Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
PHASE I

CMMC Phase I in 2026: Self-Assessment Requirements

What Phase I means after the 2026 policy change, with a practical checklist for self-assessment, affirmation, SPRS, and award readiness.

Illustration comparing CMMC Level 1 and Level 2 Self requirements as two stacked blocks, framed as self-assessment not certification.

Phase I is the part of CMMC that a small defense contractor can encounter in real procurements right now. After the July 2026 suspension of Phase II, the Department's current CMMC materials say Phase I remains in place and emphasize self-assessment. That makes the practical work much less about memorizing a rollout chart and much more about matching a solicitation to an assessed system.

Read the solicitation before choosing an assessment path

There are two recurring self-assessment paths to understand: Level 1 for systems handling Federal Contract Information and Level 2 Self for systems handling CUI when the solicitation permits the self-assessment path. Both require more than a questionnaire. The assessment result, system boundary, SPRS record, and affirmation have to describe the environment that will actually perform the contract.

Start with the procurement document, then read it against the current implementation posture. DFARS 252.204-7025 still contains both Level 2 Self and Level 2 C3PAO designations, but the current August 2026 program page says implementation is paused in Phase 1 and may only require Level 1 Self and Level 2 Self during this period. Phase I does not mean every contractor is automatically Level 1; it means award-readiness work should reconcile the solicitation with current guidance instead of relying on the old four-phase calendar.

Capture that designation in the proposal file rather than relying on a salesperson's summary. Also record which information system will process, store, or transmit the relevant FCI or CUI. This creates a bridge between the contract requirement and the technical evidence instead of leaving the proposal team and security team with two unrelated versions of 'compliance.'

Level 1: annual self-assessment and affirmation

For Level 1, the current program page points to the 15 safeguarding requirements in FAR 52.204-21. The self-assessment and affirmation are annual. Because POA&Ms are not permitted for Level 1 status, a missing required safeguard should be treated as an implementation gap to close, not as something to park for later while still representing the system as meeting the level.

A good Level 1 evidence set is modest but real: named user accounts, access-removal records, endpoint and boundary settings, media controls, basic physical safeguards, and examples showing that updates and malicious-code protections operate. A one-page policy saying 'we protect FCI' does not demonstrate those practices.

Level 2 Self: three-year assessment, annual affirmation

The current Phase I guidance describes Level 2 Self as an assessment against the 110 NIST SP 800-171 Rev. 2 requirements every three years, with affirmation after the assessment and annually thereafter. The status can lapse if the required affirmation is not maintained. For bid readiness, the annual date deserves the same calendar discipline as the larger reassessment cycle.

Level 2 Self also raises a much harder scoping problem than Level 1. CUI assets, security protection assets, contractor risk-managed assets, specialized assets, and external service dependencies need to be handled consistently with the current scoping guide. If the asset inventory and SSP disagree about what is inside the boundary, the assessment can be internally inconsistent even when individual controls look strong.

SPRS is part of the workflow, not an archive

SPRS is where the government can verify assessment-related information used in the contracting process. Treat it as an operational system of record. After an assessment or affirmation, verify that the expected status, dates, and identifiers appear correctly rather than assuming the submission step completed the entire task.

Small firms often concentrate knowledge in one IT administrator. That becomes a proposal risk when an offer is due and nobody else can locate a CMMC UID, assessment date, or affirmation record. Maintain a controlled internal register with the system name, owner, SPRS identifiers, status type, relevant dates, and the opportunities that use that system.

Scope the system before scoring it

A self-assessment is only meaningful if the boundary is stable enough to evaluate. Trace the government information from receipt to storage, collaboration, backup, remote access, and deletion. Then identify the services that protect those paths, including identity, endpoint management, logging, network controls, and privileged administration. That exercise often reveals systems that a simple workstation list misses.

Do the scoping before the scoring. Otherwise teams end up with a score tied to an environment that keeps changing under the assessment. When a material architecture change occurs after the assessment, document it, evaluate whether the prior evidence still represents the system, and decide whether any government or contract record needs to be updated.

Build a repeatable Phase I operating rhythm

The easiest way to keep Phase I from becoming a proposal fire drill is to assign dates and owners. Put annual affirmations, annual Level 1 assessments, Level 2 Self reassessment dates, Basic Assessment currency, and major contract renewals on one calendar. Pair that calendar with a quarterly evidence refresh for artifacts that age quickly, such as access reviews, vulnerability results, backup tests, and incident-response exercises.

Before each proposal, perform a short reconciliation instead of a full re-audit: confirm the required level, confirm the intended system, verify current status and affirmation, check whether the architecture materially changed, and record the person who completed the review. That five-step routine is far more defensible than copying last year's compliance language into a new bid.

What a Phase I readiness file should contain

A useful readiness file is not a full duplicate of the evidence repository. Start with a one-page system sheet: system name, short boundary description, information type, responsible executive, technical owner, CAGE mapping, current CMMC status, assessment date, affirmation date, UID, and any open conditional closeout date. Link from that sheet to the SSP and evidence index rather than attaching copies.

Add a solicitation log that shows which opportunities rely on the system and what CMMC designation each procurement uses. When a proposal manager changes a planned performance environment, the system sheet should be updated before the offer is released. This one cross-functional control prevents a large share of last-minute confusion.

Keep an assessment-history section with prior dates and why reassessments occurred. A reassessment triggered by a major migration should be distinguishable from one triggered by normal expiration. History helps a new compliance owner understand why the current record looks different from an old proposal attachment.

Finally, keep a short exceptions list. If one remote workflow, specialized asset, or provider relationship has special treatment, name it and point to the supporting record. Phase I self-assessment is easier to maintain when the unusual cases are visible instead of buried inside a long SSP narrative.

The easy date to miss is the annual affirmation. A Level 2 Self assessment can have a three-year assessment cycle, but the status still depends on the required annual affirmation. Put both dates in the bid register, assign a primary and backup owner, and verify the live record before a proposal relies on it. This prevents the sales team from treating the three-year assessment date as a three-year permission slip for every related representation.

WORKING CHECKLIST

A short working check

  • Confirm the required CMMC level in the solicitation
  • Define the in-scope system before assessing
  • Complete the correct self-assessment
  • Record the result in SPRS when required
  • Complete the required affirmation
  • Set a calendar for expiration and annual affirmation dates
  • Assign an owner for the next annual affirmation

Common questions

Does Phase I mean every contractor is Level 1?

No. Phase I is an implementation stage, not a universal level. The solicitation and the information handled determine the relevant requirement.

Can a proposal rely on an old assessment?

Only if it is still current under the applicable rule and matches the system used for the work. Verify the specific SPRS status before relying on it.

What should proposal teams verify first?

Verify the CMMC level and the exact contractor information system that will perform the work, then check the current assessment and affirmation records for that system.

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.