Practitioner Proof · CMMC Level 2 Self-Assessment

We Scored a Perfect 110 on Our Own CMMC Level 2 Self-Assessment

What is a CMMC Level 2 self-assessment? It is an assessment a defense contractor conducts on itself against all 110 NIST SP 800-171 Rev. 2 requirements, following NIST SP 800-171A and scored under 32 CFR 170.24. The results go into SPRS with an affirmation from a senior official. A Level 2 certification assessment is instead performed by an authorized or accredited C3PAO.

Almost every firm selling CMMC compliance help has never sat on the other side of the table. They have read NIST SP 800-171. They have not scored their own business against all 110 of its requirements, watched the points come off, and closed every gap before attesting to the result. We did. In June 2026, Petronella Technology Group, Inc. completed a full CMMC Level 2 self-assessment of our own environment and reached a perfect Supplier Performance Risk System score of 110 out of 110, with an empty Plan of Action and Milestones.

We did it for the same reason a surgeon should be willing to be operated on by their own methods: you should not ask a defense contractor to trust you with their compliance if you have never proven you can pass the same bar yourself. This page is the full, honest account of what that score means, exactly how we earned it, and why a compliance partner that has graded its own environment against every objective is a fundamentally different partner than one that has only studied the framework.

110/110
SPRS self-assessment score
0
Open POA&M items
110
NIST 800-171 requirements met
320
Assessment objectives implemented

What a 110 SPRS score actually means

CMMC Level 2 is built directly on the 110 security requirements in NIST Special Publication 800-171, which decompose into 320 discrete assessment objectives. To produce a Supplier Performance Risk System score, an organization measures itself against all 110 requirements. The scale begins at 110 and subtracts points for every requirement that is not fully met. Some deductions are one point, many are three, and a handful are five points because they represent the highest-risk gaps. Because the deductions are weighted and there are more than 110 points of possible loss, the scale bottoms out at negative 203.

When contractors measure themselves honestly for the first time, the results are sobering. It is common to see initial scores in the double digits, and not unusual to see negative numbers. A 110 is the ceiling: it means every single one of the 110 requirements is fully implemented and the Plan of Action and Milestones, the running list of open gaps, is empty. Nothing is deferred. Nothing is outstanding. For a contractor competing for work that involves Controlled Unclassified Information, a 110 is the score the Department of Defense wants to see before award. Our SPRS calculator lets you model exactly how those deductions add up against your own environment.

Self-assessment, stated plainly and precisely

Precision is the entire discipline in this field, so we will be exact about what we did. What Petronella Technology Group completed is a CMMC Level 2 self-assessment, scored and attested by a CMMC Registered Practitioner. It is not a third-party certification, and we will never describe it as one. Under the CMMC program, only an authorized C3PAO can certify a Level 2 environment, and only the government assesses Level 3. Any vendor promising to make you "CMMC certified" over a weekend is describing something that does not exist, and you should treat that promise as a disqualifying red flag. If and when a formal certification is required, our C3PAO selection guide walks through how to choose an assessor.

Why a self-assessment still matters enormously: a self-assessment is the honest baseline every certification is built on. It is the same exercise a C3PAO grades you against, performed first by you, so there are no surprises when the stakes are highest. You cannot remediate what you have not measured, and no contractor should walk into a formal assessment without already knowing their own number. We ran the exercise on ourselves for exactly the reason we recommend it to every client: know your score before anyone else scores you.

CMMC Level 2 self-assessment vs. Level 2 certification assessment

32 CFR Part 170 defines two separate ways to hold a Level 2 CMMC Status, and they are not interchangeable. Under section 170.16, the organization seeking assessment "must conduct a Level 2 self-assessment in accordance with NIST SP 800-171A Jun2018" and "must upload the results into SPRS." Under section 170.17, "An authorized or accredited C3PAO must perform a Level 2 certification assessment," and "the C3PAO must upload the results into the CMMC instantiation of eMASS." Both measure the same requirement set: the rule states that "The security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2."

FactorLevel 2 self-assessmentLevel 2 certification assessment
Who performs itThe contractor itself (the organization seeking assessment)An authorized or accredited C3PAO
Resulting CMMC StatusConditional or Final Level 2 (Self)Conditional or Final Level 2 (C3PAO)
RequirementsAll 110 NIST SP 800-171 Rev. 2 requirementsAll 110 NIST SP 800-171 Rev. 2 requirements
Assessment procedureNIST SP 800-171A Jun2018NIST SP 800-171A Jun2018
ScoringCMMC Scoring Methodology, 32 CFR 170.24CMMC Scoring Methodology, 32 CFR 170.24
Where results goUploaded by the contractor into SPRSUploaded by the C3PAO into the CMMC instantiation of eMASS, which transmits them to SPRS
Repeat cycleEvery three yearsWithin three years of the CMMC Status Date
AffirmationAt each assessment and annually thereafterAt each assessment and annually thereafter
POA&M closeoutCloseout self-assessment by the contractor within 180 daysCloseout certification assessment by a C3PAO within 180 days

A certification assessment also covers the self-assessment tier. Section 170.17 states that achieving Level 2 (C3PAO) "also satisfies the requirements for a CMMC Statuses of Level 1 (Self) and Level 2 (Self)" for the same CMMC Assessment Scope. The work behind both is the same: every requirement must reach a MET result, and section 170.24 defines MET as "All applicable objectives for the security requirement are satisfied based on evidence." It adds that "All evidence must be in final form and not draft." A self-assessment that leans on draft policies would not hold up in front of a C3PAO, and it should not hold up in front of you either.

Which Level 2 assessment does your contract require?

You do not pick between self-assessment and certification; the Department of Defense does. Under 32 CFR 170.3(d), "DoD Program Managers or requiring activities are responsible for selecting the CMMC Status that will apply for a particular procurement or contract based upon the type of information, FCI or CUI, that will be processed on, stored on, or transmitted through a contractor information system." The contract clause DFARS 252.204-7021 then carries that choice: the contracting officer inserts one of "CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)", and the contractor must "Have and maintain for the duration of the contract a current CMMC status at the following CMMC level, or higher."

Read the solicitation before you plan. Where it names Level 2 (Self), section 170.16(b) sets two requirements before award: the contractor must hold "a CMMC Status of either Conditional Level 2 (Self) or Final Level 2 (Self)" and "must submit an affirmation of compliance into SPRS." Where it names Level 2 (C3PAO), only a certification assessment meets it, and your self-assessment becomes the rehearsal. Waivers are narrow. Under section 170.5(d), only "In very limited circumstances" may a Service Acquisition Executive or Component Acquisition Executive "elect to waive inclusion of CMMC Program requirements in a solicitation or contract," and even then "contractors and subcontractors will remain obligated to comply with all applicable cybersecurity and information security requirements." Section 170.5(e) adds that the CMMC Program "does not alter any separately applicable requirements to protect FCI or CUI," including DFARS 252.204-7012. Our DFARS 252.204-7012 guide covers that clause in detail.

POA&M rules in a CMMC Level 2 self-assessment

A self-assessment does not have to score 110 on day one, but the rule is strict about what may stay open. 32 CFR 170.21(a)(2) permits a Conditional Level 2 (Self) or Conditional Level 2 (C3PAO) status only "if all the following conditions are met":

  • "The assessment score divided by the total number of CMMC Level 2 security requirements is greater than or equal to 0.8;" against 110 requirements, that means a score of at least 88.
  • "None of the security requirements included in the POA&M have a point value of greater than 1 as specified in the CMMC Scoring Methodology set forth in § 170.24, except SC.L2-3.13.11 CUI Encryption may be included on a POA&M if encryption is employed but it is not FIPS-validated, which would result in a point value of 3;"
  • "None of the following security requirements are included in the POA&M": AC.L2-3.1.20 External Connections (CUI Data), AC.L2-3.1.22 Control Public Information (CUI Data), CA.L2-3.12.4 System Security Plan, PE.L2-3.10.3 Escort Visitors (CUI Data), PE.L2-3.10.4 Physical Access Logs (CUI Data), and PE.L2-3.10.5 Manage Physical Access (CUI Data).

Then the clock starts. Under section 170.16, the contractor "must remediate any NOT MET requirements, must perform a POA&M closeout self-assessment, and must post compliance results to SPRS within 180 days of the CMMC Status Date associated with the Conditional Level 2 (Self)." If that does not happen, "the Conditional Level 2 (Self) CMMC Status for the information system will expire." A POA&M is also not a shortcut to a passing finding: section 170.24 states that "A POA&M addressing NOT MET security requirements is not a substitute for a completed requirement." Our own self-assessment closed with an empty POA&M, which is the Final Level 2 (Self) path: section 170.16 grants Final status when the self-assessment "results in a passing score as defined in § 170.24."

The System Security Plan deserves special attention because it can never sit on a POA&M. Section 170.24 states that the absence of an up to date SSP at the time of the assessment "would result in a finding that 'an assessment could not be completed due to incomplete information and noncompliance with 48 CFR 252.204-7012.'" That is why our readiness assessment starts with the SSP.

What a Level 2 self-assessment posts to SPRS, and what follows

Under 32 CFR 170.16(a)(1)(i), the results entered in SPRS "shall include, at minimum" the CMMC Level, the CMMC Status Date, the CMMC Assessment Scope, "All industry CAGE code(s) associated with the information system(s) addressed by the CMMC Assessment Scope," the "Overall Level 2 self-assessment score (e.g., 105 out of 110)," and "POA&M usage and compliance status, if applicable." Four obligations follow the submission:

  • Affirmation. "Affirmation of the Level 2 (Self) CMMC Status is required for all Level 2 self-assessments at the time of each assessment, and annually thereafter." Under section 170.22, the Affirming Official is "the senior level representative from within each Organization Seeking Assessment (OSA) who is responsible for ensuring the OSA's compliance with the CMMC Program requirements."
  • Repeat cycle. The contractor "must conduct a Level 2 self-assessment every three years and submit the results in SPRS."
  • Evidence retention. "The artifacts used as evidence for the assessment must be retained by the OSA for six (6) years from the CMMC Status Date."
  • Government verification. "The DoD reserves the right to conduct a DCMA DIBCAC assessment of the OSA, as provided for under the 48 CFR 252.204-7020." If that review shows requirements were not maintained, "these DCMA DIBCAC results will take precedence over any pre-existing CMMC Status."

Cloud and outsourced services are inside the scope, not outside it. For a Level 2 (Self) requirement, section 170.16(c)(2) allows a cloud offering that "is FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline" or that "meets security requirements equivalent to those established by the FedRAMP Moderate (or higher) baseline." For an external service provider that is not a cloud provider, section 170.16(c)(3) requires that "The ESP services used to meet OSA requirements are assessed within the scope of the OSA's assessment against all Level 2 security requirements." Narrowing where CUI lives is usually the fastest way to shrink that scope; our CMMC enclave design page explains the approach.

How we implemented all 110 requirements

The 110 requirements of NIST 800-171 are organized into fourteen control families. Reaching a 110 is not about one heroic technical control; it is about closing every family completely, including the unglamorous administrative ones that quietly cost the most points. Here is how we approached each domain, described in vendor-neutral terms because we advise our clients never to publish the specific products that protect their environment, and we hold ourselves to the same rule.

Access Control and Identification and Authentication

These two families account for 33 of the 110 requirements, more than any other pair, and they are where scores most often bleed points. We enforce least-privilege access to every system that touches Controlled Unclassified Information, multifactor authentication on all privileged and remote access, unique identification for every user and device, session controls, and a documented process for provisioning and de-provisioning accounts. CUI is confined to an isolated, encrypted enclave rather than scattered across general-purpose file shares, which shrinks the access-control problem to a defensible boundary.

Audit and Accountability, System and Communications Protection, System and Information Integrity

Logging, monitoring, encryption, and integrity make up the technical backbone. We centralize audit logging, retain and review it, encrypt CUI both in transit and at rest with full-disk encryption on endpoints, segment the network, and run continuous monitoring backed by a managed detection stack that pairs automated tooling with human analysts covering SIEM, vulnerability scanning, and threat response. This is the same private, sovereign approach that underpins our private AI infrastructure: sensitive data stays inside a controlled boundary rather than transiting third-party services.

Awareness and Training, Personnel Security, Physical Protection

The requirements auditors weight most heavily are rarely the flashy ones. They are the human controls: scheduled security awareness training, defined roles and responsibilities, screening of personnel with access to CUI, and physical protection of the environment where that data lives. Because CUI in our environment is accessed only through the encrypted enclave and is not stored on local devices, the physical protection requirements are satisfied by design rather than by bolt-on controls. Our security awareness program runs on a fixed cadence, and the completion records are part of the evidence set.

Configuration Management, Maintenance, Media Protection, Risk Assessment, Incident Response, Security Assessment

The remaining families cover disciplined operations: hardened baseline configurations and change control, controlled maintenance, sanitization and handling of media, a documented risk assessment following NIST SP 800-30, a tested incident response plan, and the periodic self-assessment process itself. Our founder holds a state-licensed Digital Forensics Examiner credential, and that expertise sits directly behind the incident response and personnel families as documented evidence rather than as a good intention. We produced a full risk assessment report as part of the package, not a checkbox.

Verifiable identity. Our self-assessment was performed against our real, registered business identity, not a hypothetical. Petronella Technology Group, Inc. is registered in the System for Award Management with CAGE code 3S2G3 and Unique Entity ID KBTYTZB8JK25, NAICS 541511, headquartered at 5540 Centerview Drive, Suite 200, Raleigh, North Carolina 27606. We have been in business since 2002 and carry a BBB A+ rating.

How long it really took, and how we did it

A complete Level 2 package is substantial: a System Security Plan, policies and procedures mapped to all 110 requirements, a risk assessment, and the evidence that connects each control to how the business actually operates. Assembled by hand in a word processor, that work routinely consumes months of consultant time. We built ours in days, because we generated it with ComplianceArmor®, our own compliance documentation platform, layering our organization profile, our site details, and the CMMC Level 2 control set into a complete, internally consistent package.

That speed is not a shortcut around the work; it is the removal of the busywork so that the real work, implementing and evidencing controls, gets the attention. It is also the clearest possible demonstration that the same platform we sell can produce a defensible package fast, because we used it to produce our own. Speed applies to the documentation and the self-assessment. It does not apply to certification, which runs on the government and C3PAO timeline, and we never conflate the two.

The DoD mandate behind the score

The reason a SPRS score matters at all is contractual. Under DFARS clause 252.204-7012, any contractor that handles Controlled Unclassified Information must safeguard it in line with NIST SP 800-171 and report cyber incidents to the Department of Defense within 72 hours. DFARS 252.204-7019 and 252.204-7020 go further: they require contractors to perform the NIST 800-171 self-assessment and post the resulting score to the Supplier Performance Risk System, where contracting officers can see it before award. In practice, your SPRS score has become a gating number. A low or negative score can quietly remove you from consideration for work you are otherwise qualified to win.

That is the environment our own 110 was produced for. We handle client Controlled Unclassified Information as part of our compliance and managed services work, which places our business squarely inside the same obligations we help clients meet. Scoring our own environment was not a marketing exercise; it was the same requirement any defense contractor faces, met the same way we ask clients to meet it. If you are early in understanding these obligations, our CMMC compliance guide maps the DFARS clauses to the CMMC levels they drive.

The five-point requirements that decide most scores

Not every requirement is worth the same number of points, and understanding the weighting is the difference between a strategic remediation plan and a scattershot one. The DoD Assessment Methodology, and the CMMC Scoring Methodology in 32 CFR 170.24, assign a five-point deduction to the requirements that carry the greatest risk when they are missing, a three-point deduction to the next tier, and one point to the rest. A single unmet five-point requirement does more damage to your score than five minor gaps combined.

Among the heaviest-weighted requirements are foundational technical controls: multifactor authentication (IA.L2-3.5.3, which costs five points if MFA is not implemented for any users and three points if it covers only remote and privileged users), FIPS-validated encryption of Controlled Unclassified Information (SC.L2-3.13.11, five points if encryption is not employed and three if it is employed but not FIPS-validated), boundary protection (SC.L2-3.13.1), and public-access system separation (SC.L2-3.13.5). These are precisely the controls that a thin, checkbox approach skips or half-implements. Reaching a 110 meant fully satisfying every five-point requirement first, then working down through the three-point and one-point items, rather than chasing easy wins that barely move the number. When we grade a client environment through our readiness assessment, we prioritize the same way, because the fastest path to a defensible score is to stop the biggest deductions first. You can experiment with the weighting yourself in our SPRS calculator.

The honest footnote

A 110 is a scored, Registered-Practitioner-attested self-assessment. It is a genuine achievement and a rare one, and it is also a living discipline rather than a trophy on a shelf. Maintaining evidence for every one of the 110 requirements, keeping training current, reviewing logs, and re-assessing as the environment changes is continuous work. That is precisely the standard we hold ourselves to, and it is the standard we help clients build toward. We would rather tell you this plainly than let a headline number imply that compliance is ever finished.

Why our 110 is your advantage

CMMC applies across three levels, and we work across all three. Level 1 covers basic safeguarding of Federal Contract Information. Level 2 is the 110-requirement bar for most Controlled Unclassified Information, and it is the level most of our defense clients need to reach. Level 3 adds the most advanced requirements and is assessed by the government for the highest-risk programs. We have now measured ourselves at the Level 2 bar and closed it completely.

That changes the quality of the help you get. When we explain a requirement, we are describing a decision we have already made in our own environment. When we tell you how long the documentation takes or which objectives quietly cost the most points, we are reading from our own scorecard, not a training slide. When we say a strong self-assessment is achievable without a year of open-ended consulting fees, we have the receipts on our own books. Explore how we deliver that as CMMC-aligned managed IT services, review the full framework in our CMMC compliance guide, see how CMMC compares in our CMMC versus ISO 27001 breakdown, or weigh the market in our CMMC alternatives analysis. North Carolina contractors can also work with our Raleigh CMMC consultants directly.

From a 110 self-assessment to a C3PAO certification

A perfect self-assessment is not the finish line; it is the strongest possible starting position for whatever comes next. For many contracts, a current self-assessment posted to SPRS, combined with an annual affirmation from a senior company official, is what the contract requires today. For contracts that call for CMMC Level 2 certification, a C3PAO conducts a formal assessment against the same 110 requirements, and a clean, honest self-assessment is exactly what makes that engagement short and predictable. The organizations that struggle with certification are the ones that never measured themselves first and discover their real gaps in front of an assessor.

This is the path we walk clients through: measure with a readiness assessment, close gaps through documentation and technical implementation, maintain the evidence, and, when a contract demands it, prepare for a C3PAO using our C3PAO selection guide. We can deliver the underlying security controls as ongoing CMMC-aligned managed IT services, so the score you reach does not decay the moment the project ends. Because we reached and now maintain our own 110, we are describing a road we travel continuously, not one we have only mapped.

Get your own SPRS score

The first move is the one we made: measure honestly. Our readiness assessment grades your environment against all 110 requirements and hands you your SPRS self-score plus a prioritized remediation plan.

Start your CMMC readiness assessment Talk to a practitioner

Frequently asked questions

Is a CMMC Level 2 self-assessment the same as certification?

No. A self-assessment is performed and attested by the organization itself, ideally with a CMMC Registered Practitioner, and it produces a SPRS score. A certification is performed by an authorized C3PAO for Level 2, or by the government for Level 3. Both matter, but they are not interchangeable, and only a C3PAO or the government can certify.

What does a 110 SPRS score mean?

The SPRS scale for NIST 800-171 starts at 110 and subtracts weighted points for every requirement not fully met, bottoming out at negative 203. A 110 means all 110 requirements are fully implemented with no open Plan of Action and Milestones items. It is the maximum possible score.

Why does it matter that Petronella completed its own self-assessment?

Because it proves capability rather than claiming it. A partner that has scored its own environment against all 110 requirements has made the same decisions, produced the same documentation, and closed the same gaps that your assessment will demand. That is experience you cannot get from reading the framework.

How long does a CMMC Level 2 package take to produce?

Assembled manually, the documentation often takes months. Using our ComplianceArmor® platform, we produced a complete, internally consistent Level 2 package in days. The technical implementation and evidence work is separate and ongoing, and certification runs on the C3PAO and government timeline.

Can Petronella help us reach our own 110?

Yes. We help contractors at all three CMMC levels, from an initial readiness assessment and SPRS self-score through documentation, technical implementation, and preparation for a formal C3PAO assessment. Start with a readiness assessment or call us at (919) 348-4912.

How do I improve my SPRS score for DFARS 252.204-7012 compliance?

Fully implement the NIST SP 800-171 requirements you have not yet met, close their Plan of Action and Milestones items, and resubmit your score in SPRS. The scale subtracts weighted points for every requirement not fully implemented, so the highest-weighted gaps raise your score fastest. That is exactly how Petronella Technology Group reached its own 110 out of 110: working the full requirement list, documenting each control with ComplianceArmor®, and closing every POA&M item before attesting. We run the same gap-closing process for defense contractors under DFARS 252.204-7012.

What is the difference between a CMMC Level 2 self-assessment and a Level 2 certification assessment?

Both measure the same 110 NIST SP 800-171 Rev. 2 requirements using NIST SP 800-171A and the scoring in 32 CFR 170.24. In a self-assessment, the contractor assesses itself and uploads the results into SPRS. In a certification assessment, an authorized or accredited C3PAO performs the assessment and uploads the results into the CMMC instantiation of eMASS, which transmits them to SPRS.

Who decides whether my contract needs Level 2 (Self) or Level 2 (C3PAO)?

The Department of Defense does. Under 32 CFR 170.3(d), DoD program managers or requiring activities select the CMMC Status for each procurement based on the type of information involved, and the contracting officer names the required level in DFARS 252.204-7021. A Level 2 (C3PAO) status also satisfies a Level 2 (Self) requirement for the same assessment scope.

Can a CMMC Level 2 self-assessment include a POA&M?

Yes, within the limits of 32 CFR 170.21. The score divided by the number of Level 2 requirements must be at least 0.8, no POA&M item may be worth more than 1 point (except SC.L2-3.13.11 when encryption is employed but not FIPS-validated), and six requirements, including the System Security Plan, can never be on it. All open items must be closed with a closeout self-assessment posted to SPRS within 180 days.

How often must a CMMC Level 2 self-assessment be repeated?

32 CFR 170.16 requires a Level 2 self-assessment every three years, with the results submitted in SPRS. An affirmation of continuing compliance is required at each assessment and annually thereafter.

How long must we keep self-assessment evidence?

Under 32 CFR 170.16, the artifacts used as evidence for the assessment must be retained for six years from the CMMC Status Date.

Can the government check our self-assessment score?

Yes. 32 CFR 170.16 reserves the right for DoD to conduct a DCMA DIBCAC assessment under DFARS 252.204-7020, and if that review shows the requirements were not achieved or maintained, its results take precedence over the existing CMMC Status.