How the self-assessment works
A CMMC L2 self-assessment is only permitted for a limited set of CUI programs — most CUI-carrying contracts require a C3PAO third-party assessment. But every organization should run an internal self-assessment first: it produces your SPRS score, drives your SSP, and tells you whether you're ready to invite a C3PAO.
The workflow, at a glance:
- Scope — identify which assets store, process, or transmit CUI. Wrong scope = wrong score.
- Assess every objective in each of the 110 requirements against NIST 800-171A. All-or-nothing per control.
- Score — start at 110, subtract 1/3/5 points per unmet control (DoD Assessment Methodology weights).
- POA&M the gaps you can close in 180 days (score must be ≥ 88 and control must be POA&M-eligible).
- Submit the score, scope, and assessment date to SPRS with an affirming-official attestation.
Doing this by hand takes days.
Athena runs the same 110-control assessment in ~60 seconds and shows you exactly where the deductions land. Free — no signup.
Start the free Quick ScoreThe 14 domains — 110 controls total
| Code | Domain | Controls | What it covers |
|---|---|---|---|
| AC | Access Control | 22 | Least privilege, session control, remote access, external systems. |
| AT | Awareness & Training | 3 | Security awareness for users and privileged roles. |
| AU | Audit & Accountability | 9 | Logging, review, protection, and retention of audit records. |
| CM | Configuration Management | 9 | Baselines, change control, least functionality, USB/software allow-lists. |
| IA | Identification & Authentication | 11 | Unique IDs, MFA, password complexity, credential management. |
| IR | Incident Response | 3 | IR plan, handling, reporting, and testing. |
| MA | Maintenance | 6 | Controlled maintenance, media sanitization, remote maintenance MFA. |
| MP | Media Protection | 9 | Marking, storage, transport, and sanitization of media and CUI. |
| PS | Personnel Security | 2 | Screening and termination/transfer procedures. |
| PE | Physical Protection | 6 | Facility access, visitor logs, alternate sites, monitoring. |
| RA | Risk Assessment | 3 | Risk assessments and vulnerability scanning cadence. |
| CA | Security Assessment | 4 | SSP, control assessment, POA&M, continuous monitoring. |
| SC | System & Communications Protection | 16 | Boundary protection, FIPS crypto, session termination, DNS. |
| SI | System & Information Integrity | 7 | Flaw remediation, malicious code protection, monitoring, alerts. |
| — | Total | 110 |
How SPRS scoring works, in one paragraph
You start at 110. Each of the 110 requirements is worth 1, 3, or 5 points, weighted by risk under the DoD Assessment Methodology. Scoring is all-or-nothing per control — miss one objective (per NIST 800-171A) and you lose the full point value. The lowest possible score is -203. A Final CMMC L2 status requires 110 with all controls met; Conditional is available at 88–109 with a valid POA&M closed within 180 days; below 88 there is no CMMC status.
Full walkthrough with worked examples: how to calculate your SPRS score.
Checklist structure — how to run it by domain
For each of the 14 domains, do the same four passes:
- Read every requirement's objectives in NIST 800-171A. This is what an assessor grades against — not the requirement summary.
- Ask "who does this, on what asset, and how do I know?" — the answer is the evidence.
- Mark met / not met per objective. If any objective is not met, the whole control is not met.
- Capture the evidence artifact (policy, config export, log sample, screenshot) with the date and the person who produced it.
For domain-specific evidence examples, see the Athena CMMC control evidence library, which has per-control pages for the highest-weighted requirements (3.1.1 access control, 3.5.3 MFA, 3.13.11 FIPS encryption, and more).
Run all 110 automatically.
Get an evidence-backed SPRS score projection in 60 seconds — free, no signup, no credit card.
- All 110 controls
- SPRS score projection
- No signup required