Short answer: your contract decides, not you. CMMC Level 2 exists in two assessment types — Level 2 (Self), an annual self-assessment your own company performs and affirms, and Level 2 (C3PAO), a certification assessment performed every three years by an accredited CMMC Third-Party Assessment Organization. The solicitation or contract specifies which one applies to you, and the Department has been clear that it expects the large majority of contracts involving Controlled Unclassified Information (CUI) to require the C3PAO version. The security requirements underneath are identical either way: the 110 requirements of NIST SP 800-171.
That's the answer. The rest of this article is how to confirm it for your contract, what each path actually involves, and the one mistake that makes the question moot.
Start with the clauses, not the acronyms
Open your contract or the solicitation you're bidding and search for these DFARS clauses. Each one answers a different question:
- 252.204-7012 — the baseline. If you handle CUI, you implement NIST SP 800-171 and report cyber incidents. This clause has been in effect for years and is not conditioned on CMMC at all.
- 252.204-7019 / 7020 — the scoring pair. You perform a NIST 800-171 self-assessment using the Department's scoring methodology and post the score in SPRS, and you agree to government access to verify it.
- 252.204-7021 — the CMMC clause. When present, it states the CMMC level required, and the solicitation identifies the assessment type. This is where "self-assessment or C3PAO" is actually decided.
If you only handle Federal Contract Information (FCI) and no CUI, you're looking at Level 1 — always a self-assessment, annually, with an affirmation in SPRS. Our Level 1 vs Level 2 guide covers that boundary question in detail. Everything below assumes CUI is in play.
What Level 2 (Self) actually involves
"Self-assessment" sounds like the easy path. Read it as "same exam, you grade it, and an officer of your company signs the grade":
- You assess all 110 NIST SP 800-171 requirements against your in-scope environment, annually, using the same assessment methodology a C3PAO would use.
- You enter the results in SPRS.
- A senior official — the rule calls them the Affirming Official — affirms continuing compliance, by name, every year.
That affirmation is the part to take seriously. A knowingly false or careless one is exactly the kind of statement the Department of Justice has pursued under the False Claims Act. Self-assessment shifts the assessor's work onto you; it does not shrink the requirements, and it arguably concentrates the personal accountability.
What Level 2 (C3PAO) actually involves
- An accredited C3PAO assesses your in-scope environment against the same 110 requirements, once every three years.
- Limited use of a Plan of Action & Milestones is allowed for a subset of lower-weight requirements — with a conditional status and a 180-day window to close the gaps. The highest-weight requirements cannot be POA&M'd.
- Between assessments, you still affirm continuing compliance annually in SPRS.
The practical difference from Self is cost, scheduling, and evidence discipline: a third party will ask you to show, not tell. If your documentation lives in people's heads, that's the gap that fails assessments — our C3PAO assessment preparation work is mostly about closing exactly that.
So which one will YOUR contract require?
Three ways to find out, in order of authority:
- The solicitation or contract itself. With 252.204-7021 present, the required level and assessment type are stated. This is the only answer that binds.
- Your contracting officer or prime. If the paperwork is ambiguous or predates the current rule, ask in writing. Primes also flow CMMC requirements down to subcontractors handling CUI — a prime's flow-down can require certification even while government milestones are in flux.
- The Department's stated expectation. Planning with no clause in hand yet? The rule's own commentary anticipates that the large majority of Level 2 contracts will require C3PAO certification, with self-assessment reserved for a small slice of programs. Bidding CUI work and hoping for the self-assessment lane is not a plan.
The current wrinkle: Phase 2 is suspended
As we covered in our July analysis, the Department suspended the CMMC Phase 2 rollout on July 13, 2026 and launched a reform review, which took the November 2026 certification deadline off the calendar. Three things did not change: 252.204-7012 and NIST 800-171 still apply to CUI, SPRS self-assessment obligations under 7019/7020 still apply, and prime flow-downs still say whatever they say. The suspension changed when certification is enforced at award — not whether the requirements exist, and not what a reformed program will assess against.
Why the answer changes less than you'd think
Here's the part that should reframe the whole question: the preparation is the same either way. Both paths assess the same 110 requirements over the same scoped environment, using the same methodology. The delta is who performs the assessment and how often. Which means:
- Scope your CUI boundary first — the single highest-leverage decision, because every requirement applies to everything inside it.
- Build the System Security Plan and close your SPRS gaps honestly — an accurate score you improve beats an inflated one you have to defend.
- Keep evidence as you go. If a C3PAO turns out to be required, you're ready; if self-assessment suffices, your Affirming Official signs with confidence instead of hope.
The bottom line
Read your clauses; ask your CO or prime in writing when they're ambiguous; assume C3PAO for CUI work unless your contract says otherwise. Then prepare in a way that doesn't care which answer comes back — because the 110 requirements don't.
Working out your scope, SSP, or SPRS position? See our CMMC & NIST 800-171 readiness services, start with a gap assessment, or start a conversation.
