Technology Guidance for Business Leaders | Ntiva Blog

Inside the Audit: Treat the CMMC Self-Assessment as Your Cyber Checkup

Written by Shon Lyublanovits | Aug 10, 2026, 2:58:33 PM

This is the first edition of Inside the Audit, our new series for government contractors working to stay compliant with CMMC and federal cybersecurity requirements. Each one brings in an Ntiva expert to break down a piece of the process in plain terms.

If you’ve ever gone to the doctor for a checkup or an annual physical, you know how it works. You try to take care of yourself all year, then you sit down with a doctor who checks whether you are actually as healthy as you think you are. You get a diagnosis, and usually a few things to work on before the next visit.

A Cybersecurity Maturity Model Certification (CMMC) Level 2 self-assessment is your cyber checkup. It is the moment you take an honest look at your security program and confirm that it is doing what you believe it is doing. Like a physical, it only helps you if you take it seriously and act on what it tells you.

With third-party certification paused right now, a lot of contractors are asking whether the checkup still matters. It absolutely does. Let me walk you through why, and how to approach it.

Key Takeaways

  • A Level 2 self-assessment measures how mature your security program is, not whether you filled out a form. It looks at your governance and policies, whether your technology is current, and whether your people can explain how you protect your environment.
  • The pause applies only to third-party certification. Your obligation under the FAR and DFARS to safeguard CUI has not changed, so the smart move is to keep strengthening your program now.
  • Every control has to be backed by real, observable evidence. If you cannot log in and show a control working the way your policy describes, you can’t claim it.
  • Assessing risks is the hardest part to get right, because risks keep evolving. Keeping it front and center is what keeps you thinking ahead.
  • Your System Security Plan is your blueprint and your POA&M is your get-well plan. Together they show where you stand and what you still need to fix.
  • Staying compliant is ongoing work between assessments. Continuous monitoring, risk reviews, and tabletop exercises keep you ready, and the right partner adds depth.

What Does a CMMC Level 2 Self-Assessment Actually Measure?

At the simplest level, a Level 2 self-assessment is where you score your organization against the 110 security controls in NIST SP 800-171. While your score itself is important, what you’re actually measuring is how mature your security program has become.

That shows up in a few places. Your governance and policies need to be written down and actually followed. Your technology needs to be in place and current. And you need people who can speak to how you protect your environment, because a strong policy means very little if no one on your team can explain how it works in practice.

Underneath all of it is operational evidence. It is not enough to say you have a firewall. Can you prove it is there and that it protects you from what it is supposed to? A good checkup relies on real results, not on what the patient says they have been doing.

Is CMMC Certification Still Required During the Assessment Pause?

This is the part causing confusion right now. The government has suspended the requirement to bring in a third-party assessor, and some contractors have taken that to mean the whole thing went away. But it didn’t.

Your obligation under the FAR and DFARS to safeguard controlled unclassified information is still fully in force. What is in flux is what the official stamp of approval will look like and what it will cost to get there. Skipping the appointment does not make the underlying need disappear.

With that in mind, the suspension is actually a healthy move. Cost has always been one of the hardest parts of CMMC, and even after the program was scaled back, there was not enough consideration for small businesses that would have to spend real money simply to get assessed. Taking a beat to ask whether that burden is set at the right level is a fair thing for the federal government to do.

But the worst thing you can do with the extra time is nothing. Keep strengthening your policies and your understanding of what actually happens inside your organization, so that when the requirement returns you’re ready instead of scrambling.

How to Prove CMMC Compliance: The PROVE Framework

When it comes to your health, a doctor doesn’t simply take your word for it. They run the labs. Your self-assessment works the same way, and I use a simple acronym to keep it straight: PROVE.

  • P - Policy. What you have committed to in your governance.
  • R - Reality. The control you actually run, not the one you meant to set up.
  • O - Objective evidence. Proof that what your policy says is really happening.
  • V - Validation. People who can speak to how the control works, like your administrators and security officers.
  • E - Evaluation. A judgment on whether your evidence supports a control that is genuinely in place. This is the step where a third-party assessor normally comes in.

Every CMMC practice must be proven. If you take away one thing, take that. Real evidence is something you can observe. With access control, for example, you should be able to log into a system and see the password rules and screen locks set the way your policy describes. If you can’t show it, you can’t claim it.

What Is the Hardest CMMC Control to Implement?

People ask which of the 110 controls are hardest. You could point to the technical ones because of how much work they take to implement. For me, the hardest is risk assessment, and it is hard for the same reason your health doesn’t remain fixed in place. You can’t assess risk today the same way you did yesterday. Conditions and circumstances change and evolve as time goes on. From a cybersecurity standpoint, that means new threats are emerging all the time.

Risk also forces uncomfortable tradeoffs. Do you spend money upgrading your servers, or on insider-threat training for your staff? Those questions are easy to put off when everything feels fine. Keeping risk assessment at the front of your mind is what keeps an organization thinking ahead rather than reacting after something goes wrong.

SSP vs. POA&M: What's the Difference?

Two documents do a lot of the work in a self-assessment. Your System Security Plan (SSP) is your blueprint. Picture the blueprint for a house. It describes your architecture in writing and shows how your systems connect to one another and where your boundaries sit. It’s the full picture of your environment, the same way your medical chart is the full picture of you.

Your Plan of Action and Milestones (POA&M) is your get-well plan. Anything you still need to improve becomes an item on it, along with how you intend to address it. It is the honest list of what to work on before the next visit.

How to Maintain CMMC Compliance Between Assessments

The real work of staying healthy happens between doctor’s appointments, and the same is true here. Once you are compliant, NIST SP 800-171 becomes your guide for staying that way. Think of it as the navigation that keeps you on the right path. That means continuous monitoring to sustain compliance and regular reviews of your risk. It also means running tabletop exercises so your team has practiced for an incident before one actually happens.

The way you maintain rigor without an assessor in the room comes down to one word: habit. Security has to be built into how you work day to day, not something you dust off once a year. That includes the unglamorous work of getting your leadership aligned with that mission, because reaching certification and sustaining it takes both people and funding, and someone has to make that case to the board.

This is also where the right partner helps. A knowledgeable partner adds depth to your team and gives you access to people who understand what you are trying to accomplish, so the right expertise is in place and the work gets done with confidence. It is a lot like having a doctor you trust rather than trying to diagnose yourself.

Why Your CMMC Self-Assessment Only Works If You Act on It

Come back to the physical one more time. You can go through all the motions, but none of it does you any good unless you act on what you learn. A self-assessment is the same. The diagnosis is only useful if it changes what you do next.

Plenty of people can hand you a list of controls. What matters more is understanding why having a certification protects your organization and your mission, and finding ways to make these requirements workable for a small or midsize business.

Treat your Level 2 self-assessment like a checkup you actually intend to act on, and it stops being a box to check. It becomes the thing that keeps your organization healthy.

Wondering where your Level 2 self-assessment stands? Talk to us to learn more about how Ntiva supports government contractors with CMMC compliance.