Skip to content
Cyber Defense Technologies

Compliance

CMMC Level 2 Self-Assessment vs. Third-Party Assessment: Which Applies to You?

With the Phase 2 third-party requirement suspended, Level 2 self-assessments carry more weight than ever. How the two paths differ, and how to prepare so either one goes smoothly.

By Cyber Defense Technologies August 18, 2026 5 min read

CMMC Level 2 protects Controlled Unclassified Information (CUI) using the 110 requirements of NIST SP 800-171 Revision 2. There are two ways to demonstrate it: a self-assessment performed by your own organization, or a certification assessment performed by an authorized CMMC Third-Party Assessment Organization (C3PAO).

Which one you need depends on the contract, and on where the CMMC rollout stands. Here is how the two paths compare and what to do now.

Level 2 self-assessment vs. third-party assessment

Self-assessment

Required in Phase 1 solicitations

  • Performed by your organization against all 110 requirements
  • Score posted in SPRS
  • A senior official affirms compliance annually
  • Subject to government review and False Claims Act exposure if inaccurate

Third-party (C3PAO) assessment

Phase 2 requirement currently suspended

  • Performed by an authorized C3PAO
  • Results recorded by the assessor
  • Valid for three years, with annual affirmations
  • Still available voluntarily, and valued by primes and customers

Where things stand

The CMMC acquisition rule took effect on November 10, 2025, starting Phase 1. Solicitations in Phase 1 can require Level 1 or Level 2 self-assessments. Phase 2, planned for November 10, 2026, would have made Level 2 third-party certification a condition of award for many CUI contracts.

On July 13, 2026, the Department of War (DoW) suspended Phase 2 and set up a CMMC Reform Task Force to review the program. At the time of writing, the task force's findings have not been published. Until official guidance changes, contractors should expect:

  • Level 2 self-assessments in solicitations that require CMMC
  • Continued DFARS 252.204-7012 obligations to implement NIST SP 800-171
  • SPRS score postings and annual affirmations
  • The possibility of government-led assessments by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)

The self-assessment path

A Level 2 self-assessment follows the same assessment objectives a C3PAO would use. Your organization evaluates each of the 110 requirements, scores the result using the DoD Assessment Methodology, and records the score in the Supplier Performance Risk System (SPRS). A senior official then affirms that the organization meets, and continues to meet, the requirements, and must reaffirm annually.

Two points are easy to underestimate:

  • The standard is the same. "Self" describes who performs the assessment, not how rigorous it is.
  • The affirmation has consequences. Affirming compliance that does not exist can expose the company to False Claims Act liability. The Department of Justice has pursued cybersecurity-related cases under its Civil Cyber-Fraud Initiative, including against defense contractors.

The third-party path

In a C3PAO assessment, certified assessors examine documentation, interview staff and test controls, then record the results. A final certification is valid for three years, with annual affirmations. If the organization scores at least 88 and its remaining gaps are eligible for a Plan of Action and Milestones, it may receive conditional status, with 180 days to close those items.

Although the Phase 2 requirement is suspended, C3PAO assessments remain available. Some organizations choose one voluntarily because:

  • Prime contractors increasingly ask subcontractors for independent evidence.
  • A certification completed now is likely to retain value once third-party requirements return in some form.
  • An independent assessment validates the self-assessment score a senior official must affirm.

Choosing your path

Ask these questions for each contract and customer:

  1. What does the solicitation or contract actually require? Look for the CMMC level and assessment type in the solicitation and the DFARS clauses.
  2. What do your primes expect? Flow-down requirements and supplier questionnaires may ask for more than the minimum.
  3. How confident are you in your score? If you have never had an outside review, an independent readiness assessment reduces the risk behind your affirmation.
  4. What is your pipeline? If upcoming opportunities are likely to require certification once the program resumes, preparing now avoids a scramble for assessor time.

Prepare to the higher standard

Whichever path applies, the preparation is the same:

  • Scope carefully so only the systems that need to handle CUI are in the assessment boundary.
  • Write an accurate System Security Plan that describes how every requirement is implemented.
  • Gather evidence for each requirement: configurations, logs, records of reviews, training completions.
  • Close high-weight gaps first, especially multifactor authentication, incident response and encryption.
  • Run a mock assessment with someone independent of the team that built the controls.

An organization prepared for a C3PAO can pass a self-assessment with confidence, and can affirm it without worry.

How to run a credible self-assessment

A self-assessment is only as good as its rigor. To make yours defensible:

  • Use the assessment objectives. Each requirement has specific objectives in NIST SP 800-171A. A requirement is met only when every objective is met.
  • Separate duties. Have the assessment performed or reviewed by someone who did not implement the controls.
  • Examine, interview and test. Look at evidence, talk to the people responsible, and try the controls. Do not score from documents alone.
  • Score conservatively. If a requirement is partially implemented, it is not met. Record it on the POA&M and deduct the points.
  • Keep the working papers. Record what was examined, who was interviewed and what was tested for each requirement, so you can support the score later.
  • Brief the affirming official. The senior official who affirms should understand the method, the score and the open items.

Frequently asked questions

Does a self-assessment score need to be 110? No. Your score must be accurate and posted as required. However, the CMMC rule sets conditions for Level 2 status, including a minimum score and limits on what can remain open. Check the solicitation for what is required for award.

Can we get a C3PAO assessment now even though Phase 2 is suspended? Voluntary third-party assessments remain available. Confirm current program guidance and discuss with prospective assessors how results will be recorded.

What happens if our score is wrong? Correct it. An inaccurate score, especially one affirmed by a senior official, carries far more risk than an honest lower score with a credible plan to improve.

How CDT can help

CDT provides independent readiness assessments, remediation and assessment support for Level 2 through our CMMC and NIST SP 800-171 and security control assessment services. CDT provides readiness services; we are not a C3PAO.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.