Skip to main content
GuidesBy Jason LeeAugust 27, 20269 min read

SPRS Self-Assessments and Annual Affirmations Still Apply in 2026

SPRS Self-Assessments and Annual Affirmations Still Apply in 2026

The direct answer: yes, you still need your self-assessment, your SPRS score, and your annual affirmation. The July 13, 2026 suspension froze the Phase 2 escalation that would have made third-party C3PAO certification a condition of award on CUI contracts starting November 10, 2026. It did not touch Phase 1, which has been live in new solicitations since November 10, 2025. Level 1 and Level 2 self-assessments, SPRS score posting, and the annual affirmation of continuous compliance by a named Affirming Official under 32 CFR 170.22 all remain mandatory. A current affirmation is a prerequisite to contract award and to option exercise, which makes a lapse a revenue event, not a paperwork event.

Status verified August 27, 2026. This page is updated when the regulatory status changes.

What the pause suspended, and what it left alone

The suspension memoranda issued on July 13, 2026 stopped the transition to Phase 2 requirements and froze Phases 3 and 4 along with all future implementation milestones. What they did not do is change a single word of the DFARS clauses or repeal the 32 CFR Part 170 program rule. Both remain on the books. We cover the mechanics and the timeline of the freeze in detail in our status page on the CMMC Phase 2 suspension; this page answers the narrower and more urgent question of what you are still legally obligated to do while the review runs.

The distinction that matters is between the assessment type and the assessment obligation. The pause suspended the escalation from self-assessment to certified third-party assessment. It did not suspend the obligation to assess yourself, score the result, post the score, and affirm it. If your compliance program was built around a November 2026 C3PAO date, the date moved. If it was built around a current SPRS entry, nothing moved.

The clause chain that still binds you

Four DFARS clauses do the work, and per DLA Piper's August 3, 2026 analysis, all four survived the pause with no text changes. Contracting officers are still inserting 252.204-7021, and Phase 1 requirements under it are still enforced.

Clause What it requires Status today
252.204-7012Safeguard covered defense information and report cyber incidents to DIBNet within 72 hoursFully in effect. The 72-hour reporting duty is unaffected by the pause.
252.204-7019Have a current NIST SP 800-171 self-assessment posted in SPRS to be eligible for awardUnchanged. This is the clause that makes a stale score an eligibility problem.
252.204-7020Maintain the SPRS posting, allow government verification, and flow the requirement to subcontractorsUnchanged. Paragraph (d) self-reporting remains a live False Claims Act hook.
252.204-7021Meet and maintain the CMMC level specified in the contractStill appearing in solicitations and contracts. Only the Phase 2 escalation to third-party assessment is suspended.

The self-assessment score itself runs on the familiar scale that tops out at 110 and can fall as low as negative 203, depending on how many of the 110 controls are unimplemented and what weight each carries. A negative score is not automatically disqualifying, but it is visible to every contracting officer and every prime that asks, and it is the number a plaintiff or a relator will start from if the affirmation is ever challenged.

The affirmation, and who is allowed to sign it

The annual affirmation under 32 CFR 170.22 is the part most companies handle carelessly, and it is the part with personal and corporate consequences. The rule requires a named Affirming Official to affirm continuing compliance with the applicable CMMC level, per covered system, on an annual cycle.

The Affirming Official is always a senior official of your company. It is a company role. It cannot be outsourced, and no consultant, MSP, assessor, or advisory firm can hold it or sign in its place, because the affirmation is a representation your business makes to the United States government about your own environment. In practice the role usually lands on a president, a COO, a CFO, or a senior executive with direct oversight of the covered systems, and the right test is simple: the person signing should be someone who can credibly say they know the state of the environment and have the authority to commit the company to keeping it that way.

That has a direct implication for how you use outside help. An outside team can scope the environment, run the gap analysis, build the SSP, maintain the POA&M, assemble the evidence, calculate the score, and brief the official on exactly what they are about to affirm and where the soft spots are. It stops there. The signature, the representation, and the risk stay with your executive. Any vendor that offers to be your Affirming Official or to sign the affirmation for you is offering something the rule does not permit, and you should treat that as disqualifying.

Not sure your affirmation would survive scrutiny?

A Z Cyber advisor can walk your scope, your score, and your open POA&M items with the executive who signs, so the person affirming knows exactly what they are affirming before they do it.

Talk to an Advisor →

Why the affirmation is the sharpest liability in the program

A score posted in SPRS is data. An affirmation is a representation that induces the government to award a contract or exercise an option. That difference is what converts an optimistic self-assessment into False Claims Act exposure, with treble damages and per-claim penalties attached. The Department of Justice Civil Cyber-Fraud Initiative continues to pursue false cybersecurity certifications, and the theory does not require anyone to prove a breach occurred. It requires only that the representation was false and material to payment.

Holland & Knight's January 2026 analysis labels this the CMMC affirmation trap, and flags it as a recurring finding in defense M&A diligence: a buyer inherits a target's prior affirmations along with the entity, and a historical affirmation that overstated implementation becomes a priced risk in the deal or a reason to restructure it. If you are on either side of a transaction in the defense industrial base, the affirmation history is diligence-grade material.

The practical defense is unglamorous. Score honestly, document every unimplemented control in a POA&M with a real remediation date, keep the evidence dated and retrievable, and never let the affirmation reflect a target state rather than the current one. A middling score with an accurate POA&M is a commercial disadvantage. A score of 110 you cannot substantiate is a legal problem.

Which control set you are actually affirming against

Rev 2, not Rev 3. The class deviation issued on May 2, 2024 pins DFARS 252.204-7012 compliance to NIST SP 800-171 Revision 2 and its 110 controls, and that deviation still governs. Organizationally Defined Parameter values for Rev 3 were published in April 2025 as preparatory guidance, alongside an explicit reaffirmation that Rev 2 remains the compliance baseline. Rulemaking to adopt Rev 3 into the DFARS was expected somewhere between late 2026 and mid-2027 before the July pause, and the reform review makes that timeline less predictable, not more.

So if a vendor is quoting you an assessment against Rev 3 for DFARS or CMMC purposes today, they are selling you work that no clause requires. Reading Rev 3 to understand where the standard is heading is sensible. Scoring, affirming, or rebuilding your SSP against it is not. If the relationship between the underlying control set and the certification program is still fuzzy, our guide to the differences between NIST 800-171 and CMMC lays out which document supplies the controls and which supplies the verification.

What to do in the next thirty days

Five concrete items, in order. First, confirm the date of your current SPRS entry and the date of your last affirmation, per covered system, and put both renewal dates on a calendar owned by a named person. Second, re-scope: confirm whether you are handling FCI, CUI, or both, because level assignment errors are the most common structural mistake in small manufacturers. Third, reconcile the score to reality by walking each control marked implemented and asking what evidence proves it. Fourth, refresh the POA&M so every gap has an owner and a date. Fifth, brief the Affirming Official in a working session before the next renewal, not in the five minutes before the signature.

If a prime has sent you a flow-down letter demanding certification despite the pause, that is a contract term rather than a regulatory one, and it is answered separately in our page on CMMC flow-down to subcontractors during the pause. For the broader program view, our compliance advisory practice and our defense and government sector page describe how the assessment, the evidence, and the executive briefing fit into an ongoing program rather than an annual scramble.

What to watch next

Three dates. On or about September 13, 2026, the CMMC Reform Task Force report is due to the Department CIO, which is the first real signal about whether third-party assessment returns, is narrowed to a subset of contractors, or is replaced by an enhanced self-assessment plus executive attestation model. Note that every scenario currently under discussion keeps self-assessment and attestation, so the work on this page holds under all of them. Mid-October 2026 is the earliest point analysts expect formal determinations, with slippage into late 2026 or early 2027 entirely plausible. And the DFARS rulemaking to adopt NIST SP 800-171 Rev 3 remains unscheduled, so treat Rev 2 as the baseline until a final rule says otherwise. We will update this page when any of the three moves.

Frequently Asked Questions

Do I still need my SPRS self-assessment during the CMMC pause?

Yes. The July 13, 2026 suspension applies to the Phase 2 escalation that would have required third-party C3PAO certification on CUI contracts. Phase 1 has been live in new solicitations since November 10, 2025 and was not suspended. Level 1 and Level 2 self-assessments, SPRS score posting under DFARS 252.204-7019 and 7020, and the annual affirmation under 32 CFR 170.22 all remain mandatory. A current affirmation is a prerequisite to contract award and to option exercise.

Who should be the CMMC Affirming Official?

A senior official of your own company with the authority to affirm that the organization is and will remain in compliance with the applicable CMMC level. It is a company role, not a vendor role. A consultant, an MSP, or an outside advisor cannot hold it and cannot sign for it, because the affirmation is a representation your business makes to the government. In practice this is usually a president, COO, CFO, or a senior executive with direct oversight of the covered systems.

Can a false SPRS affirmation trigger the False Claims Act?

Yes, and that is the sharpest liability in the whole program. An affirmation is a representation to the government that induces award and option exercise, so an inaccurate one is treated as a false claim, exposing the company to treble damages and per-claim penalties. The Department of Justice Civil Cyber-Fraud Initiative continues to target false cybersecurity certifications, and law firms have flagged the affirmation as a recurring finding in defense M&A diligence.

Do I score against NIST 800-171 Rev 2 or Rev 3 in 2026?

Rev 2. The class deviation issued on May 2, 2024 pins DFARS 252.204-7012 compliance to NIST SP 800-171 Revision 2 and its 110 controls, and that deviation still governs. The Department published Organizationally Defined Parameter values for Rev 3 in April 2025 as preparatory guidance while reaffirming Rev 2 compliance. Nobody should be building an SSP, scoring SPRS, or affirming against Rev 3 for DFARS or CMMC purposes today.

What happens if my SPRS affirmation lapses?

A lapsed affirmation is a business problem before it is a compliance problem. A current affirmation is a prerequisite to contract award and to option exercise, so the practical consequence is that a contracting officer cannot make the award or exercise the option until the affirmation is refreshed. That timing rarely aligns with your pipeline. Track the affirmation renewal date per covered system the same way you track an insurance renewal or a registration expiry.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.