The key differences between L1 self-assessment and L2 C3PAO certification, drawn from 32 CFR §§ 170.15 and 170.17 and the CMMC Assessment Scope guides.
What's being assessed
| Dimension | Level 1 Self-Assessment | Level 2 C3PAO Certification |
|---|---|---|
| Standard | FAR 52.204-21 basic safeguarding (17 CMMC practices) | NIST SP 800-171 Rev 2 (110 practices) |
| Assessment scope | Per CMMC L1 Scoping Guide (FCI processing assets) | Per CMMC L2 Scoping Guide v2.13 (5 asset categories) |
| Who performs it | The OSA (your team or your consultants acting as you) | An independent Certified Third-Party Assessor Organization (C3PAO) authorized by the Cyber AB |
| Assessment methods | Self-determination of MET / NOT MET | Examine, Interview, and Test per NIST SP 800-171A; assessor reaches an objective determination |
| Result | Score submitted to SPRS | Final Level 2 (C3PAO) CMMC Status entered in SPRS and the eMASS CMMC instance |
| Validity period | Annual; new self-assessment + affirmation each year | 3 years between certification assessments, with annual affirmations during the period |
| Affirmation | Required annually by senior company official, in SPRS | Required annually by senior company official, in SPRS, in addition to the certification |
| POA&M permitted at conclusion | No — all practices must be MET | Yes for most controls, with closeout required within 180 days; some controls cannot be on a POA&M |
| Cost driver | Internal time + tooling | C3PAO assessor fees + internal preparation cost |
What a C3PAO assessment actually involves
The C3PAO assessment is conducted using the three NIST SP 800-171A methods:
- Examine — review documents, records, mechanism configurations.
- Interview — discuss practices and procedures with personnel responsible for the controls.
- Test — observe controls operating, including hands-on testing of authentication, logging, configuration, etc.
For each of the 110 practices, the assessor evaluates the assessment objectives in NIST SP 800-171A. Each practice receives a finding of MET or NOT MET. A score is calculated using the DoD Assessment Methodology: each practice is worth 1, 3, or 5 points; the maximum score is 110 and contracts specify the minimum required.
What the L1 self-assessment requires you to do
- Perform an annual self-assessment against the 17 L1 practices implementing FAR 52.204-21.
- Document evidence supporting each practice's MET status (or remediate to MET before affirming).
- Enter your score in SPRS.
- Have a senior company official sign the affirmation in SPRS asserting compliance.
- Maintain documentation supporting the assessment for the period required by your contract.
Important nuance: there is also a Level 2 Self-Assessment
The L2 Self-Assessment is a third path that confuses many contractors. It is a self-assessment against the full 110-practice NIST SP 800-171 standard, performed by the OSA, with the score and annual affirmation entered in SPRS. It applies when the CUI is in the NARA CUI Registry but not in the Defense OIG. It is not the same as L1 self-assessment, even though both are self-conducted. The C3PAO path is required only when the CUI is in the Defense OIG, as confirmed by the CMMC Level Determination guidance.