CMMC Level 2 Self Assessment Guide: What It Is, What It Costs, and How to Complete One
If you are a government contractor and recently saw language in a solicitation requiring a CMMC Level 2 Self Assessment, you are not alone.
Many organizations are seeing cybersecurity requirements appear in contracts and are unsure what they actually need to do.
The good news is that a CMMC Level 2 Self Assessment is often much less intimidating than it sounds.
This guide will explain what it is, why government contracts require it, what is involved, how SPRS scores are calculated, and how your organization can determine where it stands today.
See your SPRS score and compliance gaps instantly.
Run Free Readiness Check →What Is a CMMC Level 2 Self Assessment?
A CMMC Level 2 Self Assessment is an evaluation of your organization's implementation of the 110 security requirements found in NIST SP 800-171.
The purpose is to determine whether your company properly protects Controlled Unclassified Information (CUI).
This is not just about having tools in place. It is about whether those controls are implemented, enforced, and documented consistently across the organization.
Why Are Government Contracts Asking for It?
The Department of Defense requires these assessments to reduce supply chain cybersecurity risk.
Contractors are increasingly targeted because they often have weaker security than federal systems.
As a result, cybersecurity is now a **contract requirement, not just an IT function**.
Understanding NIST SP 800-171
NIST SP 800-171 defines 110 controls that protect CUI in non-federal systems.
These controls ensure organizations can restrict access, monitor activity, respond to incidents, and maintain secure system configurations.
What Information Will You Need?
- Network diagrams
- Security policies and procedures
- Asset inventory
- MFA configuration
- Incident response plans
- Backup and recovery processes
- Training documentation
What Is an SSP?
The System Security Plan (SSP) documents how your organization implements security controls.
It acts as the “blueprint” of your cybersecurity environment and is required for demonstrating compliance.
What Is a POAM?
A Plan of Action and Milestones (POA&M) tracks security gaps and outlines remediation steps.
Understanding SPRS Scores
SPRS starts at 110 points and decreases based on missing controls.
More severe gaps result in larger deductions, and scores can even become negative in high-risk environments.
Common Gaps Found
- Incomplete MFA enforcement
- Missing asset inventory
- Weak or undocumented incident response plans
- Inconsistent access reviews
- SSP documentation gaps
Does This Mean You Are Certified?
No. A self assessment does not equal certification.
Some contracts require third-party certification through a C3PAO instead.
How Long Does It Take?
Depending on maturity, it can take anywhere from a few days to several weeks.
What About CMMC Certification Cost?
Cost varies based on maturity, tooling, and remediation needs.
Most costs come from fixing gaps, not performing the assessment itself.
How to Prepare
- Build and maintain an SSP
- Track SPRS score regularly
- Document security controls
- Close gaps incrementally
Get Your Free CMMC Level 2 Self Assessment
Generate your SSP, SPRS score, and compliance gaps in under an hour.
Start Free Assessment
