Skip to content
CMMC Guidance
CMMC Level 2 · MSSP · 100% US-based

The certificate lasts three years.
The affirmation is due every twelve.

Under 32 CFR Part 170, a Level 2 assessment is valid for three years and a senior official has to affirm continued compliance in the Supplier Performance Risk System (SPRS) every year in between. All 110 requirements assessed against your real environment, an SPRS package built from the findings, and the same engineer keeping both current when the affirmation comes due.

  • No-cost gap review to start
  • NDA first before anything technical
  • US-based engineers, no exceptions
How SPRS scoring works3 of 110

Three requirements. Fifteen points.

You start at 110 and subtract. These three are each worth 5 points — the heaviest weighting the methodology assigns.

Are the security controls in the CUI environment periodically assessed for effectiveness?

3.12.1 · 5 points

Is multifactor authentication enforced for privileged accounts and network access?

3.5.3 · 5 points

Are incidents tracked, documented, and reported to the designated officials?

3.6.2 · 5 points

Score after these three

110 / 110

Answer all three to see the deduction.

Three of 110. Almost every requirement is met or it is not — only multifactor authentication and FIPS-validated encryption carry partial credit. The other 107 carry the rest of the points at risk.

US citizen analysts and engineers
100%US citizen analysts and engineers
Requirements assessed, not sampled
110 / 110Requirements assessed, not sampled
US-based security operations
24 / 7US-based security operations
Between affirmations, reconciled each time
12 monthsBetween affirmations, reconciled each time
The CMMCg Method

Four stages. One hundred and ten requirements. No stage five.

In the order they actually happen, not the order that makes a proposal look tidy. Stage three produces the System Security Plan and the Plan of Action and Milestones the submission is built from. Stage four has no end date, because the obligation does not have one either.

Read The CMMCg Method in full

Stage 01 · Week 1

Draw the smallest boundary you can defend.

Before anything is assessed, we establish where CUI actually lives: which systems process it, which people touch it, and which of your networks can honestly be excluded. Scope determines the size of everything downstream, which is why it is the highest-return hour in the engagement and the one most often skipped.

  • A CUI data-flow walkthrough with the people who actually handle it
  • Enclave options priced against assessing the whole environment
  • A written boundary an assessor can follow without you in the room

Who is involved: Whoever handles CUI day to day, plus IT

You receive

Scope statement and boundary diagram

A boundary diagram and written scope statement, in the form a Certified Third-Party Assessment Organization (C3PAO) expects to receive it.

Scope statementspecimen
People in scope
11 of 80
Endpoints in scope
16
Networks excluded
3
Boundary
Enclave
Read the sample report
Continuous guidance

A score is a snapshot. The environment keeps moving.

A supplier who submits a 110 in March and changes identity providers in June has changed their score, and usually does not know it. When the annual affirmation comes due, a senior official signs their name to a number nobody has checked in eleven months.

We monitor the controls that drift, refresh the evidence behind them, and reconcile the SPRS entry before anyone has to sign it.

Every 3 years
Assessmentthe Level 2 certification cycle under 32 CFR Part 170
Every 12 months
Affirmationa senior official affirms continued compliance in SPRS
Continuous
Evidencemonitoring, refresh, and score reconciliation in between

SPRS score

sample series

−128

at intake

110

held since

  • Score
  • Remediation milestone
  • Drift caught in monitoring
NIST SP 800-171 Rev 2

All 110, on one page.

Fourteen families. Each square is one requirement. Pick a family to read what it covers and where suppliers usually lose the points.

AC22 requirements · 54 points

Access Control

Who can reach CUI, from where, and what they can do once they are in. The largest family, and it touches every system you own.

7
requirements worth 5 points
2
requirements worth 3 points
13
requirements worth 1 point

A common way to lose points here

Remote access is allowed but not routed through managed access control points.

Read the AC requirements

Requirement text and counts are taken from NIST SP 800-171 Rev 2, the same index this site’s assistant answers from. Point values are the Department of Defense Assessment Methodology’s own lists (Version 1.2.1, 24 June 2020, §3.a): an unmet requirement deducts 5, 3, or 1 point from a starting 110. Multifactor authentication (3.5.3) and FIPS-validated encryption (3.13.11) are the two that carry partial credit, and are counted here at their maximum.

Built for

Defense suppliers.

Large enough to hold Controlled Unclassified Information (CUI) and a prime’s attention. Small enough that compliance lands on someone who already has a full job.

01

You handle CUI

and a prime has started asking what your SPRS score is, with a date attached.

02

You have no security staff

and the IT director who would own this already has a full job.

03

You have a stack of tools

and nobody who owns the number they produce or the evidence they generate.

Knowledge base

Read it before you buy anything.

The reference section is the product before it is a funnel. Every one of the 110 requirements is published with its text, every topic is cited to a primary source you can open, and none of it sits behind a form.

A supplier who reads this and decides they can handle it themselves has been given something useful. That is the trade. It starts where your obligation does: the Defense Federal Acquisition Regulation Supplement (DFARS) clause in your contract.

Open the knowledge base

Find out what your score really is.

Thirty minutes with an engineer who does the assessments, not a sales rep. You leave with your scoping boundary sketched and the requirements costing you the most points named.

  • Your CUI boundary sketched on the call
  • The requirements costing you the most points, named
  • A written summary afterward, yours to keep
Book the readiness call

NDA signed before anything technical. No cost, no obligation.