Updated September 29, 2026
A reminder from DoD lands in the owner's inbox, and the question comes down the hall: what exactly am I signing? The owner or president usually signs. They are telling the federal government, under their own name, that the systems you assessed still meet every security requirement today. Your MSP (managed service provider, the outside IT firm) can prepare the paperwork. Only someone inside your company can sign it.
That signature carries real weight. The Justice Department uses the False Claims Act against contractors that say they meet these requirements when they don't (DOJ Civil Cyber-Fraud Initiative). In July 2025, a California defense contractor and its private-equity owner paid $1.75 million to settle claims that it hadn't implemented required NIST SP 800-171 controls on an Air Force contract (DOJ). An affirmation is exactly the kind of statement those cases are built on.
What the affirmation is
CMMC is DoD's program for checking that its suppliers protect sensitive defense information. At Level 2, that means 110 security requirements, from multi-factor login to backups to visitor logs. The signer the rule calls the Affirming Official is "the senior level representative" responsible for your company's compliance (32 CFR 170.4). They log in to SPRS, DoD's supplier-risk website, and confirm that the requirements are still in place.
The rule (32 CFR 170.22) asks for an affirmation at four moments. The first is when you reach Conditional status, which means you passed with a few items still open. The second is when you reach Final status. The third is when you close out your POA&M (plan of action and milestones: your written list of unfinished fixes and their due dates). After that, it's every year from the Final status date. The full Level 2 self-assessment repeats every three years.
For whoever enters it: in SPRS, the person who entered the assessment clicks Transfer to AO; the official reviews it, certifies the affirmation statement, and clicks Affirm (SPRS quick-entry guide). The official needs their own PIEE account, the DoD login that SPRS sits behind.
The memo to hand them first
The first affirmation comes right after an assessment, so everything is fresh. The yearly ones are harder, because the question becomes what changed while nobody was looking. We have the IT lead or MSP write the official a one-page memo about two weeks before the date. This is the one we use. The technical lines are for your IT person to fill in; the owner only has to read the answers.
To: [Affirming Official] Re: CMMC Level 2 annual affirmation, due [date]
What you're affirming. Environment [Engineering E-04], CAGE codes [x, y], assessed [date], SPRS record [ID]. All 110 requirements were MET at that assessment. Evidence index: [location].
What changed since the last affirmation.
- [Change]. Effect: [none, and why / records updated on (date) / open, see below].
- …
What kept running. Access reviews: [dates]. Log reviews: [cadence, last date]. Backups and restore test: [last date]. Patching: [last cycle]. Vulnerability scans (3.11.2): [last date].
Open items. [None / item, owner, date it will be fixed, and whether it affects status].
Recommendation. [Affirm / hold until (item) is fixed]. Prepared by [name], [date].
(A CAGE code is the five-character ID DoD assigns each of your business locations. The evidence index is the list of where each piece of proof lives.)
The changes section is the real work
Say you switched backup providers in April. Before that line can read "records updated," someone has to answer four questions. Does the new provider hold CUI (controlled unclassified information: the drawings, specs, and technical data the government marks as sensitive)? If it does, is it FedRAMP Moderate or equivalent, the government cloud-security standard that DFARS 252.204-7012 requires for any cloud holding CUI? Who does what under the new contract? Are there backup and restore records since the switch? And do your scope statement, your System Security Plan (the SSP, the document describing your systems), and your asset inventory name the new provider?
Four yeses and the change is closed. One no, and it goes under open items with a name next to it. When a vendor change means reassessment →
Our position: the official holds the affirmation until the open items are fixed. They don't sign with a note. The statement in SPRS has no box for "mostly." If something turns out to be unsupportable, deal with that first.
Keep the trail
Keep the memo, the questions the official asked, the answers, and the date they clicked Affirm. Next year's official, or an assessor, should be able to see what was affirmed and why it was true that day. A signed PDF that says "we remain compliant" doesn't show either.
DoD's own cost model puts each annual affirmation at $1,459 of staff time. That holds when the records were kept current all year. It doesn't when someone spends the week before the deadline rebuilding them.
If you haven't named your Affirming Official yet, name them this week and get them a PIEE account. Then put the affirmation date on their calendar, with the memo due two weeks before it.
