Skip to content
CMMC 2.0 — Authoritative Reference

CMMC 2.0 FAQ

Answers grounded in 32 CFR Part 170, DFARS 252.204-7012/7021, DoD Class Deviation 2024-O0013, and NIST SP 800-171 Rev 2. Not legal advice.

Rev 2 vs Rev 3Phase 2 timelineC3PAO processConditional certFCA liabilitySPRS submission

Rev 2 vs Rev 3 — which version applies?

Which version of NIST SP 800-171 does CMMC use?

NIST SP 800-171 Revision 2. DoD Class Deviation 2024-O0013 (published January 24, 2024) explicitly locks CMMC certification assessments to Rev 2. The deviation states that until the Department issues a superseding class deviation, no CMMC assessments may be conducted against Rev 3.

Rev 3 added 26 new requirements and restructured the control families. Any tool or consultant that claims to assess against Rev 3 for CMMC purposes is producing results that will not satisfy the DFARS 252.204-7021 clause.

When will CMMC move to NIST SP 800-171 Rev 3?

Not yet — and there is no public timeline. DoD will need to issue a new class deviation or amend the CMMC rule (32 CFR Part 170) before Rev 3 applies to assessments. Aegis Firma will not update scoring to Rev 3 until that happens. If you hear otherwise from a vendor, ask them to cite the specific regulatory authority.

How many controls are in NIST SP 800-171 Rev 2?

110 security requirements across 14 control families (e.g., Access Control, Audit & Accountability, Configuration Management, Identification & Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System & Communications Protection, System & Information Integrity, System & Services Acquisition). The DoD Assessment Methodology v1.2.1 assigns point values totaling a maximum of +110, with deficiencies reducing the score down to a floor of −203.

What is DoD Class Deviation 2024-O0013?

A class deviation is a DoD-wide exception to the Federal Acquisition Regulation (FAR) or Defense FAR Supplement (DFARS). Class Deviation 2024-O0013, issued January 24, 2024, modified DFARS 252.204-7021 to clarify that CMMC assessments are conducted against NIST SP 800-171 Rev 2 — not Rev 3, which NIST had published in May 2023. The deviation prevents confusion during the transition period and ensures assessment consistency across all CMMC Level 2 contracts.

CMMC Phase 2 — suspension status and contract requirements

When does CMMC Phase 2 begin?

It does not, for now — Phase 2 is suspended. Phase 2 was scheduled to begin November 10, 2026, after which DoD contracts involving Controlled Unclassified Information (CUI) would have required a C3PAO Level 2 assessment under DFARS 252.204-7021 as a condition of award. On July 13, 2026 the Department of War suspended Phase 2 and froze the later implementation phases pending a top-to-bottom review by a CMMC Reform Task Force. A follow-up directed that active solicitations and contracts carrying Level 2 or Level 3 assessment requirements be amended to remove them. The 32 CFR program rule and the DFARS were not rescinded, so this is a policy suspension rather than a repeal, and a reformed program is expected to follow the review.

What is CMMC Phase 1?

Phase 1 began March 1, 2025. During Phase 1, DoD began including CMMC requirements in select new solicitations on a case-by-case basis to test the assessment ecosystem. If your contract was issued after March 1, 2025, check whether it includes DFARS 252.204-7021. Phase 1 self-assessment requirements were not affected by the Phase 2 suspension and remain in place.

My contract was signed before Phase 2. Do I still need CMMC certification?

Possibly. DFARS 252.204-7021 binds the contractor as a flow-down clause in each contract where it appears. If your existing contract contains the clause, you must comply within the timeline it specifies. Option-year exercises on pre-Phase-2 contracts typically require compliance before the option period begins. Review your contract carefully and consult legal counsel.

What is the difference between Level 1 and Level 2 CMMC?

Level 1 (Foundational): 17 security requirements from FAR 52.204-21. Self-assessment only — no C3PAO required. Annual self-attestation submitted to SPRS. Required for contracts that involve Federal Contract Information (FCI) but not CUI.

Level 2 (Advanced): All 110 NIST SP 800-171 Rev 2 requirements. Third-party assessment by a C3PAO is required for contracts that involve CUI. Some contracts allow a subset of CMMC Level 2 via self-assessment (specific acquisition programs at DoD discretion), but most CUI-handling contracts require the full C3PAO path.

C3PAO assessment — what to expect

What is a C3PAO and why do I need one?

A C3PAO (Certified Third-Party Assessment Organization) is an organization accredited by the CMMC Accreditation Body (The Cyber AB) to conduct CMMC Level 2 assessments. DoD requires that the assessment be performed by an accredited C3PAO — not a self-assessment — for most contracts involving CUI. C3PAOs are listed on the Cyber AB Marketplace. Assessments are conducted by Certified CMMC Assessors (CCAs) employed by the C3PAO.

What does the C3PAO assessment actually examine?

The C3PAO evaluates all 110 NIST SP 800-171 Rev 2 controls using the assessment objectives from NIST SP 800-171A Rev 2 (the assessment guide). Each objective is scored as MET, NOT MET, or NOT APPLICABLE based on examinations, interviews, and tests.

Assessors typically request: your System Security Plan (SSP), evidence packages for each control family, policy documents, configuration screenshots or exports, audit logs, and interviews with system owners, security officers, and IT personnel. The Aegis Firma mock assessment engine scores every NIST SP 800-171A assessment objective in its library across all 110 controls to identify gaps before your real C3PAO review.

What happens if I fail the C3PAO assessment?

If your score is at or above 88 (SPRS) and remaining deficiencies are on an acceptable POA&M (per 32 CFR 170.21), the C3PAO may certify you at Conditional Level 2 — meaning you are certified pending POA&M closeout within 180 days. If your score is below 88, no certification is issued. You must remediate and reschedule. C3PAO assessments require advance scheduling; lead times are 6–12 months at busy C3PAOs. Start now.

How much does a C3PAO assessment cost?

C3PAO assessment fees are set by each C3PAO individually and are not regulated. Typical costs range from $30,000 to $150,000+ depending on organization size, number of systems in scope, and C3PAO selection. Aegis Firma is not a C3PAO and does not perform assessments. We prepare your documentation so the C3PAO assessment is as efficient as possible.

Does Aegis Firma submit my assessment results to DoD?

No. Aegis Firma generates your SPRS documentation, affirmation packet, and SSP. You submit your SPRS score and annual affirmation to SPRS.mil using your own CAC or PKI credentials. We never store your SPRS login credentials and never submit anything on your behalf. The affirmation you submit to SPRS is your legal attestation under penalty of the False Claims Act.

Conditional certification and SPRS score floor

What SPRS score do I need for CMMC Level 2 certification?

88 or above for Conditional Level 2 certification (32 CFR 170.17). This is a hard floor — there is no exception. A score of 87 or lower means no certification, even conditional, can be issued by the C3PAO.

Full Level 2 certification requires a score of 110 (all controls fully met) or a score ≥ 88 with all POA&M items closed within 180 days.

What is the SPRS score range?

The SPRS score ranges from −203 to +110 under DoD Assessment Methodology v1.2.1. Each of the 110 NIST controls has an assigned point value (1 to 5 points). Fully implemented controls add their point value; not-implemented controls subtract their point value. Partially-implemented controls contribute half-credit only for 3.5.3 (multi-factor authentication) and 3.13.11 (FIPS-validated cryptography). A brand-new organization with zero controls implemented would score −203.

Can I get certified if I have a POA&M?

Yes — with restrictions. A POA&M (Plan of Action & Milestones) is permitted under 32 CFR 170.21 for certain controls, allowing Conditional Level 2 certification while remediation is in progress. However, 32 CFR 170.21 prohibits POA&M for the following 6 controls:

  • 3.1.20 — External Connections (CUI traversal over external systems)
  • 3.1.22 — Control Posted or Processed Information (publicly accessible systems)
  • 3.10.3 — Escort Visitors
  • 3.10.4 — Physical Access Logs
  • 3.10.5 — Manage Physical Access Devices
  • 3.12.4 — System Security Plan

Additionally, every remaining control worth more than 1 point is POA&M-ineligible, with exactly one named exception: 3.13.11 (CUI Encryption) may sit on a POA&M at the partial-implementation level (encryption in place but not FIPS-validated) under 32 CFR 170.21(a)(2)(ii). 3.5.3 (multi-factor authentication) is not part of that exception — even a partial MFA gap must be fully implemented before assessment, despite separately earning reduced scoring credit. These prohibitions are hard-coded in Aegis Firma; no setting can override them.

How long do I have to close a POA&M after conditional certification?

180 days (32 CFR 170.21(b)). Each POA&M item must have a scheduled completion date no more than 180 days from the date of assessment. If you miss the deadline, your conditional certification lapses and you must reschedule the C3PAO assessment. Aegis Firma tracks each POA&M item's deadline and warns you at 30-day and 14-day intervals.

POA&M — rules and prohibited controls

What are the 6 POA&M-prohibited controls and why?

32 CFR 170.21 identifies certain controls as so foundational that no conditional certification is possible if they are not fully implemented:

3.1.20External Connections

Uncontrolled external connections are a primary attack vector. A contractor that cannot document and authorize all external CUI paths fails a basic trust boundary.

3.1.22Control Posted or Processed Information

Publicly accessible systems hosting CUI represent immediate disclosure risk. Cannot be deferred.

3.10.3Escort Visitors

Physical access control to areas with CUI is a baseline physical security requirement.

3.10.4Audit Physical Access

Without an audit log of physical access, there is no accountability for insider threat or unauthorized access to CUI.

3.10.5Manage Physical Access Devices

Keys, access cards, and combination codes that are not managed create uncontrolled physical access.

3.12.4System Security Plan

The SSP is the foundational document that every other control references. Without it, the assessment has no baseline to evaluate against.

What are the 5-point controls and why are they POA&M-ineligible?

The DoD Assessment Methodology v1.2.1 assigns 5 points to controls that have the highest security impact. Because these controls carry the most weight in the SPRS calculation, DoD determined that partial implementation is insufficient — they must be fully met before assessment.

The 5-point controls under NIST SP 800-171 Rev 2 are in the areas of multi-factor authentication (3.5.3), cryptographic protection (3.13.8, 3.13.10, 3.13.11), and session lock (3.1.10). Implementing these before your C3PAO assessment is a prerequisite to achieving a score ≥ 88.

Does Aegis Firma enforce POA&M prohibitions automatically?

Yes. When you attempt to add a POA&M item for one of the 6 prohibited controls or for any 5-point control, Aegis Firma blocks the action and shows the citation (32 CFR 170.21 and the specific control ID). These blocks are hard-coded — there is no admin setting or override that can disable them. Your compliance officer cannot accidentally create a non-compliant POA&M in Aegis Firma.

False Claims Act — personal liability for false certifications

What is the False Claims Act and how does it apply to CMMC?

The False Claims Act (31 U.S.C. §§ 3729–3733) imposes liability on anyone who knowingly submits a false claim to the federal government. When a defense contractor submits a SPRS self-assessment score or annual affirmation that overstates their actual cybersecurity posture, that submission may constitute a false claim. Penalties include treble damages (3× the government's damages) plus $13,000–$27,000 per false claim. Individual employees and executives can be held personally liable — not just the company.

What happened in the Penn State case?

In 2024, Penn State University agreed to pay $1.25 million to resolve False Claims Act allegations that it submitted inaccurate CMMC self-assessments to DoD. The allegations arose from a whistleblower suit. Penn State's Applied Research Laboratory had certified compliance with cybersecurity requirements in its DoD contracts despite allegedly not meeting those requirements. The case illustrates that universities and research institutions are held to the same standard as commercial defense contractors.

What happened in the Aerojet Rocketdyne case?

In 2023, Aerojet Rocketdyne agreed to pay $9 million to settle False Claims Act allegations related to cybersecurity compliance misrepresentations in DoD and NASA contracts. The settlement arose from a whistleblower suit filed by a former employee. Aerojet had allegedly misrepresented its compliance with cybersecurity requirements in contract certifications. This was one of the first major FCA cybersecurity cases and established the precedent that DoD will pursue contractors who overstate their compliance posture.

What does "annual affirmation" mean and why does it matter for FCA exposure?

32 CFR 170.22 requires that a senior company official (C-suite or equivalent) affirm annually to SPRS.mil that the organization continues to meet its CMMC requirements. This is a personal attestation — signed under penalty of the False Claims Act. If the organization's cybersecurity posture has degraded since the last assessment (e.g., a new system was added without controls, a control implementation lapsed), the affirmation would be false. Aegis Firma generates the affirmation packet for you and reminds you of upcoming deadlines. You — not Aegis Firma — sign and submit it to SPRS.mil.

Does Aegis Firma provide legal advice on FCA compliance?

No. Aegis Firma is a compliance workflow platform. Nothing in this FAQ or in the Aegis Firma product constitutes legal advice. Before submitting any SPRS self-assessment score or annual affirmation, consult legal counsel familiar with defense contracts and the False Claims Act. The DOJ Cyber-Fraud Initiative (announced October 2021) is actively pursuing FCA cybersecurity cases.

SPRS — submission and scoring

What is SPRS and what do I submit there?

The Supplier Performance Risk System (SPRS.mil) is DoD's system for contractor performance data, including CMMC self-assessment scores and certifications. Level 1 contractors must submit their self-assessment score and annual affirmation. Level 2 contractors must submit their SPRS score (after C3PAO assessment), their C3PAO certificate reference, and annual affirmations. Access to SPRS requires a CAC (Common Access Card) or PKI certificate.

How does Aegis Firma calculate the SPRS score?

Aegis Firma applies DoD Assessment Methodology v1.2.1 point weights to each of the 110 NIST SP 800-171 Rev 2 controls. You mark each control as Implemented, Not Implemented, or Partially Implemented. Partially-implemented controls contribute half-credit only for 3.5.3 and 3.13.11 — no other control has partial credit under the DoD methodology. The calculator displays your running score and the per-family breakdown. The score you see in Aegis Firma is the score you would report to SPRS.mil.

Can I use Aegis Firma to submit my score to SPRS?

No, and we will never offer this feature. SPRS submission requires your personal CAC or PKI credentials. Storing those credentials in a third-party system would itself violate the access control requirements you are certifying to. Aegis Firma generates the affirmation text, documents the score calculation, and provides step-by-step SPRS submission instructions. You use your own credentials to log in to SPRS.mil and submit.

What is the DFARS 252.204-7021 clause?

DFARS 252.204-7021 is the contract clause that incorporates CMMC requirements into a DoD contract. When a solicitation or contract contains this clause, the contractor must achieve the specified CMMC level before the contract is awarded (or, during Phase 1 transition, within a specified timeframe). The clause also requires the contractor to flow down the requirement to any subcontractors handling CUI (DFARS 252.204-7012 addresses incident reporting obligations).

What is DFARS 252.204-7012 and does it apply to my subcontractors?

DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting) requires contractors to: implement NIST SP 800-171 controls, report cyber incidents within 72 hours, preserve images of compromised systems, and flow the requirements down to subcontractors that process, store, or transmit covered defense information (CUI). If your subcontractors handle CUI on your behalf, you are the prime responsible for ensuring they meet these requirements — Aegis Firma's subcontractor flow-down tracker helps you document this.

Legal disclaimer

This FAQ is provided for informational purposes only and does not constitute legal advice. CMMC, DFARS, and FCA requirements are complex and fact-specific. Nothing here should be relied upon as a substitute for advice from qualified legal counsel. Regulatory citations are provided to help you locate primary sources — always verify with the current regulatory text.

Ready to run your CMMC self-assessment?

Aegis Firma enforces every rule on this page — POA&M prohibitions, Rev 2 controls, the SPRS floor. Start for free.