CMMC Assessment Levels · 1 of 3

Level 2 self-assessment and conditional status

← All Insights

In short

  • The self-assessment is repeated every three years.
  • A POA&M allows conditional status if the score ratio is at least 0.8.
  • Open items must be closed within 180 days.
Published10 October 2026
Last reviewed10 October 2026
Sources current as of10 October 2026

1. What a Level 2 self-assessment requires

Under the Cybersecurity Maturity Model Certification (CMMC) rule, an organization may reach Level 2 by assessing itself where the contract calls for Level 2 (Self). The organization seeking assessment must complete and achieve a MET result for all security requirements of Level 2, which are those of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2 (32 CFR 170.16(a)(1)). It conducts the self-assessment under the rule’s procedures and submits the results in the Supplier Performance Risk System (SPRS). Achieving Level 2 (Self) also satisfies Level 1 (Self) for the same assessment scope (32 CFR 170.16(a)).

For the systems within the assessment scope, the self-assessment is performed against NIST SP 800-171A, dated June 2018, applying the Level 2 scoping rules (32 CFR 170.16(c)(1)). It is scored under the CMMC scoring methodology and the results are uploaded into SPRS. To keep the status, the organization must repeat the self-assessment within three years of the CMMC status date associated with Conditional Level 2 (Self) and submit the results in SPRS (32 CFR 170.16(a)(1)).

2. What goes into SPRS

The SPRS entry must include, at a minimum, six items (32 CFR 170.16(a)(1)(i)). They are the CMMC level, the CMMC status date, the assessment scope, and all industry Commercial and Government Entity (CAGE) codes associated with the systems in scope. The others are the overall self-assessment score, such as 105 out of 110, and the plan of action and milestones (POA&M) usage and compliance status, if applicable. The CMMC status date is the date results are submitted to SPRS or to the CMMC instance of the Enterprise Mission Assurance Support Service (eMASS), as appropriate (32 CFR 170.4).

3. How requirements are scored

Each assessed requirement receives one of three findings (32 CFR 170.24(b)). A requirement is MET when all applicable objectives are satisfied based on evidence, and all evidence must be in final form (32 CFR 170.24(b)(1)). Working papers, drafts, and unofficial or unapproved policies are among the unacceptable forms of evidence. Enduring exceptions described in the system security plan with any mitigations are assessed as MET. So are temporary deficiencies properly addressed in operational plans of action.

A requirement is NOT MET when one or more applicable objectives are not satisfied, and the assessor documents why the evidence does not conform (32 CFR 170.24(b)(2)). A requirement or objective is not applicable when it does not apply at the time of assessment, and that finding counts the same as MET (32 CFR 170.24(b)(3)). The methodology credits partial implementation only in limited cases, such as multifactor authentication (32 CFR 170.24(a)).

4. Conditional status and the 180-day closeout

The organization achieves Conditional Level 2 (Self) if the self-assessment results in a POA&M that meets the rule’s POA&M requirements (32 CFR 170.16(a)(1)(ii)). The conditions are set out in the POA&M rules (32 CFR 170.21(a)(2)). The assessment score divided by the number of Level 2 requirements must be at least 0.8. No requirement on the POA&M may have a point value above 1, except that Controlled Unclassified Information (CUI) encryption may be included if encryption is used but is not validated under the Federal Information Processing Standards (FIPS). Six requirements may never be on the POA&M, among them external connections, the system security plan, and visitor escort and physical access controls.

The organization must remediate every NOT MET requirement, perform a POA&M closeout self-assessment and post compliance results to SPRS within 180 days of the conditional status date (32 CFR 170.16(a)(1)(ii)(B)). If the POA&M is not closed out in time, the conditional status expires. If it expires during a contract, standard contractual remedies apply. The organization is then ineligible for further awards requiring Level 2 (Self) or higher for those systems until it achieves a new status.

The organization achieves Final Level 2 (Self) when the self-assessment results in a passing score, either at first or after a POA&M closeout self-assessment (32 CFR 170.16(a)(1)(iii)).

5. DIBCAC override and cloud use

The Department reserves the right to have the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) of the Defense Contract Management Agency assess the organization. Such an assessment is made under the Defense Federal Acquisition Regulation Supplement (DFARS) clause at 252.204-7020 (32 CFR 170.16(a)(1)(iv)). If a subsequent DIBCAC assessment shows the rule’s requirements have not been achieved or maintained, its results take precedence over any existing CMMC status. Standard contractual remedies are then available, and the organization is ineligible for further awards requiring Level 2 (Self) or higher for those systems until it achieves a new status.

A cloud environment may hold CUI under a Level 2 (Self) requirement in two cases. The first is an offering authorized under the Federal Risk and Authorization Management Program (FedRAMP) at the Moderate baseline or higher, as shown in the FedRAMP Marketplace (32 CFR 170.16(c)(2)(i)). The second is an offering without that authorization that meets security requirements equivalent to the FedRAMP Moderate baseline, under Defense policy (32 CFR 170.16(c)(2)(ii)). The on-premises infrastructure connecting to the offering is part of the assessment scope and is also assessed (32 CFR 170.16(c)(2)(iii)).

6. Affirmation, eligibility and records

Affirmation of Level 2 (Self) status is required at the time of each assessment and annually after that (32 CFR 170.16(a)(2)). The affirming official is the senior representative responsible for the organization’s compliance, with authority to affirm continuing compliance (32 CFR 170.22(a)(1)). The affirmation names that official and states that the organization has implemented, and will maintain, all applicable requirements for its status across the systems in scope (32 CFR 170.22(a)(2)).

Before award of any contract or subcontract requiring Level 2 (Self), two conditions must be met (32 CFR 170.16(b)). The organization must hold Conditional or Final Level 2 (Self), and it must have submitted an affirmation of compliance in SPRS. The artifacts used as evidence for the assessment must be kept for six years from the CMMC status date (32 CFR 170.16(c)(4)). The third-party route is covered in Level 2 certification by a C3PAO.

Key terms

Level 2 (Self)Level 2 status reached by the organization’s own assessment against NIST SP 800-171.
SPRSThe Supplier Performance Risk System, where results and affirmations are entered.
POA&MA plan of action and milestones, allowed for limited requirements to reach conditional status.
Closeout assessmentThe assessment, within 180 days, that confirms all open items are fixed.
Affirming officialThe senior representative who attests to continuing compliance.

Every statement above links to the document behind it. The full source list for this piece is on the sources page.

This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.

How Sentfore supports this

Small subcontractors often reach Level 2 through self-assessment. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.