Pass SPRS: CMMC Self Assessment for Small DoD Contractors

Every contractor handling Federal Contract Information or Controlled Unclassified Information must perform the corresponding CMMC self-assessment, Level 1 for FCI or Level 2 for CUI, and log the results plus an executive affirmation in the Supplier Performance Risk System (SPRS). The DoD paused CMMC Phase II's third-party assessor rollout on July 13, 2026, but self-assessment obligations under existing contract clauses have not gone anywhere. If you hold a DoD contract today, you likely already owe SPRS an entry.
TL;DR:
- Contractors must perform and log self-assessments under existing contract clauses, regardless of the paused Phase II assessor rollout.
- Scope must explicitly include assets processing FCI for Level 1 or touching CUI for Level 2, with documented evidence of controls inherited from service providers.
- Evidence collection should follow a structured process involving interviews, document reviews, and testing, with clear findings and remediation plans for gaps.
- Results in SPRS must be accurate and complete, avoiding common errors like missing dates, incomplete POA&Ms, or math discrepancies, with a three-year validity for Level 2 scores.
- Small contractors often confuse policy documentation with evidence, risking liability, and should prioritize quick wins like MFA and patching while leveraging MSP-reported logs for efficient evidence gathering.
Table of Contents
- Who Must Self-Assess Now and Where DoD Policy Stands
- Scoping Your Assessment: Assets, Data, and Outsourced Services
- How to Run the Self-Assessment and Build Your Report
- Scoring and Submitting Results in SPRS
- POA&Ms, Remediation Timelines, and What They Can't Cover
- Where Self-Assessments Usually Fall Apart
- What Small Contractors Get Wrong About "Good Enough"
- How Great Plains Networking Supports Your CMMC Self-Assessment
- Official Resources Worth Bookmarking
- Sources
Who Must Self-Assess Now and Where DoD Policy Stands
Your assessment obligation traces back to your contract, not to whichever version of CMMC is making headlines. If a solicitation or contract carries DFARS 252.204-7012, you're already required to safeguard Covered Defense Information under NIST SP 800-171, regardless of where CMMC rulemaking currently sits. DFARS 252.204-7020 layers on the assessment mechanics: a current score in SPRS, refreshed at least every three years unless the solicitation says otherwise.
Here's the part that trips people up: the DoD CIO's July 2026 announcement paused Phase II, the ramp-up of independent third-party assessors for higher-risk contracts. It did not pause Level 1 or Level 2 self-assessment requirements. Those keep running on the existing timeline.
Practical takeaways for your compliance calendar:
- Prime contractors must confirm their own SPRS status and verify subcontractors have flowed down the same clauses.
- Subcontractors handling FCI or CUI on a prime's behalf owe their own self-assessment, independent of the prime's status.
- New solicitations increasingly cite 252.204-7021 alongside 7012 and 7020, so read every clause list rather than assuming last year's contract language still applies.
- Phase II's pause is a scheduling change for third-party assessors, not a compliance holiday.
Scoping Your Assessment: Assets, Data, and Outsourced Services
Scope determines everything that follows, and getting it wrong is the single most common way contractors waste weeks on self-assessment work that doesn't hold up. Level 1 scope covers any asset that processes, stores, or transmits FCI, mapped against the practices in FAR 52.204-21. Level 2 scope is broader: any asset touching CUI, plus the security protection assets that safeguard it, following the boundary definitions in 32 CFR Part 170 and NIST SP 800-171.
Your System Security Plan (SSP) needs to name these assets explicitly, not describe them in general terms. If you use an External Service Provider, an MSP, a cloud host, a SIEM vendor, that provider's controls can be inherited into your SSP, but only with documented evidence:
- A signed responsibility matrix or shared-responsibility document from the ESP
- Configuration exports or attestation letters showing the specific controls the ESP implements on your behalf
- Evidence the ESP's own security posture doesn't introduce gaps into your CUI boundary
Pro Tip: Ask your MSP for a written control-inheritance letter before you start testing. Chasing that document down mid-assessment is the single biggest schedule killer contractors report.
How to Run the Self-Assessment and Build Your Report
Treat this as a project with a defined sequence, not an afternoon of checkbox clicking. Skipping steps here is exactly how contractors end up with an SSP full of policy statements and no evidence to back them up.
- Stand up your evidence repository first. Before testing a single control, organize a folder structure or shared drive that mirrors your SSP's control list, so evidence has a home the moment you generate it.
- Apply NIST SP 800-171A's three methods to each practice. Interview the people responsible for a control, examine the relevant documents and configurations, and test the control in operation. A firewall rule you only read about isn't tested; a firewall rule you watch block a probe is.
- Record a clear finding for every practice. Use MET, NOT MET, or Not Applicable, and attach the specific evidence artifact, a screenshot, a log export, a config file, that supports each call.
- Open a POA&M line for every Level 2 gap. Each entry needs a named owner, a remediation plan, and a target completion date. Vague entries like "will fix later" don't survive a review.
- Calculate your summary-level score and run an internal check. Before anything touches SPRS, have someone who wasn't grading the practices review the findings for consistency.
Roughly 110 controls make up the NIST SP 800-171 baseline that Level 2 self-assessments score against, according to practitioner guidance on the process. That's the number driving your entire evidence-collection workload, and it's why teams that start evidence gathering only after the SSP is "done" almost always run out of runway.
Scoring and Submitting Results in SPRS
Level 1 reporting is simple by design: each of the 15 FAR 52.204-21 practices gets a MET or NOT MET finding, refreshed with an annual self-assessment and annual executive affirmation. Level 2 works differently. You calculate a numeric score (starting from 110 and subtracting points for unmet practices), which can land you in full compliance or in conditional status if a POA&M covers the remaining gaps. Level 2 self-assessments carry a three-year validity cycle.
Entering results in SPRS follows a defined workflow, walked through in DISA's own tutorials: select the appropriate CMMC level, enter your score and assessment date, attach your POA&M details if applicable, and route the record to your organization's Affirming Official for signature.
Watch for these recurring submission errors:
- Missing or incorrect assessment date, which throws off the three-year clock
- POA&M items without target completion dates, which auto-flags the record for review
- Forgetting to transfer the entry to the Affirming Official, leaving it stuck in draft status indefinitely
- Scoring math that doesn't match the underlying findings documented in the SSP
POA&Ms, Remediation Timelines, and What They Can't Cover
Conditional Level 2 status exists for contractors close to full compliance but not quite there, and it comes with real limits, not a blanket pass. A minimum score threshold applies before conditional status is even available, and certain baseline practices are excluded from POA&M treatment entirely; some controls simply have to be MET before you submit, full stop.
Every POA&M entry needs specific fields: the unmet practice, root cause, remediation steps, an assigned owner, and a target date, generally within 180 days. Closing a POA&M means retesting the control with the same interview, examine, test rigor you used originally, then updating your SPRS entry to reflect the new score once every open item is resolved.
- Conditional status is temporary, not a permanent compliance category.
- Excluded practices must show MET status before submission, regardless of POA&M eligibility.
- Closing items requires fresh evidence, not just a status update.
Where Self-Assessments Usually Fall Apart
The gap between a policy document and a passing self-assessment is where most contractors get burned. A written access-control policy proves you have intentions. A screenshot of your access-control list, a log showing failed login lockouts, or an exported configuration file proves you have a control that actually works. Reviewers, and any future third-party assessor, look for the second kind of evidence.
Prioritize quick wins before tackling multi-month projects: enabling MFA across remote access, closing stale user accounts, and applying outstanding patches often close more findings per hour of effort than any other activity. Save network segmentation projects and SIEM deployments for your longer POA&M timeline.
- Screenshots, log exports, and configuration files beat policy narratives every time.
- MFA, patch management, and account hygiene are usually your fastest point gains.
- An MSP can supply inheritable evidence, monitoring logs, patch histories, configuration snapshots, but you remain the Affirming Official responsible for what gets submitted.
Pro Tip: Pull your last 90 days of patch and monitoring logs before you start scoring anything. Half your Level 2 evidence probably already exists somewhere in your MSP's dashboard.
What Small Contractors Get Wrong About "Good Enough"
The conventional wisdom around CMMC self-assessment treats it as a paperwork exercise: fill in the SSP, check the boxes, submit to SPRS, move on. That framing misses the actual risk. The DoD holds you legally accountable for the accuracy of your self-assessment even when an MSP does the technical work, which means a self-assessment built on assumptions instead of evidence isn't a compliance shortcut. It's a liability sitting in SPRS with your organization's name on it.

Small contractors also tend to underestimate how often "we have a policy for that" substitutes for actual testing. It shouldn't. A Cape Cod defense contractor guide makes a similar point: the contractors who struggle most are rarely the ones with the fewest resources. They're the ones who treated documentation as the finish line instead of the starting point.
Hiring an MSP makes sense once evidence collection starts eating more hours than your team can spare, especially for ongoing monitoring data that needs to exist before an assessor ever asks for it. In-house remediation still works fine for a contractor with a dedicated IT lead and a small control gap. The math changes fast once you're staring down a dozen open POA&M items with no one tracking target dates.
— Nicholas
How Great Plains Networking Supports Your CMMC Self-Assessment
Great Plains Networking is the practical alternative to piecing together evidence collection, SSP drafting, and remediation on your own, or paying a large compliance consultancy retainer for work your existing IT partner should already be doing. Our team helps Oklahoma City metro contractors gather the logs, screenshots, and configuration evidence your self-assessment actually needs, close POA&M items with documented remediation steps, and keep the monitoring data flowing so your next SPRS refresh isn't a scramble.

If your last self-assessment leaned more on policy documents than test evidence, that's worth fixing before your next contract renewal, not after a prime contractor asks questions. Start with our managed IT support services built around 24/7 monitoring, evidence capture, and no long-term contract commitments, or reach out directly to scope your SSP and POA&M priorities together.
Official Resources Worth Bookmarking
Keep these on hand for every assessment cycle:
- SPRS CMMC portal: submission tutorials and Affirming Official workflow
- DoD CIO CMMC page: policy status, including the Phase II pause
- NIST SP 800-171A: assessment methodology and evidence procedures
- DFARS 252.204-7020: assessment currency and posting requirements
Sources
- Cybersecurity Maturity Model Certification
- Supplier Performance Risk System (SPRS) CMMC
- DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting
- NIST SP 800-171 Rev. 2 (and assessment guidance links)
Recommended
Want help putting this into practice?
We'll audit your security, speed, and hardware in under an hour — no commitment, no sales pitch. Just a clear roadmap of what to fix and why.