CMMC does not assign the affirmation to a particular corporate title. 32 CFR 170.22 defines the Affirming Official as the senior-level representative inside the Organization Seeking Assessment who is responsible for ensuring CMMC Program compliance and has authority to affirm continuing compliance. That makes authority, responsibility, and access to reliable compliance information more important than whether the person's title says CEO, CIO, president, or vice president.
The affirmation is also not a one-time signature attached to a three-year assessment. It is required after specified assessment/status events and annually thereafter. A useful internal process therefore gives the Affirming Official a repeatable way to verify that the assessed scope has not drifted and that the implementation being affirmed is still true.
Use the regulation's two-part test for the signer
First ask whether the person is a senior-level representative of the OSA with responsibility for CMMC Program compliance. Then ask whether that person has the organizational authority to affirm continuing compliance for the relevant systems. A technically knowledgeable administrator can brief the signer without automatically satisfying that role definition.
Do not solve the question with a title chart alone. In a small contractor, the president may be the natural choice; in a larger organization, a business-unit or security leader may hold the required responsibility and authority. Document why the selected role fits the regulatory definition and who serves as backup if the role changes.
- Senior-level representative from within the OSA
- Responsible for ensuring CMMC Program compliance
- Authorized to affirm continuing compliance
- Able to obtain evidence for the relevant assessment scope
Know when a new affirmation is actually required
32 CFR 170.22 requires affirmation after assessments and annually thereafter. It specifically calls for affirmation upon achievement of Conditional CMMC Status when applicable, upon achievement of Final CMMC Status, annually following a Final CMMC Status Date, and following a POA&M closeout assessment when applicable. The exact workflow varies by Level 1, Level 2 Self, Level 2 C3PAO, and Level 3, but annual affirmation is a recurring control across the program.
For Level 2 Self, a three-year assessment cycle does not remove the annual affirmation requirement. That distinction is easy to miss because teams focus on the larger reassessment date. The current CMMC program page warns that the status can lapse when annual affirmation is not maintained. A proposal calendar should therefore track the assessment date and the annual affirmation date as separate deadlines.
Tie the reminder to the Final CMMC Status Date, not to an arbitrary year-end compliance meeting. If a POA&M closeout produces the Final Status at a different point in the year, the resulting dates may not line up with the company's usual audit season. The register should store the actual status date, affirmation history, and next due event.
Translate the attestation into reviewable questions
The official is attesting that the organization has implemented and will maintain the applicable CMMC security requirements for the information systems in the relevant assessment scope. Before submission, turn that statement into concrete questions: Is the scope still the same? Are any required controls known to be failing? Did a major architecture change move CUI or security functions? Are POA&M items closed when the status assumes they are?
A certification report, consultant memo, or green dashboard should not substitute for those questions. The signer needs a current management view of known exceptions and scope changes, because the affirmation concerns continuing compliance, not merely the historical fact that an assessment once occurred.
Require the functional owners to disclose contrary evidence, not only provide positive artifacts. Examples include a disabled logging connector, expired endpoint coverage, an unapproved CUI workflow, a failed backup test, a new privileged bypass path, or a cloud service that entered the data flow without scope review. The affirmation process is stronger when it actively asks what is not working instead of collecting only evidence selected to show success.
If a known deficiency affects a requirement included in the affirmed CMMC Status, escalate it before submission and determine what the rule/status permits; do not ask the signer to rely on a future remediation promise. The annual management review should make unresolved compliance questions visible early enough for technical, contracts, and legal stakeholders to resolve them before the affirmation is entered in SPRS.
Build a compact affirmation packet instead of a signature chase
Use a short packet that a senior-level representative can realistically review: current CMMC status and dates, assessment scope identifier, system/network diagram revision, open security exceptions, material changes since the last affirmation, POA&M status where applicable, and named owners who certify the underlying evidence.
The packet should identify what changed since the prior affirmation instead of reprinting the whole SSP. If a new SaaS platform, facility, MSP tool, remote-work pattern, or acquisition changed where CUI is processed or where security protection is provided, that change deserves explicit treatment.
Keep the packet with the affirmation record and the evidence used to support management's decision. This creates a defensible chain showing how the organization reached the statement it submitted.
Treat the annual cycle as a governance control
The affirmation review should leave behind a dated record of what was checked. Keep the source documents reviewed, the change summary, exception disposition, approvers, SPRS submission confirmation, and the next due date. That record is useful later when a customer, auditor, or new executive asks what 'annual affirmation completed' actually meant.
Do not create artificial zero-defect language. A security program can have tickets, routine vulnerabilities, and planned maintenance while still maintaining controls. The decision point is whether applicable CMMC security requirements are implemented and maintained for the assessed scope. If the team finds evidence that a requirement is no longer met, escalate the issue before asking the official to attest.
Treat the process like a release gate. The technical team provides objective evidence, compliance verifies traceability to the assessed requirements, contracts verifies the business use of the status, and the senior official makes the final affirmation. That is more defensible than a calendar reminder that simply says 'log into SPRS and click affirm.'
Assign a calendar owner and a scope-review owner separately. Missing a submission date and failing to notice that the environment changed are different failure modes, and the process should be designed to catch both.
Include personnel turnover in the annual review. If the system owner, security lead, contracts lead, or managed-service contact changed, confirm that the new owner understands the same assessment boundary and unresolved issues. An affirmation process that depends on knowledge held by one departed employee can look complete in SPRS while the organization has lost the operational understanding needed to maintain compliance.
Before the proposal moves
- ✓Name the internal senior-level representative who meets the regulatory definition
- ✓Document why that role has responsibility and authority for CMMC compliance
- ✓Track every assessment/status event that triggers an affirmation
- ✓Review scope changes and known control exceptions before submission
- ✓Provide a concise evidence-backed management packet
- ✓Retain the affirmation and the evidence supporting the decision
- ✓Assign owners for both the annual calendar and scope-change review
Common questions
Does the Affirming Official have to be the CEO?
No specific universal job title is mandated. The person must be a senior-level representative within the OSA who is responsible for CMMC compliance and has authority to affirm continuing compliance.
Is annual affirmation required when a Level 2 assessment is valid for three years?
Yes. The assessment cycle and annual affirmation are separate obligations; current CMMC guidance notes that the status can lapse if the required annual affirmation is not maintained.
Can an MSP or outside consultant be the Affirming Official?
The regulatory definition places the role within the Organization Seeking Assessment. An MSP, C3PAO, consultant, or attorney can support evidence review, but the OSA should select an internal senior-level representative who meets the responsibility and authority requirements in 32 CFR 170.22.
What should happen if the selected Affirming Official changes jobs?
Update the internal role assignment promptly, preserve the prior affirmation record, and ensure the replacement senior-level representative receives the current scope, status, exceptions, and evidence needed for the next required affirmation.
Official sources used for this guide
Open the primary source before making a contract-specific decision. Regulations and program implementation can change.


