CMMC Phase 1 · Level 2 Self

Prepare a supportable CMMC Level 2 Self assessment.

If your solicitation or contract requires CMMC Level 2 (Self), your organization assesses the 110 NIST SP 800-171 Revision 2 security requirements, submits the required result in SPRS, and maintains the status with annual affirmation. Cyberneza helps define scope, evaluate implementation, remediate gaps, build the SSP and supporting evidence, and prepare the submission information. Your organization performs the self-assessment, submits the result, and makes the required affirmation.

Current status · August 2026

Phase II is suspended. Phase I self-assessments remain in force.

The Department suspended CMMC Phase II requirements on July 13, 2026. Its current CMMC guidance says the program is paused in Phase 1 and may require Level 1 (Self) or Level 2 (Self). For Level 2 Self, the assessment is conducted by the Organization Seeking Assessment every three years, the results are entered in SPRS, and an affirmation is required after the assessment and annually thereafter.

Primary source: Department CMMC overview. Review the CMMC level and assessment type in the solicitation, contract, order or flow-down that applies to your organization.

Level 2 Self requirements

The assessment repeats every three years; compliance activities continue between assessments.

110 Rev. 2 requirements

CMMC Level 2 uses the 110 security requirements in NIST SP 800-171 Revision 2. The current CMMC rule scores Level 2 against those requirements; Revision 3 exists, but it is not the Level 2 CMMC baseline today.

See the Level 2 requirements →

Self-assessment every three years

32 CFR 170.16 requires the organization to conduct the Level 2 Self assessment and submit its results to SPRS every three years to maintain Level 2 (Self) status.

Annual affirmation

An affirming official submits an affirmation after the assessment and annually thereafter. If the annual affirmation is not maintained, the assessment status lapses.

Final evidence

Under the CMMC scoring rule, a requirement is MET when all applicable assessment objectives are satisfied based on evidence. Draft or unofficial evidence does not qualify as final evidence.

Limited POA&M use

Level 2 can reach Conditional status only under the rule's POA&M conditions. Eligible items must be closed through the required closeout assessment within 180 days. Requirements that are not POA&M-eligible must be satisfied for the applicable status.

SPRS status

Current DFARS procedures require contracting officers to check SPRS for a current CMMC status at the level required by the solicitation for the contractor information systems identified by CMMC UID.

Cyberneza readiness support

  • Contract and information review: identify the required level and assessment type and determine whether CUI is present.
  • CMMC scope: identify CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets and defensible Out-of-Scope Assets.
  • Gap assessment: evaluate all 110 requirements and applicable assessment objectives against the operating environment.
  • Implementation: remediate technical, administrative and operational gaps.
  • SSP and evidence: document the implemented environment and connect requirements to final supporting evidence.
  • SPRS preparation: prepare the information required for the Level 2 Self submission. Where a separate DFARS 7019/7020 Basic Assessment applies, calculate and document that numeric score separately.

Contractor responsibilities

  • Your organization performs the self-assessment.
  • Your organization submits the CMMC Level 2 Self result in SPRS.
  • Your affirming official makes the required affirmation.
  • Your organization remains responsible for continuing compliance and material changes to the assessed environment.

Cyberneza provides readiness, implementation and documentation support. We do not make the government-facing representation for you and we do not issue CMMC certifications.

Scope and architecture

Reduce unnecessary scope before selecting a broader CUI environment.

CMMC Level 2 scope is broader than only devices that directly hold CUI, but it is not automatically every computer in the company. The rule includes CUI Assets and relevant Security Protection Assets and defines treatment for Contractor Risk Managed Assets, Specialized Assets, external service providers and Out-of-Scope Assets. The architecture therefore matters before major licensing or migration decisions.

Where the business workflow allows it, a secure CUI enclave can confine CUI to a smaller set of users, systems and workflows instead of allowing it to spread through ordinary commercial email and file sharing. That can reduce the assessment footprint and may reduce implementation and operating cost. It does not automatically make every surrounding system out of scope; the actual boundary still has to satisfy 32 CFR 170.19.

PreVeil is one enclave option. PreVeil states that its service is FedRAMP Moderate Equivalent and uses AES-256-GCM cryptography in a FIPS 140-3 validated module. It is designed to run alongside existing Microsoft 365 or Google Workspace workflows, allowing general business work to remain on the existing platform while CUI is handled in the protected enclave. Cyberneza is a PreVeil referral partner and can scope, deploy and document that architecture.

Cloud use remains subject to the CMMC and DFARS requirements applicable to the service and your connected environment. A tool does not by itself satisfy all 110 requirements.

Recommended sequence

Confirm the requirement, define scope, implement, document, then assess.

1. Confirm the requirement

Review the solicitation, contract and prime flow-down and identify the required CMMC level and assessment type.

2. Define the CUI boundary

Trace where CUI enters, is stored, is processed, is transmitted and leaves the environment before broad technology purchases.

3. Implement and collect evidence

Remediate gaps, build the SSP from the operating environment, and collect final evidence as the requirements are performed.

4. Assess, submit and affirm

Conduct the Level 2 Self assessment, submit the result in SPRS, complete the required affirmation and maintain the assessed environment between assessment cycles.

Need Level 2 Self readiness support?

Send us the applicable contract clauses, the systems and services that handle CUI, and the security controls already in place. Cyberneza can define the preliminary boundary, assess the 110 requirements, identify remediation work, and organize the SSP and evidence required for your self-assessment.

Primary government references

This page is written against current Department CMMC implementation guidance, 32 CFR Part 170, DFARS Subpart 204.75 and NIST SP 800-171 Revision 2. Product-specific statements are attributed to the product publisher in the page text; contractual and regulatory requirements are grounded in the government sources below.