CMMC ANSWER ENGINE

Who at my company signs the annual CMMC affirmation, and what does it commit to?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14

The annual affirmation is one of the most-overlooked obligations in CMMC because the technical assessment gets all the attention. Skipping the affirmation, however, invalidates the CMMC Status no matter how well the technical assessment went.

The legal basis

32 CFR § 170.22 establishes the affirmation requirement. The CMMC 101 (Nov 2025) brief is explicit: every assessment outcome — Level 1, Level 2 (Self), Level 2 (Certification), and Level 3 — requires annual affirmation of continued compliance in SPRS.

Who is the Affirming Official

The Affirming Official (AO) is a senior company official with the authority to affirm on behalf of the company that the OSA continues to comply with all applicable CMMC security requirements. Typical AOs:

  • CISO or Information Security Officer.
  • CIO or Information Technology Officer.
  • COO or another executive officer.
  • For smaller contractors, the company owner or president.

The AO must have actual authority to bind the company on the affirmation — this is not a delegable IT staff function.

What the affirmation commits to

The AO's signature attests that:

  • The OSA continues to comply with the CMMC security requirements at the level corresponding to its CMMC Status.
  • The CMMC Assessment Scope on which the affirmation is based has not changed in ways that would invalidate the assessment.
  • The OSA continues to operate the controls described in the SSP.
  • For Level 2 and Level 3 with open POA&M items, those items are being closed within the 180-day window.

Affirmation cadence by CMMC Status

CMMC StatusUnderlying assessment cadenceAffirmation cadence
Final Level 1 (Self)Annual self-assessmentAnnual
Final Level 2 (Self)Annual self-assessmentAnnual
Final Level 2 (C3PAO)Every 3 yearsAnnual during the 3-year period
Final Level 3 (DIBCAC)Per DoW guidance (still being clarified)Annual

The affirmation is independent of the assessment cadence — even with a current 3-year C3PAO certification, the OSA must affirm annually.

The SPRS workflow

Per the DoW CIO's CMMC SPRS Brief (Feb 2025):

  1. The AO logs into SPRS via the Procurement Integrated Enterprise Environment (PIEE) single sign-on, with the SPRS Cyber Vendor User role assigned by the company's Contractor Administrator.
  2. The AO opens the assessment record in "Pending Affirmation" status.
  3. The AO verifies their personal information and their authority to affirm.
  4. The AO can optionally add additional points of contact for government contracting officers to use when discussing the assessment.
  5. The AO reviews the assessment results and signs the affirmation.
  6. SPRS records the affirmation and updates the CMMC Status with an expiration date.

What happens if the affirmation lapses

  • The CMMC Status becomes invalid until the affirmation is signed.
  • The OSA cannot represent itself as holding a current CMMC Status to contracting officers.
  • Contracts that require a current CMMC Status are at risk during the gap.
  • The fix is to complete and submit the affirmation in SPRS — usually a same-day correction once the AO is engaged.

Common errors

  • Treating the assessment as the only obligation. Even a flawless C3PAO assessment doesn't satisfy CMMC if the annual affirmation is missing.
  • Designating the wrong AO. A staff member without actual binding authority cannot affirm on behalf of the company. The AO must be a senior official with the authority to bind.
  • AO not having the SPRS Cyber Vendor User role. Without the role, the AO cannot complete the affirmation in SPRS.
  • Affirming when the scope has materially changed. If your assessment scope no longer matches the affirmation, you may need a new initial assessment, not just an affirmation.
  • Forgetting the calendar. Affirmations follow an annual cycle independent of the assessment cycle — track them in a maintenance schedule.

Sources

  • 32 CFR Part 170 — § 170.22 — Affirmation — link
  • CMMC SPRS Brief (Feb 2025) — link
  • CMMC 101 Brief (Nov 2025) — link
  • Supplier Performance Risk System (SPRS) — link
  • Procurement Integrated Enterprise Environment (PIEE) — link
Rulebook version: CMMC 2.0 Final Rule (32 CFR 170, § 170.22); CMMC SPRS Brief Feb 2025; CMMC 101 Nov 2025 brief

Track annual affirmations and assessment cycles.

The CMMC Compliance Engine includes the MAINT-SCH-01_Compliance_Monitoring_Maintenance_Schedule for tracking the annual affirmation cycle alongside the underlying assessment cadence — so the affirmation never lapses.

Get the CMMC Compliance Engine
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.