CMMC Level 2 Self-Assessment: How Rolle IT Helps You Get It Right
CMMC Compliance Guide
For many Defense Industrial Base (DIB) contractors handling Controlled Unclassified Information (CUI), CMMC Level 2 doesn’t require a third-party assessment — it requires a self-assessment. But “self” doesn’t mean “easy.” A Level 2 self-assessment demands rigorous evaluation of all 110 NIST 800-171 controls, formal documentation, accurate SPRS scoring, and annual affirmation by a senior official. Get it wrong, and you risk losing contracts, failing audits, or — under the False Claims Act — facing serious legal consequences for misrepresenting your compliance posture.
At Rolle IT Cyber Security (RIT-SEC), we guide DIB contractors through the Level 2 self-assessment process with the same rigor a C3PAO would apply. Our team includes Cyber AB Certified CMMC Professionals (CCP) and Certified CMMC Assessors (CCA) — people who know exactly what assessors look for, because they are assessors.
What Is a CMMC Level 2 Self-Assessment?
CMMC Level 2 requires organizations to implement all 110 security requirements from NIST SP 800-171 Rev 2. Depending on the contract and the sensitivity of CUI involved, the DoD may require either:
- Self-assessment — Your organization evaluates its own compliance, calculates a SPRS score, and submits it to the DoD. A senior official provides annual affirmation.
- C3PAO assessment — A CMMC Third-Party Assessment Organization conducts a formal certification assessment.
The determination is made by the contracting officer based on the DFARS clauses in your contract. Many CUI-handling contracts will allow self-assessment — but the bar is still high. You must:
- Evaluate all 110 NIST 800-171 controls honestly and accurately
- Document your implementation in a System Security Plan (SSP)
- Create POA&Ms for any controls not fully met
- Calculate and submit your SPRS score
- Have a senior official affirm the results annually
The Stakes Are Real: Under the False Claims Act and DFARS 252.204-7012, misrepresenting your SPRS score or compliance posture can result in contract termination, debarment, and civil liability. Your self-assessment is a legally binding assertion that your organization meets the controls you claim.
Where Most Organizations Struggle
We see the same problems repeatedly when DIB contractors attempt self-assessments without expert guidance:
1. Scoping Errors
Organizations either scope too broadly (assessing systems that don’t touch CUI, inflating cost and complexity) or too narrowly (missing systems where CUI actually flows, leading to inaccurate scores). Proper CUI scoping is the foundation of a valid assessment — get it wrong, and everything downstream is unreliable.
2. Generous Self-Scoring
Without understanding what “fully implemented” actually means for each control, organizations tend to score themselves higher than an assessor would. A control that’s “mostly there” or “we plan to do that” is not met. Rolle IT applies assessor-level scrutiny to every control evaluation.
3. Inadequate Evidence
Saying you have MFA enabled isn’t evidence. Assessors want screenshots, configuration exports, policy documents, and audit logs that prove implementation. Many organizations can’t produce evidence on demand because they never organized it. Rolle IT helps build an evidence framework that’s ready for scrutiny at any time.
4. Weak or Missing SSP
The System Security Plan must document how each control is implemented in your specific environment — not generic template language. An SSP that says “we use access control” without describing your Conditional Access policies, group structures, and authentication flows won’t survive review.
5. POA&M Mismanagement
Plans of Action & Milestones aren’t a parking lot for controls you’ll “get to someday.” POA&Ms must have defined timelines (180 days max), responsible parties, milestones, and realistic remediation plans. Open-ended POA&Ms signal that compliance isn’t being taken seriously.
How Rolle IT Supports Your Level 2 Self-Assessment
Rolle IT provides structured, expert-led self-assessment support that mirrors the rigor of a C3PAO evaluation — so when you submit your SPRS score, you can stand behind it with confidence.
Step 1: CUI Scoping & Boundary Definition
- Identify where CUI is created, received, stored, processed, and transmitted
- Define the system boundary — what’s in scope for assessment
- Map data flows to ensure no CUI pathways are missed
- Document the assessment scope clearly for your SSP
Step 2: Control-by-Control Evaluation
- Evaluate all 110 NIST 800-171 requirements against your actual implementation
- Score each control as Met, Not Met, or Not Applicable (with justification)
- Apply assessor-level rigor — no generous scoring
- Identify gaps immediately and categorize by severity
Step 3: Evidence Collection & Organization
- Gather evidence artifacts for every implemented control
- Screenshots, configuration exports, policy documents, audit logs
- Organize evidence in a structured framework mapped to control families
- Establish ongoing evidence collection processes for annual affirmation
Step 4: SSP Development
- Document how each control is implemented in your specific environment
- Describe the system boundary, architecture, and data flows
- Map responsible parties for each control (your team, your MSP, your CSP)
- Write implementation descriptions that would satisfy an assessor’s review
Step 5: POA&M Development
- Create actionable Plans of Action for every unmet control
- Define realistic timelines (within 180-day requirement)
- Assign responsible parties and milestones
- Prioritize by risk — critical gaps first
Step 6: SPRS Score Calculation & Submission
- Calculate your score accurately using the DoD Assessment Methodology
- Factor in weighted values for each unmet control
- Validate the score against evidence and SSP documentation
- Support SPRS submission and senior official affirmation preparation
Rolle IT’s Approach: We don’t just hand you a template and wish you luck. Our team sits with you, evaluates your controls with the same methodology a C3PAO uses, and produces documentation that would withstand formal assessment scrutiny. When your senior official signs that affirmation, they can do so with confidence.
What You Get When We’re Done
| Deliverable | Description |
|---|---|
| Reviewed System Security Plan (SSP) | Your SSP reviewed, validated, and updated to accurately document your system boundary, control implementations, data flows, and responsible parties |
| POA&M Document | Plans of Action & Milestones for any unmet controls with timelines, responsible parties, and remediation steps |
| SPRS Score | Accurately calculated score ready for submission to the DoD SPRS system |
| Evidence Package | Organized evidence artifacts mapped to each control — ready for review or audit at any time |
| Control Scorecard | Visual breakdown of all 110 controls by family showing Met/Not Met status and compliance percentage |
| Affirmation Support | Briefing materials and documentation for senior official to confidently provide annual affirmation |
Annual Affirmation: What Your Senior Official Needs to Know
CMMC Level 2 self-assessment requires a senior official within your organization to annually affirm that your compliance posture remains accurate. That affirmation carries legal weight under the False Claims Act.
Rolle IT helps your senior official by providing:
- Clear compliance status briefing — plain-language summary of where you stand
- Evidence that controls remain implemented — not just a point-in-time snapshot, but ongoing proof
- POA&M status update — what’s been closed, what’s in progress, what’s changed
- Change log — any environment changes since last assessment and their compliance impact
- Risk acknowledgment documentation — clear articulation of any remaining risks
After the Self-Assessment: Maintaining Compliance
A self-assessment is not a one-time event. Between triennial assessments, you must maintain your security posture and be prepared to demonstrate it at any time. Rolle IT offers ongoing support through:
- Continuous monitoring — detect configuration drift, policy violations, and new vulnerabilities
- Evidence management — ongoing collection and organization through the CARI compliance platform
- POA&M tracking — monitor remediation progress and ensure 180-day closure timelines are met
- Annual affirmation preparation — refresh assessment documentation for yearly senior official sign-off
- Environment change management — evaluate compliance impact of any infrastructure or process changes
- Remediation support — technical implementation to close gaps identified during the assessment
About Rolle IT Cyber Security
Rolle IT Cyber Security (RIT-SEC) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) headquartered in Melbourne, Florida. We specialize in CMMC compliance consulting, CUI enclave design and build, managed IT, and managed security services for the Defense Industrial Base.
Our CMMC team includes Cyber AB Certified CMMC Professionals (CCP) and Certified CMMC Assessors (CCA). As a DoD contractor ourselves, Rolle IT is subject to the same CMMC requirements as the clients we serve. Our team is led by a former NSA Cybersecurity expert who focuses on compliance as a minimum and security as a non-negotiable.
CAGE Code: 892K3 | UEI: R7DLKL224EM5 | DUNS: 116953947
Awards: HIRE Vets Platinum Medallion (U.S. Department of Labor) · Florida Companies to Watch Top 50 (2024)
Contact: [email protected] · 321-872-7576 · rit-sec.com
Frequently Asked Questions
What is a CMMC Level 2 self-assessment?
A CMMC Level 2 self-assessment is an internal evaluation of your organization’s compliance with all 110 NIST SP 800-171 security requirements. Organizations that handle CUI but are not required to undergo a C3PAO assessment may self-assess and submit their score to the Supplier Performance Risk System (SPRS). The self-assessment must be conducted by qualified personnel and supported by a System Security Plan (SSP) and Plans of Action & Milestones (POA&Ms).
What SPRS score do I need?
A perfect SPRS score is 110, meaning all 110 NIST 800-171 controls are fully implemented. Organizations can submit scores below 110 if they have POA&Ms for unmet controls, but those POA&Ms must be closed within 180 days. Your contracting officer may require a minimum score. Rolle IT helps organizations calculate accurate SPRS scores and develop realistic POA&Ms with clear remediation timelines.
What documents do I need for a Level 2 self-assessment?
A CMMC Level 2 self-assessment requires a System Security Plan (SSP), Plans of Action & Milestones (POA&Ms) for any unmet controls, a valid SPRS score submitted to the DoD, and evidence artifacts demonstrating control implementation. You also need to designate a senior official who can provide annual affirmation that the assessment remains accurate. Rolle IT helps organizations develop and organize all required documentation.
How long does a Level 2 self-assessment take?
Timeline depends on organizational readiness. For organizations with existing security controls but limited documentation, Rolle IT typically completes a full self-assessment engagement in 2-4 weeks.
Can Rolle IT help if I’ve already started my self-assessment?
Yes. Rolle IT regularly supports organizations at any stage — whether you haven’t started, you’re partway through and stuck, or you’ve completed an assessment but aren’t confident in the results. We can review existing work, identify gaps in your scoring or documentation, and bring the assessment to a defensible standard.
Get Started
If your contracts require CMMC Level 2 and you need to self-assess, don’t guess at your score or submit documentation you can’t defend. Rolle IT Cyber Security brings assessor-level expertise to your self-assessment so your SPRS score, SSP, and annual affirmation are accurate, defensible, and compliant.
Contact us at [email protected] or call 321-872-7576 to discuss your self-assessment needs.
CMMC Level 2 Self-Assessment: How Rolle IT Helps You Get It Right Read More »
