Self-Assessment Has Limits — Know Your Path Before You Submit
This tool generates a NIST SP 800-171 Basic Assessment score using the official DoD Assessment Methodology v1.2.1: start at 110 points, deduct 1, 3, or 5 points per unmet control. That score is required in SPRS under DFARS 252.204-7019 / 7020 for every contractor handling CUI.
Self-assessment is NOT the same as CMMC Level 2 Certification. Under CMMC 2.0, the majority of contracts handling CUI require a C3PAO-conducted certification assessment, not self-assessment. Self-assessment is permitted only for a limited subset of L2 contracts. Verify your required assessment type in your contract, DD-254, or with your contracting officer before relying on a self-assessed score for compliance.
POA&M caveats at L2:
- Not every control is POA&M-eligible. Controls weighted at 5 points (the highest tier) are generally NOT eligible and must be fully implemented before submission.
- For CMMC 2.0 conditional certification, POA&M items must be closed within 180 days or the certification lapses.
- Partial implementation takes the full point deduction under the DoD Assessment Methodology.
Annual senior official affirmation in SPRS is required regardless of whether you self-assess or certify via a C3PAO. Submitting a false or inflated score creates False Claims Act liability. Score each control honestly based on what is actually implemented.
L2 Policy Mini-Set Generator
The Mini-Set generates one policy per NIST 800-171 control family — 14 policies total — plus System Security Plan (SSP) and POA&M templates. These documents are sufficient for L2 self-attestation. They are not a substitute for the audit-ready documentation package required for C3PAO assessments.
Print this section to save the full Mini-Set as PDF. Each policy uses your organization name and assessment date from the Organization tab.
- Full gap analysis across all 110 NIST SP 800-171 controls
- Audit-ready SSP, POA&M, and evidence package
- System boundary scoping and CUI flow mapping
- Per-control implementation walkthroughs
- Mock assessment with C3PAO-style questioning
- Annual SPRS affirmation and 180-day POA&M support
Applied as credit toward your Compliance Foundation engagement