Achieving CMMC compliance is a major milestone for any organization that aims to do business with the U.S. Department of War—but your compliance journey doesn’t end there.
To maintain eligibility for defense contracts, organizations must complete periodic affirmations attesting that they remain in compliance with CMMC requirements.
What are these affirmations, and why are they so important? Here’s what you need to know:
Let’s dive deeper.
Most often submitted annually, affirmations of CMMC compliance must include a statement “attesting that the [organization] has implemented and will maintain implementation of all applicable CMMC security requirements to their CMMC Status for all information systems within the relevant CMMC Assessment Scope.”
An affirmation for CMMC must also include the name and title of the person submitting it, as well as their contact information.
All affirmations are submitted to the Department of War electronically in the Supplier Performance Risk System (SPRS).
Affirmations must be submitted by an “affirming official” who represents the business or organization. This person must be a “senior-level” official who is both responsible for ensuring the organization complies with CMMC and has the authority to affirm that it continues to do so.
It is important to choose an individual who is hands-on in the organization and understands its compliance posture. This could be a CISO or other C-suite leader, or another high-ranking individual within the organization’s executive team.
If the affirmation includes false claims, both the organization overall and the affirming official themselves can be held liable.
There are many circumstances under which organizations must submit affirmations of their CMMC compliance.
At CMMC Level 1, organizations must complete an affirmation of compliance alongside their annual self-assessment. This affirms that they are compliant with the 15 security requirements in FAR clause 52.204-21.
At CMMC Level 2, organizations must undergo a self-assessment or formal C3PAO assessment every three years, depending on the specifications of their contract. An affirmation of compliance with the 110 security requirements in the latest version of NIST SP 800-171 must be completed alongside this assessment, and annually thereafter. For organizations that are able to undergo post-assessment remediation in the form of a Plan of Action & Milestones (POA&M), an affirmation is also required when the POA&M is closed out.
Affirmations are also required when a material change occurs that could impact the organization’s compliance. This could include new or updated products or services.
In addition, organizations must affirm their CMMC compliance when submitting a proposal for a new contract and each year after the contract goes into effect.
CMMC compliance isn’t a one-and-done accomplishment—it’s an ongoing operational commitment. Because senior leaders face personal liability for false attestations, maintaining continuous compliance and submitting accurate affirmations is essential to winning and keeping contracts.
Partnering with an experienced C3PAO like BARR Advisory helps ensure your organization stays audit-ready and compliant year after year. Contact us today for a free consultation.