The CMMC assessment process: from self-assessment to certification
A self-assessment is the record that stands behind your SPRS score and your affirmation. How to run one control by control, what evidence counts, how the score is calculated, and what a C3PAO does with it.
Key takeaways
- Your self-assessment is the record. A C3PAO validates it; during the suspension, your affirmation rests on it alone.
- Assess per objective, not per requirement. NIST SP 800-171A breaks each of the 110 into determinations an assessor decides one at a time.
- Evidence must be dated, specific to your environment, and attributable to you.
- The SPRS score starts at 110 and subtracts the weight of each unmet requirement; the system security plan is not scored but is required.
Two phases, one record
Phase 1: self-assessment
What you do internally. Work through all 110 requirements, determine status per objective, collect evidence, calculate the SPRS score, and produce the system security plan. This article is about that record.
Phase 2: C3PAO assessment
What the assessor does. A certified C3PAO validates your self-assessment through document review, interviews and testing. The third-party mandate is suspended as of July 2026, so these assessments are voluntary for now. The C3PAO guide covers how one runs.
Either way the self-assessment is what everything rests on. A thorough one is the single biggest factor in passing a third-party assessment on the first try, and the only thing standing behind an affirmation without one.
Control by control
The core of the work is going through each of the 110 requirements and, for each:
- Evaluating the assessment objectives. NIST SP 800-171A breaks every requirement into specific, testable determination statements. A requirement is met only when every objective is.
- Determining status. Met, not met, or not applicable to your environment.
- Writing the implementation statement. How the requirement is met in your environment, not just that it is.
- Linking evidence. Artifacts that show the objective is true.
NIST also names what an assessor may examine, whom they may interview, and what they may test for every requirement. Our guide lists them on each requirement's page, so you can see what you will be asked for before you are asked.
In Bedrock CMMC
Each requirement is broken into its 800-171A objectives. You record status per objective, write the implementation statement, and link evidence, so the self-assessment maps directly onto what an assessor evaluates. See a live package.
Evidence that holds up
Evidence is the proof that a control is implemented and working. Every met objective needs something an assessor can review:
- Policies and procedures that describe how the control is implemented.
- Configuration exports and screenshots of system settings, group policy, firewall rules.
- Scan results and reports: vulnerability scans, STIG reports, malware scan logs.
- Records and logs: training completions, access reviews, incident response tests, log reviews.
Evidence quality matters. It must be dated, specific to your environment rather than a generic template, and attributable to your organization. An undated screenshot or a policy with another company's name on it will not pass.
How the SPRS score works
Your Supplier Performance Risk System score is a number contracting officers can see. It follows the DoD Assessment Methodology:
- Start at 110, the score with every requirement met.
- Subtract the weight of each requirement not met: 5 for the 44 highest-impact requirements, 3 for 14, 1 for 51.
- The floor is minus 203.
- The system security plan (3.12.4) carries no points, but without one an assessment cannot be conducted.
Two requirements have a partial-credit rule, multi-factor authentication and FIPS-validated cryptography, deducting three instead of five in one specific case each. Bedrock CMMC applies the same table and the same rules the export prints, so the score on the dashboard is the score you post.
The system security plan
The SSP is the centrepiece. It describes your boundary, your environment, who is responsible, and how each requirement is implemented. Requirement 3.12.4 asks for it, and an assessment cannot proceed without one.
A generated plan beats a template. Templates go stale the day after they are written; a plan generated from your actual control implementations always reflects your current posture, and assessors can see that the documentation matches reality.
Readiness checklist
- All 110 requirements assessed, each with a status and an implementation statement.
- Evidence attached to every met objective, dated and attributable.
- SPRS score calculated and submitted, and it reflects your current posture.
- System security plan generated and reviewed, covering boundary, personnel and every requirement.
- POA&M created for open items, with owners, milestones and dates.
- External service providers documented, with CUI handling and responsibility matrices.
- People prepared for interviews: the staff who run a control can explain it and point to evidence.
After the assessment
A C3PAO assessment ends in one of three outcomes:
- Certification. Every requirement met. Valid for three years with annual affirmations.
- Conditional. A limited number of eligible requirements open on a POA&M, with 180 days to close them. The POA&M guide.
- Not certified. Too many gaps. Remediate and schedule a reassessment.
After certification you enter continuous monitoring: maintaining controls, affirming annually, and preparing for reassessment.
Questions people ask
What is a CMMC self-assessment?
Your internal evaluation against all 110 NIST SP 800-171 Revision 2 requirements: status per objective, implementation statements, and evidence. Since the July 2026 suspension it is how Level 1 and Level 2 compliance is demonstrated, affirmed in SPRS, and it doubles as preparation for a voluntary C3PAO assessment.
How is the SPRS score calculated?
Start at 110 and subtract the weight of each unmet requirement: five, three or one point. The minimum is minus 203. The score is submitted to SPRS and is visible to contracting officers.
What evidence do I need?
Documented proof for each met objective: policies and procedures, configuration evidence, scan results, access reviews, training records, incident response tests, network diagrams. Dated, specific, attributable.
What are NIST 800-171A assessment objectives?
Each requirement's determination statements. Requirement 3.1.1, for example, has six covering the identification of users, processes and devices and the limiting of access to each. An assessor decides each one separately.
How long does certification last?
Three years, with annual affirmations and a continuous monitoring program in between, then reassessment. Third-party assessments are voluntary while the Phase 2 mandate is suspended.
Keep the proof, not just the plan.
Bedrock CMMC tracks every objective, links the evidence behind it, calculates the SPRS score and keeps the POA&M honest, in one package with a chain of custody an assessor can follow.