APTSecurity Management

How CMMC Level 1 Self-Attestation Works

Cody D. Martin//Updated August 9, 2026

Level 1 self attestation means assessing your own compliance against 15 basic safeguarding requirements, posting the result in SPRS, and having a senior company official affirm it annually. The signature carries False Claims Act exposure, which is why the assessment should be honest.

Self attestation sounds like the easy path, and administratively it is. There is no assessor, no scheduling, no fee.

What it is not is informal. A senior company official signs a statement, in a federal system, that specific security requirements are in place. That signature is the reason to take the assessment seriously.

The mechanics

  1. Assess yourself against the 15 requirements in FAR 52.204-21
  2. Record the result, including anything not met
  3. Post your score in the Supplier Performance Risk System
  4. A senior company official affirms it
  5. Repeat annually

There is no submission of evidence. Nobody reviews your answers unless something prompts them to.

What the signature carries

An affirmation of compliance is a representation to the government. If it is inaccurate, the exposure runs through the False Claims Act, which carries treble damages, and the Department of Justice has an active Civil Cyber Fraud Initiative built specifically around cybersecurity misrepresentations in federal contracts.

Settlements in this space have involved companies that claimed controls they did not have. Not sophisticated fraud. Optimiztic answers on a form.

The practical consequence: assess honestly, and where something is not in place, say so. An accurate score with gaps is a compliance position. An inflated one is a liability with your name on it.

Who counts as a senior official

Someone with authority to bind the company. An owner, an officer, or a director level manager with delegated authority. Not the IT contractor, and not an administrator who happened to be the one filling in the form.

The person signing should understand what they are signing, which means the assessment work and the signature usually need a conversation between them.

What to keep

Nothing is submitted, and that is exactly why records matter. If the question is ever asked, the difference between a defensible position and a bad afternoon is whether you can show your working.

Keep:

  • The assessment itself, showing each requirement and your determination
  • Evidence for anything you claimed: configuration screenshots, policy documents, the account review you ran
  • The date, and who did it
  • Anything remediated during the assessment, with dates

A simple spreadsheet with a row per requirement and a link to evidence is sufficient. It does not need to be elaborate. It needs to exist.

The annual part

Affirmation is annual, and this is where companies drift. The first assessment is done carefully. The second year it is re affirmed without anyone re checking, and by year three the environment has changed enough that the original assessment describes a system you no longer run.

Put it in a calendar with the person who signs it, and spend an afternoon on it rather than five minutes.

After the July 2026 suspension

Unchanged. The suspension paused Level 2 third party assessment and Level 3. Level 1 self assessment and the annual affirmation were never part of what was paused, and remain required under DFARS 252.204-7021.

If anything, Level 1 obligations are the clearest part of the current picture.

  • CMMC
  • SPRS
  • self assessment
  • Level 1
  • False Claims Act

More on compliance