This is the first edition of Inside the Audit, our new series for government contractors working to stay compliant with CMMC and federal cybersecurity requirements. Each one brings in an Ntiva expert to break down a piece of the process in plain terms.
If you’ve ever gone to the doctor for a checkup or an annual physical, you know how it works. You try to take care of yourself all year, then you sit down with a doctor who checks whether you are actually as healthy as you think you are. You get a diagnosis, and usually a few things to work on before the next visit.
A Cybersecurity Maturity Model Certification (CMMC) Level 2 self-assessment is your cyber checkup. It is the moment you take an honest look at your security program and confirm that it is doing what you believe it is doing. Like a physical, it only helps you if you take it seriously and act on what it tells you.
With third-party certification paused right now, a lot of contractors are asking whether the checkup still matters. It absolutely does. Let me walk you through why, and how to approach it.
At the simplest level, a Level 2 self-assessment is where you score your organization against the 110 security controls in NIST SP 800-171. While your score itself is important, what you’re actually measuring is how mature your security program has become.
That shows up in a few places. Your governance and policies need to be written down and actually followed. Your technology needs to be in place and current. And you need people who can speak to how you protect your environment, because a strong policy means very little if no one on your team can explain how it works in practice.
Underneath all of it is operational evidence. It is not enough to say you have a firewall. Can you prove it is there and that it protects you from what it is supposed to? A good checkup relies on real results, not on what the patient says they have been doing.
This is the part causing confusion right now. The government has suspended the requirement to bring in a third-party assessor, and some contractors have taken that to mean the whole thing went away. But it didn’t.
Your obligation under the FAR and DFARS to safeguard controlled unclassified information is still fully in force. What is in flux is what the official stamp of approval will look like and what it will cost to get there. Skipping the appointment does not make the underlying need disappear.
With that in mind, the suspension is actually a healthy move. Cost has always been one of the hardest parts of CMMC, and even after the program was scaled back, there was not enough consideration for small businesses that would have to spend real money simply to get assessed. Taking a beat to ask whether that burden is set at the right level is a fair thing for the federal government to do.
But the worst thing you can do with the extra time is nothing. Keep strengthening your policies and your understanding of what actually happens inside your organization, so that when the requirement returns you’re ready instead of scrambling.
When it comes to your health, a doctor doesn’t simply take your word for it. They run the labs. Your self-assessment works the same way, and I use a simple acronym to keep it straight: PROVE.
Every CMMC practice must be proven. If you take away one thing, take that. Real evidence is something you can observe. With access control, for example, you should be able to log into a system and see the password rules and screen locks set the way your policy describes. If you can’t show it, you can’t claim it.
People ask which of the 110 controls are hardest. You could point to the technical ones because of how much work they take to implement. For me, the hardest is risk assessment, and it is hard for the same reason your health doesn’t remain fixed in place. You can’t assess risk today the same way you did yesterday. Conditions and circumstances change and evolve as time goes on. From a cybersecurity standpoint, that means new threats are emerging all the time.
Risk also forces uncomfortable tradeoffs. Do you spend money upgrading your servers, or on insider-threat training for your staff? Those questions are easy to put off when everything feels fine. Keeping risk assessment at the front of your mind is what keeps an organization thinking ahead rather than reacting after something goes wrong.
Two documents do a lot of the work in a self-assessment. Your System Security Plan (SSP) is your blueprint. Picture the blueprint for a house. It describes your architecture in writing and shows how your systems connect to one another and where your boundaries sit. It’s the full picture of your environment, the same way your medical chart is the full picture of you.
Your Plan of Action and Milestones (POA&M) is your get-well plan. Anything you still need to improve becomes an item on it, along with how you intend to address it. It is the honest list of what to work on before the next visit.
The real work of staying healthy happens between doctor’s appointments, and the same is true here. Once you are compliant, NIST SP 800-171 becomes your guide for staying that way. Think of it as the navigation that keeps you on the right path. That means continuous monitoring to sustain compliance and regular reviews of your risk. It also means running tabletop exercises so your team has practiced for an incident before one actually happens.
The way you maintain rigor without an assessor in the room comes down to one word: habit. Security has to be built into how you work day to day, not something you dust off once a year. That includes the unglamorous work of getting your leadership aligned with that mission, because reaching certification and sustaining it takes both people and funding, and someone has to make that case to the board.
This is also where the right partner helps. A knowledgeable partner adds depth to your team and gives you access to people who understand what you are trying to accomplish, so the right expertise is in place and the work gets done with confidence. It is a lot like having a doctor you trust rather than trying to diagnose yourself.
Come back to the physical one more time. You can go through all the motions, but none of it does you any good unless you act on what you learn. A self-assessment is the same. The diagnosis is only useful if it changes what you do next.
Plenty of people can hand you a list of controls. What matters more is understanding why having a certification protects your organization and your mission, and finding ways to make these requirements workable for a small or midsize business.
Treat your Level 2 self-assessment like a checkup you actually intend to act on, and it stops being a box to check. It becomes the thing that keeps your organization healthy.
Wondering where your Level 2 self-assessment stands? Talk to us to learn more about how Ntiva supports government contractors with CMMC compliance.