Self-assessment is a standing CMMC requirement — mandatory at Level 1, and permitted for many Level 2 contracts that don’t involve the most critical national security information. But it’s also something else, useful to nearly every defense contractor regardless of which assessment type ultimately applies: an honest, structured way to find out where you actually stand before someone else tells you.

Organizations pursuing C3PAO certification still benefit from self-assessment as preparation — it’s the readiness check that surfaces gaps while you still have time to close them, rather than during an assessment that’s already underway. This guide covers how to conduct an accurate self-assessment, the specific mistakes that produce an inflated score without contractors realizing it, and how to use the process either as your standing compliance requirement or as preparation for a future third-party review.

Note: CMMC Phase 2 third-party certification requirements were suspended by the Department of War in July 2026, pending a program review. Self-assessment requirements, including annual affirmation, remain fully in force. See CMMC Phase II Is Suspended. Your DFARS Obligations Are Not. for full detail.

CMMC Self-assessment: A Comprehensive Guide for Businesses

Executive Summary

Main Idea: Self-assessment is the process of evaluating your own environment against required CMMC controls and reporting a score to the Supplier Performance Risk System (SPRS). It’s a standing requirement at Level 1 and for many Level 2 contracts, and a useful readiness check even for organizations ultimately pursuing C3PAO certification — but its accuracy depends entirely on the rigor of the process behind it.

Why You should Care: Kiteworks’ own August 2026 survey of 273 DIB organizations found a significant gap between confidence and evidence: 96% of respondents said they were confident their self-attested SPRS score would hold up under review, but the same research found confidence didn’t track actual knowledge of current requirements, and nearly a third of already-qualified organizations scored low on both compliance maturity and governance response combined. An inaccurate self-assessment isn’t a paperwork problem — it’s a False Claims Act exposure that 84% of surveyed contractors already say they’re concerned about.

Key Takeaways

  1. Self-assessment isn’t limited to Level 1 — it applies to many Level 2 contracts too. Level 1 is always self-assessed. Level 2 contracts not involving the most critical national security information may also qualify for self-assessment rather than requiring full C3PAO certification, depending on the specific program.
  2. Self-assessment is also a practical readiness check, regardless of which assessment type ultimately applies to you. Organizations pursuing C3PAO certification commonly conduct an internal self-assessment first, specifically to surface gaps while there’s still time to remediate them before a formal, higher-stakes review begins.
  3. Confidence in a self-assessed score and the accuracy of that score are two different things. Survey data on the DIB found that contractors who described themselves as “very confident” in their understanding of current requirements scored no better on a factual knowledge test than those who described themselves as only “somewhat confident” — confidence and accuracy aren’t the same measurement.
  4. The most common scoring mistake is treating partial or planned implementation as complete implementation. A control that’s configured but not fully deployed, or documented as a future plan rather than current practice, is not the same as a control that’s actually implemented — but it’s frequently scored as if it were, inflating the resulting SPRS score.
  5. An inaccurate self-attested score carries legal exposure, not just compliance risk. The DoJ’s Civil Cyber-Fraud Initiative pursues False Claims Act cases against contractors who misrepresent their cybersecurity compliance — and a large majority of surveyed contractors already report engaging legal or compliance review specifically because of this exposure.

How Self-Assessment Actually Works

Self-assessment requires evaluating your organization’s environment against every required control for your level — 17 practices for Level 1, all 110 NIST SP 800-171 controls for Level 2 — and reporting the result to the Supplier Performance Risk System (SPRS). For Level 2, the standard scoring methodology assigns point deductions for each control not fully implemented, producing a score that reflects how close the organization is to full compliance.

A senior company official then formally affirms the accuracy of that assessment. This affirmation matters more than it might initially appear: it’s a specific, individual attestation that the reported score reflects reality, not a general organizational assurance. That distinction is exactly what creates personal and organizational legal exposure if the affirmation turns out to be inaccurate.

Scores are valid for a defined period, but annual affirmation of continued compliance is required in between — meaning self-assessment isn’t a one-time event even for organizations whose ongoing requirement is self-assessment rather than third-party certification.

The Mistakes That Produce an Inflated Score

Self-assessment accuracy depends on rigor, and the same handful of mistakes show up repeatedly across organizations that later discover their score didn’t hold up under scrutiny.

Scoring planned or partial implementation as complete. This is the single most common error. A control that’s been configured in a test environment but not deployed organization-wide, or one that’s documented as a near-term plan rather than current practice, is not fully implemented — but it’s frequently scored as though it were, especially under deadline pressure to report a strong number.

Incomplete scoping. An accurate self-assessment requires knowing every system that touches CUI or FCI — not just the obvious ones. Email, file sharing, web forms, and systems managed by third parties are commonly excluded from the assessment’s scope, producing a score that reflects only part of the organization’s actual environment.

Treating documentation gaps as implementation gaps, or vice versa. A control that’s genuinely implemented but poorly documented is a different problem than a control that isn’t implemented at all — but self-assessments sometimes conflate the two, either under-scoring a real control because the paperwork is thin, or over-scoring an absent control because a policy document describes an intention rather than a practice.

Confidence substituting for verification. Survey data on the DIB found that contractors’ stated confidence in their self-assessed score didn’t correlate with their actual, tested knowledge of current requirements — respondents who called themselves “very confident” scored identically on a factual test to those who called themselves only “somewhat confident.” Confidence is not evidence, and a self-assessment built on impression rather than direct verification of each control is exactly the kind of gap that surfaces at the worst possible time — during an audit, an incident investigation, or a False Claims Act inquiry.

Using Self-Assessment as C3PAO Preparation

Even if your ultimate requirement is third-party certification, conducting an internal self-assessment first is common and valuable practice. It surfaces the same gaps a C3PAO would find — but while you still control the timeline and can remediate before a formal assessment begins, rather than during one, when a discovered gap can delay certification and cost additional assessment fees to resolve.

The discipline required for an accurate self-assessment — genuine scoping, honest scoring of partial implementation, and documentation that matches actual practice — is the same discipline a C3PAO assessment will test directly through document review, interviews, and technical verification. For what that formal assessment process specifically involves, see our guide on what happens during a CMMC assessment and after you pass.

Kiteworks offers a free CMMC 2.0 Readiness Assessment that generates a personalized gap analysis and compliance readiness score in minutes — a practical starting point for either a standing self-assessment requirement or preparation ahead of a C3PAO review.

Why Self-Assessment Accuracy Matters More Than It Might Seem

Kiteworks’ August 2026 survey of 273 confirmed DoW-business organizations found a pattern worth taking seriously: 96% of respondents said they were confident their self-attested SPRS score would hold up under review, but that confidence was largely detached from actual evidence. The research introduced two measurements — a CMMC Compliance Maturity Score and a Suspension Governance Score — and found that when combined by multiplication rather than simple averaging (since a strong compliance record can’t compensate for a passive governance response, and vice versa), nearly a third of an already-qualified population scored low on both dimensions simultaneously.

The same survey found that 48% of contractors didn’t know that Phase 1 self-assessment obligations continue during the current Phase 2 pause — a basic factual gap with real consequences, since organizations operating on the mistaken belief that all CMMC obligations are paused are, by definition, not maintaining the self-assessment and affirmation requirements that remain fully active. Separately, 84% of respondents said they’re concerned about False Claims Act exposure from an inaccurate self-attested score, and 92% report already engaging legal or compliance review as a result. For the full findings, see State of CMMC 2.0 Preparedness in the DIB.

How Kiteworks Supports Accurate Self-Assessment

Kiteworks supports nearly 90% of CMMC 2.0 Level 2 requirements out of the box, and the same infrastructure that supports implementation also supports the evidence an accurate self-assessment depends on. A unified Data Policy Engine consolidates access controls, encryption, and audit logging across secure email, secure file sharing, managed file transfer, and SFTP — addressing the scoping problem directly, since CUI moving through any of these channels is visible and governed in one place rather than scattered across disconnected systems that are easy to leave out of an assessment’s scope.

A single, consolidated, immutable audit trail gives an organization real evidence to score against, rather than an impression of compliance based on policy documents that may or may not reflect current practice. That distinction — evidence versus confidence — is exactly what the DIB survey data found most contractors are currently missing.

To see how Kiteworks supports an accurate, defensible self-assessment, schedule a custom demo, or start with the free CMMC 2.0 Readiness Assessment.

Frequently Asked Questions

No. Self-assessment is always required at Level 1, but it also applies to many Level 2 contracts — specifically those that don’t involve the most critical national security information. Level 2 contracts meeting a higher criticality threshold require third-party C3PAO certification instead. Whether self-assessment or C3PAO certification applies to a specific Level 2 contract depends on the program itself, so contractors should confirm this directly rather than assuming either path applies by default.

Scoring planned or partially implemented controls as though they were fully implemented. A control that’s configured in a test environment, documented as a near-term plan, or deployed for only part of the organization is not the same as a control that’s fully and consistently operating — but it’s commonly scored as complete, especially under pressure to report a strong number. Incomplete scoping — leaving out systems like email or third-party-managed tools that also touch CUI — is another common source of an inaccurate score.

Yes. Conducting an internal self-assessment before a formal C3PAO review is common and valuable practice, since it surfaces the same gaps a third-party assessor would find, while the organization still controls the timeline for remediation. Discovering a gap during a self-assessment allows time to fix it; discovering the same gap during a live C3PAO assessment can delay certification and add cost. The rigor required for an accurate self-assessment — genuine scoping, honest scoring, and documentation that matches practice — is the same discipline a C3PAO assessment will test directly.

An inaccurate self-attested CMMC score can expose an organization and the individual who affirmed it to False Claims Act liability under the Department of Justice’s Civil Cyber-Fraud Initiative, which specifically pursues cases involving misrepresented cybersecurity compliance. Survey data on the DIB found 84% of contractors are already concerned about this exposure, and 92% report engaging legal or compliance review as a direct result — reflecting that self-assessment accuracy is understood industry-wide as a legal question, not just a technical or administrative one.

Back to Risk & Compliance Glossary

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Share
Tweet
Share
Explore Kiteworks