A CMMC Level 2 assessment can show strong controls on paper, yet an unsupported annual affirmation can still create contract risk. For senior officials, the CMMC annual affirmation is a formal statement that your organization continues to meet its reported CMMC requirements.
We see many defense contractors focus on the assessment date but overlook the work required between assessments. The affirmation calls for current evidence, clear ownership, and a truthful view of your security posture.
Key Takeaways
- A CMMC Level 2 annual affirmation in SPRS is a senior-official attestation, not an administrative renewal.
- The Affirming Official needs credible evidence that the reported CMMC assessment status remains accurate.
- Level 2 self-assessments and C3PAO certifications have different assessment paths, but both require ongoing accountability.
- Security changes, open remediation items, and control failures can affect what an official can affirm.
- Contract clauses and CMMC rollout dates can vary, so we verify each solicitation and award before setting compliance deadlines.
What the Annual Affirmation Means for CMMC Level 2
The CMMC Program rule in 32 CFR Part 170 establishes the framework for CMMC assessments, affirmations, and status reporting. For Level 2, the annual affirmation is entered in the Supplier Performance Risk System, commonly called SPRS.
An annual affirmation is not a new assessment. Instead, it is a statement from an authorized senior official that the organization continues to comply with the CMMC requirements associated with its assessment status.
The person making the affirmation must have the authority to speak for the company and enough visibility into its security program to make that statement responsibly. In practice, that may be a CEO, president, owner, CIO, CISO, or another executive with direct accountability for CMMC compliance.
An affirmation should reflect evidence available today, not assumptions based on last year’s assessment.
CMMC Level 2 aligns with the 110 security requirements in NIST SP 800-171 for protecting Controlled Unclassified Information, or CUI. A company cannot treat its prior score, certificate, or assessment report as permanent proof of compliance. Systems change. Staff change. Vendors change. Those changes can affect the accuracy of the organization’s CMMC status.
The Department of Defense CMMC Program page provides current program resources, model information, and implementation materials. However, we advise clients to check the exact language in their solicitation and contract award. Requirements can differ based on clause inclusion, contract type, CMMC phase-in status, and DoD rulemaking.
SPRS Reporting and the Senior Official’s Role
SPRS is more than a score repository. It is the DoD system used to record assessment information and CMMC-related affirmations. Contractors should maintain the right entity identifiers, user access, and role assignments well before an annual deadline approaches.
The SPRS portal is the authoritative access point for organizations reporting supplier assessment information. Senior officials should not wait until the final week to discover that the company lacks the correct SPRS or PIEE account permissions.
For Level 2, the process generally involves confirming the organization’s current assessment status and entering an annual affirmation through SPRS. The exact workflow may change as DoD systems and policy guidance develop. Therefore, we confirm current portal instructions before a client submits anything.
The senior official’s responsibility is larger than pressing “submit.” They should understand:
- Which CAGE code and legal entity the affirmation covers.
- Whether the organization has a Level 2 self-assessment or a C3PAO-issued certification.
- Whether the assessment status remains current and accurate.
- Whether approved remediation items or POA&Ms remain within permitted CMMC limits.
- Whether a major security event, system change, or failed control has altered the compliance position.
An affirmation must match reality. If a control no longer operates as documented, the company needs to assess the impact before an official attests to continued compliance. We recommend that executives request a short evidence briefing from the compliance owner, security lead, and IT leadership before every affirmation.
Separate CMMC Affirmations From NIST 800-171 Scores
Many contractors already know SPRS because of DFARS 252.204-7019 and 252.204-7020. Those clauses address NIST SP 800-171 assessment scores. CMMC adds a separate contractual structure that includes required assessment levels and annual affirmations.
The DFARS 252.204-7021 clause is where contract-specific CMMC requirements appear. A solicitation may require a particular CMMC level before award, while the related assessment path may require either a self-assessment or third-party certification.
This distinction matters because the following records answer different questions:
| Record | Primary purpose | Typical owner |
|---|---|---|
| NIST SP 800-171 score | Records a Basic, Medium, or High Assessment result | Organization or DoD assessor |
| CMMC Level 2 assessment | Determines CMMC assessment status | Organization or authorized C3PAO |
| Annual SPRS affirmation | Confirms continued compliance with reported CMMC status | Authorized Affirming Official |
A strong score alone doesn’t support a CMMC affirmation. Likewise, an old System Security Plan cannot prove that current controls work. We review the full evidence set, including policies, technical settings, access records, training records, incident documentation, and remediation status.
Build an Evidence Package Before You Affirm
Senior leaders don’t need to personally inspect every endpoint or firewall rule. However, they do need a reliable process that turns technical activity into defensible evidence.
We recommend a formal pre-affirmation review at least 60 to 90 days before the annual due date. That window gives the organization time to resolve gaps, collect missing evidence, or seek contract and legal guidance when facts are unclear.
A practical review should address five areas:
- Control ownership and evidence. Confirm that each CMMC Level 2 practice has an owner, current evidence, and a documented operating process.
- System Security Plan accuracy. Compare the SSP against the real environment. Review cloud tenants, endpoints, remote access, network diagrams, administrative accounts, and CUI data flows.
- Remediation status. Review POA&Ms and corrective actions. Open items must be allowed under the applicable CMMC assessment rules and tracked to completion.
- Security events and changes. Consider incidents, major platform migrations, acquisitions, new managed service providers, and changes to CUI handling.
- Executive attestation record. Keep meeting notes, evidence summaries, approvals, and the submitted affirmation date. These records support internal accountability if questions arise later.
For example, an Office 365 Migration can change identity controls, data retention, mobile-device management, and audit logging. A migration to Microsoft 365 GCC High may improve alignment with defense requirements, but it does not by itself validate every CMMC practice. We verify configuration, administrative access, evidence retention, and user workflows before treating a cloud project as compliant.
Keep CMMC Controls Operating Between Assessment Dates
An annual affirmation becomes manageable when compliance is part of normal IT operations. It becomes risky when a company rebuilds its evidence binder every year.
We help organizations connect Small Business IT operations with CMMC evidence requirements. That work includes Cloud Infrastructure, Cloud Management, and Secure Cloud Architecture that maintain access control, logging, backup protection, and documented administration.
Our Cybersecurity Services also cover Endpoint Security, Device Hardening, vulnerability management, incident-response planning, and security policy maintenance. These controls should generate evidence as staff perform routine work.
For companies seeking Managed IT for Small Business, the service provider relationship needs defined responsibilities. An outsourced IT firm may operate systems, but company leadership still owns the accuracy of the annual affirmation. We document who reviews alerts, approves access, applies patches, manages backups, and responds to incidents.
Some companies use the same environment to support unrelated operations. Restaurant POS Support and Kitchen Technology Solutions may be necessary for a parent company, yet those systems should be separated from the CUI environment when possible. Clear scoping reduces risk and makes it easier to show which assets fall within CMMC boundaries.
Use Technology Consulting to Support an Honest Affirmation
A mature CMMC program needs more than annual paperwork. It needs a Business Technology Partner that can connect security requirements to operational decisions.
We provide Technology Consulting, Infrastructure Optimization, and IT Strategy for SMBs that align compliance work with business needs. Our approach includes gap assessments, SSP support, remediation planning, Microsoft 365 guidance, and executive-level reporting.
Innovative IT Solutions should not add complexity without control. Tailored Technology Services can help a defense contractor document its CUI boundary, improve endpoint visibility, reduce unmanaged accounts, and prepare evidence for review.
Digital Transformation projects also need a security checkpoint before deployment. New collaboration tools, cloud storage platforms, field devices, or remote-access methods can affect CMMC scope. We assess those changes before they create a problem at affirmation time.
Business Continuity & Security also belong in the executive review. A tested recovery process, protected backups, and practiced incident procedures support ongoing compliance. They also reduce operational disruption if a ransomware event or supplier failure occurs.
We don’t treat an annual affirmation as legal advice, and no technology provider should suggest that an official can affirm without substantiating evidence. When contract interpretation is uncertain, we encourage senior officials to involve qualified legal counsel and verify applicable clauses with their contracting contacts.
A Defensible Annual Affirmation Starts With Daily Discipline
A CMMC annual affirmation in SPRS is a statement of ongoing compliance, backed by the condition of your systems and evidence. Senior officials should ask for a current, documented view of control performance before they attest.
The strongest position comes from routine review, clear ownership, and prompt remediation, not a last-minute document search. With those habits in place, CMMC Level 2 compliance becomes a managed responsibility rather than an annual scramble.
Discover more from Guide to Technology
Subscribe to get the latest posts sent to your email.
