149 a month. Still deciding which path applies? Start with the free Level 1 checklist.
Know what you are signing before you sign it
The free CMMC Map assessment walks all 110 requirements with an evidence pointer next to each one, so the affirming official can see what is really MET. No credit card, no trial clock.
Start free in CMMC Map