The Cybersecurity Maturity Model Certification (CMMC) is nearing full enforcement, and defense contractors are asking a critical question: Can we self-assess for CMMC Level 2?
Dig deeper below to learn when self-assessment applies and when it doesn’t.
A Level 2 self-assessment may apply if:
In all other cases, defense contractors must go through a third-party assessment performed by a C3PAO.
Here’s how to determine whether a self-assessment is a valid path for your organization:
Only the DoD, or your prime contractor when authorized, can confirm your assessment level. If the contract is silent or unclear, your safest course is to prepare for a third-party assessment.
The main reason most defense contractors will require a third-party assessment at CMMC Level 2 comes down to the type of CUI they handle. The majority of CUI in defense contracting environments is considered sensitive or high-risk, which places it in the “prioritized” category that requires a C3PAO certification.
This includes common categories such as:
If your organization handles any of this information, you will likely need to:
Assuming you can just self-assess without explicit DoD or prime contractor authorization creates risk. This not only affects your contracts, but your compliance posture overall. When in doubt, prepare for the third-party path.
If you are confirmed eligible for Level 2 self-assessment:
Keep in mind, self-assessment does not mean shortcut. It still requires complete technical implementation and thorough documentation.
Even if your current contracts do not demand third-party certification, you should begin preparing for it now. According to the DoD’s phased rollout of 48 CFR, C3PAO assessments for Level 2 will become mandatory for prioritized acquisitions starting in Phase II, which begins 12 months after the rollout starts (likely in late 2026).
However, many prime contractors are expected to flow down third-party assessment requirements earlier as part of their own risk management programs. Even if not contractually required by the DoD yet, your eligibility as a subcontractor could be influenced by your readiness to undergo a formal certification.
The safest course of action is to plan for and achieve Level 2 (C3PAO) certification. This allows your company to be eligible for all Level 2 contract opportunities.
No. A POA&M outlines how you will remediate gaps. A self-assessment is a formal review of control implementation and must reflect actual performance, not intention.
No. Each entity that handles CUI is responsible for meeting CMMC requirements independently unless they are operating within the prime’s controlled environment under documented agreements.
Yes, most likely. The self-assessment path is limited. Future contracts, renewals, or task orders may trigger a third-party requirement.