Skip to main content

DEFENSE & CMMC

What Is CMMC Affirming Official?

DEFINITION

A CMMC Affirming Official is the senior company official who is responsible for ensuring the organization's compliance with CMMC requirements and who affirms, in the Supplier Performance Risk System, that the organization has implemented and will maintain its required security posture. Affirmations are made after each assessment and annually thereafter, and a false affirmation can create liability under the False Claims Act.

The Affirming Official is CMMC's accountability mechanism. The CMMC rule requires each organization seeking assessment to designate a senior official, someone with authority over and responsibility for the organization's compliance with CMMC requirements, who personally affirms continuing compliance in SPRS. Affirmations are required at the completion of each assessment or self-assessment, annually thereafter, and following closeout of a POA&M. The affirmation is not a formality: it is a representation to the federal government that the stated security posture is real and being maintained.

Every contractor and subcontractor subject to CMMC must name one, so the role reaches deep into the supply chain. In a mid-market company the Affirming Official is typically the CEO, COO, CIO, or another executive rather than a line IT manager, because the rule contemplates someone senior enough to answer for the organization.

The practical implication is personal and legal exposure. The Department of Justice has pursued False Claims Act cases over misrepresented cybersecurity compliance, and an affirmation signed without a defensible basis is exactly the kind of statement those cases turn on. Affirming Officials should insist on current assessment evidence, a maintained score, and documented POA&M status before signing. As of mid-2026, annual affirmations remain mandatory even while third-party assessments are suspended. Our defense and government practice helps executives build that evidence base.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →