Insights · CMMC & NIST SP 800-171
The affirmation isn’t paperwork. Read what it commits you to.
A named senior executive certifies that the organization has implemented — and will maintain — every applicable requirement. With Phase 2 paused, no independent assessor stands behind that statement. Only they do.
Most contractors approach affirmation in the wrong order. Security completes the assessment. Someone calculates the score. Contracts or compliance enters the result into SPRS. Then, near the end of the process, somebody asks who should sign the affirmation.
That is backwards.
The Affirming Official should be identified before the assessment starts, because the assessment is producing the evidence that allows that individual to make a defensible statement to the government. This is not an approval workflow.
Under 32 CFR § 170.22, a named senior-level representative from within the organization affirms continuing compliance with the applicable CMMC requirements. The affirmation identifies that individual by name, title and contact information. The organization owns the compliance obligation. The Affirming Official owns the decision to make the affirmation.
Section one
What § 170.22 actually requires
The governing language sits in one short section of the CMMC rule. There are several things I would expect every CISO, compliance lead and executive signatory to understand before an affirmation is submitted.
The Affirming Official is defined by responsibility and authority
The regulation does not say the Affirming Official must be the CISO, CIO, CEO, president or owner. It establishes a functional test. The individual must be a senior-level representative from within the Organization Seeking Assessment, must be responsible for ensuring compliance with CMMC Program requirements, and must have the authority to affirm the organization’s continuing compliance.
That is a governance requirement, not a job-title requirement. A CISO may satisfy it. A CIO may satisfy it. In a smaller defense contractor, the president or owner may be the appropriate person. What matters is whether the individual genuinely holds the responsibility and authority described by the rule.
That is also why I would be cautious about assigning the role to the person who knows the technical environment best. A systems administrator may understand every firewall rule, endpoint configuration and enclave boundary in the company and still not have the organizational authority to make the affirmation.
The same issue applies to outside providers. Your MSP, MSSP, consultant or C3PAO can supply evidence, technical advice and assessment results. None of them substitutes for the internal senior-level representative the rule requires.
The responsibility also does not move through the supply chain. A prime affirms for the prime. A subcontractor affirms for itself. Each Organization Seeking Assessment carries its own.
The statement is broader than “our SPRS score was correct”
This is the part of § 170.22 that deserves more attention than it normally receives. The required affirmation states that the organization has implemented and will maintain implementation of all applicable CMMC security requirements for its CMMC Status, across the information systems within the relevant CMMC Assessment Scope.
Three assertions live inside that sentence.
| Assertion | What it commits you to |
|---|---|
| Implementation | The applicable requirements are actually implemented — not planned, not procured, not scheduled. |
| Scope | The assertion applies across every system belonging within the relevant assessment boundary. |
| Continuity | The organization will maintain implementation after the assessment is complete. |
That last one changes how a CISO should think about affirmation. You are not confirming that a spreadsheet was accurate on the day somebody calculated the score. You are making an assertion about a living control environment.
And living environments drift. A new SaaS platform starts processing CUI. An administrator creates a file share outside the approved enclave. A privileged account is added without the expected controls. An MFA exception intended to last three days becomes permanent. A subcontractor changes how information is exchanged. A security tool stops reporting. A system previously considered out of scope becomes connected to an in-scope workflow.
None of those events waits for your next annual assessment.
So the operational question is not whether the environment was compliant when you assessed it. It is whether you have enough change control, asset governance, evidence and executive oversight to know when the statement you affirmed is no longer supportable. That is a considerably higher standard than completing an annual compliance exercise.
Affirmation is event-driven as well as annual
Organizations often reduce the requirement to “we have to affirm once a year.” That is incomplete. Affirmation is required upon achieving Conditional CMMC Status, upon achieving Final CMMC Status, annually following the Final CMMC Status Date, and following a POA&M closeout assessment where applicable.
Your compliance calendar should therefore follow your CMMC status dates and assessment events — not your fiscal year, insurance renewal, contract anniversary, or whatever month your organization traditionally runs its annual security review. The Final CMMC Status Date matters. So does POA&M closeout. Those dates belong in a calendar with accountable owners and escalation before expiration, not in somebody’s inbox.
Every organization affirms for itself
This matters particularly in complex corporate structures, shared-service environments and prime/subcontractor relationships. Several legal entities may use the same Microsoft 365 tenant. They may share a security team, a SOC, an MSP, a SIEM, an identity provider and network infrastructure.
None of that makes their CMMC responsibilities interchangeable. The legal entity, contracts, CUI flows, assessment scope, information systems and CMMC status still have to line up with what is being affirmed.
Shared infrastructure can simplify operations. It can also make scope considerably harder to defend. This is one of the areas where I would want architecture, contracts, security and compliance looking at the same diagram before an executive signs anything.
Section two
Cadence by assessment level
| CMMC status | Affirmation required |
|---|---|
| Level 1 (Self) | Following completion of the self-assessment and annually thereafter. Level 1 does not permit POA&Ms. |
| Level 2 (Self) | Following the self-assessment, annually following the Final CMMC Status Date, and following POA&M closeout where applicable. |
| Level 2 (C3PAO) | Following the certification assessment, annually following the Final CMMC Status Date, and following POA&M closeout where applicable. |
| Level 3 (DIBCAC) | Following the Level 3 certification assessment, annually following the Final CMMC Status Date, and following POA&M closeout where applicable. |
There is an additional point organizations pursuing Level 3 need to understand. The Level 3 affirmation does not eliminate the Level 2 affirmation. The rule requires the organization to maintain the applicable annual Level 2 (C3PAO) affirmation as well, because the C3PAO and DCMA DIBCAC assessments address different requirement sets.
Higher maturity does not erase the lower assessment record. Both matter.
Section three
What I would require before an executive signs
The regulation tells you who must affirm and what must be affirmed. It does not design your internal executive assurance process for you. That is the organization’s job.
If I were accountable for the security program, I would not put an affirmation in front of a senior executive with nothing more than an SPRS score and an email asking for approval. The executive should receive an affirmation package — not a 300-page evidence dump, but a concise management package explaining what the organization is about to represent and why management believes that representation is supportable.
Seven questions the package must answer
- What exactly are we affirming? Legal entity, CMMC level, assessment type, assessment date, current status, relevant SPRS record. No ambiguity about which organization or assessment the executive’s name attaches to.
- What is the assessment scope? The current boundary. CUI flows, in-scope systems, asset categories, external service providers, material dependencies — and what changed since the assessment.
- What is the current assessment result? Do not hand the executive a number without explaining what supports it. If management cannot trace an implemented requirement back to current evidence, that is a problem before submission, not after.
- What remains open? Permitted POA&M items, operational exceptions, known control degradation, overdue remediation. An executive cannot decide well using information the security team filtered out because it was uncomfortable.
- What changed after the assessment? Systems, applications, identities, networks, cloud services, external providers, CUI processing. The assessment date is not a freeze-frame around the environment.
- Who validated the package? Security, IT, compliance, contracts and, where appropriate, legal. The Affirming Official should not be the first person outside the security team to discover a material scope problem.
- What is management’s conclusion? Stated plainly. Does management believe the organization can support the affirmation, and why? Identify assumptions, exceptions and unresolved matters before the signature, not after.
The purpose is not to manufacture paperwork around the executive. It is to establish a decision record.
If the affirmation is questioned eighteen months later, an email saying “please approve” will not tell the story. A useful record shows what the organization knew, what it tested, what had changed, what remained open, who reviewed those facts, and why management concluded the affirmation was supportable.
The signature does not transfer security’s responsibility
Because a senior executive signs, security teams sometimes start talking as though the executive has now “accepted the risk” and everyone underneath is protected. That is the wrong model.
The Affirming Official depends on representations coming from system owners, security personnel, compliance staff, service providers and business leadership. If those representations are incomplete or unsupported, an executive signature does not cure the underlying problem. The signatory needs reasonable assurance. The security organization has to produce it.
Section four
SPRS access is part of the control
There is also a very ordinary way for an otherwise mature process to fail: the right executive cannot access SPRS when the affirmation is due.
I would treat that as an identity and continuity issue, not an administrative inconvenience. The Affirming Official needs PIEE access with the appropriate SPRS role, established and tested well before the deadline. The account belongs to the individual, not the company. If that person leaves, retires, changes roles or no longer holds the necessary authority, the organization needs a succession process — designed in advance, not discovered during a departure.
At minimum, maintain a documented role owner, successor, required system access, affirmation dates and escalation path.
The same principle applies to the security team. If only one employee knows how the assessment was calculated, where the evidence is stored, or why certain assets were classified a particular way, you do not have a sustainable compliance process. You have key-person dependency.
Section five
What the False Claims Act changes about the conversation
Cybersecurity obligations in federal contracts do not exist separately from federal enforcement law. 18 U.S.C. § 1001 addresses materially false statements made knowingly and willfully in matters within federal jurisdiction. The False Claims Act creates a separate civil framework where its statutory elements — including falsity, knowledge and materiality — are satisfied.
Those distinctions matter, and they cut in the contractor’s favour as often as against. A failed security control does not automatically equal fraud. An inaccurate assessment does not automatically establish False Claims Act liability. A cybersecurity deficiency does not, by itself, prove that an Affirming Official committed a criminal offense. I would be careful about overstating that connection.
But organizations should be equally careful about assuming the opposite. The Department of Justice’s Civil Cyber-Fraud Initiative specifically targets knowing cybersecurity noncompliance, misrepresentation of cybersecurity practices, and related failures involving government contractors and recipients of federal funds.
The enforcement history is now significant enough that evidence integrity belongs in your compliance architecture. The question is no longer only whether you implemented the control. It is also what you represented about that control, what evidence supported that representation, what you knew when you made it, and what happened afterward.
What recent enforcement should teach a CISO
The lesson is not that every security deficiency creates FCA liability. That would be wrong. The more useful lesson is that the government can examine the distance between what an organization represented and what its own records show it knew about the environment.
Which means internal security records, assessments, SSPs, tickets, risk decisions, POA&Ms and executive representations need to tell a coherent story.
- If the SSP says MFA is enforced but an internal ticket says MFA was disabled six months ago with no remediation date, you have more than a documentation problem.
- If the assessment says a requirement is implemented but the control owner says the evidence came from a decommissioned system, you have more than an evidence problem.
- If the SPRS score assumes one CUI boundary but engineering has been moving CUI through systems outside it, you have more than a scoping problem.
You have conflicting organizational representations. That is what should concern a CISO.
Section six
External providers, M&A, and the C3PAO question
External providers do not remove the obligation
Modern defense contractors depend heavily on external providers. MSPs, MSSPs, cloud platforms, SaaS applications and specialized security providers may operate significant parts of the technical environment. That can be entirely appropriate.
But outsourcing the technology does not outsource the contractual representation. If a provider participates in the storage, processing, protection or transmission of CUI, or provides security functions supporting the environment, understand exactly how that relationship affects scope, responsibility and evidence.
Do not accept “our MSP handles that.” Ask which requirement, which system, who operates it, who configures it, who monitors it, where the evidence lives, what the contract obliges the provider to do, what happens when the provider changes the service — and who tells you when it does.
A third party can operate the control. Your organization still has to understand what it is representing about that control.
M&A diligence now needs a CMMC history
If you are acquiring a defense contractor, do not stop at “are you CMMC compliant?” That question is almost useless by itself.
Ask for the history. Prior SPRS scores. SSP versions. Assessment results. POA&Ms. Material security incidents. CUI scoping decisions. Known exceptions. Prior representations to contracting officers and prime contractors. What management knew when those representations were made — compared against the environment you are actually acquiring.
A change in ownership does not make the historical record irrelevant. The better diligence question is whether the target’s evidence supports the representations it has already made to the government and its customers.
A C3PAO assessment is evidence — not a liability shield
An independent C3PAO assessment provides valuable assurance. A qualified external assessment organization has examined the applicable environment against the relevant requirements and reached a result. That matters.
But it is not immunity. The organization still owns the accuracy of the information supplied to the assessor. It owns systems or CUI flows omitted from scope. It owns material changes after the assessment. It owns control degradation that occurs afterward. And the Affirming Official still carries a separate responsibility under § 170.22.
So I would not brief an executive with “the C3PAO certified us, so you can sign.” I would brief them this way: the independent assessment is one important source of assurance; here is what has changed since, here are the current open items, here is the evidence supporting our present position, and here is why management believes the affirmation remains supportable.
Section seven
What the Phase 2 suspension actually changes
The September 2026 environment requires precision. On 13 July 2026 the Department suspended advancement to CMMC Phase 2, which had been scheduled to begin on 10 November 2026 and would have expanded the use of Level 2 (C3PAO) certification requirements. Class Deviation 2026-O0025, Revision 3, signed 3 September 2026, carried that direction into the acquisition framework used by contracting officers.
The mistake is reading that as “CMMC is paused, so we can stop.” That is not a security strategy.
Separate the assessment mechanism from the underlying security obligation. The pause affects advancement into Phase 2 third-party requirements. It does not erase the safeguarding obligations that continue to apply under applicable DoD contract clauses, including DFARS 252.204-7012 and the applicable NIST SP 800-171 Rev. 2 requirements for covered contractor information systems.
That distinction should affect budget decisions. If an external C3PAO assessment is no longer immediately required by the acquisition path in front of you, reconsidering the timing of that assessment spend is reasonable. Stopping implementation or operation of the controls is not.
Identity management still has to work. CUI still has to be protected. Incident response still has to function. The SSP still has to describe reality. Scope still has to make sense. Suppliers still need governance. Evidence still needs to exist.
One DFARS numbering issue worth cleaning up
The 2026 acquisition changes have created a documentation problem inside many compliance programs. Under the applicable 2026 class-deviation framework, the NIST SP 800-171 DoD Assessment Requirements language appears at DFARS 252.240-7997. Many existing policies, procedures, compliance matrices and contract reviews still reference DFARS 252.204-7020.
Do not blindly find-and-replace. Your internal documentation should identify which authority and version applies. Class deviations and codified acquisition regulations do not necessarily move on the same timetable, and good compliance documentation preserves that distinction rather than hiding it.
Section eight
What I would do before the next affirmation
Twelve steps
- Formally identify the Affirming Official. Document the individual, role, authority basis and successor. Confirm they actually satisfy the responsibility and authority test — not that their title sounds senior enough.
- Verify PIEE and SPRS access. Test it before the affirmation window. Do not discover an account or role problem on the due date.
- Re-establish the assessment boundary. Validate current CUI flows, enclaves, endpoints, cloud services, external service providers, security protection assets and other relevant asset categories. Do not carry last year’s diagram forward untested.
- Compare today’s environment with the assessed environment. Review significant changes since evidence was collected — identity, networking, cloud, SaaS, privileged access, remote access, CUI exchange.
- Reconcile implementation claims to current evidence. For every requirement represented as implemented, ask whether you could produce defensible evidence today. Not last March. Today.
- Review the SSP as an operating document. If it describes a process, architecture or control that no longer exists, something has to change. Fix the environment or correct the documentation. Do not knowingly maintain two versions of reality.
- Review POA&M items and exceptions. Confirm every open item is permitted, accurately represented and actively managed. Look hard at missed remediation dates — a temporary exception that quietly became permanent deserves executive attention.
- Review external providers. MSPs, MSSPs, cloud providers and SaaS platforms are frequent sources of scope and evidence problems. Validate technical responsibility, contractual responsibility, information flows and evidence availability.
- Brief the Affirming Official. Scope, result, material changes, open risks, management recommendation. Do not ask someone to sign a statement they do not understand.
- Preserve the decision record. Evidence package, assessment artifacts, approvals, assumptions, management conclusion. The question years later may be what you knew when this was signed. Make sure the record answers it.
- Calendar every trigger. Final CMMC Status Date, annual affirmation, POA&M closeout events, executive succession, material contract changes. Do not rely on memory.
- Monitor the suspension separately. Regulatory monitoring is its own control. Do not let the program decay during the pause and then find the organization cannot respond when acquisition requirements change again.
The question I would ask before signing
Not “did we complete the assessment?” Not “is there a score in SPRS?” And not “did the consultant say we’re good?”
If the answer is yes, the affirmation is the final step in a functioning assurance process.
If the answer is “probably,” “mostly,” or “the consultant handled that,” you are not dealing with an SPRS problem. You are dealing with a governance problem. And that is exactly why the Affirming Official requirement matters.
References
Primary sources for this brief
- 32 CFR § 170.22 — Affirmation, including Affirming Official definition, affirmation content and submission triggers
- 32 CFR Part 170, Subpart D — CMMC status requirements at Levels 1, 2 and 3
- SPRS Affirming Official tutorial — Supplier Performance Risk System, DISA
- DFARS 252.204-7012 — safeguarding covered defense information and cyber incident reporting
- DFARS 252.240-7997 — NIST SP 800-171 DoD Assessment Requirements, as renumbered under the 2026 class-deviation framework
- Class Deviation 2026-O0025, Revision 3, signed 3 September 2026
- Department of War CIO memorandum, Suspension of the Advancement to CMMC Phase 2 Requirements, 13 July 2026
- 18 U.S.C. § 1001 — false statements
- 31 U.S.C. § 3729 — False Claims Act; DOJ Civil Cyber-Fraud Initiative
FAQ
Common questions
Who can serve as Affirming Official?
The rule sets a functional test rather than naming a title: a senior-level representative from within the organization, responsible for ensuring compliance with CMMC Program requirements, with authority to affirm continuing compliance. A CISO, CIO, president or owner may all qualify. What matters is whether the individual genuinely holds that responsibility and authority.
Can our MSP, consultant or C3PAO affirm on our behalf?
No. The rule requires a senior-level representative from within the Organization Seeking Assessment. External parties can supply evidence, technical advice and assessment results. None of them can make the affirmation.
We are a subcontractor. Does the prime’s affirmation cover us?
No. Each Organization Seeking Assessment affirms for itself, whether prime or subcontractor. The obligation does not flow up or down the supply chain.
Does the Phase 2 suspension remove the affirmation requirement?
The suspension addresses advancement to Phase 2 assessment requirements. Obligations arising under your existing contract clauses — including safeguarding under DFARS 252.204-7012 and the accuracy of what you have submitted — are a separate question, and one to review against your own contracts rather than a policy announcement.
Our environment changed after the assessment. Does that affect the affirmation?
It can. The affirmation reaches forward as well as backward: the organization has implemented and will maintain implementation. Material change after the assessment date is exactly the circumstance that should be surfaced to the Affirming Official before the next submission, not discovered afterward.
Our Affirming Official is leaving. What do we need to do?
Treat it as a continuity control. The successor needs their own PIEE account with the appropriate SPRS role, and the handoff needs to include the assessment basis, evidence location, open POA&M items and affirmation dates. Start well before the next affirmation falls due; account provisioning is not instant.
Does a C3PAO certificate protect the Affirming Official?
It is assurance, not immunity. The organization still owns the accuracy of what it supplied to the assessor, anything omitted from scope, and any change or degradation afterward. The affirmation is a separate obligation with its own standard.
Would your affirmation survive an evidence request tomorrow?
We review the scope, SPRS position and evidence behind the statement your executive is being asked to make — before their name goes on it.
Book a scope call. Thirty minutes, no charge. Or take the self-check first.
This series
- 01 · C3PAO wasn’t removed. Read the status list.
- 02 · The affirmation isn’t paperwork. Read what it commits you to. (you are here)
- 03 · What moved to DFARS Part 240, and what your documents still cite — forthcoming
- 04 · Reading a class deviation: what binds and what doesn’t — forthcoming
Related briefs
This brief reflects published guidance as of 15 September 2026. Class Deviation 2026-O0025 has been revised three times since issuance and remains in effect until rescinded or incorporated into the FAR, DFARS and DFARS PGI — verify the current revision before relying on it. CMMC Level 2 is assessed against NIST SP 800-171 Rev. 2. Advisory content, not legal advice. Affirmation, disclosure and contract-specific decisions should be evaluated with qualified counsel against the applicable solicitation, contract clauses, amendments, modifications and current Government guidance.
Cyber DSC · Insights · CMMC Regulatory Brief 02 · 15 Sep 2026
