Built by SpreadRunBeta

CMMC Self-Assessment Score Validator

Check the math before you post it. Send your CMMC Level 2 self-assessment results, all 110 NIST SP 800-171 Rev 2 requirements, with the details that go into SPRS. You get back the score recomputed with the published DoD method, whether it matches the score you planned to post, what the result qualifies for, and every gap in the package, each with its rule and source.

Why the number matters

  • The score is yours to stand behind. A Level 2 self-assessment is posted in SPRS and affirmed by a senior official, at each assessment and every year after.
  • False Claims Act exposure. In March 2025 a defense contractor paid $4.6 million to settle allegations that included a posted score of 104 that a consultant later put at -142. In June 2026 another paid $507,144 after a DoD assessment scored it -170, near the bottom of the -203 to 110 range.
  • Self-assessment carries the weight. DoD suspended the planned November 2026 move to Phase 2, so Level 2 (Self) stays the designation for CUI work.

Sources: the DOJ releases, DFARS 252.204-7021 and the DoD CIO memo, linked at the bottom of this page.

Where this fits. SPRS has no file upload for this: you type the score and details into SPRS yourself. SpreadRun checks the package before you do. The scoring method is public and free spreadsheets exist; what this adds is verified math with the rule cited on every finding, the POA&M limits spreadsheets tend to skip, the SPRS and affirmation checks, and an API for consultants and MSPs who run many clients.

A verified score is arithmetic, not a certification. It is computed from the results you enter. It is not a CMMC assessment, not legal or compliance advice, and a PASS does not mean your company meets NIST SP 800-171 or that DoD will accept the score.

What it checks

  • The score. 110 minus the published value of each requirement NOT MET: 5, 3 or 1 point, with partial credit only for 3.5.3 (multifactor authentication) and 3.13.11 (FIPS-validated cryptography). N/A counts as MET.
  • Your claimed score. Flagged if it does not match the recomputed score, or falls outside -203 to 110.
  • Completeness. All 110 requirements, each once, with a valid result. Unknown or duplicate rows are flagged.
  • The system security plan. 3.12.4 must be MET. Without an SSP no score can be posted.
  • POA&M rules. A POA&M for every NOT MET requirement, and each one allowed on a POA&M: 1-point requirements, plus 3.13.11 when encryption is not FIPS-validated, never the six that are excluded.
  • The threshold. Final (110), Conditional (at least 88, every gap allowed on a POA&M), or no Level 2 (Self) status, with the 180-day POA&M closeout window when you give the CMMC Status Date.
  • SPRS details. At least one CAGE code, each five characters; a defined assessment scope; an assessment date that is real, not in the future and under three years old.
  • The affirmation. Official named, title and contact included, statement made, dated on or after the assessment and within the last year.

Every report ends with a submission checklist: each area marked Ready, Review or Fix.

Who it's for

  • Defense contractors and subcontractors: check the number before the senior official affirms it.
  • MSPs and MSSPs: run every client through the same check, from a script.
  • Readiness consultants: a second look at a client's math, with the rule behind each finding.
  • Software and automation: a plain REST endpoint with JSON in and JSON out.

Not checked

  • Whether each requirement is really MET. SpreadRun never sees your systems, evidence or SSP.
  • Whether your scope, asset categories and CAGE codes are the right ones for your contracts.
  • Whether a CAGE code is registered to you. Only the format is checked.
  • The SPRS entry itself.
  • Level 1 and Level 3, and C3PAO certification assessments.

Input and output

  1. Send

    JSON with assessment (level 2, assessment date, claimed score, CAGE codes, and yes or no for scope, SSP and POA&M), affirmation (yes or no for each part, and the date), and the 110 results as a list or as the CSV you already keep. Up to 256 KB.

  2. Check

    Every rule on this page. No network calls, nothing stored.

  3. Report

    JSON with verifiedScore, band, claimedScore, deductions (requirement and points), readiness (the checklist) and findings (severity, ruleId, path, requirement, message, source).

Every field and all rule IDs are in the API docs.

Try it now

The sample packages run free. Your own results, answered here or uploaded as a CSV, run as a paid verification at $25.00 from your credit.

Free demo, no account: the three sample packages, 10 runs a day. For full validations from this form, sign in and buy credits: $25.00 per completed report, packs from $50.

Assessment and SPRS details

Affirmation

We never ask for names. Each box is a yes or no.

Requirement results

0 of 110 answered. , then change the exceptions. PARTIAL is only offered where the method gives partial credit.

Access Control (22)
Awareness and Training (3)
Audit and Accountability (9)
Configuration Management (9)
Identification and Authentication (11)
PARTIAL: MFA is implemented only for remote and privileged users.
Incident Response (3)
Maintenance (6)
Media Protection (9)
Personnel Security (2)
Physical Protection (6)
Risk Assessment (3)
Security Assessment (4)
System and Communications Protection (16)
PARTIAL: Encryption is employed but is not FIPS-validated.
System and Information Integrity (7)

Processed in memory and not stored. Reports never repeat your CAGE codes, dates or scores you entered.

Sample report
Invented contractor with planted errors
FAIL
Verified score94 of 110No Level 2 (Self) status
Claimed score does not match6 not MET16 points deducted5 errors5 warnings
  • ReadyAll 110 requirements assessed, once each
  • ReadySystem security plan in place (3.12.4)
  • FixScore verified against the methodology
  • FixPOA&M in place and allowed for every NOT MET requirement
  • FixSPRS details: level, date, scope and CAGE codes
  • FixAffirmation by the Affirming Official
  • ReviewScore reaches a Level 2 (Self) status
Deductions (6)
RequirementPoints
3.1.10-1
3.3.4-1
3.5.3 (partial)-3
3.10.4-1
3.13.11-5
3.14.6-5
SeverityRuleWhere and what
ErrorCMMC-AFFIRM-BEFORE/affirmation/affirmationDate
The affirmation is dated before the assessment. An affirmation is required at the time of each assessment.
ErrorCMMC-AFFIRM-MISSING/affirmation/statementAffirmed
The affirmation statement attests that all applicable CMMC requirements are implemented and will stay implemented. It has not been made.
ErrorCMMC-CAGE-FORMAT/assessment/cageCodes[1]
A CAGE code is five characters, letters and digits only.
ErrorCMMC-POAM-MISSING/assessment/poamInPlace
There are NOT MET requirements, so a POA&M must be in place for each one (poamInPlace: true). A POA&M is not a substitute for a completed requirement, and the points stay deducted.
ErrorCMMC-SCORE-MISMATCH/assessment/claimedScore
The claimed score does not match the score recomputed from the requirement results. Post the verified score, or correct the results it came from.
WarningCMMC-BAND-NONE/score
This score does not reach a Level 2 (Self) status. It can still be posted, but a contract that requires Level 2 (Self) cannot be awarded on it.
WarningCMMC-POAM-INELIGIBLE/requirement/3.10.4
NOT MET, and this requirement is on the list that may never be on a POA&M. It must be MET before a Level 2 (Self) status is possible.
WarningCMMC-POAM-INELIGIBLE/requirement/3.13.11
NOT MET, and this requirement is worth more than 1 point as scored, and only 1-point requirements (or 3.13.11 when encryption is employed but not FIPS-validated) may be on a POA&M. It must be MET before a Level 2 (Self) status is possible.
WarningCMMC-POAM-INELIGIBLE/requirement/3.14.6
NOT MET, and this requirement is worth more than 1 point as scored, and only 1-point requirements (or 3.13.11 when encryption is employed but not FIPS-validated) may be on a POA&M. It must be MET before a Level 2 (Self) status is possible.
WarningCMMC-POAM-INELIGIBLE/requirement/3.5.3
NOT MET, and this requirement is worth more than 1 point as scored, and only 1-point requirements (or 3.13.11 when encryption is employed but not FIPS-validated) may be on a POA&M. It must be MET before a Level 2 (Self) status is possible.

Pricing

$25.00 per completed verification. One self-assessment, one full report.

  • Billed when a report is produced, PASS, WARN or FAIL. Invalid input is never billed.
  • Paid from the same prepaid credits as every SpreadRun API, in $5, $20, $50 or $100 packs. A $50 pack covers 2 verifications and a $100 pack covers 4. Credits never expire. All pricing
  • Running many clients? Talk to us first so we can tell you honestly whether this fits.

Call it from code

Fields, rule IDs, error codes and limits are in the API docs.

curl -X POST "https://www.spreadrun.com/api/v1/cmmc-self-assessment-validator" \
  -H "Authorization: Bearer $SPREADRUN_API_KEY" \
  -H "Content-Type: application/json" \
  --data-binary @self_assessment.json

Questions

Does a PASS mean we are compliant, or that DoD will accept our score?

No. A PASS means the score you plan to post matches the published scoring method applied to the results you entered, and that the package has what SPRS and the affirmation need. SpreadRun cannot see your systems or evidence, so it cannot tell whether a requirement is really MET. A verified score is arithmetic, not a CMMC certification or assessment, and not legal or compliance advice.

The scoring method is public. Why pay for this?

It is public, and free scoring spreadsheets exist. If a spreadsheet works for you, use it. What this adds: the math checked against the regulation with the rule cited on every finding, the POA&M limits a spreadsheet usually skips (which requirements may never be on one, and the partial-credit exceptions), the SPRS and affirmation details, and an API so a consultant or MSP can run every client the same way.

How is the score calculated?

Start at 110, one point per requirement. For each requirement NOT MET, subtract its value from 32 CFR 170.24: 5, 3 or 1 point. Two requirements give partial credit: 3.5.3 costs 3 points instead of 5 if multifactor authentication covers only remote and privileged users, and 3.13.11 costs 3 instead of 5 if encryption is used but is not FIPS-validated. N/A counts as MET. The lowest possible score is -203. Without a system security plan (3.12.4) there is no score at all.

What makes a score Conditional or Final?

Final Level 2 (Self) needs every requirement MET or N/A: 110. Conditional needs a score of at least 0.8 of 110, which is 88, with every NOT MET requirement allowed on a POA&M: only 1-point requirements, plus 3.13.11 when encryption is used but not FIPS-validated, and never 3.1.20, 3.1.22, 3.10.3, 3.10.4, 3.10.5 or 3.12.4. The POA&M must then be closed out within 180 days of the CMMC Status Date, or the conditional status expires.

Does the Phase 2 suspension change anything here?

Not for self-assessments. DoD suspended the planned November 2026 move to Phase 2, which leaves Level 1 (Self) and Level 2 (Self) as the designations in use. Where a contract includes DFARS 252.204-7021, the contractor still enters current self-assessment results in SPRS and keeps an annual affirmation current. Check the sources below for anything newer.

Why do you not ask for the Affirming Official's name?

Because nothing in the check needs it, and SpreadRun does not take personal data. The affirmation checks are yes or no: is the official named, are title and contact information included, and has the statement been made.

Is my data stored?

No. The package is processed in memory for the length of the request and is not stored or shared. The report names requirement IDs and rules, never your CAGE codes, dates or the score you claimed. For billing and usage we log the time, endpoint, result status, size and duration, never the contents.

When is a run charged?

When the verification finishes and returns a report, whether it says PASS, WARN or FAIL: $25.00 per completed verification. Requests rejected before a report exists are free, such as a body that is not JSON, a level other than 2, or no requirement results.

Can I try it for free?

Yes, on the three sample packages on this page: a clean 110, a conditional result and a package with errors. They run free, up to 10 times a day. Verifying your own results, through the walk-through or a CSV, is the paid verification: sign in with at least $25.00 of credit and run it from the same form, or call the API.

Sources

SpreadRun is not affiliated with or endorsed by the Department of Defense, NIST or the Cyber AB. Where this check and the regulations differ, the regulations control.

More validators: WH-347 Certified Payroll Pre-Check | the full catalog