· CMMC  · 8 min read

CMMC Affirmation Requirements: The Senior Official's Annual Responsibility

CMMC puts a named executive on the record in SPRS each year, and after key assessment events, to affirm continuing implementation of all required security controls across the assessed scope.

CMMC puts a named executive on the record in SPRS each year, and after key assessment events, to affirm continuing implementation of all required security controls across the assessed scope.

CMMC puts a named executive on the record. 32 CFR 170.22 requires an Affirming Official from each Organization Seeking Assessment to submit electronic affirmations in SPRS that state the organization “has implemented and will maintain implementation of all applicable CMMC security requirements” for the assessed scope. That signature recurs each year and after specific assessment events.

Affirming Official defined in 32 CFR 170.22

32 CFR 170.22 defines the Affirming Official as the senior representative inside the Organization Seeking Assessment with authority to bind the company. The rule assigns this person responsibility for ensuring compliance with CMMC Program requirements and for affirming continuing compliance in SPRS. The affirmation must include the official’s name, title, and contact information, and the statement that the organization has implemented and will maintain implementation of all applicable requirements across in-scope information systems.

The designation applies to primes and subcontractors. DoD ties the program to contract performance through DFARS clauses and the CMMC Program rule, so every company that handles FCI or CUI under a contract with a CMMC obligation needs a named senior official who can stand behind the state of implementation.

Required affirmation cadence by CMMC level

The rule sets an event-driven cadence, then adds a recurring affirmation each year after the Final CMMC Status Date for the applicable level.

Level 1. After each Level 1 self-assessment, the Affirming Official submits an affirmation in SPRS that covers Level 1 requirements, then repeats the affirmation each year.

Level 2, self-assessment path. After the Level 2 self-assessment, the Affirming Official submits the affirmation, then repeats the affirmation each year after the Final CMMC Status Date. If the organization uses POA&Ms and performs a POA&M closeout self-assessment, the official submits another affirmation at that event.

Level 2, C3PAO certification path. After the Level 2 certification assessment, the Affirming Official submits the affirmation, then repeats the affirmation each year after the Final CMMC Status Date. If a POA&M closeout certification assessment occurs, the official submits another affirmation at that event.

Level 3. After the Level 3 certification assessment by DIBCAC, the Affirming Official submits the affirmation, then repeats the affirmation each year after the Final CMMC Status Date. If a POA&M closeout certification assessment occurs, the official submits another affirmation at that event.

The cadence makes the senior official accountable at the end of each assessment phase and throughout the cycle. The organization does not wait for the next external assessment to attest to the state of control implementation.

DFARS 252.204-7021 contract obligations

DFARS 252.204-7021 requires contractors to complete and maintain an affirmation in SPRS each year for the CMMC level required by the contract for each applicable information system. The clause extends this duty to subcontractors. A prime must ensure each covered subcontractor completes an affirmation before subcontract award, and that the subcontractor maintains that affirmation each year.

This clause sits alongside other DFARS obligations. DFARS 252.204-7012 still requires incident reporting to DoD and specific safeguarding practices for covered defense information. The senior official who signs the CMMC affirmation needs a view of that entire compliance picture. For context on 7012 scope and reporting, see DFARS 252.204-7012 requirements.

False Claims Act risk for the senior official

The affirmation is a formal representation to the U.S. government by a named executive. The text states that the organization “has implemented and will maintain implementation of all applicable CMMC security requirements” for the assessed scope. Government contractors face liability if they submit false representations. Industry legal analysis has highlighted potential False Claims Act exposure for inaccurate or misleading affirmations by an executive who knew, or should have known, that the attestation did not match the state of implementation.

You do not need a scare tactic to take this seriously. You need a governance system that gives the Affirming Official defensible evidence of control implementation, scoping, exceptions, and change decisions over time.

Governance practices that support the affirmation duty

The rule places a recurring signature on the executive calendar. The work under that signature sits in the control families that already govern continuous assessment, documentation, risk, and change. A practical program gives the official traceable proof for each control in scope and a record that shows how the team kept those controls in place between assessment events.

System security plan and scoping. Maintain a current system security plan per NIST SP 800-171 control CA.L2-3.12.4. Define system boundaries, data flows for FCI and CUI, enclave decisions, external services, and inherited controls. Make the plan the single source of truth for scope and implementation state. Build change control around it so the plan changes when the environment changes. For structure and content expectations, see System Security Plan for NIST 800-171.

POA&M strategy and closure. Use formal plans of action and milestones to capture deficiencies per CA.L2-3.12.2. Tie each action to a control requirement, assign ownership, define milestones, set due dates, and track risk acceptance decisions. When you close a POA&M item, capture evidence that shows the requirement now meets the objective. The rule requires a new affirmation after a POA&M closeout assessment, so keep closure packages organized. For mechanics and pitfalls, see POA&M management for CMMC.

Ongoing assessment and risk management. Run periodic control assessments per CA.L2-3.12.1 and risk reviews per RA.L2-3.11.1. Use sampling plans and objective evidence. Record results, corrective actions, and dates. Treat control health like any other operational metric that leaders review. The Affirming Official needs a current dashboard that shows the true state of implementation.

Configuration and asset discipline. Establish and maintain baseline configurations and inventories per CM.L2-3.4.1. Tie the inventory to the CUI boundary. Require change requests for deviations from baselines, with exception end dates and documented compensating controls. This gives the official confidence that the scope is controlled and that drift has a record.

Evidence management. Create evidence packages for key controls that the team refreshes on a defined cadence. Store attestable artifacts, not screenshots without provenance. Use control owners to certify that evidence still reflects reality on the ground. Include supplier evidence for inherited controls from cloud and managed service providers.

SPRS operations. Align compliance operations with SPRS mechanics. Maintain SPRS access in PIEE for the Affirming Official or a designated submitter under the official’s direction. Track each CMMC UID, its Final CMMC Status Date, and the next affirmation due date. Align self-assessment updates and affirmations so scores and attestations stay in sync. For background on reporting, score math, and SPRS entries for NIST SP 800-171, see SPRS scoring for NIST 800-171.

Subcontractor oversight. Flow DFARS 252.204-7021 to covered subcontractors. Collect each subcontractor’s CMMC UID and SPRS status. Require evidence that the subcontractor submitted an affirmation before award and each year. Update supplier risk records when a subcontractor’s affirmation lapses or a POA&M package affects delivery risk.

Executive sign-off cadence. Put the affirmation timeline on the corporate calendar. Tie it to internal reviews that walk the Affirming Official through scope, score changes, open POA&Ms, incidents, material system changes, and supplier status. The official needs time to ask hard questions before signing.

Microsoft cloud support for control implementation

Many defense contractors use Microsoft government clouds to meet technical and administrative control objectives. Microsoft 365 GCC High and Azure Government include capabilities that support implementation of controls aligned to CMMC and NIST SP 800-171 when configured to a documented standard. Microsoft states this support plainly and does not claim that its services confer CMMC status.

  • Microsoft 365 GCC High supports organizations that must meet CMMC Level 2 and Level 3 requirements, DFARS, FedRAMP High, and DISA CC SRG Impact Level 4 when configured to meet those obligations. Microsoft documents this in its government compliance materials.

  • Azure Government and related services describe how features map to CMMC-aligned controls. Microsoft positions this as support for implementation, not an authorization or certification.

Microsoft also publishes a Product Placemat for CMMC as an informational mapping resource. Treat it as guidance. It does not replace your own control implementation evidence, system security plan, or scoping decisions.

The Affirming Official should expect the team to produce tenant configuration standards, change records, audit outputs, and inherited control statements that tie Microsoft service features to specific CMMC and NIST SP 800-171 requirements. The official’s signature rests on that body of evidence, not on a vendor claim.

Practical takeaways for the senior official

Assign the role in writing to an executive with authority to bind the company. Give that person clear sightlines into scope, assessments, POA&Ms, supplier status, and incidents. Run a review before each affirmation event and each year after the Final CMMC Status Date. Keep the SPRS calendar current. Require objective evidence for every claim in the system security plan. Record each exception and the compensating control. Expect your team to keep the record straight between assessments, not only during the assessment window.

A repeatable process, solid documentation, and disciplined change management protect the company and the individual who signs. The rule asks for a name, a title, contact information, and a statement that the organization has implemented and will maintain implementation of required controls for the assessed scope. Treat that signature as an operational commitment you manage every day.

Sources

32 CFR 170.22 - Affirmation requirements and definition of Affirming Official (Office of the Federal Register, NARA)

DFARS 252.204-7021 - Contractor Compliance with CMMC Level Requirements (Acquisition.gov)

About the Cybersecurity Maturity Model Certification (CMMC) (DoD CIO)

NIST SP 800-171 Rev. 2 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (NIST)

Microsoft and the Cybersecurity Maturity Model Certification (CMMC) (Microsoft)

Azure compliance offering for CMMC (Microsoft)

Microsoft Product Placemat for CMMC - October 2024 update (Microsoft Tech Community)

Want a structured starting point?

Our 27-question CMMC technical readiness self-survey covers tenant, identity, endpoint, data protection, audit logging, documentation, and the 72-hour DFARS reporting plan. The score is produced in your browser from your answers alone. Nothing is verified or stored.

Back to Blog

Related Posts

View All Posts »