Not every CMMC requirement means hiring an assessor. For a large share of small defense contractors, the actual obligation is a self-assessment — you evaluate your own compliance, score it, and affirm the result in the government's system. Done right, it's manageable without a five-figure consultant. Done sloppily, it's a false attestation you signed your name to.

This guide walks through what a CMMC self-assessment is, when you're allowed to do one, and the step-by-step process for getting it right — including how the score works and where it goes.

What Is a CMMC Self-Assessment?

A self-assessment is exactly what it sounds like: instead of a third party evaluating you, you assess your own environment against the CMMC requirements and report the result. Two levels can involve self-assessment:

The key thing to understand: a self-assessment holds you to the same standard as a certified one. The controls don't get easier because you're grading yourself. The only difference is who signs off — and when you self-assess, that's a senior official at your own company, on the record.

⚠️ A self-assessment is a legal attestation. When you submit your score and affirmation to the DoD, a senior official is certifying it's accurate. Inflating your score to look ready has real False Claims Act exposure — the DOJ has already pursued contractors for misrepresenting their cybersecurity compliance. Score yourself honestly.

Can You Self-Assess for Level 2?

This is the question that trips people up. The answer is: it depends on your contract and the CUI you handle.

Your situation Assessment path
You handle FCI only Level 1 self-assessment (15 requirements), annually
You handle CUI, lower-risk program Level 2 self-assessment (all 110 controls), where permitted
You handle CUI, higher-risk program Level 2 certified — a C3PAO assessment is required

Don't guess. Check the specific requirement written into your contract, and if you're not certain whether you even handle CUI, start there — most small contractors get the CUI-vs-FCI question wrong, and it drives everything else.

Step-by-Step: How to Run Your Self-Assessment

1. Define your scope and boundary

Before you score anything, decide what's in the assessment. Which systems, devices, cloud services, and people touch your government information? A tight, accurate boundary is the single most valuable decision you'll make — draw it too wide and you're securing your whole company; too narrow and you've left CUI unprotected.

2. Write (or update) your System Security Plan

You can't assess against nothing. The SSP describes how each control is implemented in your environment. It's both the roadmap for your self-assessment and a required document in its own right. If you don't have one, this is where you start.

3. Score every control

Go control by control and mark each as MET or NOT MET based on what's actually in place — not what you intend to do. "MET" means the control is fully implemented and you can prove it with evidence. Partial credit doesn't exist: a control is either fully met or it counts against you.

4. Collect evidence for each MET control

For every control you're calling met, you need proof: a policy, a configuration screenshot, a log, a record. If you couldn't hand an assessor evidence tomorrow, don't score it as met. This is the discipline that separates a real self-assessment from wishful thinking.

5. Build a POA&M for the gaps

Every NOT MET control goes on your Plan of Action and Milestones with a remediation plan and target date. Note that not every control is even eligible for a POA&M, and there's a minimum score threshold — the POA&M is a bridge, not a permanent excuse.

How the Score Works

For a Level 2 self-assessment, you use the DoD Assessment Methodology. It's subtractive:

Start at 110. Subtract the weighted value of every control you don't fully meet — 1, 3, or 5 points each depending on its security impact. The result is your SPRS score.

Because the highest-impact controls are worth 5 points each, a handful of missing ones can sink your score fast — and unlike a test, this score can go negative. A perfect 110 means all controls are met. We break the math down in detail in our SPRS scoring guide, but the headline is simple: focus your remediation on the 5-point controls first.

Score all 110 controls without the guesswork

CMMC Map walks you through every control in plain English, scores your SPRS number automatically, flags your gaps, and assembles your SSP and POA&M as you go. Starter is $49/mo, Pro is $149/mo — a fraction of a consultant.

Start Your Free 7-Day Trial

Submitting and Affirming in SPRS

Your self-assessment doesn't count until it's recorded. You enter your score into SPRS (the Supplier Performance Risk System), the DoD's official database that primes and contracting officers can see. Under CMMC, a senior company official must affirm annually that your information is accurate — and that affirmation repeats every year, not just once. Miss the annual re-affirmation and your compliance status lapses, which can put contract eligibility at risk.

✓ The self-assessment path is a real advantage — use it well. If you qualify to self-assess, you save the cost and scheduling of a C3PAO. But you inherit the responsibility of doing it accurately. The contractors who benefit most are the ones who treat the self-assessment with the same rigor an assessor would.

The Bottom Line

A CMMC self-assessment isn't a shortcut around the work — it's the same 110-control standard, graded by you and attested by a senior official on the record. Scope tightly, document honestly, collect real evidence, and put every gap on a POA&M. Do that, and your self-assessment is both defensible and a genuine head start if you ever do need a certified assessment down the road.