Back to Knowledge Center
Planning5 min read
After Certification: Maintaining CMMC Compliance
Getting certified is not the finish line. Annual affirmations, triennial reassessments, continuous monitoring, and incident response readiness are all ongoing obligations.
CMMC certification is a point-in-time event with ongoing obligations. Too many contractors treat the certificate as a three-year pass and move on — only to discover that their posture has degraded when the next C3PAO assessment reveals it.
Annual affirmation requirement
Every year after initial certification, a senior official must affirm to the DoD that the organization's CMMC compliance remains accurate. Before signing, verify:
- ✓All controls are still implemented as described in the SSP
- ✓No new systems have been added to the CUI boundary without SSP updates
- ✓Training was completed for all staff in the past 12 months
- ✓Open POA&M items have been closed or updated with current progress
Continuous monitoring obligations
- ✓SI.L2-3.14.3 (Security alerts): receive alerts and advisories and act on them
- ✓AU.L2-3.3.5 (Audit log review): review audit logs regularly for anomalous activity
- ✓RA.L2-3.11.2 (Vulnerability scans): scan for vulnerabilities periodically and remediate based on risk
- ✓CM.L2-3.4.8 (User-installed software): continuously enforce restrictions on unauthorized software
The three-year reset
Mark your reassessment date on your strategic calendar on day one. Reassessment preparation should begin no later than 6 months before expiration — meaning start at month 30 of your 36-month certification window.
Ready to start your CMMC journey?
Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.
More in Planning
