Everything You Need to Know About CMMC Annual Affirmations—And How BARR Can Help As Your C3PAO

August 11, 2026 | CMMC

Achieving CMMC compliance is a major milestone for any organization that aims to do business with the U.S. Department of War—but your compliance journey doesn’t end there.

To maintain eligibility for defense contracts, organizations must complete periodic affirmations attesting that they remain in compliance with CMMC requirements. 

What are these affirmations, and why are they so important? Here’s what you need to know:

  • Organizations that have undergone CMMC Level 1 or Level 2 self-assessments are required to complete affirmations of CMMC compliance at the time of each self-assessment, and annually thereafter. 
  • For organizations that choose to work with a C3PAO to achieve CMMC Level 2 certification, affirmation is required when the formal C3PAO assessment concludes as well as annually throughout the three-year certification period.
  • These affirmations must be completed by a senior leader within the organization, and that individual can be held personally liable if it is discovered that false claims were made.

Let’s dive deeper.

What’s Included?

Most often submitted annually, affirmations of CMMC compliance must include a statement “attesting that the [organization] has implemented and will maintain implementation of all applicable CMMC security requirements to their CMMC Status for all information systems within the relevant CMMC Assessment Scope.”

An affirmation for CMMC must also include the name and title of the person submitting it, as well as their contact information.

All affirmations are submitted to the Department of War electronically in the Supplier Performance Risk System (SPRS).

Who Must Affirm?

Affirmations must be submitted by an “affirming official” who represents the business or organization. This person must be a “senior-level” official who is both responsible for ensuring the organization complies with CMMC and has the authority to affirm that it continues to do so.

It is important to choose an individual who is hands-on in the organization and understands its compliance posture. This could be a CISO or other C-suite leader, or another high-ranking individual within the organization’s executive team. 

If the affirmation includes false claims, both the organization overall and the affirming official themselves can be held liable.

When Is It Required?

There are many circumstances under which organizations must submit affirmations of their CMMC compliance

At CMMC Level 1, organizations must complete an affirmation of compliance alongside their annual self-assessment. This affirms that they are compliant with the 15 security requirements in FAR clause 52.204-21.

At CMMC Level 2, organizations must undergo a self-assessment or formal C3PAO assessment every three years, depending on the specifications of their contract. An affirmation of compliance with the 110 security requirements in the latest version of NIST SP 800-171 must be completed alongside this assessment, and annually thereafter. For organizations that are able to undergo post-assessment remediation in the form of a Plan of Action & Milestones (POA&M), an affirmation is also required when the POA&M is closed out.

Affirmations are also required when a material change occurs that could impact the organization’s compliance. This could include new or updated products or services.

In addition, organizations must affirm their CMMC compliance when submitting a proposal for a new contract and each year after the contract goes into effect.

The Bottom Line

CMMC compliance isn’t a one-and-done accomplishment—it’s an ongoing operational commitment. Because senior leaders face personal liability for false attestations, maintaining continuous compliance and submitting accurate affirmations is essential to winning and keeping contracts. 

Partnering with an experienced C3PAO like BARR Advisory helps ensure your organization stays audit-ready and compliant year after year. Contact us today for a free consultation.

Let's Talk