CMMC Level 3: DIBCAC Assessment and Affirmation
A deep dive into the requirements for CMMC Level 3 certification, including DIBCAC assessments and the role of SPRS affirmations.
The CMMC Level 3 Landscape
CMMC Level 3 represents the pinnacle of the Cybersecurity Maturity Model Certification framework, specifically designed for contractors handling the most sensitive Controlled Unclassified Information (CUI) [3]. Unlike Level 2, which allows for self-assessment in certain contexts, Level 3 requires a formal certification assessment conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) [3].
The DIBCAC Assessment Process
Achieving Level 3 status is a rigorous process that involves a comprehensive audit of your information systems. The DIBCAC team will verify that all security requirements specified in the CMMC framework are met [3]. The results of this assessment are submitted into the CMMC instantiation of eMASS, which then triggers an automated transmission to the Supplier Performance Risk System (SPRS) [3].
Managing POA&Ms and Affirmations
While the goal is a 'MET' result, the reality of complex IT environments often leads to the use of a Plan of Action and Milestones (POA&M). However, under the current rules, a Level 3 POA&M is strictly limited and must meet specific requirements to be considered valid [3].
| Requirement | Status | Impact | |---|---|---| | DIBCAC Assessment | Mandatory | Required for Level 3 certification | | SPRS Affirmation | Annual | Mandatory for all CMMC levels | | POA&M | Restricted | Must meet § 170.21 requirements |
Strategic Considerations for Compliance
For compliance leads, the focus must be on maintaining a 'continuous compliance' posture. The SPRS affirmation is not a one-time event; it is an annual requirement that carries significant legal weight under the False Claims Act [4]. Ensure that your internal governance structure includes a senior official who is authorized to sign off on these affirmations. Furthermore, maintain a clear boundary between your CMMC assessment scope and the rest of your corporate network to minimize the cost and complexity of the DIBCAC audit. By isolating CUI-handling systems, you reduce the surface area that requires Level 3 certification, thereby streamlining the assessment process.
The GovCon Architect editorial team writes practitioner guidance on federal capture, compliance, and proposal operations. GovCon Architect is an AI-powered federal government contracting platform for opportunity intelligence, capture, compliance, competitive intelligence, and proposal workflows.
