With third-party CMMC certification paused, it's tempting to think nobody is looking at your self-assessment. The opposite is true. Your work is still being checked — just by different people, with different methods: a prime contractor's supply-chain team deciding whether you stay on the bid, a DIBCAC reviewer running a government-led assessment, a consultant doing a pre-gap before you sign your annual affirmation, or a Department of Justice attorney reading your SPRS submission after a whistleblower call.
All of them work through your package in roughly the same order. If you know the checklist, you can run it against yourself before anyone else does. Here it is.
1. Is there a current score in SPRS — and can you show your math?
The first question is the simplest: is there a NIST 800-171 self-assessment score posted in SPRS, is it less than three years old, and does the company know how it was calculated? A surprising number of contractors have a score in the system that nobody currently employed can explain. Reviewers notice. Keep the scoring worksheet — which controls were met, which weren't, and the DoD-methodology deductions for each — with the score's date, so the number has a paper trail.
2. Does the SSP describe the system you actually run?
The System Security Plan is the anchor document — required by DFARS 252.204-7012 whether or not CMMC ever knocks. Reviewers read it for freshness first: does it name the platforms you actually use today, the office you actually work from, the people who actually hold the roles it describes? An SSP that still lists a decommissioned file server or a departed employee tells a reviewer everything they need to know about the rest of the package. If your environment changed and the SSP didn't, that's the first fix.
3. Does the POA&M have dates — and movement?
Nobody expects a small contractor to be perfect. Reviewers expect the gaps to be managed. A Plan of Action & Milestones with owners and target dates reads as a program; one without dates reads as a wish list; none at all — while controls sit unimplemented — reads as denial. The strongest signal is movement: items that closed since the last version, dates that were met. Keep old versions. The history is the proof.
4. Is there evidence behind "implemented"?
This is where most self-assessments come apart. A reviewer picks a sample of controls you marked implemented — they start with the five-point requirements: multifactor authentication, FIPS-validated encryption, audit logging — and asks the only question that matters: show me.
- Configuration proof: screenshots or exports showing the setting enforced — MFA enrollment reports, encryption settings, firewall rules — with visible dates.
- Written policies: with effective dates and an approver, covering the control families.
- Records of operation: training completions, log review sign-offs, incident response tests. Controls that are supposed to happen on a schedule need proof they happened.
- Inherited controls: where your MSP or cloud platform performs the work, documentation of who does what — a shared responsibility matrix — plus the provider's own attestation.
The dangerous list is the quiet one: controls marked implemented with no artifact attached and no written statement of how they're met. Under self-attestation, that list is exactly what a False Claims Act case is built from — and exactly what your Affirming Official is signing for every year. Know which of your controls are on it before someone else finds out.
5. Do the N/A calls have justifications?
"Not applicable" is a legitimate answer — plenty of small shops genuinely have no wireless, no mobile devices, no publicly accessible systems. But every N/A needs a written justification, because it's the first thing a skeptical reviewer probes. An unjustified N/A looks like a dodge even when it isn't one.
6. Do the policies exist — and match the practice?
Most 800-171 families expect a written policy behind the technical controls. Reviewers cross-check in both directions: a policy that mandates something your configuration doesn't do is worse than no policy, and a practice with no written policy behind it earns a finding even when the practice is sound. Fourteen short, honest documents beat one aspirational binder.
Run the checklist on yourself first
Every item above is knowable in an afternoon: pull your score and its math, open the SSP next to your actual environment, count the undated POA&M lines, list every implemented control with nothing behind it, and read your N/A justifications as a stranger would. That one-page picture — where you're ready, where you need attention, what a reviewer will flag — is the readiness report that matters, and it's worth assembling before the prime's questionnaire, the DIBCAC email, or the affirmation deadline puts you on someone else's clock.
If you advise multiple companies — an MSP or consultant preparing clients — this same checklist is the deliverable your clients need monthly: not another controls spreadsheet, but the reviewer's-eye view of whether the package holds up.
Get the reviewer's-eye view of your own assessment
CMMC Map tracks all 110 requirements with your evidence attached, calculates your DoD-weighted SPRS score, and generates the documents a reviewer asks for — SSP, POA&M, and a readiness report that flags exactly what's asserted but not yet evidenced. The assessment is free.
Start your free assessment