Not every CMMC requirement means hiring an assessor. For a large share of small defense contractors, the actual obligation is a self-assessment — you evaluate your own compliance, score it, and affirm the result in the government's system. Done right, it's manageable without a five-figure consultant. Done sloppily, it's a false attestation you signed your name to.
This guide walks through what a CMMC self-assessment is, when you're allowed to do one, and the step-by-step process for getting it right — including how the score works and where it goes.
What Is a CMMC Self-Assessment?
A self-assessment is exactly what it sounds like: instead of a third party evaluating you, you assess your own environment against the CMMC requirements and report the result. Two levels can involve self-assessment:
- CMMC Level 1 — if you only handle Federal Contract Information (FCI), you self-assess annually against 15 basic safeguarding requirements.
- CMMC Level 2 (self-assessment path) — for certain lower-risk CUI, you self-assess against all 110 controls from NIST SP 800-171 rather than bringing in a C3PAO.
The key thing to understand: a self-assessment holds you to the same standard as a certified one. The controls don't get easier because you're grading yourself. The only difference is who signs off — and when you self-assess, that's a senior official at your own company, on the record.
Can You Self-Assess for Level 2?
This is the question that trips people up. The answer is: it depends on your contract and the CUI you handle.
| Your situation | Assessment path |
|---|---|
| You handle FCI only | Level 1 self-assessment (15 requirements), annually |
| You handle CUI, lower-risk program | Level 2 self-assessment (all 110 controls), where permitted |
| You handle CUI, higher-risk program | Level 2 certified — a C3PAO assessment is required |
Don't guess. Check the specific requirement written into your contract, and if you're not certain whether you even handle CUI, start there — most small contractors get the CUI-vs-FCI question wrong, and it drives everything else.
Step-by-Step: How to Run Your Self-Assessment
1. Define your scope and boundary
Before you score anything, decide what's in the assessment. Which systems, devices, cloud services, and people touch your government information? A tight, accurate boundary is the single most valuable decision you'll make — draw it too wide and you're securing your whole company; too narrow and you've left CUI unprotected.
2. Write (or update) your System Security Plan
You can't assess against nothing. The SSP describes how each control is implemented in your environment. It's both the roadmap for your self-assessment and a required document in its own right. If you don't have one, this is where you start.
3. Score every control
Go control by control and mark each as MET or NOT MET based on what's actually in place — not what you intend to do. "MET" means the control is fully implemented and you can prove it with evidence. Partial credit doesn't exist: a control is either fully met or it counts against you.
4. Collect evidence for each MET control
For every control you're calling met, you need proof: a policy, a configuration screenshot, a log, a record. If you couldn't hand an assessor evidence tomorrow, don't score it as met. This is the discipline that separates a real self-assessment from wishful thinking.
5. Build a POA&M for the gaps
Every NOT MET control goes on your Plan of Action and Milestones with a remediation plan and target date. Note that not every control is even eligible for a POA&M, and there's a minimum score threshold — the POA&M is a bridge, not a permanent excuse.
How the Score Works
For a Level 2 self-assessment, you use the DoD Assessment Methodology. It's subtractive:
Start at 110. Subtract the weighted value of every control you don't fully meet — 1, 3, or 5 points each depending on its security impact. The result is your SPRS score.
Because the highest-impact controls are worth 5 points each, a handful of missing ones can sink your score fast — and unlike a test, this score can go negative. A perfect 110 means all controls are met. We break the math down in detail in our SPRS scoring guide, but the headline is simple: focus your remediation on the 5-point controls first.
Score all 110 controls without the guesswork
CMMC Map walks you through every control in plain English, scores your SPRS number automatically, flags your gaps, and assembles your SSP and POA&M as you go. Starter is $49/mo, Pro is $149/mo — a fraction of a consultant.
Start Your Free 7-Day TrialSubmitting and Affirming in SPRS
Your self-assessment doesn't count until it's recorded. You enter your score into SPRS (the Supplier Performance Risk System), the DoD's official database that primes and contracting officers can see. Under CMMC, a senior company official must affirm annually that your information is accurate — and that affirmation repeats every year, not just once. Miss the annual re-affirmation and your compliance status lapses, which can put contract eligibility at risk.
The Bottom Line
A CMMC self-assessment isn't a shortcut around the work — it's the same 110-control standard, graded by you and attested by a senior official on the record. Scope tightly, document honestly, collect real evidence, and put every gap on a POA&M. Do that, and your self-assessment is both defensible and a genuine head start if you ever do need a certified assessment down the road.