CMMC Level 2 Self Assessment Guide: What It Is, What It Costs, and How to Complete One

If you are a government contractor and recently saw language in a solicitation requiring a CMMC Level 2 Self Assessment, you are not alone.

Many organizations are seeing cybersecurity requirements appear in contracts and are unsure what they actually need to do.

The good news is that a CMMC Level 2 Self Assessment is often much less intimidating than it sounds.

This guide will explain what it is, why government contracts require it, what is involved, how SPRS scores are calculated, and how your organization can determine where it stands today.

Not sure where you stand?

See your SPRS score and compliance gaps instantly.

Run Free Readiness Check →

What Is a CMMC Level 2 Self Assessment?

A CMMC Level 2 Self Assessment is an evaluation of your organization's implementation of the 110 security requirements found in NIST SP 800-171.

The purpose is to determine whether your company properly protects Controlled Unclassified Information (CUI).

This is not just about having tools in place. It is about whether those controls are implemented, enforced, and documented consistently across the organization.

Why Are Government Contracts Asking for It?

The Department of Defense requires these assessments to reduce supply chain cybersecurity risk.

Contractors are increasingly targeted because they often have weaker security than federal systems.

As a result, cybersecurity is now a **contract requirement, not just an IT function**.

Understanding NIST SP 800-171

NIST SP 800-171 defines 110 controls that protect CUI in non-federal systems.

These controls ensure organizations can restrict access, monitor activity, respond to incidents, and maintain secure system configurations.

What Information Will You Need?

What Is an SSP?

The System Security Plan (SSP) documents how your organization implements security controls.

It acts as the “blueprint” of your cybersecurity environment and is required for demonstrating compliance.

What Is a POAM?

A Plan of Action and Milestones (POA&M) tracks security gaps and outlines remediation steps.

Understanding SPRS Scores

SPRS starts at 110 points and decreases based on missing controls.

More severe gaps result in larger deductions, and scores can even become negative in high-risk environments.

Common Gaps Found

  • Incomplete MFA enforcement
  • Missing asset inventory
  • Weak or undocumented incident response plans
  • Inconsistent access reviews
  • SSP documentation gaps

Does This Mean You Are Certified?

No. A self assessment does not equal certification.

Some contracts require third-party certification through a C3PAO instead.

How Long Does It Take?

Depending on maturity, it can take anywhere from a few days to several weeks.

What About CMMC Certification Cost?

Cost varies based on maturity, tooling, and remediation needs.

Most costs come from fixing gaps, not performing the assessment itself.

How to Prepare

  • Build and maintain an SSP
  • Track SPRS score regularly
  • Document security controls
  • Close gaps incrementally

Get Your Free CMMC Level 2 Self Assessment

Generate your SSP, SPRS score, and compliance gaps in under an hour.

Start Free Assessment

Free SPRS Check

Check Now

Generate SSP

Create SSP

For More Content

What Security Tools Will Be Required for FedRAMP 20x

Learn what security tools support FedRAMP 20x, including automation, evidence, monitoring, IAM, vulnerability, and readiness needs.

FedRAMP 20x Evidence Requirements Explained

Learn FedRAMP 20x evidence requirements, including machine-readable evidence, KSI validation, automation, and readiness steps for SaaS.

How to Prepare for FedRAMP 20x Certification

Learn how to prepare for FedRAMP 20x certification, build reusable evidence, address KSIs, and connect FedRAMP Moderate readiness to Class C.

Can Azure Help With FedRAMP and CMMC Compliance?

Learn how Azure and Azure Government can support FedRAMP and CMMC compliance, what they help with, and what your team still owns

Can FedRAMP 20x Help You Achieve CMMC Level 2?

Learn how FedRAMP 20x can support CMMC Level 2 readiness, where the frameworks overlap, and what gaps contractors still need to close.