← Custodia
32 CFR 170.16

CMMC Level 2 Self-Assessment Requirements

In plain English

32 CFR 170.16 governs the subset of CMMC Level 2 work that DoD allows to be self-assessed (rather than certified by a C3PAO). It requires a triennial self-assessment against all 110 NIST SP 800-171 controls, supplemented by an annual senior-official affirmation, for the specific programs DoD designates as eligible for self-assessment.

Who must comply

Contractors handling CUI on contracts where DoD has designated Level 2 self-assessment (rather than C3PAO certification) as sufficient.

What it requires

  1. 01Conduct a self-assessment against all 110 NIST SP 800-171 controls every three years.
  2. 02Score the assessment using the DoD Assessment Methodology and post the score to SPRS.
  3. 03Submit an annual senior-official affirmation of continued compliance.
  4. 04Implement any allowed POA&M items within the timelines specified in 32 CFR 170.21.
Primary source
Read 32 CFR 170.16 at its source

Related clauses

Related terms

Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)