Who typically needs to complete a CMMC self-assessment
CMMC 2.0 (Cybersecurity Maturity Model Certification) applies to companies in the Defense Industrial Base that process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under a DoD contract or subcontract. The requirement attaches to the type of information you handle, not to your company's size or whether you deal with the DoD directly.
- Level 1 covers FCI only — 17 basic safeguarding practices drawn from FAR 52.204-21. It's satisfied with an annual self-assessment and an affirmation from a senior company official; no outside assessor is involved.
- Level 2 covers CUI — 110 practices aligned to NIST SP 800-171. For most non-prioritized acquisitions, an annual self-assessment with affirmation is sufficient. The government reserves third-party assessment, performed by a Certified Third-Party Assessment Organization (C3PAO), for a smaller set of prioritized, higher-risk acquisitions.
- Level 3 adds practices from NIST SP 800-172 for the highest-sensitivity programs, with a government-led assessment. It applies to a much smaller slice of the industrial base.
In practice, the vendors most often facing a self-assessment rather than a third-party assessment are exactly the group this guide is written for: manufacturing subs, engineering subs, IT and managed-service subs, and other subcontractors who receive CUI passed down through a prime's subcontract. Many of these companies hold no direct contract with the DoD at all — they're still in scope, because the obligation travels with the information down the supply chain through flow-down clauses, not with the contract number.
It's also worth separating two clocks that run at different speeds. CMMC's own contract clause is being phased into new and modified DoD contracts gradually, so not every subcontractor has it in their agreement yet. The underlying NIST SP 800-171 obligation under DFARS 252.204-7012, covered in the next section, already applies whenever covered defense information is involved — independent of whether the CMMC clause itself has landed in your specific contract.
What a CMMC self-assessment questionnaire usually covers
A Level 2 self-assessment walks through all 110 NIST SP 800-171 practices, organized into 14 control families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
For each practice, the assessment typically asks three things: whether it's fully implemented, partially implemented, or not implemented; what evidence supports that status; and, for anything short of fully implemented, what the plan and target date are for closing the gap. The scoring follows the DoD Assessment Methodology described in NIST SP 800-171A — the maximum score is 110, and points are deducted for each practice that isn't fully in place, with the deduction weighted by that practice's assessed impact on security.
Beyond the scored questions, a complete self-assessment package usually produces:
- A System Security Plan (SSP) describing how each control is actually implemented in your specific environment — not a generic security policy, but a document that maps to the 110 practices one by one.
- A Plan of Action and Milestones (POA&M) for anything not yet fully implemented, with a specific remediation owner and target date rather than a vague "in progress."
- A numeric score submitted to the Supplier Performance Risk System (SPRS), the DoD system where contractor self-assessments are recorded.
- An annual affirmation, signed by a senior company official, that the reported information is accurate as of the assessment date.
How DFARS 252.204-7012 requests commonly show up from a prime
DFARS 252.204-7012 is the contract clause that requires "adequate security" for covered defense information — in practice, implementing NIST SP 800-171 — plus reporting cyber incidents to the DoD within 72 hours of discovery, preserving related media and logs for at least 90 days, and flowing the same clause down to any subcontractor who will handle covered defense information.
Because 7012 is a contractual obligation rather than a submission to a government portal, primes typically operationalize their own verification by sending subcontractors a questionnaire that mirrors 800-171 and 7012 language directly. The specific questions vary by prime, but a few show up consistently:
- What is your current SPRS score, and when was it last updated?
- Do you have a current SSP and POA&M, and can they be shared — often under NDA, sometimes as a summary rather than the full document?
- Who is your incident-reporting point of contact, and does your process meet the 72-hour DoD reporting window?
- Where is covered defense information stored, and if any of it sits with a cloud service provider, does that provider meet the government's required security level for that data?
- Has the 7012 clause itself been flowed down to any of your own sub-tier suppliers who touch the same information?
Two related clauses shape the same picture. DFARS 252.204-7019 requires a current NIST SP 800-171 self-assessment score — no older than three years — to be posted in SPRS before contract award. DFARS 252.204-7020 gives the government, and in practice often the prime doing its own risk review, a basis to request access to the documentation behind that score.
The important distinction to hold onto: a prime's own questionnaire is not itself a DoD assessment. It's the prime's private due-diligence instrument for satisfying its own flow-down and supply-chain risk obligations, and it can reasonably ask for more detail than the underlying clause strictly requires — diagrams, named contacts, specific evidence — in whatever format that particular prime has built for its vendor base.
Where these two overlap and where they differ
The overlap is substantial by design: both use NIST SP 800-171 as the common control baseline, and both typically ask for the same core artifacts — an SSP, a POA&M, and a current SPRS score. A single, accurate, up-to-date documentation set is what answers most of both requests without starting from scratch each time.
CMMC self-assessment
A formal program requirement tied to your own contract once the CMMC clause is written into it. Submitted with an affirmation to SPRS, the government's system of record. A fixed, standardized set of 110 practices, scored the same way for every company at Level 2.
Prime's DFARS 7012 questionnaire
An informal, prime-designed instrument that borrows the same control vocabulary but is a private contractual check, not a government submission. Format and depth vary by prime. It applies as soon as covered information flows to you — whether or not the CMMC clause itself is yet written into your specific subcontract.
The practical consequence is that most small defense vendors end up answering some version of the same 110 controls more than once, in different formats, for different audiences — SPRS for the government, a custom sheet for one prime, a different custom sheet for another. Keeping one canonical, current SSP, POA&M, and score is what turns each subsequent version into a formatting exercise instead of a re-investigation.
Getting organized before you answer
A few habits make each new self-assessment, SPRS refresh, or prime questionnaire faster to produce than the last one:
One current SSP, mapped to all 14 families
Not a generic security policy — a document that walks through each of the 14 NIST SP 800-171 control families and states plainly how your environment implements it today.
A live POA&M with real dates
Specific completion dates and named owners for anything not fully implemented, kept current rather than rewritten from memory each time someone asks for it.
Refresh the SPRS score when things change
Update it after material changes to your environment, and don't let it drift toward the multi-year window where a stale score becomes its own finding.
A small evidence library per control
Configuration exports, log samples, network diagrams, and your incident-response runbook — primes and assessors increasingly want the evidence behind the score, not just the number.
The last piece is consistency across audiences: a new questionnaire from a different prime is rarely a genuinely new set of questions — it's usually the same roughly 110 controls in a different order and vocabulary. Answers that don't match across two documents shown to two different primes tend to read as a bigger risk than any individual documented gap.
Reply Engine drafts from your SSP, POA&M, and prior answers.
Reply Engine matches each question on a self-assessment or a prime's DFARS questionnaire against your own documentation, drafts a cited first pass, and routes it to your team's approval queue. Drafts, not attestations — your security team remains the accountable reviewer.