For many defense contracts, you do not need a third-party assessor to meet CMMC. For Level 1 (Federal Contract Information) and for many Level 2 (non-critical Controlled Unclassified Information) requirements, you assess your own environment, post a score, and have a senior official affirm it. But “self-assessment” is not the same as “informal” — an inaccurate or inflated score can expose your company to serious liability under the False Claims Act.
Who can self-assess — Level 1 vs. Level 2
- Level 1 (FCI): covers the 15 basic safeguarding requirements from FAR 52.204-21. Contractors perform an annual self-assessment and an annual affirmation — no third party required.
- Level 2 (CUI): covers the 110 controls of NIST SP 800-171. For non-prioritized / non-critical CUI acquisitions, a contractor may self-assess (on a triennial basis) with an annual affirmation. The most sensitive (prioritized) CUI requires a third-party C3PAO assessment.
The SPRS score: how it works
Level 2 self-assessments are scored using the DoD Assessment Methodology. You start at a perfect 110 and subtract weighted points for each control that is not fully met — some controls are worth 1 point, others 3 or 5, based on risk — so a score can even go negative. You then enter that score, the assessment date, the scope, and your CAGE code(s) into the Supplier Performance Risk System (SPRS).
This matters because contracting officers check SPRS before award. No score in SPRS can mean no contract — and a missing or out-of-date entry can stall an award just as easily as a low one.
Affirmation by management is a personal attestation
After the assessment, a senior company official — the Affirming Official — must affirm in SPRS that the organization meets the required security standard, and must renew that affirmation annually. This is not a clerical checkbox. It is a formal statement, made on behalf of the company by someone with authority, that the score and the underlying implementation are accurate. Treat it that way.
The False Claims Act risk of a fudged score
Here is where it gets serious. When you submit a score in SPRS or affirm compliance, you are making a representation to the federal government. If that score is inflated, or the affirmation claims controls you have not actually implemented, it can be a false statement — and that triggers the False Claims Act (FCA).
Since launching its Civil Cyber-Fraud Initiative in 2021, the U.S. Department of Justice has used the FCA to pursue contractors who misrepresent their cybersecurity. The penalties are severe: treble (three times) damages plus per-claim penalties. And the FCA’s whistleblower (qui tam) provisions let employees sue on the government’s behalf and share in the recovery — so the people who know a score was faked have a direct financial incentive to report it.
Recent settlements make the risk concrete:
- MORSECORP (2025) — $4.6M: the contractor admitted, among other things, that it had submitted an SPRS score for its NIST 800-171 implementation that was far higher than what a third-party consultant later calculated.
- Raytheon / Nightwing (2025) — $8.4M: settled allegations of falsely representing NIST 800-171 compliance across roughly 30 DoD contracts and subcontracts.
These are not the only cases, and enforcement has been accelerating — 2025 was a record year for cyber-related FCA activity.
How to stay on the right side of the line
- Score honestly. Base the SPRS number on a real assessment against every control, with evidence to back it.
- A low score is not the problem — a false one is. A score below 110 with a documented System Security Plan (SSP) and Plan of Action & Milestones (POA&M) is normal and defensible.
- Let the Affirming Official review the basis before they affirm — they are attesting to it.
- Keep it current. Re-assess and update SPRS when your environment changes; do not let a stale, optimistic score sit there.
- Document everything. Evidence is what turns “we believe we comply” into “we can prove it.”
Not sure your score would hold up to scrutiny? A gap assessment is the fastest way to find out. See also how CMMC and DFARS work together and CMMC & NIST SP 800-171.