Regulatory Guide

CMMC Annual Affirmation: What It Is, Who Signs It, and What Happens If You Miss It

Published: 2026-04-10  ·  9 min read

Cert vs. Affirmation What It Requires Who Can Sign Where It's Submitted What Triggers It Consequences False Statements Risk How to Prepare 1TEN Affirmation Module FAQ

Certification Is Not the Finish Line

Passing a CMMC Level 2 assessment is a significant accomplishment. It means a third-party assessor (C3PAO) reviewed your implementation of all 110 NIST SP 800-171 requirements, validated your evidence, and determined you meet the standard. Your certification is valid for three years.

What most contractors don't fully absorb until after certification: the three-year certificate does not stand on its own. Under 32 CFR Part 117, the regulation that gives CMMC its legal teeth, every organization with a CMMC Level 2 certification must submit an annual affirmation confirming that the security controls documented in their System Security Plan remain in place. This affirmation is due every 12 months regardless of where you are in your three-year certification cycle.

The Math
A three-year CMMC Level 2 certification requires three annual affirmations. One at the end of year one, one at the end of year two, and the certification renewal assessment at year three. Missing any of those affirmations puts your certification status at risk before your assessment cycle even comes up.

The affirmation requirement also applies to organizations that handle CUI and have submitted a self-assessment score to the Supplier Performance Risk System (SPRS) under DFARS 252.204-7019/7020, even without a formal C3PAO assessment. Those organizations must also affirm annually that their self-assessed posture remains accurate.

What the Affirmation Actually Requires

The affirmation is a formal attestation: a signed statement that your organization continues to implement the security requirements of NIST SP 800-171 in all covered contractor information systems. It is not a checkbox. It is a legal declaration made to the Department of Defense.

The substance of the affirmation is straightforward: you are attesting that your security posture has not materially degraded since your last assessment or affirmation. Specifically:

What You Are Attesting What That Means in Practice
Controls remain implemented The security requirements in your SSP are still in place. Not just documented, but actively operating.
SSP remains accurate The system boundary, asset inventory, and control descriptions in your SSP reflect your current environment
No material degradation No significant control failures, architectural changes, or scope expansions that would change your compliance status have occurred without documentation
POA&M items are being tracked Any open Plan of Action and Milestones items are documented and being actively remediated within their scheduled timeframes

The affirmation is not an audit or assessment. Nobody is verifying your controls before you sign. That is precisely what makes the requirement significant, and what makes the false statements risk (covered below) the part of this requirement that senior officials need to understand before they sign.

Who Can Sign the Affirmation

32 CFR Part 117 requires the affirmation to be made by a senior official of the organization. Not the IT administrator, not the compliance consultant, not the ISSO. The regulation is explicit: this must be an individual with organizational authority to make compliance representations to the federal government on behalf of the company.

In practice, this means the CEO, President, CISO, or an executive with delegated authority over the company's compliance obligations. The individual signing the affirmation is personally attesting to the accuracy of the compliance representation, a fact that becomes material if the affirmation is later found to be inaccurate.

Who Qualifies as a Senior Official
For small DIB contractors, this is typically the company owner, CEO, or President. For larger organizations, a CISO or VP of Compliance with documented delegated authority also qualifies. The key requirement is that the individual has actual organizational authority, not just a title, to make compliance representations to the government. Document the basis for that authority in your SSP.

The named senior official and their title must be recorded as part of the affirmation documentation. This creates an auditable record establishing who made the attestation, when, and under what authority. 1TEN captures this in the Annual Affirmation module: official name, title, affirmation date, and the SSP version in effect at the time of signature.

Where the Affirmation Is Submitted

Annual affirmations for CMMC Level 2 are submitted through the Supplier Performance Risk System (SPRS), the same DoD portal where contractors post their self-assessment scores. SPRS serves as the authoritative record of a contractor's CMMC compliance status, and the affirmation creates a timestamped entry in that record.

The SPRS entry must reflect the date of affirmation and identify the affirming official. Contracting Officers review SPRS records as part of contract award decisions and ongoing contract monitoring. An expired or missing affirmation is visible in SPRS to every DoD contracting activity that checks your record.

Record Type Where It Lives Who Sees It
CMMC Assessment Score SPRS (via C3PAO submission) DoD Contracting Officers, primes reviewing your compliance status
Self-Assessment Score SPRS (direct contractor entry) DoD Contracting Officers, primes
Annual Affirmation SPRS (direct contractor entry) DoD Contracting Officers, primes
Internal Affirmation Record Your SSP / compliance platform C3PAO assessors, internal audit

Maintaining an internal affirmation record in addition to the SPRS submission is important for assessment readiness. When your three-year assessment comes up, the C3PAO will review your affirmation history as part of evaluating whether you've maintained a continuous compliance posture, or whether certification was achieved and then allowed to drift.

What Triggers an Earlier Affirmation

The standard cycle is annual, every 12 months from your last affirmation or assessment. But certain events require an updated affirmation outside the normal schedule:

Triggering Event Why It Matters
New systems added to CUI boundary Your SSP system boundary has changed. The existing affirmation no longer accurately covers your environment.
Significant architecture changes Network segmentation changes, cloud migrations, or new remote access infrastructure that affects control implementation
New CUI handling processes Acquiring a new contract with different CUI categories, or standing up new workflows that bring systems into scope
Control failure or security incident An incident that compromised or degraded a control that was attested as implemented. The affirmation may no longer be accurate.
Senior official departure The named official who made the last affirmation is no longer with the organization. The record should be updated with the new responsible official.

The rule of thumb: if your SSP changes materially, your affirmation should be refreshed. An affirmation made against a prior version of your SSP that no longer accurately describes your environment is a gap, and assessors will probe it.

What Happens If You Miss the Affirmation Deadline

Missing the annual affirmation deadline does not immediately revoke your CMMC certificate, but it creates a visible gap in your SPRS record and puts your compliance status in question. The consequences compound depending on how long the lapse runs and when it is discovered.

Scenario Consequence
Missed deadline, discovered before contract award Contracting Officer may find the affirmation lapse disqualifying. Contract award can be delayed or denied.
Missed deadline, discovered during active contract Contracting Officer notification required. Potential cure notice. Remediation required to restore compliant status.
Missed deadline, discovered during C3PAO reassessment Assessors will document the gap in continuous compliance maintenance. Finding against CA.L2-3.12.4 (SSP currency).
Affirmation submitted but inaccurate False Claims Act exposure for the signing official and the organization (see next section)

For small DIB contractors, the most common failure mode is not malicious. It's administrative. The company completes its C3PAO assessment, receives certification, and then nobody calendars the 12-month affirmation deadline. Twelve months pass. The deadline is missed. The SPRS record shows an expired affirmation, and a contracting opportunity surfaces where the prime demands current CMMC status. The problem is discovered at exactly the wrong time.

The False Statements Risk Senior Officials Need to Understand

This is the part of the annual affirmation requirement that receives the least attention in CMMC guidance, and it carries the most individual risk for the person who signs.

When a senior official submits an annual affirmation to SPRS, they are making a representation to the Department of Defense. That representation is subject to the False Claims Act (31 U.S.C. § 3729) and 18 U.S.C. § 1001 (false statements to the federal government). Knowingly or recklessly submitting an inaccurate affirmation, attesting that controls are in place when they are not, creates personal civil and criminal exposure for the signing official, not just corporate liability.

This is not hypothetical. The Department of Justice has already pursued and settled multiple False Claims Act cases against defense contractors specifically for misrepresenting cybersecurity compliance. These cases establish the enforcement posture your senior official is signing into.

Case Year Settled Settlement / Fine What Happened
Aerojet Rocketdyne 2023 $9 million Company misrepresented its compliance with DFARS cybersecurity requirements in contract representations. A whistleblower (former employee) brought the case under the FCA qui tam provision. Settlement included no admission of liability but established that cybersecurity misrepresentation in federal contracting is prosecutable under the FCA.
Penn State University 2024 $1.25 million University research contractor failed to implement required DFARS cybersecurity controls on systems handling DoD research data while representing compliance in contract certifications. Case brought by a former IT director as a whistleblower. Settled under the FCA.
Georgia Tech Research Corp. Ongoing (filed 2022) Pending DoJ intervened in a whistleblower suit alleging the university knowingly submitted false cybersecurity compliance certifications to obtain DoD contracts. Case alleged that a required System Security Plan was never completed and that NIST 800-171 controls were not implemented as represented. Active litigation as of 2024.
The Civil Cyber-Fraud Initiative
The Department of Justice launched the Civil Cyber-Fraud Initiative in October 2021 specifically to pursue False Claims Act cases against contractors who misrepresent their cybersecurity posture to obtain or retain government contracts. Deputy Attorney General Lisa Monaco stated at launch that the initiative would use the FCA "to pursue companies and individuals that put U.S. information or systems at risk by knowingly providing deficient cybersecurity products or services, knowingly misrepresenting their cybersecurity practices or protocols, or knowingly violating obligations to monitor and report cybersecurity incidents and breaches." The annual affirmation is a recurring opportunity to create, or avoid, exactly that exposure.

The practical implication: a senior official should not sign an annual affirmation as a routine administrative task. Before signing, they should have an actual basis for the attestation: a review of open POA&M items, a confirmation from the ISSO or IT lead that controls remain operational, and documentation that the SSP still accurately describes the environment. That review process and its outcome should be documented.

This is not an argument against signing. It is an argument for building the internal process that makes the signature defensible. The 1TEN Annual Affirmation module structures that process so the pre-signature review is documented before the signing request ever reaches the senior official.

Building a Repeatable Annual Affirmation Process

The affirmation is an annual event, which means the process for preparing it should be built into your compliance calendar, not improvised each time the deadline approaches. A repeatable process has three phases:

Phase 1: Pre-Affirmation Review (30 Days Before)

Thirty days before the affirmation due date, the ISSO or compliance lead conducts a structured review of the compliance posture. This includes: a walk-through of open POA&M items and their current status, a confirmation that the asset inventory and SSP system boundary still accurately reflect the environment, a review of any security incidents in the prior year and their impact on control status, and a check of any significant infrastructure changes that may have affected scope.

This review should produce a written summary, even a brief internal memo, that the senior official can reference when making the decision to sign. That summary becomes part of the affirmation documentation package.

Phase 2: Senior Official Review and Signature

The senior official reviews the pre-affirmation summary, asks questions where necessary, and makes an informed decision. If the review surfaces a material control gap that was not previously documented, that gap must be added to the POA&M before the affirmation is signed. Not after. Signing over a known undocumented gap is the scenario that creates False Claims Act exposure.

Once satisfied, the senior official signs the affirmation. The internal record captures their name, title, signature date, the SSP version reviewed, and a reference to the pre-affirmation review memo.

Phase 3: SPRS Submission and Record Update

The affirmation is submitted to SPRS. The internal compliance record is updated with the submission confirmation. The next affirmation due date is calendared: 12 months from today, with a 30-day prep reminder. That is the complete cycle.

How 1TEN Manages the Annual Affirmation

The 1TEN Annual Affirmation module is purpose-built for this requirement. It captures everything the affirmation record needs: the affirming official's name and title, the affirmation date, the SSP version in effect at time of signature, and the covered systems. Each cycle creates a timestamped entry in an auditable affirmation history.

The module integrates with the Compliance Calendar to generate a renewal task 30 days before the affirmation deadline. The task appears in the calendar assigned to the compliance lead, with a direct link to the affirmation record and a checklist for the pre-affirmation review. The senior official is not presented with a signature request without a documented review record in place.

For contractors subject to 32 CFR Part 117, 1TEN also tracks the affirmation status as part of the DIB Compliance Tracker, alongside SAM.gov registration, SPRS score currency, and DIBNET enrollment. The affirmation does not expire silently while other compliance tasks absorb attention.

Frequently Asked Questions

Both. 32 CFR Part 117 requires annual affirmations from any organization that handles CUI under a DFARS-covered contract, whether you hold a formal C3PAO-issued CMMC Level 2 certificate or have submitted a self-assessment score to SPRS under DFARS 252.204-7019/7020. The affirmation obligation follows the CUI handling obligation, not just the formal certification pathway.

It depends on their organizational role. If your compliance manager also holds a senior executive title (VP, C-suite, or equivalent) with actual authority to make compliance representations to the government, they can serve as the affirming official. An ISSO or IT manager who manages the day-to-day compliance program but does not hold executive authority is not the right signer. The requirement is about organizational authority, not technical expertise. For small companies, the owner or CEO is the correct signer in most cases.

If a control has degraded and is not yet remediated, the degradation should be documented in your POA&M before the affirmation is submitted. The affirmation covers the posture as documented, including open POA&M items that are being actively tracked and remediated. What it cannot cover is a known gap that is not documented anywhere. Add the gap to the POA&M, document the remediation plan and timeline, and then the affirmation accurately reflects a posture that includes known, managed deficiencies. That is the correct process. Signing an affirmation with no POA&M entry for a known gap is the exposure scenario.

No. The annual affirmation does not restart your three-year certification cycle. The certification was issued on a specific date by the C3PAO, and it expires three years from that date. The annual affirmation is a separate obligation that runs on its own 12-month cycle within that three-year window. You need both: a current certification and a current affirmation. When your three-year certification expires, you need a new C3PAO assessment. The affirmation alone does not extend it.

Your first annual affirmation is due 12 months from the date your CMMC Level 2 certificate was issued. Calendar that date immediately after receiving your certificate, not when the deadline is approaching. Your second affirmation is due at the 24-month mark, and your C3PAO reassessment is due before the 36-month expiration of the original certificate. All three milestones should be in your compliance calendar on day one.

Retain: the SPRS submission confirmation with timestamp, the internal affirmation record (official name, title, date, SSP version covered), the pre-affirmation review summary, a snapshot of the POA&M at time of affirmation, and the current SSP version. This documentation package demonstrates to a C3PAO assessor that affirmation was not a rubber stamp. It was a deliberate review with a documented basis. Retain each cycle's records for at least the duration of your current certification period, and ideally through one complete reassessment cycle beyond that.

Air-gapped. On-premises.

1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.

Request a Demo