The short answer
A qualified CMMC readiness consultant can help a small defense contractor determine the applicable assessment path, define the CUI boundary, evaluate implementation against the required assessment objectives, organize evidence, reconcile the SSP and POA&M, prepare accurate SPRS inputs, and give the Affirming Official a decision-ready package.
The consultant cannot certify the company, choose the requirement that belongs in a Government contract, or affirm continuing compliance on leadership's behalf.
For a CMMC Level 2 (Self) assessment, the contractor remains the Organization Seeking Assessment and conducts the assessment. Under 32 CFR 170.16, it must assess the systems within the CMMC Assessment Scope using the incorporated NIST SP 800-171A assessment procedures, score the result using the CMMC methodology, and upload the result to the Supplier Performance Risk System, or SPRS. A senior-level Affirming Official from within the organization must then affirm continuing compliance in SPRS under 32 CFR 170.22.
The best use of a consultant is therefore not to outsource accountability. It is to make the contractor's scope, conclusions, evidence, remediation plan, and executive decision more defensible.
First confirm which assessment you actually need
Many contractors use “self-assessment” to describe several different activities. They are not interchangeable.
| Activity | What it is | Who performs it | Where it leads |
|---|---|---|---|
| Readiness or gap assessment | An internal advisory review of scope, implementation, evidence, and gaps | The contractor, often with a consultant | A remediation and evidence plan; not an official CMMC status |
| NIST SP 800-171 DoD Basic Assessment | A contractor self-assessment based on the SSP and the DoD Assessment Methodology | The contractor | A summary score posted in SPRS under DFARS 252.204-7020 |
| CMMC Level 2 (Self) assessment | The formal self-assessment path specified by 32 CFR 170.16 when the applicable CMMC requirement calls for Level 2 (Self) | The Organization Seeking Assessment | Conditional or Final Level 2 (Self) status after the required submission and affirmation |
| CMMC Level 2 certification assessment | The independent certification path specified by 32 CFR 170.17 when the applicable requirement calls for Level 2 (C3PAO) | An authorized or accredited C3PAO | Conditional or Final Level 2 (C3PAO) status |
DFARS 252.204-7020 defines a Basic Assessment as a contractor-generated NIST SP 800-171 assessment based on the contractor's SSP and the DoD Assessment Methodology. The clause says the resulting score carries a “Low” confidence level because it is self-generated.
That existing SPRS score should not be casually relabeled as a CMMC Level 2 (Self) status. The formal CMMC self-assessment has its own scope, procedures, scoring, status, submission, POA&M, artifact-retention, and affirmation rules in 32 CFR part 170 and the applicable contract clauses.
The practical starting point is the solicitation, contract, subcontract, and flow-down language. A consultant can help interpret the technical and operational impact, but the contracting authority and the actual terms of the agreement control the requirement.
Does the Phase II suspension make self-assessment work less important?
No. It changes the near-term rollout context; it does not erase existing safeguarding duties.
On July 13, 2026, the Department announced the immediate suspension of the transition to CMMC Phase II and stated that Phase I self-assessment requirements remain in place. The same announcement said the Department would continue enforcing NIST SP 800-171 Revision 2 through self-assessments and select Government-led assessments during the review. It also stated that contractors and subcontractors remain obligated to safeguard covered defense information when DFARS 252.204-7012 applies.
That makes disciplined self-assessment support commercially relevant now. Small contractors still need to understand what their contracts require, whether CUI is present, what their SPRS record represents, and whether their claimed safeguards match current implementation.
It would be equally risky to assume that every contractor now needs a Level 2 (Self) status or that no contractor should prepare for an eventual third-party assessment. Follow the requirement attached to the actual opportunity and preserve the ability to move to the appropriate assessment path as program implementation evolves.
What CMMC Level 2 self-assessment help should include
A useful engagement should leave the contractor with decisions, evidence, and repeatable processes—not merely a completed spreadsheet.
1. Assessment-path confirmation
The consultant should help assemble the facts needed to distinguish among:
- a NIST SP 800-171 DoD Basic Assessment;
- a CMMC Level 2 (Self) assessment;
- a CMMC Level 2 (C3PAO) certification assessment; and
- an internal readiness review that does not itself create a CMMC status.
The output should identify the source of the requirement, the relevant contract or opportunity, the information involved, the expected assessment type, and the assumptions that still need confirmation.
2. Defensible CUI scope
Scope is not a preface to the assessment. It determines which systems, people, facilities, providers, and security dependencies must be considered.
A consultant should trace where CUI is received, created, stored, processed, transmitted, backed up, administered, and protected. That work should identify:
- CUI assets;
- security protection assets;
- contractor risk-managed assets;
- specialized assets;
- external service providers;
- cloud services;
- administrators and users;
- network and identity dependencies; and
- boundaries or data flows that require a management decision.
The result should be reflected consistently in diagrams, inventories, the SSP, provider documentation, and assessment evidence. If the boundary is wrong, an otherwise polished evidence package can support the wrong environment.
For more on this decision, see CMMC enclave versus whole-company scope.
3. Objective-by-objective evaluation
32 CFR 170.16 requires a Level 2 self-assessment to use the NIST SP 800-171A June 2018 assessment procedures incorporated into the rule. Although NIST has since published Revision 3 materials, the current CMMC rule expressly incorporates the June 2018 assessment publication for this purpose.
That distinction matters. A generic control checklist does not establish that every applicable assessment objective has been satisfied.
The consultant should help the contractor evaluate each objective using the appropriate methods:
- examine documents, configurations, records, and artifacts;
- interview people responsible for implementing and operating the requirement; and
- test technical or procedural mechanisms where needed.
The contractor should retain the reasoning behind each MET or NOT MET conclusion and the artifacts that support it. Under 32 CFR 170.16, artifacts used as evidence for a Level 2 self-assessment must be retained for six years from the CMMC Status Date.
4. SSP, evidence, and implementation alignment
The SSP should describe the environment that actually exists. Policies should describe the processes people actually follow. Evidence should demonstrate that the claimed implementation is operating.
A strong consultant should challenge mismatches such as:
- the SSP names a tool that has been replaced;
- policy requires a review that cannot be evidenced;
- an MSP performs an activity but responsibility is not documented;
- MFA is described broadly but has material exceptions;
- log collection exists without the review process being claimed;
- a diagram omits a cloud or remote-access dependency; or
- an artifact is a template rather than proof of performance.
The goal is not to manufacture documentation around a desired score. It is to make documentation, implementation, and evidence tell the same truthful story.
5. Provider-responsibility mapping
Small contractors often rely heavily on MSPs, MSSPs, cloud providers, secure collaboration platforms, and other external service providers.
32 CFR 170.16 requires relevant provider relationships and services to be represented in the SSP. For cloud services that process, store, or transmit CUI, the rule also addresses FedRAMP Moderate authorization or equivalency and requires customer responsibilities to be documented or referenced in the SSP.
A consultant should create a responsibility matrix showing what is:
- performed by the contractor;
- performed by a provider;
- shared between the parties;
- inherited from a platform; and
- still unsupported by evidence.
A vendor statement that a platform is “CMMC compliant” does not establish how the contractor has configured it or fulfilled its own responsibilities.
6. Accurate scoring and POA&M decisions
The engagement should preserve the link between each assessment objective, the associated requirement, the evidence, the result, and the scoring rationale.
A POA&M is not a general permission slip for unfinished work. Under 32 CFR 170.21, Conditional Level 2 status is available only when the score and open requirements satisfy specific eligibility conditions. Certain requirements cannot be placed on a Level 2 POA&M, and a permitted POA&M must be closed through the appropriate closeout assessment within 180 days of the Conditional CMMC Status Date.
A consultant should identify the rule that permits or prohibits each proposed POA&M item, the remediation owner, the required closeout evidence, and the deadline. Leadership should see the difference between an internal remediation tracker and a CMMC POA&M that supports Conditional status.
7. SPRS and affirmation readiness
The consultant can prepare a controlled submission package containing the approved score, scope, CAGE codes, status information, POA&M status, and supporting references. The contractor should validate the final inputs and control who submits them.
The affirmation is a separate executive responsibility. Under 32 CFR 170.22, the Affirming Official must be a senior-level representative from within the organization with responsibility and authority for CMMC compliance. The official attests that the organization has implemented and will maintain the applicable requirements for the relevant assessment scope.
That official should receive a concise package covering:
- the assessment path and CMMC status;
- the defined scope and material assumptions;
- the final score and how it was derived;
- any permitted POA&M and closeout obligations;
- material provider dependencies;
- known exceptions or unresolved questions;
- changes since the evidence was collected; and
- the evidence owners who can reproduce the result.
See what a CMMC Affirming Official should validate before signing for a deeper governance checklist.
What a consultant should not do
A credible provider should not:
- describe a readiness review as an official certification assessment;
- promise that hiring the consultant guarantees a CMMC status or contract award;
- select a convenient boundary that does not match the real CUI flow;
- treat policies alone as proof that practices operate;
- convert every technical scan finding directly into a CMMC score;
- hide NOT MET conclusions to reach a preferred result;
- place ineligible requirements on a CMMC POA&M;
- submit a score the contractor has not reviewed and approved;
- act as the contractor's internal Affirming Official; or
- imply that the consultant can determine the Government's contractual requirement.
HostBreach is not a C3PAO and does not conduct official Level 2 certification assessments. When a C3PAO assessment is required, readiness support should remain separate from the independent assessor's determination.
Where threat-informed readiness adds value
CMMC Level 2 assesses implementation of specified security requirements within a defined scope. That internal assessment and evidence work is the foundation.
A threat-informed advisory layer asks an additional question: Are externally observable conditions challenging any of the assumptions in the internal evidence?
Passive outside-in intelligence may surface conditions worth validating, such as an unexpected internet-facing service, credential-exposure signal, email-authentication weakness, newly visible subdomain, or technology that is not represented in the documented boundary.
Those observations do not independently prove compromise, CUI exposure, scope, noncompliance, or a failed assessment objective. They are leads for internal validation and risk prioritization.
That distinction is important. A scan is not a CMMC assessment, but a contractor should not ignore credible evidence that its externally visible environment may differ from the environment described in its SSP or evidence package.
HostBreach uses its Cyber Intel Engine and CMMC Cyber Snapshot as this outside-in intelligence layer within end-to-end readiness. The internal assessment, system-owner validation, and contractor decision remain essential.
A practical deliverable checklist
Before the engagement ends, the contractor should know whether it will receive:
- an assessment-path and applicability memo;
- a current CUI data-flow and scope diagram;
- a scoped asset and provider inventory;
- an objective-by-objective assessment workbook;
- an evidence index with owners and collection dates;
- an SSP aligned to the actual environment;
- a provider-responsibility matrix;
- a scored findings register with rationale;
- a rule-aligned remediation plan and POA&M, if permitted;
- an SPRS submission-readiness package;
- an Affirming Official briefing package; and
- a repeatable process for maintaining evidence and detecting material changes.
If the proposal promises “CMMC readiness” but does not identify the assessment path, scope decisions, evidence work, remediation responsibilities, and executive handoff, the buyer may be purchasing documents without assurance.
Questions to ask before hiring a CMMC self-assessment consultant
Ask prospective providers:
- How will you distinguish a DFARS 252.204-7020 Basic Assessment from a CMMC Level 2 (Self) assessment?
- How will you validate CUI flows and the proposed assessment boundary?
- Will your work map evidence to every applicable assessment objective?
- How do you test implementation rather than review policies alone?
- How will you document MSP, MSSP, cloud, and other provider responsibilities?
- How do you determine whether a finding is eligible for a CMMC POA&M?
- What will the Affirming Official receive before being asked to sign?
- Who retains ownership of the workbook, evidence index, diagrams, and SSP?
- How do you handle conflicts between documentation and observed implementation?
- What work is advisory, and what would require an independent C3PAO?
The answer should be specific enough to show a repeatable method and candid enough to preserve the contractor's responsibility.
For a broader buying framework, read how to choose a CMMC readiness company and the CMMC readiness assessment checklist.
The HostBreach approach
HostBreach provides principal-led CMMC consulting and readiness advisory for small and midsized defense contractors.
The work can connect:
- contract and assessment-path review;
- CUI scoping and enclave decisions;
- NIST SP 800-171 gap analysis;
- SSP, POA&M, and evidence development;
- provider-responsibility validation;
- SPRS and affirmation preparation;
- remediation coordination; and
- passive outside-in intelligence that identifies conditions requiring internal validation.
The outcome is not a consultant-owned claim of compliance. It is a contractor-owned readiness position supported by clearer scope, stronger evidence, transparent gaps, and an executive who understands the basis for the submission.
If you need help preparing a Level 2 self-assessment, clarifying what your current SPRS score represents, or building an evidence-backed path toward a future independent assessment, visit HostBreach CMMC Consulting and Readiness Advisory or book a call with Franco Velasquez.
Sources
- Electronic Code of Federal Regulations, 32 CFR Part 170 — Cybersecurity Maturity Model Certification Program.
- Electronic Code of Federal Regulations, 32 CFR 170.16 — CMMC Level 2 self-assessment and affirmation requirements.
- Electronic Code of Federal Regulations, 32 CFR 170.21 — Plan of Action and Milestones requirements.
- Electronic Code of Federal Regulations, 32 CFR 170.22 — Affirmation.
- Acquisition.gov, DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements.
- Acquisition.gov, DFARS 252.204-7021 — Contractor Compliance With the CMMC Level Requirements.
- NIST, SP 800-171A — Assessing Security Requirements for Controlled Unclassified Information.
- Office of Industrial Base Growth, Department announcement suspending CMMC Phase II requirements.
