The annual SPRS affirmation of a Level 2 self-assessment
CMMC Level 2 annual affirmation pack
We refresh your system security plan from this year's records, re-assess the 110 requirements, recompute the score, update the plan of action and draft the memo your official affirms from.
Your official affirms only what your current records show; a requirement we cannot see stays NOT MET with a plan-of-action item.
| Part | Who |
|---|---|
| 3.1.1 Authorized users: MET. Your current account export matches the plan's user roster, dated this quarter | Ready |
| 3.11.2 Vulnerability scans: NOT MET. No scan record newer than last year's affirmation | You supply |
| System security plan refreshed from your current records | We prepare |
| The recomputed score and each plan-of-action item's status against the 180-day closeout | We prepare |
| Affirmation memo drafted for your senior official | We prepare |
| You enter the score in SPRS and your own official affirms | You supply |
$2,900per company per year, due when you confirm the order, refunded in full if the checked affirmation pack is not delivered by the agreed deadline
- You send
Your current system security plan and plan of action, as Word, PDF or Excel files, without any CUI in them.
- We prepare
We refresh the plan from your current records, mark each requirement MET or NOT MET, recompute the score, update each plan-of-action item and draft the affirmation memo.
- You pay
$2,900
You enter the score in SPRS and your own senior official affirms it. We never affirm, score in SPRS or certify for you.
yourcompany.com Found
The public pages read are listed, each with its title.
- Your pages say
- A line from your site, linked to its page
- May fit
- CMMC Level 2 annual affirmation pack, with its cited rule
- The one record
- Your current system security plan and plan of action, as Word, PDF or Excel files, without any CUI in them.
- Fee
- $2,900
Accept termsConfirm the order
What it takes, step by step
- 01
Today
Send the first record: your current system security plan and plan of action. Never upload CUI itself.
- 02
A free partial finding
Which requirements your current records still show met, which have changed, and the next record to send.
- 03
Exact terms
Scope, fee and deadline in writing; nothing is invoiced until you confirm the order.
- 04
The checked affirmation pack
The refreshed plan, all 110 requirements re-assessed, the score, the updated plan of action and the memo.
- 05
You affirm
You enter the score in SPRS and your own senior official affirms it.
What the annual pack refreshes from your current records
- System security plan (NIST SP 800-171 3.12.4)needs your record
- Each of the 110 requirements re-assessedneeds your record
- The score by DoD's assessment methodneeds your record
- Each plan-of-action item's statusneeds your record
- The 180-day closeout checkneeds your record
- Evidence listed by requirementneeds your record
- What changed since the last assessmentneeds your record
- Affirmation memo for the senior officialneeds your record
Public pages never establish an item: each is checked only against the records you send.
The rules that usually decide this
For Level 2 (Self), the contractor submits its self-assessment results in SPRS, repeats the self-assessment every three years, and its Affirming Official affirms continuing compliance at each assessment, annually thereafter and after POA&M closeout.
32 CFR 170.16(a)(1)-(2); 170.22(b)(2)The Affirming Official, the senior-level representative responsible for the organization's CMMC compliance, submits the Level 2 (Self) affirmation in SPRS at completion of the self-assessment, annually thereafter and after each POA&M closeout.
32 CFR 170.22(a)(1), (b)(2)A Conditional Level 2 (Self) status requires its POA&M items to be closed out within 180 days of the Conditional CMMC Status Date, confirmed by a POA&M closeout self-assessment; otherwise the Conditional status expires.
32 CFR 170.21(b); 170.16(a)(1)(ii)(B)Requirement 3.12.4: develop, document and periodically update system security plans that describe system boundaries, environments of operation, how the security requirements are implemented, and the relationships with or connections to other systems.
NIST SP 800-171 Rev. 2, requirement 3.12.4A System Security Plan (CA.L2-3.12.4) describing each in-scope system must be in place at assessment; without an up-to-date SSP the assessment cannot be completed. The SSP requirement may never be placed on a POA&M.
32 CFR 170.24(c)(2)(i)(B)(5); 170.21(a)(2)(iii)(C)Under DFARS 252.204-7021 the contractor must have and maintain a current CMMC status for the contract's duration: a Level 2 (Self) status not older than three years, with its annual affirmation current in SPRS.
DFARS 252.204-7021(a) (definition of Current), (d) (NOV 2025)
General rules for this kind of work, from their sources: not yet checked against your company.
Dates that decide this work
Each date runs from its own event, drawn to scale above the rule that sets it.
Close out the Level 2 POA&MConditional CMMC Status Date
Affirm your Level 2 (Self) status annuallyThe CMMC Status Date of your Level 2 (Self) status
Fees
Know the fee before any work
The first look is free. Before any paid work, we agree the exact documents, deadline and fee. Each service has one published price, paid when you confirm the order; we start once your payment arrives, and if the agreed, checked documents are not delivered by the deadline, you get the fee back in full. A score, grade or contract award never changes the fee.
You accept exact termsScope, fee and when it is due are written out before any paid work. Nothing is agreed until you press Accept or submit the complete acceptance statement shown in your private case.
No invoice until you confirm the orderAn invoice follows only your own confirmation in your private case, for exactly the agreed amount.
One private page for the whole caseMessages, terms, files and invoices stay on one page you keep.
We use public sources for the first look. If you continue, we work from records you choose to share. We prepare CMMC self-assessments, security plans and written safety programs for you to review, sign, affirm and upload. We do not contact the DoD, your customer, an assessor or a prequalification platform for you, and we never affirm or certify on your behalf.
Questions
What is in the pack, and what is not?
One company, one system, once a year: your system security plan refreshed from current records, all 110 NIST SP 800-171 Rev. 2 requirements re-assessed MET or NOT MET, the recomputed score, the plan of action updated with each item's status against the 180-day closeout, and a draft affirmation memo for your senior official. Not included: fixing gaps, entering the score in SPRS, affirming, assessor liaison or certification. Checked means a separate automated review, independent of the one that prepared it, compares every answer with your records and the rule's text before you receive it.
What if a requirement is no longer met this year?
It stays NOT MET in the refreshed plan, with what is missing and its plan-of-action item, and the score reflects it; nothing is carried forward as met without a current record. That protects the official who affirms: False Claims Act settlements have followed inaccurate self-attestations (Honeywell Aerospace, $2,042,518, 1 September 2026, reported by Nixon Peabody; LOGZONE, $507,144, June 2026, US Department of Justice).
Which AI providers do the work?
AI models from third-party providers prepare and check the work. The privacy page names the hosting and email providers; ask in your case and we name the model providers used for your work. No CUI is ever sent to them, because we never ask for CUI.
CMMC Level 2 annual affirmation pack
$2,900per company per year, due when you confirm the order, refunded in full if the checked affirmation pack is not delivered by the agreed deadline
Show me what applies