Finishing the Assessment Isn’t the Same as Posting It
The certification requirement is under review. The expectation that you can show where you stand is not. This is the whole distance between doing the work and being able to prove you did it.
A prime asks for your SPRS score. Not eventually. This quarter, in a questionnaire or a portal field, with a due date on it.
It is a fair question, and it has a short answer. Either there is a current score posted under your CAGE code, or there is not.
That question did not go away in July. The Department of War suspended the Phase 2 certification requirement and put the program under review, and I understand why some people read that as the pressure coming off. What changed is who verifies the work. Self-assessment did not pause, and neither did the expectation that you can show where you stand.
So the question worth your attention right now is not when Phase 2 comes back. It is whether the work you have already done is visible to the people asking about it.
The gap between having a score and having a status
Picture a company that did the work. They ran the self-assessment against all 110 requirements, argued their way through the hard ones, wrote the system security plan, and built a plan of action for what was not finished. The number lives in a spreadsheet on the compliance lead’s desktop. Someone says we are a 92, and everyone believes it, because it is true.
Then the questionnaire arrives asking for the SPRS score and the date it was posted. Someone logs in to check and finds out nobody at the company has an account. The request for access has to be approved by whoever the System for Award Management lists as their Electronic Business point of contact, and that person left eighteen months ago. A five-minute answer is now a two-week problem, and the questionnaire is due Friday.
Nothing about that company’s security posture changed in the story. Their answer changed. That is the whole distance between doing the work and being able to prove you did it.
When I was the compliance lead, the pressure that actually moved us was not the federal rule. It was our customers asking questions we had to be able to answer. Our CIO never had to sell the program internally by pointing at a deadline. He could point at the questions already sitting in our inbox.
Posting is its own project
The score is something you determine. The status is something you publish.
Those are two different activities, and the second one is a project of its own. Until the assessment is posted, your customer has no way to see it, and neither does a contracting officer. The number in your spreadsheet is real to you and invisible to everyone else.
There is a requirement underneath the customer’s question, too, which is what makes this worth doing regardless of what the review decides. You are expected to be able to show a current self-assessment in SPRS. The status your prime is asking to see is the same one you already carry an obligation to maintain. One piece of work answers both.
The clause numbers around that obligation changed in 2026, which is one reason the current environment can feel confusing. Older and newer contracts may cite different DFARS clauses for the same underlying work. I would check the clauses in your actual contract rather than assuming the latest headline changed your obligation.
What posting actually involves
None of this is complicated. It is just unfamiliar the first time, and most of the delay is in one step people do not expect.
Get the access before you need it
SPRS lives inside the Procurement Integrated Enterprise Environment, and entering an assessment takes the SPRS Cyber Vendor User role tied to your CAGE code. Your request is approved by your company’s Contractor Account Administrator, usually whoever SAM lists as the Electronic Business point of contact, and then by the SPRS program office. SPRS says plainly that this can take multiple business days. Do not wait until a customer asks for the record to request access. Make sure the right people hold the Cyber Vendor User role before the assessment is ready to post.
Do the assessment outside the system
SPRS is a repository, not an assessment tool. You score yourself against the DoW Assessment Methodology, and the methodology expects a system security plan plus a plan of action for every requirement you have not implemented. Without those, the number does not mean much.
Know what the form is going to ask you for
The assessment date, the standard, the confidence level, your score, a plan of action completion date if you are below 110, and your system security plan’s name, version, and date. Basic is the only confidence level a company can select for itself. Medium and High are government-conducted.
Know who affirms, and know it is not automatically the person typing
Entering an assessment and affirming it are two different acts. The Cyber Vendor User role gets the record into SPRS. The affirmation is made by your Affirming Official, the senior representative responsible for the organization’s compliance, and holding the Cyber Vendor User role does not make someone the Affirming Official. Decide who that person is before the record is sitting there waiting on them.
Decide which CAGE codes the assessment actually covers
The hierarchy is pulled from your SAM registration, and only the entities you include are covered by what you post. For a company with subsidiaries or divisions, this is a scoping decision, not a data-entry one, and it is worth a real conversation before anyone clicks save.
Put both clocks on a calendar
There are two, and they are not the same thing. How often you conduct a new self-assessment depends on your level: annually at Level 1, and every three years at Level 2. The affirmation runs on its own schedule, and at Level 2 it happens at the time of the assessment and annually after that. Confirm which level your contract requires, then put both dates on a calendar. Drift between what you posted and what is true is the thing you are managing.
That last one is where the affirmation earns its weight, and it is worth being plain about. An accurate 70 tells the government and your customers where you actually stand. An unsupported 110 creates a representation you may not be able to defend. When I was responsible for this inside a defense contractor, the question that mattered was not whether we believed our score was accurate. It was whether we could support it when someone outside the company asked.
A new stop every Tuesday and Thursday.
Our twice-weekly series breaking CMMC down one step at a time. Opt in and we’ll send each one to your inbox.
This is more within reach than it feels
When a prime asks about your cybersecurity status, remember what they are trying to understand: risk. Can they depend on you? Do you know where you stand? Do you have a plan for what is not finished yet?
This is where people can get discouraged. They treat every questionnaire like a pass-or-fail test. In my experience it is usually the start of a conversation. Customers know their suppliers are at different stages. What is harder to work with is uncertainty.
A current, honest score gives them something to work with. It will not guarantee the work, but it is a much stronger position than guessing, overstating, or avoiding the conversation. And posting a score costs an account and an afternoon, not a budget cycle.
What I’d do if I were in your seat
Find out what SPRS says about you today
Not what you believe it says. If nobody at your company can log in and look, that is your first project, not your last one.
Confirm who your Electronic Business point of contact is in SAM
This is the step that stalls people, and it is easy to fix while nothing is urgent. While you are in there, make sure a second person is named, so one departure does not lock you out.
Compare what is posted to how you actually operate
If the score is old, or it describes a network you have since changed, fix that before you answer anyone. An inaccurate posting is worse than a low one.
Write one short status you can hand any customer
Your score and the date it was posted, your SSP, your plan and dates, and who owns it. One source of truth you can translate into any prime’s format instead of rebuilding it five times.
Where this leaves you
The certification model is under review. The expectation that you can say where you stand is not. The encouraging part is that these are not two separate projects competing for the same budget. Posting an accurate score answers your customer’s question and satisfies a requirement you already carry.
So here is the question worth sitting with, and it is worth asking out loud in your next leadership meeting.
If a prime pulled our SPRS record this afternoon, what would they see, and when was it last true? If nobody in the room knows, that is not a failure. It is just the next thing to go do.
CMMC: Everything You Need to Know to Get Started (6th Edition)
Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.
A few sources
- SPRS assessment entry, vendor access, and Affirming Official guidance: the PIEE registration and Cyber Vendor User role, who approves access, the fields the entry form requires, and who affirms the record.
- 32 CFR 170.15 and 170.16: the self-assessment and affirmation requirements at Level 1 and Level 2, including how often each is required.
- DoD Class Deviation 2026-O0025 (Revolutionary FAR Overhaul, DFARS Part 240), effective February 1, 2026 and revised July 16, 2026, with Class Deviation 2024-O0013, alongside the U.S. Department of War CMMC Phase II suspension announcement (July 13, 2026): the clause renumbering, the standard you assess against, and what was suspended.