Briefings · Assessment
Self-assessment vs. C3PAO assessment
CMMC is assessed three ways: you assess yourself, an authorized third party certifies you, or the government assesses you directly. Which path applies is not a choice you make; it follows from your level and the data your contract involves. The requirements underneath are identical across all three. What changes is who does the judging, and how much that judgment weighs.
Paths · at a glance
The short version
The bar is the same 110 requirements no matter who checks. A self-assessment is your own attestation, signed by a senior official and posted to SPRS. A C3PAO assessment is independent certification. A DIBCAC assessment is the government itself. A self-assessment is not the easy path; it is the same path, self-graded, carrying the same legal weight if the grade is wrong.
The three paths
Who assesses whom
The path follows the level, and the level follows your data and your contract.
| Level | Who assesses | Data & cadence | Result |
|---|---|---|---|
| Level 1 | You (self-assessment) | FCI only; annual | SPRS self-score + affirmation |
| Level 2 (self) | You (self-assessment) | Some CUI contracts; annual | SPRS self-score + affirmation |
| Level 2 (C3PAO) | Authorized third party | Prioritized CUI contracts; every 3 years | Certified CMMC status |
| Level 3 | Government (DIBCAC) | Highest-sensitivity CUI; every 3 years | Government-assessed status (Level 2 first) |
Which Level 2 path applies to a given contract is set by the government, not chosen by the contractor. When third-party assessments run, the contract tells you which column you are in.
Same bar, different weight
Why "self" is not "easier"
The most expensive misconception in CMMC is that a self-assessment is a lighter lift. It is not. Both a self-assessment and a C3PAO assessment measure the same 110 requirements broken into the same 320 assessment objectives, and both expect the same evidence that each objective is met. The preparation, the system security plan, the operating history, the artifacts, is identical. What you save on an assessor's fee you do not save on the work of being ready.
What actually differs is scrutiny and consequence. A C3PAO independently verifies your evidence and issues a certified status. A self-assessment is your own attestation: a senior official signs an affirmation in SPRS that the assessment is accurate and compliance is being maintained. That signature is a representation the government relies on at award, which is exactly why the Department of Justice has pursued False Claims Act settlements over inaccurate cybersecurity attestations. Grading your own work does not lower the bar. It moves the risk of getting it wrong from an assessor's report onto a signature with legal weight.
The practical implication: prepare a self-assessment exactly as rigorously as you would prepare for a C3PAO. The evidence briefing covers what "prepared" means in both cases, and the readiness-gaps briefing covers where it usually falls short.
Right now
What the 2026 pause changed
Timing matters here. During the 2026 program review, the department directed contracting officers to include only self-assessment levels in new solicitations and to remove third-party certification requirements from active ones. In practice, that means most contractors right now are in a self-assessment posture, whether or not their contract would have required a C3PAO before the pause. The full picture of what stopped and what still binds is in the pause briefing.
This does not lower what you must do, and it may raise the stakes on doing it honestly. With third-party verification set aside for now, the government leans harder on your self-attestation and on select government-led assessments. The signature carries more, not less. A contractor who prepares a self-assessment to certification standard is ready for whatever the reform review decides, because the requirements it will be measured against are not changing. That is the position an engineered program is built to hold: the same system passes a self-assessment today and a C3PAO tomorrow, because it is built to the requirements, not to the audit.
Straight answers
Asked and answered
What's the actual difference?
Who judges. A self-assessment is your own attestation posted to SPRS; a C3PAO assessment is independent certification. Same 110 requirements, different verifier and different weight of consequence.
Which level needs a third party?
Level 1 never. Level 2 splits by contract into self and C3PAO paths. Level 3 is always the government's DIBCAC, and needs a Level 2 certification first.
Is self-assessment easier?
No. The preparation is identical because the requirements are identical. You save the assessor's fee, not the work, and you take on the legal weight of the affirmation.
Who signs it?
A senior company official affirms compliance in SPRS, annually and after each assessment. It is a representation the government relies on, with False Claims Act exposure if it is inaccurate.
Sources
- 32 CFR Part 170, the CMMC Program final rule (assessment levels, affirmations, three-year cycle)
- 32 CFR 170.18 (Level 3 certification assessment by DIBCAC)
- DFARS 252.204-7019 and 252.204-7020 (SPRS scores and government assessment)
Next up
A scoping call is this conversation, applied to your contracts: which assessment path they put you on, and how far you are from being ready for it.
Schedule a Demo