The CMMC 2.0 Final Rule: Operationalizing SPRS and Affirmation

With the CMMC Final Rule now in effect, contractors must move beyond self-assessment to formal SPRS affirmation and CMMC UID management.

GovCon Architect Editorial Team·August 24, 2026

The New Compliance Baseline

The Department of Defense (DoD) officially ushered in the new era of cybersecurity compliance on November 10, 2025, when the CMMC Final Rule took effect [2, 7, 10]. For capture managers and compliance leads, this is no longer a theoretical exercise in NIST 800-171 mapping; it is a hard gate for contract award [3]. Under DFARS 252.204-7025, offerors must now provide CMMC unique identifiers (CMMC UIDs) in their proposals for every information system that processes, stores, or transmits Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) [3].

SPRS: The Single Source of Truth

The Supplier Performance Risk System (SPRS) is now the primary mechanism for verifying compliance [3]. Contractors must ensure their current CMMC status is accurately reflected in SPRS (https://piee.eb.mil) [3]. If your status is listed as 'Conditional,' you are required to have a valid Plan of Action and Milestones (POA&M) in place to achieve 'Final' status [3].

Practitioners should note that the affirmation of continuous compliance is a critical, non-negotiable step [3]. This is not a one-time checkbox; it is a recurring requirement that must be updated whenever new CMMC UIDs are generated [3]. Failure to maintain this status in SPRS renders an offeror ineligible for award, regardless of technical merit or price [3].

NIST 800-171 and Beyond

While CMMC 2.0 is heavily influenced by NIST SP 800-171 [6], the transition to the final rule requires a more rigorous approach to documentation. NIST SP 800-171 Rev. 2 and the evolving standards in Rev. 3 remain the bedrock for protecting CUI [5, 18]. However, the CMMC framework adds the layer of third-party assessment for higher levels [6].

For organizations currently operating under the DFARS 252.204-7012 clause, the transition to CMMC 2.0 means that self-attestation is increasingly being replaced by formal certification requirements [6]. If your organization has not yet engaged a C3PAO (Certified Third-Party Assessment Organization), the time to act is now. The limited availability of C3PAOs means that firms waiting for a solicitation to drop before seeking an assessment will likely face significant delays that could jeopardize their ability to bid [6].

Actionable Steps for Capture Teams

  1. Audit Your System Boundaries: Clearly define which information systems touch CUI. Each system requires its own CMMC UID [3].
  2. Validate SPRS Data: Ensure your SPRS entry is current and that your affirmation of continuous compliance is documented [3].
  3. Prepare for Flow-Downs: As a prime, you are responsible for ensuring your subcontractors meet the applicable CMMC level requirements [3]. Update your teaming agreements to include CMMC compliance as a condition of participation.
  4. Monitor Solicitations: Review all new DoD solicitations for the inclusion of CMMC requirements, as the DoD is now actively incorporating these into new contracts [2, 7].

The GovCon Architect editorial team writes practitioner guidance on federal capture, compliance, and proposal operations. GovCon Architect is an AI-powered federal government contracting platform for opportunity intelligence, capture, compliance, competitive intelligence, and proposal workflows.

Explore the platform