The CMMC Affirming Official Signs Alone: What That Signature Commits You To
Every CMMC status recorded in SPRS depends on one named person inside your company attesting that the organization meets its requirements and will keep meeting them. That person is the affirming official, and because the affirmation is a statement made to the federal government, the risk of it being wrong can land on that person, not only on the company.
In This Article
- What Is an Affirming Official Under the CMMC Rule?
- What Exactly Is the Affirming Official Attesting To, and When?
- Why Does the Affirmation Create Personal Exposure?
- Does a C3PAO Certification Take the Pressure Off the Affirming Official?
- How Should an Affirming Official Prepare Before Signing?
- Frequently Asked Questions
Recent coverage of Level 2 self-assessments, including PreVeil's walkthrough of submitting a self-assessment score to SPRS, focuses mostly on the score. Less attention goes to the signature that has to come with it. This post covers what the role is, what the affirmation says, when it is due, and why the person who signs should understand the evidence before signing.
What Is an Affirming Official Under the CMMC Rule?
The CMMC Program rule at 32 CFR Part 170 defines the affirming official as the senior level representative from within the Organization Seeking Assessment (OSA) who is responsible for making sure the OSA complies with CMMC Program requirements, and who has the authority to affirm the OSA's continuing compliance with the applicable security requirements.
Three parts of that definition are worth reading closely:
- “From within” the OSA. The affirming official has to be an internal representative. A consultant, an External Service Provider (ESP) or a C3PAO cannot fill the role for you.
- “Senior level.” The rule does not require a particular title. It does expect someone with enough organizational authority to direct resources and fix gaps. Assigning the role to whoever manages the IT tickets does not match the intent.
- “Continuing compliance.” The affirmation is about the organization's current and ongoing state, not a snapshot of assessment day.
What Exactly Is the Affirming Official Attesting To, and When?
Under 32 CFR 170.22, the affirming official attests in SPRS that the OSA has implemented, and will maintain, all applicable CMMC security requirements for the CMMC status being claimed. At Level 1 that means the 15 requirements drawn from FAR 52.204-21, such as AC.L1-b.1.i (limit system access to authorized users). At Level 2 it means the 110 requirements of NIST SP 800-171 Rev 2, such as AC.L2-3.1.1 (authorized access control) and IA.L2-3.5.3 (multifactor authentication).
The rule requires an affirmation at these points:
- When any assessment is completed. This covers Level 1 self-assessments, Level 2 self-assessments, Level 2 certification assessments and Level 3 certification assessments.
- Every year after that. The annual affirmation keeps a status current between assessments. This applies even at Level 2, where the assessment itself happens every three years.
- After a POA&M closeout assessment. When open items from a conditional status are closed and verified, the affirmation confirms the requirements are now met.
The forward-looking promise, “will maintain,” links directly to the assessment domain's own requirements. CA.L2-3.12.3 requires monitoring of security controls on an ongoing basis to confirm they remain effective. In practice, an affirming official who signs every year is relying on that monitoring actually taking place.
DFARS 252.204-7021 is the contract clause that makes these SPRS entries a condition of award and of continued performance where a solicitation specifies a CMMC status. How the rollout phases will be timed is not settled, so do not assume a date. The affirmation duty applies whenever a contract calls for a CMMC status.
Why Does the Affirmation Create Personal Exposure?
The CMMC rule does not create a new penalty that targets the affirming official. The exposure comes from existing federal law that applies to statements made to the government.
- The False Claims Act (31 U.S.C. 3729 to 3733). It imposes liability on “any person” who knowingly presents, or causes to be presented, a false claim, or who knowingly makes a false record or statement material to a claim. “Knowingly” is not limited to actual knowledge. It also covers deliberate ignorance and reckless disregard of the truth. An affirmation signed without looking at the evidence is exactly the kind of conduct those words describe.
- Qui tam provisions. Under the FCA, private individuals (often current or former employees) can file suit on the government's behalf. This means a false affirmation can be exposed from inside your own company.
- DOJ's Civil Cyber-Fraud Initiative. It was announced in October 2021 and explicitly targets contractors that knowingly misrepresent their cybersecurity practices. It has already produced cases built on NIST SP 800-171 implementation and SPRS scores, and those cases predate CMMC affirmations.
- 18 U.S.C. 1001. This criminal statute covers knowing and willful false statements to the executive branch. Commentators raise it in discussions of SPRS submissions. How it would apply to a particular CMMC affirmation has not been tested.
The unsettled question is how prosecutors and courts will treat individual affirming officials in particular. The FCA clearly reaches individuals, but there is no settled body of CMMC affirmation case law yet. The prudent reading: the signature names a specific person, the statement is material to contract eligibility, and the knowledge standard is broad enough to cover signing without checking. The specific legal risk to an individual is a question for your own counsel, not for a blog post.
Does a C3PAO Certification Take the Pressure Off the Affirming Official?
Only partly, and only for a limited time. A Level 2 certification assessment gives independent evidence that the requirements were met on the day of assessment. After that, the annual affirmations are made by your affirming official, not by the C3PAO.
Several gaps can open after a successful assessment:
- Scope drift. New systems, new locations or new CUI flows can pull assets into scope that were never assessed.
- Inherited controls. If an ESP or a cloud provider handles requirements for you, your affirmation still covers them. The customer responsibility matrix and the provider's evidence matter every year, not only during assessment.
- Control decay. Accounts pile up, logging lapses, configurations drift. Requirements such as AU.L2-3.3.1 (system auditing) and CM.L2-3.4.1 (system baselining) can fail quietly.
- Conditional status. A Level 2 conditional status allows limited POA&M items, and 32 CFR 170.21 requires them to be closed within 180 days. An affirming official should not sign a closeout affirmation until those items are actually verified as closed.
How Should an Affirming Official Prepare Before Signing?
The aim is to be able to explain, with evidence, why each affirmation is true. A defensible routine usually includes:
- Read the system security plan. CA.L2-3.12.4 requires one. It should describe the assessed boundary and how each requirement is met. If it does not match reality, the affirmation will not either.
- Review the most recent assessment results and the scoring. For a self-assessment, confirm the score was calculated according to the DoD Assessment Methodology and that “met” determinations are backed by objective evidence.
- Require a periodic control review. CA.L2-3.12.1 calls for periodic assessment of security controls. Ask for a written summary before each annual affirmation, not a verbal “we're good.”
- Check POA&M status against the rule. Confirm that any open items are ones the rule permits on a POA&M, and that closeout deadlines have not passed.
- Get ESP evidence in writing. For each inherited or shared requirement, keep the provider's attestation or evidence on file.
- Document what you reviewed. A dated record of what the affirming official examined, and who supplied it, shows diligence and makes the next year's review quicker.
- Know what to do if something is wrong. If you find that a prior affirmation was inaccurate, stop affirming and bring in counsel before deciding how to correct the record. The CMMC rule does not set a self-disclosure procedure, so this should not be improvised.
If you want to understand how a Level 2 self-assessment is scored and submitted, or need help building a system security plan that supports CA.L2-3.12.4, or want to know what the CMMC rule allows on a POA&M, those posts go deeper on each piece.
Been Named Your Company's Affirming Official?
Subscribe to CMMC Ready Now for weekly, control-level guidance on what you are signing and how to support it with evidence.
Book a Free Call with RickFrequently Asked Questions
Who can serve as the CMMC affirming official?
The affirming official must be a senior level representative from within the Organization Seeking Assessment, as defined in 32 CFR 170.4. The rule does not require a specific title, but the person needs authority to ensure compliance and to affirm continuing compliance. Outside consultants, ESPs and C3PAOs cannot serve in this role.
How often does the affirming official have to submit an affirmation?
Under 32 CFR 170.22, an affirmation is required when any CMMC assessment is completed, every year after that, and after a POA&M closeout assessment. At Level 2, this means annual affirmations continue between the triennial assessments. Affirmations are submitted in SPRS.
Is the affirming official personally liable if the affirmation is false?
The CMMC rule does not create a new personal penalty. However, the False Claims Act applies to “any person” who knowingly makes a false statement material to a claim, and “knowingly” includes reckless disregard. How courts will treat individual affirming officials specifically is not yet settled, so individuals should get advice from their own counsel.
Does passing a C3PAO assessment protect the affirming official?
A certification assessment independently confirms that requirements were met at the time of assessment. The annual affirmations after it are the organization's own statements, made by its affirming official. Scope changes, inherited controls and control drift after the assessment all fall on the person who signs.
What does the affirmation cover at Level 1 versus Level 2?
At Level 1, it covers the 15 basic safeguarding requirements from FAR 52.204-21, such as AC.L1-b.1.i. At Level 2, it covers the 110 requirements of NIST SP 800-171 Rev 2, such as AC.L2-3.1.1 and IA.L2-3.5.3. In both cases the official attests that the requirements are implemented and will be maintained.
What should an affirming official do if they discover a past affirmation was wrong?
Do not submit another affirmation until the gap is understood, and bring in legal counsel before deciding how to correct the record. The CMMC rule does not set out a self-disclosure procedure. Fixing the underlying control and documenting the fix are necessary, but they are not the only steps.
Sources
- 32 CFR Part 170, CMMC Program (definitions at 170.4, POA&M at 170.21, affirmations at 170.22) (ecfr.gov)
- 31 U.S.C. 3729, False Claims Act (law.cornell.edu)
- 18 U.S.C. 1001, False statements (law.cornell.edu)
- U.S. Department of Justice, announcement of the Civil Cyber-Fraud Initiative, October 2021 (justice.gov)
- NIST SP 800-171 Rev 2 (csrc.nist.gov)
- DoD CIO, CMMC program resources (dodcio.defense.gov)
- PreVeil, “CMMC Level 2 Self-Assessment in 2026” (preveil.com)
