CMMC Phase 1 Execution: A Practitioner’s Guide to SPRS and Self-Attestation

With CMMC Phase 1 beginning November 10, 2025, defense contractors must master SPRS scoring and self-attestation to remain eligible for DoD awards.

GovCon Architect Editorial Team·August 23, 2026

The End of the Honor System

The transition from the 'honor system' of DFARS 7012 to the structured oversight of the Cybersecurity Maturity Model Certification (CMMC) 2.0 is now a reality. As of November 10, 2025, the DoD has initiated Phase 1 of the CMMC rollout. This phase mandates the inclusion of CMMC Level 1 or Level 2 self-assessment requirements in all new solicitations and contracts.

Understanding the Phase 1 Requirements

In Phase 1, the primary mechanism for compliance is the Supplier Performance Risk System (SPRS). Contractors must perform a self-assessment against the 110 controls found in NIST SP 800-171 Rev 2 and upload their score to SPRS.

Key practitioner insights for Phase 1:

  • The Score Matters: While Phase 1 allows for self-attestation, a low SPRS score is a significant risk factor. Contracting Officers (KOs) are increasingly using SPRS scores as a tie-breaker or a baseline for 'responsibility' determinations under FAR Part 9.
  • Senior Official Affirmation: CMMC requires a senior company official to affirm compliance. This creates legal liability under the False Claims Act if the self-assessment is found to be inaccurate during a later DIBACAC audit.
  • Scope Definition: The most common failure point is incorrectly defining the 'CUI Boundary.' Contractors must identify exactly where Controlled Unclassified Information (CUI) resides within their network to avoid over-scoping (which is expensive) or under-scoping (which is non-compliant).

Navigating the NIST SP 800-171 Revision Cycle

There is currently a period of overlap between NIST SP 800-171 Revision 2 and Revision 3. While the CMMC Final Rule is currently mapped to Revision 2, practitioners should be aware that Revision 3 introduces new requirements for 'automated monitoring' and 'supply chain risk management.'

If your firm is currently building a System Security Plan (SSP), it is highly recommended to build toward the Revision 2 requirements while maintaining a 'gap analysis' for Revision 3. This ensures you meet the current contract requirements while future-proofing your certification for Phase 2 and beyond.

Practical Steps for Compliance Leads

  1. Verify Your SPRS Entry: Ensure your score is not older than three years. Many contractors uploaded a score in 2021 or 2022 and have failed to update it, rendering them technically ineligible for new Phase 1 awards.
  2. Document Your POAMs: If you do not meet all 110 controls, you must have a Plan of Action and Milestones (POAM). Under CMMC 2.0, certain 'high-weight' controls cannot be on a POAM for more than 180 days.
  3. Flowdown Management: Review your sub-contracts. DFARS 252.204-7021 requires you to flow down the CMMC level requirement to your subcontractors based on the type of information they will handle. If your sub handles CUI, they must meet Level 2; if they only handle FCI, Level 1 is sufficient.

The GovCon Architect editorial team writes practitioner guidance on federal capture, compliance, and proposal operations. GovCon Architect is an AI-powered federal government contracting platform for opportunity intelligence, capture, compliance, competitive intelligence, and proposal workflows.

Explore the platform