CMMC Ready Now
Back to Knowledge Center
Planning5 min read

After Certification: Maintaining CMMC Compliance

Getting certified is not the finish line. Annual affirmations, triennial reassessments, continuous monitoring, and incident response readiness are all ongoing obligations.

CMMC certification is a point-in-time event with ongoing obligations. Too many contractors treat the certificate as a three-year pass and move on — only to discover that their posture has degraded when the next C3PAO assessment reveals it.

Annual affirmation requirement

Every year after initial certification, a senior official must affirm to the DoD that the organization's CMMC compliance remains accurate. Before signing, verify:

  • All controls are still implemented as described in the SSP
  • No new systems have been added to the CUI boundary without SSP updates
  • Training was completed for all staff in the past 12 months
  • Open POA&M items have been closed or updated with current progress

Continuous monitoring obligations

  • SI.L2-3.14.3 (Security alerts): receive alerts and advisories and act on them
  • AU.L2-3.3.5 (Audit log review): review audit logs regularly for anomalous activity
  • RA.L2-3.11.2 (Vulnerability scans): scan for vulnerabilities periodically and remediate based on risk
  • CM.L2-3.4.8 (User-installed software): continuously enforce restrictions on unauthorized software

The three-year reset

Mark your reassessment date on your strategic calendar on day one. Reassessment preparation should begin no later than 6 months before expiration — meaning start at month 30 of your 36-month certification window.

Ready to start your CMMC journey?

Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.