Certification Is Not the Finish Line
Passing a CMMC Level 2 assessment is a significant accomplishment. It means a third-party assessor (C3PAO) reviewed your implementation of all 110 NIST SP 800-171 requirements, validated your evidence, and determined you meet the standard. Your certification is valid for three years.
What most contractors don't fully absorb until after certification: the three-year certificate does not stand on its own. Under 32 CFR Part 117, the regulation that gives CMMC its legal teeth, every organization with a CMMC Level 2 certification must submit an annual affirmation confirming that the security controls documented in their System Security Plan remain in place. This affirmation is due every 12 months regardless of where you are in your three-year certification cycle.
The affirmation requirement also applies to organizations that handle CUI and have submitted a self-assessment score to the Supplier Performance Risk System (SPRS) under DFARS 252.204-7019/7020, even without a formal C3PAO assessment. Those organizations must also affirm annually that their self-assessed posture remains accurate.
What the Affirmation Actually Requires
The affirmation is a formal attestation: a signed statement that your organization continues to implement the security requirements of NIST SP 800-171 in all covered contractor information systems. It is not a checkbox. It is a legal declaration made to the Department of Defense.
The substance of the affirmation is straightforward: you are attesting that your security posture has not materially degraded since your last assessment or affirmation. Specifically:
| What You Are Attesting | What That Means in Practice |
|---|---|
| Controls remain implemented | The security requirements in your SSP are still in place. Not just documented, but actively operating. |
| SSP remains accurate | The system boundary, asset inventory, and control descriptions in your SSP reflect your current environment |
| No material degradation | No significant control failures, architectural changes, or scope expansions that would change your compliance status have occurred without documentation |
| POA&M items are being tracked | Any open Plan of Action and Milestones items are documented and being actively remediated within their scheduled timeframes |
The affirmation is not an audit or assessment. Nobody is verifying your controls before you sign. That is precisely what makes the requirement significant, and what makes the false statements risk (covered below) the part of this requirement that senior officials need to understand before they sign.
Who Can Sign the Affirmation
32 CFR Part 117 requires the affirmation to be made by a senior official of the organization. Not the IT administrator, not the compliance consultant, not the ISSO. The regulation is explicit: this must be an individual with organizational authority to make compliance representations to the federal government on behalf of the company.
In practice, this means the CEO, President, CISO, or an executive with delegated authority over the company's compliance obligations. The individual signing the affirmation is personally attesting to the accuracy of the compliance representation, a fact that becomes material if the affirmation is later found to be inaccurate.
The named senior official and their title must be recorded as part of the affirmation documentation. This creates an auditable record establishing who made the attestation, when, and under what authority. 1TEN captures this in the Annual Affirmation module: official name, title, affirmation date, and the SSP version in effect at the time of signature.
Where the Affirmation Is Submitted
Annual affirmations for CMMC Level 2 are submitted through the Supplier Performance Risk System (SPRS), the same DoD portal where contractors post their self-assessment scores. SPRS serves as the authoritative record of a contractor's CMMC compliance status, and the affirmation creates a timestamped entry in that record.
The SPRS entry must reflect the date of affirmation and identify the affirming official. Contracting Officers review SPRS records as part of contract award decisions and ongoing contract monitoring. An expired or missing affirmation is visible in SPRS to every DoD contracting activity that checks your record.
| Record Type | Where It Lives | Who Sees It |
|---|---|---|
| CMMC Assessment Score | SPRS (via C3PAO submission) | DoD Contracting Officers, primes reviewing your compliance status |
| Self-Assessment Score | SPRS (direct contractor entry) | DoD Contracting Officers, primes |
| Annual Affirmation | SPRS (direct contractor entry) | DoD Contracting Officers, primes |
| Internal Affirmation Record | Your SSP / compliance platform | C3PAO assessors, internal audit |
Maintaining an internal affirmation record in addition to the SPRS submission is important for assessment readiness. When your three-year assessment comes up, the C3PAO will review your affirmation history as part of evaluating whether you've maintained a continuous compliance posture, or whether certification was achieved and then allowed to drift.
What Triggers an Earlier Affirmation
The standard cycle is annual, every 12 months from your last affirmation or assessment. But certain events require an updated affirmation outside the normal schedule:
| Triggering Event | Why It Matters |
|---|---|
| New systems added to CUI boundary | Your SSP system boundary has changed. The existing affirmation no longer accurately covers your environment. |
| Significant architecture changes | Network segmentation changes, cloud migrations, or new remote access infrastructure that affects control implementation |
| New CUI handling processes | Acquiring a new contract with different CUI categories, or standing up new workflows that bring systems into scope |
| Control failure or security incident | An incident that compromised or degraded a control that was attested as implemented. The affirmation may no longer be accurate. |
| Senior official departure | The named official who made the last affirmation is no longer with the organization. The record should be updated with the new responsible official. |
The rule of thumb: if your SSP changes materially, your affirmation should be refreshed. An affirmation made against a prior version of your SSP that no longer accurately describes your environment is a gap, and assessors will probe it.
What Happens If You Miss the Affirmation Deadline
Missing the annual affirmation deadline does not immediately revoke your CMMC certificate, but it creates a visible gap in your SPRS record and puts your compliance status in question. The consequences compound depending on how long the lapse runs and when it is discovered.
| Scenario | Consequence |
|---|---|
| Missed deadline, discovered before contract award | Contracting Officer may find the affirmation lapse disqualifying. Contract award can be delayed or denied. |
| Missed deadline, discovered during active contract | Contracting Officer notification required. Potential cure notice. Remediation required to restore compliant status. |
| Missed deadline, discovered during C3PAO reassessment | Assessors will document the gap in continuous compliance maintenance. Finding against CA.L2-3.12.4 (SSP currency). |
| Affirmation submitted but inaccurate | False Claims Act exposure for the signing official and the organization (see next section) |
For small DIB contractors, the most common failure mode is not malicious. It's administrative. The company completes its C3PAO assessment, receives certification, and then nobody calendars the 12-month affirmation deadline. Twelve months pass. The deadline is missed. The SPRS record shows an expired affirmation, and a contracting opportunity surfaces where the prime demands current CMMC status. The problem is discovered at exactly the wrong time.
The False Statements Risk Senior Officials Need to Understand
This is the part of the annual affirmation requirement that receives the least attention in CMMC guidance, and it carries the most individual risk for the person who signs.
When a senior official submits an annual affirmation to SPRS, they are making a representation to the Department of Defense. That representation is subject to the False Claims Act (31 U.S.C. § 3729) and 18 U.S.C. § 1001 (false statements to the federal government). Knowingly or recklessly submitting an inaccurate affirmation, attesting that controls are in place when they are not, creates personal civil and criminal exposure for the signing official, not just corporate liability.
This is not hypothetical. The Department of Justice has already pursued and settled multiple False Claims Act cases against defense contractors specifically for misrepresenting cybersecurity compliance. These cases establish the enforcement posture your senior official is signing into.
| Case | Year Settled | Settlement / Fine | What Happened |
|---|---|---|---|
| Aerojet Rocketdyne | 2023 | $9 million | Company misrepresented its compliance with DFARS cybersecurity requirements in contract representations. A whistleblower (former employee) brought the case under the FCA qui tam provision. Settlement included no admission of liability but established that cybersecurity misrepresentation in federal contracting is prosecutable under the FCA. |
| Penn State University | 2024 | $1.25 million | University research contractor failed to implement required DFARS cybersecurity controls on systems handling DoD research data while representing compliance in contract certifications. Case brought by a former IT director as a whistleblower. Settled under the FCA. |
| Georgia Tech Research Corp. | Ongoing (filed 2022) | Pending | DoJ intervened in a whistleblower suit alleging the university knowingly submitted false cybersecurity compliance certifications to obtain DoD contracts. Case alleged that a required System Security Plan was never completed and that NIST 800-171 controls were not implemented as represented. Active litigation as of 2024. |
The practical implication: a senior official should not sign an annual affirmation as a routine administrative task. Before signing, they should have an actual basis for the attestation: a review of open POA&M items, a confirmation from the ISSO or IT lead that controls remain operational, and documentation that the SSP still accurately describes the environment. That review process and its outcome should be documented.
This is not an argument against signing. It is an argument for building the internal process that makes the signature defensible. The 1TEN Annual Affirmation module structures that process so the pre-signature review is documented before the signing request ever reaches the senior official.
Building a Repeatable Annual Affirmation Process
The affirmation is an annual event, which means the process for preparing it should be built into your compliance calendar, not improvised each time the deadline approaches. A repeatable process has three phases:
Phase 1: Pre-Affirmation Review (30 Days Before)
Thirty days before the affirmation due date, the ISSO or compliance lead conducts a structured review of the compliance posture. This includes: a walk-through of open POA&M items and their current status, a confirmation that the asset inventory and SSP system boundary still accurately reflect the environment, a review of any security incidents in the prior year and their impact on control status, and a check of any significant infrastructure changes that may have affected scope.
This review should produce a written summary, even a brief internal memo, that the senior official can reference when making the decision to sign. That summary becomes part of the affirmation documentation package.
Phase 2: Senior Official Review and Signature
The senior official reviews the pre-affirmation summary, asks questions where necessary, and makes an informed decision. If the review surfaces a material control gap that was not previously documented, that gap must be added to the POA&M before the affirmation is signed. Not after. Signing over a known undocumented gap is the scenario that creates False Claims Act exposure.
Once satisfied, the senior official signs the affirmation. The internal record captures their name, title, signature date, the SSP version reviewed, and a reference to the pre-affirmation review memo.
Phase 3: SPRS Submission and Record Update
The affirmation is submitted to SPRS. The internal compliance record is updated with the submission confirmation. The next affirmation due date is calendared: 12 months from today, with a 30-day prep reminder. That is the complete cycle.
How 1TEN Manages the Annual Affirmation
The 1TEN Annual Affirmation module is purpose-built for this requirement. It captures everything the affirmation record needs: the affirming official's name and title, the affirmation date, the SSP version in effect at time of signature, and the covered systems. Each cycle creates a timestamped entry in an auditable affirmation history.
The module integrates with the Compliance Calendar to generate a renewal task 30 days before the affirmation deadline. The task appears in the calendar assigned to the compliance lead, with a direct link to the affirmation record and a checklist for the pre-affirmation review. The senior official is not presented with a signature request without a documented review record in place.
For contractors subject to 32 CFR Part 117, 1TEN also tracks the affirmation status as part of the DIB Compliance Tracker, alongside SAM.gov registration, SPRS score currency, and DIBNET enrollment. The affirmation does not expire silently while other compliance tasks absorb attention.
Frequently Asked Questions
Both. 32 CFR Part 117 requires annual affirmations from any organization that handles CUI under a DFARS-covered contract, whether you hold a formal C3PAO-issued CMMC Level 2 certificate or have submitted a self-assessment score to SPRS under DFARS 252.204-7019/7020. The affirmation obligation follows the CUI handling obligation, not just the formal certification pathway.
It depends on their organizational role. If your compliance manager also holds a senior executive title (VP, C-suite, or equivalent) with actual authority to make compliance representations to the government, they can serve as the affirming official. An ISSO or IT manager who manages the day-to-day compliance program but does not hold executive authority is not the right signer. The requirement is about organizational authority, not technical expertise. For small companies, the owner or CEO is the correct signer in most cases.
If a control has degraded and is not yet remediated, the degradation should be documented in your POA&M before the affirmation is submitted. The affirmation covers the posture as documented, including open POA&M items that are being actively tracked and remediated. What it cannot cover is a known gap that is not documented anywhere. Add the gap to the POA&M, document the remediation plan and timeline, and then the affirmation accurately reflects a posture that includes known, managed deficiencies. That is the correct process. Signing an affirmation with no POA&M entry for a known gap is the exposure scenario.
No. The annual affirmation does not restart your three-year certification cycle. The certification was issued on a specific date by the C3PAO, and it expires three years from that date. The annual affirmation is a separate obligation that runs on its own 12-month cycle within that three-year window. You need both: a current certification and a current affirmation. When your three-year certification expires, you need a new C3PAO assessment. The affirmation alone does not extend it.
Your first annual affirmation is due 12 months from the date your CMMC Level 2 certificate was issued. Calendar that date immediately after receiving your certificate, not when the deadline is approaching. Your second affirmation is due at the 24-month mark, and your C3PAO reassessment is due before the 36-month expiration of the original certificate. All three milestones should be in your compliance calendar on day one.
Retain: the SPRS submission confirmation with timestamp, the internal affirmation record (official name, title, date, SSP version covered), the pre-affirmation review summary, a snapshot of the POA&M at time of affirmation, and the current SSP version. This documentation package demonstrates to a C3PAO assessor that affirmation was not a rubber stamp. It was a deliberate review with a documented basis. Retain each cycle's records for at least the duration of your current certification period, and ideally through one complete reassessment cycle beyond that.