Schedule a call

Compliance

With C3PAO assessments paused, the affirmation carries the weight

Third-party certification is on hold. The signature is not.

A CMMC affirmation is signed by one named person — not the company, not the board, not the IT provider. That person attests, in SPRS, that the requirements are met.

In practice they are often a senior official who has never read the System Security Plan they are affirming. They are told it is fine, and they sign.

What has not changed:

  • DFARS 252.204-7012 still applies.
  • NIST SP 800-171 still applies.
  • Phase I self-assessment, SPRS scores and annual affirmations continue.

And this is the part worth being precise about. The suspension paused the C3PAO route — routine third-party certification as a condition of award. It did not remove external scrutiny altogether: the Department has said select government-led assessments continue during the suspension. So the position is not “nobody is checking”. It is that the routine check is gone and the discretionary one remains, with your affirmation standing behind it either way.

If you are the person signing, the useful question is not “are we compliant”. It is “show me the evidence for the objectives we claim to meet”. There are 320 of them behind Level 2.

The honest part, including the bit that costs us the sale: most firms we look at meet fewer than they think. That is fixable, and far cheaper to find now than during a government-led assessment or a contract dispute.

More updates