Reliable Integration / Resources / Level 2 Self-Assessment
What a Level 2 self-assessment actually requires
Self-assessment does not mean self-graded. It means no outside auditor is in the room while you certify something to the federal government under penalty.
The short answer
You assess your environment against all 110 NIST SP 800-171 Rev 2 requirements, calculate a weighted score out of 110, post that score and your assessment details in SPRS, and have an Affirming Official attest to its accuracy — annually. A score of 110 earns Final status. A score of 88 to 109 can earn Conditional status if every gap is on a POA&M and none of them are requirements the rule prohibits deferring.
The word "self" refers to who runs the assessment. It does not reduce what has to be true.
Step one is scope, not controls
Before any of the 110 requirements mean anything, you have to know what they apply to. That means identifying every asset that processes, stores, or transmits CUI, plus the security protection assets that defend them.
Scope everything and you will be assessing the whole company forever. Scope an enclave and the 110 requirements apply to a defined boundary you can actually defend. This decision drives cost more than any other in the program.
How SPRS scoring actually works
You start at 110 and subtract. Each requirement you have not fully implemented costs you 1, 3, or 5 points depending on its security impact. Because there are more high-weight requirements than 110 points, the scale runs from 110 all the way down to -203.
First-time honest scores are frequently negative. That is normal and it is not by itself disqualifying. What matters is that the number is accurate and that it is moving.
| Score | What it gets you |
|---|---|
| 110 | Final Level 2 (Self) status. Every requirement MET. |
| 88–109 | Conditional Level 2 (Self), valid 180 days, if all gaps are on a POA&M and none are prohibited from deferral. |
| Below 88 | Cannot be affirmed for a CMMC status. The score is still visible to contracting officers and primes. |
The trap: 88 is 80 percent of 110. People routinely assume 80 percent means a score of 80 and come up eight points short.
Which gaps can go on a POA&M, and which cannot
A Plan of Action and Milestones lets you carry certain unmet requirements temporarily. It does not let you carry all of them. The rule at 32 CFR 170.21(a)(2)(iii) names requirements that cannot be deferred at all.
In practice this means the highest-weight requirements have to be genuinely met. A NOT MET finding on a prohibited requirement produces No CMMC Status regardless of your overall score — a 109 with the wrong gap is worth nothing. Multi-factor authentication and FIPS-validated encryption are the two that most often catch people out. Encryption has a narrow allowance: it can be deferred if cryptography is in use but not yet FIPS-validated, which is not the same as having no encryption.
If you take Conditional status, a 180-day clock starts. Close every POA&M item and pass a closeout assessment inside that window, or the status lapses.
The SSP is the deliverable that outlives everything
Your System Security Plan describes your boundary and how each of the 110 requirements is implemented in your specific environment. It is not a template exercise. An assessor reads it to understand what you built, and a good one will notice immediately if it describes a generic network rather than yours.
One thing worth doing properly: assess against the NIST SP 800-171A assessment objectives, not the requirement statements alone. There are roughly 320 objectives underneath the 110 requirements, and a requirement is only MET when every objective under it is satisfied. Scoring at the requirement level is how organizations end up with a confident 105 that collapses to 60 under scrutiny.
The affirmation is the part with teeth
An Affirming Official — a named senior person at your company — attests annually in SPRS that your assessment is accurate. That is a representation to the federal government.
DoD has already pursued False Claims Act cases against contractors for misrepresenting NIST 800-171 compliance under earlier DFARS clauses. DIBCAC's own review found that many self-reported perfect scores of 110 did not hold up, which is a substantial part of why third-party assessment was introduced in the first place.
Score conservatively. A defensible 74 with a real remediation plan is a better position than an aspirational 110 that someone will eventually test.
Keep your evidence for at least six years. DoD can ask.
What the ongoing cadence looks like
- Full self-assessment every three years.
- Affirmation in SPRS every year.
- Reassessment whenever your environment changes materially — new systems, new CUI flows, a merger.
- POA&M closeout within 180 days if you are Conditional.
Where the program stands as of August 2026
Phase 1 has been in force since 10 November 2025. Covered new DoD contracts require a current Level 1 or Level 2 self-assessment in SPRS plus an annual affirmation at time of award.
On 13 July 2026, Phases 2 and 3 were suspended pending program review, pausing the planned expansion of third-party C3PAO assessments. That suspension paused the auditor. It did not pause the obligation to implement the controls, and it has not slowed prime contractors down — several are flowing requirements to suppliers on schedules earlier than the government's own.
Common questions
What SPRS score do I need for CMMC Level 2?
A score of 110 earns Final Level 2 (Self) status, meaning every one of the 110 NIST SP 800-171 Rev 2 requirements is MET. A score of 88 to 109 can earn Conditional status, valid for 180 days, provided every unmet requirement is documented on a POA&M and none of them are requirements the rule prohibits from deferral under 32 CFR 170.21(a)(2)(iii). Scores below 88 cannot be affirmed for a CMMC status.
Can a negative SPRS score be fixed?
Yes, and negative scores are common on a first honest assessment. The scale runs from 110 down to -203 because unimplemented requirements carry weights of 1, 3, or 5 points. A negative starting score is not disqualifying on its own. What matters is that the score is accurate and that documented remediation is underway.
Which CMMC requirements cannot be placed on a POA&M?
32 CFR 170.21(a)(2)(iii) specifies requirements that cannot be deferred. In practice the highest-weighted requirements must be genuinely met, with multi-factor authentication and FIPS-validated encryption the most common failures. Encryption has a narrow exception where cryptography is in use but not yet FIPS-validated. A NOT MET finding on a prohibited requirement results in No CMMC Status regardless of the overall score.
Does self-assessment mean nobody checks my work?
No. It means no third-party assessor conducts the assessment. Your Affirming Official still attests to accuracy in SPRS annually, which is a representation to the federal government, and DoD has pursued False Claims Act cases over misrepresented NIST 800-171 compliance. DIBCAC can also audit. Evidence should be retained for at least six years.
How often do I need to reassess?
A full self-assessment every three years, an affirmation in SPRS every year, and a fresh assessment whenever your environment changes materially. If you hold Conditional status, POA&M items must be closed and verified within 180 days or the status lapses.
Want to know your real number before someone else calculates it?
The gap analysis produces an honest SPRS score, a CUI data-flow map, and a prioritized remediation plan. $7,500, two weeks, credited in full if you go on to build.
Book a 20-minute scoping call See pricingOr call 1-919-717-2707.