CMMC Self-Assessment Score Validator
Check the math before you post it. Send your CMMC Level 2 self-assessment results, all 110 NIST SP 800-171 Rev 2 requirements, with the details that go into SPRS. You get back the score recomputed with the published DoD method, whether it matches the score you planned to post, what the result qualifies for, and every gap in the package, each with its rule and source.
Why the number matters
- The score is yours to stand behind. A Level 2 self-assessment is posted in SPRS and affirmed by a senior official, at each assessment and every year after.
- False Claims Act exposure. In March 2025 a defense contractor paid $4.6 million to settle allegations that included a posted score of 104 that a consultant later put at -142. In June 2026 another paid $507,144 after a DoD assessment scored it -170, near the bottom of the -203 to 110 range.
- Self-assessment carries the weight. DoD suspended the planned November 2026 move to Phase 2, so Level 2 (Self) stays the designation for CUI work.
Sources: the DOJ releases, DFARS 252.204-7021 and the DoD CIO memo, linked at the bottom of this page.
Where this fits. SPRS has no file upload for this: you type the score and details into SPRS yourself. SpreadRun checks the package before you do. The scoring method is public and free spreadsheets exist; what this adds is verified math with the rule cited on every finding, the POA&M limits spreadsheets tend to skip, the SPRS and affirmation checks, and an API for consultants and MSPs who run many clients.
A verified score is arithmetic, not a certification. It is computed from the results you enter. It is not a CMMC assessment, not legal or compliance advice, and a PASS does not mean your company meets NIST SP 800-171 or that DoD will accept the score.
What it checks
- The score. 110 minus the published value of each requirement NOT MET: 5, 3 or 1 point, with partial credit only for 3.5.3 (multifactor authentication) and 3.13.11 (FIPS-validated cryptography). N/A counts as MET.
- Your claimed score. Flagged if it does not match the recomputed score, or falls outside -203 to 110.
- Completeness. All 110 requirements, each once, with a valid result. Unknown or duplicate rows are flagged.
- The system security plan. 3.12.4 must be MET. Without an SSP no score can be posted.
- POA&M rules. A POA&M for every NOT MET requirement, and each one allowed on a POA&M: 1-point requirements, plus 3.13.11 when encryption is not FIPS-validated, never the six that are excluded.
- The threshold. Final (110), Conditional (at least 88, every gap allowed on a POA&M), or no Level 2 (Self) status, with the 180-day POA&M closeout window when you give the CMMC Status Date.
- SPRS details. At least one CAGE code, each five characters; a defined assessment scope; an assessment date that is real, not in the future and under three years old.
- The affirmation. Official named, title and contact included, statement made, dated on or after the assessment and within the last year.
Every report ends with a submission checklist: each area marked Ready, Review or Fix.
Who it's for
- Defense contractors and subcontractors: check the number before the senior official affirms it.
- MSPs and MSSPs: run every client through the same check, from a script.
- Readiness consultants: a second look at a client's math, with the rule behind each finding.
- Software and automation: a plain REST endpoint with JSON in and JSON out.
Not checked
- Whether each requirement is really MET. SpreadRun never sees your systems, evidence or SSP.
- Whether your scope, asset categories and CAGE codes are the right ones for your contracts.
- Whether a CAGE code is registered to you. Only the format is checked.
- The SPRS entry itself.
- Level 1 and Level 3, and C3PAO certification assessments.
Input and output
Send
JSON with
assessment(level 2, assessment date, claimed score, CAGE codes, and yes or no for scope, SSP and POA&M),affirmation(yes or no for each part, and the date), and the 110 results as a list or as the CSV you already keep. Up to 256 KB.Check
Every rule on this page. No network calls, nothing stored.
Report
JSON with
verifiedScore,band,claimedScore,deductions(requirement and points),readiness(the checklist) andfindings(severity, ruleId, path, requirement, message, source).
Every field and all rule IDs are in the API docs.
Try it now
The sample packages run free. Your own results, answered here or uploaded as a CSV, run as a paid verification at $25.00 from your credit.
- ReadyAll 110 requirements assessed, once each
- ReadySystem security plan in place (3.12.4)
- FixScore verified against the methodology
- FixPOA&M in place and allowed for every NOT MET requirement
- FixSPRS details: level, date, scope and CAGE codes
- FixAffirmation by the Affirming Official
- ReviewScore reaches a Level 2 (Self) status
Deductions (6)
| Requirement | Points |
|---|---|
| 3.1.10 | -1 |
| 3.3.4 | -1 |
| 3.5.3 (partial) | -3 |
| 3.10.4 | -1 |
| 3.13.11 | -5 |
| 3.14.6 | -5 |
| Severity | Rule | Where and what |
|---|---|---|
| Error | CMMC- | /affirmation/affirmationDateThe affirmation is dated before the assessment. An affirmation is required at the time of each assessment. |
| Error | CMMC- | /affirmation/statementAffirmedThe affirmation statement attests that all applicable CMMC requirements are implemented and will stay implemented. It has not been made. |
| Error | CMMC- | /assessment/cageCodes[1]A CAGE code is five characters, letters and digits only. |
| Error | CMMC- | /assessment/poamInPlaceThere are NOT MET requirements, so a POA&M must be in place for each one (poamInPlace: true). A POA&M is not a substitute for a completed requirement, and the points stay deducted. |
| Error | CMMC- | /assessment/claimedScoreThe claimed score does not match the score recomputed from the requirement results. Post the verified score, or correct the results it came from. |
| Warning | CMMC- | /scoreThis score does not reach a Level 2 (Self) status. It can still be posted, but a contract that requires Level 2 (Self) cannot be awarded on it. |
| Warning | CMMC- | /requirement/3.10.4NOT MET, and this requirement is on the list that may never be on a POA&M. It must be MET before a Level 2 (Self) status is possible. |
| Warning | CMMC- | /requirement/3.13.11NOT MET, and this requirement is worth more than 1 point as scored, and only 1-point requirements (or 3.13.11 when encryption is employed but not FIPS-validated) may be on a POA&M. It must be MET before a Level 2 (Self) status is possible. |
| Warning | CMMC- | /requirement/3.14.6NOT MET, and this requirement is worth more than 1 point as scored, and only 1-point requirements (or 3.13.11 when encryption is employed but not FIPS-validated) may be on a POA&M. It must be MET before a Level 2 (Self) status is possible. |
| Warning | CMMC- | /requirement/3.5.3NOT MET, and this requirement is worth more than 1 point as scored, and only 1-point requirements (or 3.13.11 when encryption is employed but not FIPS-validated) may be on a POA&M. It must be MET before a Level 2 (Self) status is possible. |
Pricing
$25.00 per completed verification. One self-assessment, one full report.
- Billed when a report is produced, PASS, WARN or FAIL. Invalid input is never billed.
- Paid from the same prepaid credits as every SpreadRun API, in $5, $20, $50 or $100 packs. A $50 pack covers 2 verifications and a $100 pack covers 4. Credits never expire. All pricing
- Running many clients? Talk to us first so we can tell you honestly whether this fits.
Call it from code
Fields, rule IDs, error codes and limits are in the API docs.
curl -X POST "https://www.spreadrun.com/api/v1/cmmc-self-assessment-validator" \
-H "Authorization: Bearer $SPREADRUN_API_KEY" \
-H "Content-Type: application/json" \
--data-binary @self_assessment.jsonQuestions
Does a PASS mean we are compliant, or that DoD will accept our score?
No. A PASS means the score you plan to post matches the published scoring method applied to the results you entered, and that the package has what SPRS and the affirmation need. SpreadRun cannot see your systems or evidence, so it cannot tell whether a requirement is really MET. A verified score is arithmetic, not a CMMC certification or assessment, and not legal or compliance advice.
The scoring method is public. Why pay for this?
It is public, and free scoring spreadsheets exist. If a spreadsheet works for you, use it. What this adds: the math checked against the regulation with the rule cited on every finding, the POA&M limits a spreadsheet usually skips (which requirements may never be on one, and the partial-credit exceptions), the SPRS and affirmation details, and an API so a consultant or MSP can run every client the same way.
How is the score calculated?
Start at 110, one point per requirement. For each requirement NOT MET, subtract its value from 32 CFR 170.24: 5, 3 or 1 point. Two requirements give partial credit: 3.5.3 costs 3 points instead of 5 if multifactor authentication covers only remote and privileged users, and 3.13.11 costs 3 instead of 5 if encryption is used but is not FIPS-validated. N/A counts as MET. The lowest possible score is -203. Without a system security plan (3.12.4) there is no score at all.
What makes a score Conditional or Final?
Final Level 2 (Self) needs every requirement MET or N/A: 110. Conditional needs a score of at least 0.8 of 110, which is 88, with every NOT MET requirement allowed on a POA&M: only 1-point requirements, plus 3.13.11 when encryption is used but not FIPS-validated, and never 3.1.20, 3.1.22, 3.10.3, 3.10.4, 3.10.5 or 3.12.4. The POA&M must then be closed out within 180 days of the CMMC Status Date, or the conditional status expires.
Does the Phase 2 suspension change anything here?
Not for self-assessments. DoD suspended the planned November 2026 move to Phase 2, which leaves Level 1 (Self) and Level 2 (Self) as the designations in use. Where a contract includes DFARS 252.204-7021, the contractor still enters current self-assessment results in SPRS and keeps an annual affirmation current. Check the sources below for anything newer.
Why do you not ask for the Affirming Official's name?
Because nothing in the check needs it, and SpreadRun does not take personal data. The affirmation checks are yes or no: is the official named, are title and contact information included, and has the statement been made.
Is my data stored?
No. The package is processed in memory for the length of the request and is not stored or shared. The report names requirement IDs and rules, never your CAGE codes, dates or the score you claimed. For billing and usage we log the time, endpoint, result status, size and duration, never the contents.
When is a run charged?
When the verification finishes and returns a report, whether it says PASS, WARN or FAIL: $25.00 per completed verification. Requests rejected before a report exists are free, such as a body that is not JSON, a level other than 2, or no requirement results.
Can I try it for free?
Yes, on the three sample packages on this page: a clean 110, a conditional result and a package with errors. They run free, up to 10 times a day. Verifying your own results, through the walk-through or a CSV, is the paid verification: sign in with at least $25.00 of credit and run it from the same form, or call the API.
Sources
- 32 CFR 170.24: CMMC Scoring Methodology
- 32 CFR 170.21: Plan of Action and Milestones requirements
- 32 CFR 170.16: CMMC Level 2 self-assessment and affirmation
- 32 CFR 170.22: Affirmation
- DFARS 252.204-7021: Contractor compliance with the CMMC level requirement
- NIST SP 800-171 Rev 2: Protecting CUI in nonfederal systems
- NIST SP 800-171A: Assessing security requirements for CUI
- DoD CIO: implementing the suspension of CMMC Phase 2
- DOJ: $4.6 million settlement over cybersecurity requirements (March 2025)
- DOJ: $507,144 settlement after a DoD assessment score of -170 (June 2026)
- DLA: the CAGE code is five characters
SpreadRun is not affiliated with or endorsed by the Department of Defense, NIST or the Cyber AB. Where this check and the regulations differ, the regulations control.
More validators: WH-347 Certified Payroll Pre-Check | the full catalog