Answers grounded in 32 CFR Part 170, DFARS 252.204-7012/7021, DoD Class Deviation 2024-O0013, and NIST SP 800-171 Rev 2. Not legal advice.
NIST SP 800-171 Revision 2. DoD Class Deviation 2024-O0013 (published January 24, 2024) explicitly locks CMMC certification assessments to Rev 2. The deviation states that until the Department issues a superseding class deviation, no CMMC assessments may be conducted against Rev 3.
Rev 3 added 26 new requirements and restructured the control families. Any tool or consultant that claims to assess against Rev 3 for CMMC purposes is producing results that will not satisfy the DFARS 252.204-7021 clause.
Not yet — and there is no public timeline. DoD will need to issue a new class deviation or amend the CMMC rule (32 CFR Part 170) before Rev 3 applies to assessments. Aegis Firma will not update scoring to Rev 3 until that happens. If you hear otherwise from a vendor, ask them to cite the specific regulatory authority.
110 security requirements across 14 control families (e.g., Access Control, Audit & Accountability, Configuration Management, Identification & Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System & Communications Protection, System & Information Integrity, System & Services Acquisition). The DoD Assessment Methodology v1.2.1 assigns point values totaling a maximum of +110, with deficiencies reducing the score down to a floor of −203.
A class deviation is a DoD-wide exception to the Federal Acquisition Regulation (FAR) or Defense FAR Supplement (DFARS). Class Deviation 2024-O0013, issued January 24, 2024, modified DFARS 252.204-7021 to clarify that CMMC assessments are conducted against NIST SP 800-171 Rev 2 — not Rev 3, which NIST had published in May 2023. The deviation prevents confusion during the transition period and ensures assessment consistency across all CMMC Level 2 contracts.
It does not, for now — Phase 2 is suspended. Phase 2 was scheduled to begin November 10, 2026, after which DoD contracts involving Controlled Unclassified Information (CUI) would have required a C3PAO Level 2 assessment under DFARS 252.204-7021 as a condition of award. On July 13, 2026 the Department of War suspended Phase 2 and froze the later implementation phases pending a top-to-bottom review by a CMMC Reform Task Force. A follow-up directed that active solicitations and contracts carrying Level 2 or Level 3 assessment requirements be amended to remove them. The 32 CFR program rule and the DFARS were not rescinded, so this is a policy suspension rather than a repeal, and a reformed program is expected to follow the review.
Phase 1 began March 1, 2025. During Phase 1, DoD began including CMMC requirements in select new solicitations on a case-by-case basis to test the assessment ecosystem. If your contract was issued after March 1, 2025, check whether it includes DFARS 252.204-7021. Phase 1 self-assessment requirements were not affected by the Phase 2 suspension and remain in place.
Possibly. DFARS 252.204-7021 binds the contractor as a flow-down clause in each contract where it appears. If your existing contract contains the clause, you must comply within the timeline it specifies. Option-year exercises on pre-Phase-2 contracts typically require compliance before the option period begins. Review your contract carefully and consult legal counsel.
Level 1 (Foundational): 17 security requirements from FAR 52.204-21. Self-assessment only — no C3PAO required. Annual self-attestation submitted to SPRS. Required for contracts that involve Federal Contract Information (FCI) but not CUI.
Level 2 (Advanced): All 110 NIST SP 800-171 Rev 2 requirements. Third-party assessment by a C3PAO is required for contracts that involve CUI. Some contracts allow a subset of CMMC Level 2 via self-assessment (specific acquisition programs at DoD discretion), but most CUI-handling contracts require the full C3PAO path.
A C3PAO (Certified Third-Party Assessment Organization) is an organization accredited by the CMMC Accreditation Body (The Cyber AB) to conduct CMMC Level 2 assessments. DoD requires that the assessment be performed by an accredited C3PAO — not a self-assessment — for most contracts involving CUI. C3PAOs are listed on the Cyber AB Marketplace. Assessments are conducted by Certified CMMC Assessors (CCAs) employed by the C3PAO.
The C3PAO evaluates all 110 NIST SP 800-171 Rev 2 controls using the assessment objectives from NIST SP 800-171A Rev 2 (the assessment guide). Each objective is scored as MET, NOT MET, or NOT APPLICABLE based on examinations, interviews, and tests.
Assessors typically request: your System Security Plan (SSP), evidence packages for each control family, policy documents, configuration screenshots or exports, audit logs, and interviews with system owners, security officers, and IT personnel. The Aegis Firma mock assessment engine scores every NIST SP 800-171A assessment objective in its library across all 110 controls to identify gaps before your real C3PAO review.
If your score is at or above 88 (SPRS) and remaining deficiencies are on an acceptable POA&M (per 32 CFR 170.21), the C3PAO may certify you at Conditional Level 2 — meaning you are certified pending POA&M closeout within 180 days. If your score is below 88, no certification is issued. You must remediate and reschedule. C3PAO assessments require advance scheduling; lead times are 6–12 months at busy C3PAOs. Start now.
C3PAO assessment fees are set by each C3PAO individually and are not regulated. Typical costs range from $30,000 to $150,000+ depending on organization size, number of systems in scope, and C3PAO selection. Aegis Firma is not a C3PAO and does not perform assessments. We prepare your documentation so the C3PAO assessment is as efficient as possible.
No. Aegis Firma generates your SPRS documentation, affirmation packet, and SSP. You submit your SPRS score and annual affirmation to SPRS.mil using your own CAC or PKI credentials. We never store your SPRS login credentials and never submit anything on your behalf. The affirmation you submit to SPRS is your legal attestation under penalty of the False Claims Act.
88 or above for Conditional Level 2 certification (32 CFR 170.17). This is a hard floor — there is no exception. A score of 87 or lower means no certification, even conditional, can be issued by the C3PAO.
Full Level 2 certification requires a score of 110 (all controls fully met) or a score ≥ 88 with all POA&M items closed within 180 days.
The SPRS score ranges from −203 to +110 under DoD Assessment Methodology v1.2.1. Each of the 110 NIST controls has an assigned point value (1 to 5 points). Fully implemented controls add their point value; not-implemented controls subtract their point value. Partially-implemented controls contribute half-credit only for 3.5.3 (multi-factor authentication) and 3.13.11 (FIPS-validated cryptography). A brand-new organization with zero controls implemented would score −203.
Yes — with restrictions. A POA&M (Plan of Action & Milestones) is permitted under 32 CFR 170.21 for certain controls, allowing Conditional Level 2 certification while remediation is in progress. However, 32 CFR 170.21 prohibits POA&M for the following 6 controls:
Additionally, every remaining control worth more than 1 point is POA&M-ineligible, with exactly one named exception: 3.13.11 (CUI Encryption) may sit on a POA&M at the partial-implementation level (encryption in place but not FIPS-validated) under 32 CFR 170.21(a)(2)(ii). 3.5.3 (multi-factor authentication) is not part of that exception — even a partial MFA gap must be fully implemented before assessment, despite separately earning reduced scoring credit. These prohibitions are hard-coded in Aegis Firma; no setting can override them.
180 days (32 CFR 170.21(b)). Each POA&M item must have a scheduled completion date no more than 180 days from the date of assessment. If you miss the deadline, your conditional certification lapses and you must reschedule the C3PAO assessment. Aegis Firma tracks each POA&M item's deadline and warns you at 30-day and 14-day intervals.
32 CFR 170.21 identifies certain controls as so foundational that no conditional certification is possible if they are not fully implemented:
3.1.20 — External Connections
Uncontrolled external connections are a primary attack vector. A contractor that cannot document and authorize all external CUI paths fails a basic trust boundary.
3.1.22 — Control Posted or Processed Information
Publicly accessible systems hosting CUI represent immediate disclosure risk. Cannot be deferred.
3.10.3 — Escort Visitors
Physical access control to areas with CUI is a baseline physical security requirement.
3.10.4 — Audit Physical Access
Without an audit log of physical access, there is no accountability for insider threat or unauthorized access to CUI.
3.10.5 — Manage Physical Access Devices
Keys, access cards, and combination codes that are not managed create uncontrolled physical access.
3.12.4 — System Security Plan
The SSP is the foundational document that every other control references. Without it, the assessment has no baseline to evaluate against.
The DoD Assessment Methodology v1.2.1 assigns 5 points to controls that have the highest security impact. Because these controls carry the most weight in the SPRS calculation, DoD determined that partial implementation is insufficient — they must be fully met before assessment.
The 5-point controls under NIST SP 800-171 Rev 2 are in the areas of multi-factor authentication (3.5.3), cryptographic protection (3.13.8, 3.13.10, 3.13.11), and session lock (3.1.10). Implementing these before your C3PAO assessment is a prerequisite to achieving a score ≥ 88.
Yes. When you attempt to add a POA&M item for one of the 6 prohibited controls or for any 5-point control, Aegis Firma blocks the action and shows the citation (32 CFR 170.21 and the specific control ID). These blocks are hard-coded — there is no admin setting or override that can disable them. Your compliance officer cannot accidentally create a non-compliant POA&M in Aegis Firma.
The False Claims Act (31 U.S.C. §§ 3729–3733) imposes liability on anyone who knowingly submits a false claim to the federal government. When a defense contractor submits a SPRS self-assessment score or annual affirmation that overstates their actual cybersecurity posture, that submission may constitute a false claim. Penalties include treble damages (3× the government's damages) plus $13,000–$27,000 per false claim. Individual employees and executives can be held personally liable — not just the company.
In 2024, Penn State University agreed to pay $1.25 million to resolve False Claims Act allegations that it submitted inaccurate CMMC self-assessments to DoD. The allegations arose from a whistleblower suit. Penn State's Applied Research Laboratory had certified compliance with cybersecurity requirements in its DoD contracts despite allegedly not meeting those requirements. The case illustrates that universities and research institutions are held to the same standard as commercial defense contractors.
In 2023, Aerojet Rocketdyne agreed to pay $9 million to settle False Claims Act allegations related to cybersecurity compliance misrepresentations in DoD and NASA contracts. The settlement arose from a whistleblower suit filed by a former employee. Aerojet had allegedly misrepresented its compliance with cybersecurity requirements in contract certifications. This was one of the first major FCA cybersecurity cases and established the precedent that DoD will pursue contractors who overstate their compliance posture.
32 CFR 170.22 requires that a senior company official (C-suite or equivalent) affirm annually to SPRS.mil that the organization continues to meet its CMMC requirements. This is a personal attestation — signed under penalty of the False Claims Act. If the organization's cybersecurity posture has degraded since the last assessment (e.g., a new system was added without controls, a control implementation lapsed), the affirmation would be false. Aegis Firma generates the affirmation packet for you and reminds you of upcoming deadlines. You — not Aegis Firma — sign and submit it to SPRS.mil.
No. Aegis Firma is a compliance workflow platform. Nothing in this FAQ or in the Aegis Firma product constitutes legal advice. Before submitting any SPRS self-assessment score or annual affirmation, consult legal counsel familiar with defense contracts and the False Claims Act. The DOJ Cyber-Fraud Initiative (announced October 2021) is actively pursuing FCA cybersecurity cases.
The Supplier Performance Risk System (SPRS.mil) is DoD's system for contractor performance data, including CMMC self-assessment scores and certifications. Level 1 contractors must submit their self-assessment score and annual affirmation. Level 2 contractors must submit their SPRS score (after C3PAO assessment), their C3PAO certificate reference, and annual affirmations. Access to SPRS requires a CAC (Common Access Card) or PKI certificate.
Aegis Firma applies DoD Assessment Methodology v1.2.1 point weights to each of the 110 NIST SP 800-171 Rev 2 controls. You mark each control as Implemented, Not Implemented, or Partially Implemented. Partially-implemented controls contribute half-credit only for 3.5.3 and 3.13.11 — no other control has partial credit under the DoD methodology. The calculator displays your running score and the per-family breakdown. The score you see in Aegis Firma is the score you would report to SPRS.mil.
No, and we will never offer this feature. SPRS submission requires your personal CAC or PKI credentials. Storing those credentials in a third-party system would itself violate the access control requirements you are certifying to. Aegis Firma generates the affirmation text, documents the score calculation, and provides step-by-step SPRS submission instructions. You use your own credentials to log in to SPRS.mil and submit.
DFARS 252.204-7021 is the contract clause that incorporates CMMC requirements into a DoD contract. When a solicitation or contract contains this clause, the contractor must achieve the specified CMMC level before the contract is awarded (or, during Phase 1 transition, within a specified timeframe). The clause also requires the contractor to flow down the requirement to any subcontractors handling CUI (DFARS 252.204-7012 addresses incident reporting obligations).
DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting) requires contractors to: implement NIST SP 800-171 controls, report cyber incidents within 72 hours, preserve images of compromised systems, and flow the requirements down to subcontractors that process, store, or transmit covered defense information (CUI). If your subcontractors handle CUI on your behalf, you are the prime responsible for ensuring they meet these requirements — Aegis Firma's subcontractor flow-down tracker helps you document this.
Legal disclaimer
This FAQ is provided for informational purposes only and does not constitute legal advice. CMMC, DFARS, and FCA requirements are complex and fact-specific. Nothing here should be relied upon as a substitute for advice from qualified legal counsel. Regulatory citations are provided to help you locate primary sources — always verify with the current regulatory text.
Aegis Firma enforces every rule on this page — POA&M prohibitions, Rev 2 controls, the SPRS floor. Start for free.