Inside the Audit: How the CMMC Self-Assessment is Like a Tax Return

|By Michael Diab

All of us have completed (or have been responsible for the completion of) a tax return. There are multiple ways to get it done. You can either file the return yourself or you can hand it to an accountant who signs off that it's correct. Either way, your return is due. In both cases, someone has to stand behind the numbers. A Cybersecurity Maturity Model Certification (CMMC) Level 2 self-assessment works the same way, and the path you pick decides who owns the risk when the government reviews what you filed.

Key Takeaways

  • Filing a CMMC self-assessment is like doing your own taxes. You can do it alone or bring in help, but the return has your name on it either way, and you're the one who answers for it.
  • An experienced partner is the accountant in that analogy. They help you get to an accurate 110 and give you confidence the number holds up, but they don't take the risk off you.
  • The third-party certification requirement is suspended with no return date. All 110 NIST 800-171 controls still apply.
  • Every control needs its own proof, technical or physical, and two documents that can help you stay on track is a System Security Plan showing how you meet each control and a POA&Ms list tracking your gaps.
  • Access Control can be a challenging area to score since it's the largest domain in CMMC 2.0.
  • When you outsource your IT, the government still holds you responsible, not your vendor, so choose a partner you'd trust with that risk.

How Do You Lower Your Risk on a CMMC Self-Assessment?

Your self-assessment is built on the NIST 800-171 controls. Your organization scores itself against all 110 of them, and a full score of 110 means every control is met. That's the number you sign your name to.

One of the best ways to lower your score is to bring in a partner who's worked with GovCons before and understands what success looks like. Here’s why it’s smart to bring in a qualified, expert partner to guide you through the process:

  • When you bring in a partner to help with your self-assessment, what you're getting is more confidence that the number you signed is accurate.
  • A qualified partner knows what true compliance looks like. When you share your assessment, you're telling the federal government you meet all 110 controls, and a partner who knows this work makes sure that's true before you put your name on it.
  • Consider your taxes. File your own return and you're on your own if something's wrong. Hire an accountant and you get someone who makes sure it's right the first time and gives you some peace of mind that it'll hold up. The same idea holds true for the self-assessment. A good partner helps you meet the controls, get your evidence together, and report a score you can back up.

This is why the partner you choose matters so much. Ultimately, the government still looks at you, not the vendor you brought in, so you want a partner who treats getting you to an accurate 110 as their job to own.

How Did the CMMC Third-Party Certification Suspension Change the November 10th Deadline?

On July 13, 2026, the government suspended the Phase II requirement that would have forced contractors to get certified by a C3PAO, an independent assessor who reviews your work and certifies it to the government. Here’s what to know:

  • That certification had been scheduled to become mandatory on November 10, 2026. It's now paused with no set date to return, and a reform task force is reviewing the whole program, with its findings expected around September.
  • For now, the Level 2 self-assessment you post yourself is how you show the government you're compliant. Your duty to meet the controls are still in place.
  • The government still expects all 110 controls in place and your contract holds you to them no matter what the Pentagon announced.

What Evidence Do You Need for CMMC 800-171 Controls?

When you’re filling out your tax return, you need proof to show the government – W2’s, receipts, and other documentation. Your self-assessment has a similar requirement.

Having the ability to show your work is the key to a self-assessment, and the standard is demanding. Every one of the 110 controls needs its own proof. That applies whether the control is technical or physical.

Some are physical in a literal sense, like visitors signing a log and wearing badges, or CUI kept in a locked cabinet. When an assessor is in your building, they expect to see proof for all of it. Policies count as evidence too, and you have to show that your people follow them in day-to-day practice. Every control is meant to be checked and enforced on a regular basis, and that’s the part some GovCons struggle with.

Two examples of documents required for every self-assessment that will help demonstrate how well you’re meeting controls include:

  • Your System Security Plan. It often runs past a hundred pages, walking through each control and explaining how you meet it.
  • Your Plan of Action and Milestones (POA&Ms), where you record your gaps. Any control you haven't fully closed shows up there. By the time you reach a score of 110, that list should be empty, because a 110 means you're attesting that nothing is left open.

Please note this is not an exhaustive list of all documentation you'll need, just a solid starting point.

How Do You Keep a CMMC Self-Assessment Honest Without a C3PAO?

One of the most challenging aspects of a self-assessment is that no impartial auditor sits across the table to hold you to a standard. Here’s how you can keep your assessment accurate, and more likely to help you know where you really stand:

  • Have an experienced partner on your side. Like heading into tax season with an experienced accountant well-versed in tax law, someone who has worked these controls for years brings a level of discipline that's hard to build on your own.
  • Have a place where you can keep your documentation and other proof organized. When tax time comes around, you want your documents in order. Being organized before your self-assessment is no different. It requires discipline and planning. For Ntiva, much of that discipline comes from the GRC platform we run everything through. It tracks the full compliance journey and stores the evidence and policies behind every control in one place, along with the supporting artifacts. When you need to produce proof, you export it straight from the portal. Working that way keeps you far more organized than trying to manage a hundred-plus controls by hand.
  • Understand the risks of your self-assessment. When you self-attest, all of the risk stays with you, so when choosing a partner you want someone with a real stake in getting you to 110.

What catches people off guard is what happens once you outsource. Say you're the organization seeking certification, and you bring in a partner to run your IT. The federal government doesn't care who you handed the work to. They keep their attention on you: the organization that made the claim. They won't go chasing the vendors you paid to handle pieces of your compliance.

You're the risk owner they're watching, and that's the whole reason the partner you choose has to be someone you'd trust with that responsibility.

If you're heading into your first self-assessment and want a clear answer on where you stand, our team can help. Talk to us to learn more about how Ntiva supports government contractors with CMMC compliance.  

Back to blog

About the author

Michael Diab

Michael Diab is Ntiva's Director of Regulatory & Compliance, where he supports the company's GovCon practice and its CMMC readiness and compliance-as-a-service work for regulated clients. He’s helped take Ntiva through its own CMMC Level 2 certification via an accredited C3PAO and advises defense contractors from firsthand, auditor-tested experience.

18-ContentGroup

Explore Our Latest
Resources and Articles

08-FeaturedBlogPosts