CMMC Self-Assessment Score Validator API Reference

Beta. Verifies one CMMC Level 2 self-assessment: the score recomputed with the CMMC Level 2 Scoring Methodology in 32 CFR 170.24, the POA&M rules in 170.21, the SPRS details in 170.16 and the affirmation in 170.22. Product page and free test form.

Endpoint

PaidPOST https://www.spreadrun.com/api/v1/cmmc-self-assessment-validator, API key required, $25.00 per completed verification
DemoPOST https://www.spreadrun.com/api/demo/cmmc-self-assessment-validator, no key, 10 runs per day. Runs the three published sample packages only (clean, conditional, errors); spacing and key order do not matter, any changed value does. Your own data goes to the paid endpoint.
BodyA JSON object, UTF-8, up to 256 KB. Text values up to 200 characters, except requirementsCsv; up to 300 requirement rows.

Request

asOfOptional. YYYY-MM-DD the dates are checked against. Default: today (UTC).
assessment.levelRequired. 2. Level 1 has no score and is not supported.
assessment.assessmentDateYYYY-MM-DD. Must not be in the future or three or more years old.
assessment.claimedScoreOptional whole number: the score you plan to post. Compared with the verified score.
assessment.cageCodesList of every industry CAGE code associated with the systems in scope. Each is five letters or digits.
assessment.scopeDefinedtrue when the CMMC Assessment Scope (every asset assessed) is defined.
assessment.sspInPlacetrue when a system security plan covers every system in scope. false means no score.
assessment.poamInPlacetrue when a POA&M is in place for every requirement not MET.
assessment.statusDateOptional. YYYY-MM-DD the result was posted in SPRS (the CMMC Status Date). Used for the 180-day POA&M closeout window.
affirmation.affirmingOfficialIdentifiedtrue when the Affirming Official is named. Do not send the name.
affirmation.titleAndContactProvidedtrue when their title and contact information are included.
affirmation.statementAffirmedtrue when the affirmation statement has been made.
affirmation.affirmationDateYYYY-MM-DD of the latest affirmation.
requirementsList of objects, one per requirement: id (3.1.1, or AC.L2-3.1.1) and status. Send this or requirementsCsv.
requirementsCsvCSV text with a header row naming a requirement column (requirement, requirement id, id or control) and a status column (status or result). Other columns are ignored. Up to 64 KB.

Start from the sample package or the CSV template. The sample contractor is invented and uses the placeholder CAGE code 00000.

Requirement results

METAll applicable assessment objectives are met. No deduction. Enduring exceptions and temporary deficiencies handled as the regulation describes count as MET.
NOT METOne or more objectives not met. The requirement's full value is deducted.
NOT APPLICABLEAlso N/A or NA. Counts as MET. 3.12.4 can never be N/A.
PARTIAL3.5.3 and 3.13.11 only, 3 points deducted instead of 5. 3.5.3: MFA is implemented only for remote and privileged users. 3.13.11: encryption is employed but is not FIPS-validated.

Case and spacing do not matter: Not Met and NOT_MET both read as NOT MET.

How the score is computed

  • Start at 110, the number of Level 2 requirements.
  • For each requirement NOT MET, subtract its value: 5, 3 or 1 point (table below). PARTIAL subtracts 3 for 3.5.3 and 3.13.11. The lowest possible score is -203.
  • 3.12.4, the system security plan, has no value: without an SSP the assessment cannot be completed and there is no score.
  • Final Level 2 (Self): 110. Conditional Level 2 (Self): at least 88 (0.8 of 110), and every NOT MET requirement allowed on a POA&M, which means a 1-point requirement or 3.13.11 as PARTIAL, and never 3.1.20, 3.1.22, 3.10.3, 3.10.4, 3.10.5 or 3.12.4.

Report

FieldMeaning
statusFAIL if any error, WARN if only warnings, otherwise PASS. A conditional result is at least WARN. A PASS is not a certification and does not mean DoD will accept the score.
verifiedScore, maxScoreThe recomputed score, or null when the package is incomplete or has no SSP.
bandkey (final, conditional, none or not-scored), label and reason.
claimedScoreprovided and matches (true, false or null). Your number is never repeated.
deductions, deductionsByFamilyEach requirement that cost points, with the points and whether partial credit applied, and the totals by family.
readinessThe submission checklist: requirements, ssp, score, poam, sprs, affirmation and status, each ready, review or fix.
findingsErrors first. Each has severity, ruleId, path, message, source and, where one applies, requirement. Findings never repeat a value from the input.
counts, findingCount, findingCounts, ruleCountsTotals.
methodology, notChecked, sources, scope, input, inputSha256The method and version used, what the report does not cover, where the rules come from, what the verdict means, and a fingerprint of the request body.

Rule IDs

RuleSeverityMeaning
CMMC-REQ-MISSINGerrorNo result for a requirement. No score is given until all 110 have one.
CMMC-REQ-UNKNOWNerrorA row that is not one of the 110 NIST SP 800-171 Rev 2 requirements, or has the wrong family prefix.
CMMC-REQ-DUPLICATEerrorA requirement given more than once.
CMMC-REQ-STATUSerrorA result other than MET, NOT MET, NOT APPLICABLE or PARTIAL.
CMMC-REQ-PARTIALerrorPARTIAL on a requirement other than 3.5.3 or 3.13.11.
CMMC-SSP-MISSINGerror3.12.4 not MET, marked N/A, or sspInPlace false. No score can be given.
CMMC-SSP-CONFIRMwarningsspInPlace not confirmed.
CMMC-SCORE-MISMATCHerrorThe claimed score differs from the verified score.
CMMC-SCORE-RANGEerrorThe claimed score is outside -203 to 110.
CMMC-POAM-MISSINGerrorRequirements are NOT MET and poamInPlace is not true.
CMMC-POAM-INELIGIBLEwarningA NOT MET requirement that may not be on a POA&M, so no Level 2 (Self) status is possible until it is MET.
CMMC-BAND-NONEwarningThe verified score does not reach a Level 2 (Self) status.
CMMC-BAND-CONDITIONALwarningConditional, not Final: the POA&M must be closed out within 180 days of the CMMC Status Date.
CMMC-STATUS-EXPIRINGwarningThe 180-day closeout window ends within 30 days of asOf.
CMMC-STATUS-EXPIREDerrorMore than 180 days since the CMMC Status Date of a conditional result.
CMMC-CAGE-MISSINGerrorNo CAGE code.
CMMC-CAGE-FORMATerrorA CAGE code that is not five letters or digits.
CMMC-CAGE-DUPLICATEwarningThe same CAGE code listed twice.
CMMC-SCOPE-MISSINGerrorscopeDefined is not true.
CMMC-DATE-MISSINGerrorNo assessment date.
CMMC-DATE-FORMATerrorAssessment date not in YYYY-MM-DD form.
CMMC-DATE-FUTUREerrorAssessment date after asOf.
CMMC-DATE-EXPIREDerrorAssessment three or more years before asOf.
CMMC-AFFIRM-MISSINGerrorOne of the three affirmation items is not true.
CMMC-AFFIRM-DATEerror or warningAffirmation date missing (warning) or not a valid date (error).
CMMC-AFFIRM-FUTUREerrorAffirmation date after asOf.
CMMC-AFFIRM-BEFOREerrorAffirmation dated before the assessment.
CMMC-AFFIRM-STALEerrorLatest affirmation a year or more before asOf.

Source keys, as returned in every report:

cfr170.2432 CFR 170.24, CMMC Scoring Methodology (Level 2 point values, partial credit, SSP, N/A)
cfr170.2132 CFR 170.21, Plan of Action and Milestones requirements (0.8 threshold, eligible requirements, 180-day closeout)
cfr170.1632 CFR 170.16, CMMC Level 2 self-assessment (SPRS contents, three-year cycle, affirmation)
cfr170.2232 CFR 170.22, Affirmation (Affirming Official, content, timing)
cfr170.432 CFR 170.4, Definitions (MET, NOT MET, N/A, CMMC Status Date, Affirming Official)
nist800-171NIST SP 800-171 Rev 2, the 110 CMMC Level 2 security requirements
nist800-171aNIST SP 800-171A (June 2018), assessment objectives (a requirement is MET only when all its applicable objectives are met)
dla-cageDefense Logistics Agency: the CAGE code is five characters

Not checked

  • Whether each requirement is really MET. The score is recomputed from the results you entered; SpreadRun does not see your systems, evidence or SSP.
  • Whether your assessment scope, asset categories and CAGE codes are the right ones for your contracts.
  • Whether the CAGE codes are registered to your company. Only their format is checked.
  • The SPRS entry itself, which you complete in SPRS.
  • Level 1 and Level 3 assessments, and C3PAO certification assessments.

Point values

From 32 CFR 170.24(c)(2)(i)(B). Requirement wording is shortened from NIST SP 800-171 Rev 2.

Access Control (AC)

RequirementPointsSummary
3.1.15Limit system access to authorized users, processes acting for them, and devices.
3.1.25Limit system access to the types of transactions and functions that authorized users may execute.
3.1.31Control the flow of CUI in accordance with approved authorizations.
3.1.41Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
3.1.53Employ least privilege, including for specific security functions and privileged accounts.
3.1.61Use non-privileged accounts or roles when accessing nonsecurity functions.
3.1.71Prevent non-privileged users from executing privileged functions, and log the execution of such functions.
3.1.81Limit unsuccessful logon attempts.
3.1.91Provide privacy and security notices consistent with applicable CUI rules.
3.1.101Use session lock with pattern-hiding displays after a period of inactivity.
3.1.111Terminate a user session automatically after a defined condition.
3.1.125Monitor and control remote access sessions.
3.1.135Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
3.1.141Route remote access through managed access control points.
3.1.151Authorize remote execution of privileged commands and remote access to security-relevant information.
3.1.165Authorize wireless access before allowing such connections.
3.1.175Protect wireless access using authentication and encryption.
3.1.185Control connection of mobile devices.
3.1.193Encrypt CUI on mobile devices and mobile computing platforms.
3.1.201Verify and control or limit connections to and use of external systems.
3.1.211Limit use of portable storage devices on external systems.
3.1.221Control CUI posted or processed on publicly accessible systems.

Awareness and Training (AT)

RequirementPointsSummary
3.2.15Make managers, administrators and users aware of the security risks of their activities and of applicable policies, standards and procedures.
3.2.25Train personnel to carry out their assigned information security duties.
3.2.31Provide security awareness training on recognizing and reporting potential indicators of insider threat.

Audit and Accountability (AU)

RequirementPointsSummary
3.3.15Create and retain system audit logs and records to enable monitoring, analysis, investigation and reporting of unlawful or unauthorized system activity.
3.3.23Ensure the actions of individual users can be uniquely traced to those users.
3.3.31Review and update logged events.
3.3.41Alert in the event of an audit logging process failure.
3.3.55Correlate audit record review, analysis and reporting processes.
3.3.61Provide audit record reduction and report generation.
3.3.71Compare and synchronize internal system clocks with an authoritative source for time stamps.
3.3.81Protect audit information and audit logging tools from unauthorized access, modification and deletion.
3.3.91Limit management of audit logging functionality to a subset of privileged users.

Configuration Management (CM)

RequirementPointsSummary
3.4.15Establish and maintain baseline configurations and inventories of systems.
3.4.25Establish and enforce security configuration settings.
3.4.31Track, review, approve or disapprove, and log changes to systems.
3.4.41Analyze the security impact of changes before implementation.
3.4.55Define, document, approve and enforce physical and logical access restrictions associated with changes.
3.4.65Employ the principle of least functionality.
3.4.75Restrict, disable or prevent the use of nonessential programs, functions, ports, protocols and services.
3.4.85Apply deny-by-exception or permit-by-exception policy to prevent the use of unauthorized software.
3.4.91Control and monitor user-installed software.

Identification and Authentication (IA)

RequirementPointsSummary
3.5.15Identify system users, processes acting for users, and devices.
3.5.25Authenticate the identities of users, processes or devices before allowing access.
3.5.35 (partial 3)Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
3.5.41Employ replay-resistant authentication for network access to privileged and non-privileged accounts.
3.5.51Prevent reuse of identifiers for a defined period.
3.5.61Disable identifiers after a defined period of inactivity.
3.5.71Enforce a minimum password complexity and change of characters when new passwords are created.
3.5.81Prohibit password reuse for a specified number of generations.
3.5.91Allow temporary passwords for system logons only with an immediate change to a permanent password.
3.5.105Store and transmit only cryptographically protected passwords.
3.5.111Obscure feedback of authentication information.

Incident Response (IR)

RequirementPointsSummary
3.6.15Establish an operational incident-handling capability, from preparation to recovery and user response.
3.6.25Track, document and report incidents to designated officials and authorities.
3.6.31Test the incident response capability.

Maintenance (MA)

RequirementPointsSummary
3.7.13Perform maintenance on systems.
3.7.25Control the tools, techniques, mechanisms and personnel used for system maintenance.
3.7.31Sanitize equipment removed for off-site maintenance of any CUI.
3.7.43Check media with diagnostic and test programs for malicious code before use.
3.7.55Require multifactor authentication for nonlocal maintenance sessions, and end them when maintenance is complete.
3.7.61Supervise maintenance by personnel without required access authorization.

Media Protection (MP)

RequirementPointsSummary
3.8.13Protect (physically control and securely store) system media containing CUI, paper and digital.
3.8.23Limit access to CUI on system media to authorized users.
3.8.35Sanitize or destroy system media containing CUI before disposal or release for reuse.
3.8.41Mark media with necessary CUI markings and distribution limitations.
3.8.51Control access to media containing CUI and keep accountability for it during transport outside controlled areas.
3.8.61Use cryptography to protect CUI on digital media during transport unless otherwise protected by alternative physical safeguards.
3.8.75Control the use of removable media on system components.
3.8.83Prohibit portable storage devices that have no identifiable owner.
3.8.91Protect the confidentiality of backup CUI at storage locations.

Personnel Security (PS)

RequirementPointsSummary
3.9.13Screen individuals before authorizing access to systems containing CUI.
3.9.25Protect systems containing CUI during and after personnel actions such as terminations and transfers.

Physical Protection (PE)

RequirementPointsSummary
3.10.15Limit physical access to systems, equipment and operating environments to authorized individuals.
3.10.25Protect and monitor the physical facility and support infrastructure.
3.10.31Escort visitors and monitor visitor activity.
3.10.41Maintain audit logs of physical access.
3.10.51Control and manage physical access devices.
3.10.61Enforce safeguarding measures for CUI at alternate work sites.

Risk Assessment (RA)

RequirementPointsSummary
3.11.13Periodically assess the risk to operations, assets and individuals from operating organizational systems and processing, storing or transmitting CUI.
3.11.25Scan for vulnerabilities periodically and when new vulnerabilities are identified.
3.11.31Remediate vulnerabilities in accordance with risk assessments.

Security Assessment (CA)

RequirementPointsSummary
3.12.15Periodically assess the security controls to determine whether they are effective.
3.12.23Develop and implement plans of action to correct deficiencies and reduce or eliminate vulnerabilities.
3.12.35Monitor security controls on an ongoing basis.
3.12.4none (SSP)Develop, document and periodically update system security plans.

System and Communications Protection (SC)

RequirementPointsSummary
3.13.15Monitor, control and protect communications at external and key internal boundaries.
3.13.25Employ architectural designs, development techniques and engineering principles that promote effective security.
3.13.31Separate user functionality from system management functionality.
3.13.41Prevent unauthorized and unintended information transfer through shared system resources.
3.13.55Implement subnetworks for publicly accessible components, separated from internal networks.
3.13.65Deny network traffic by default and allow it by exception.
3.13.71Prevent remote devices from connecting to organizational systems while also connecting to resources in external networks (split tunneling).
3.13.83Use cryptography to prevent unauthorized disclosure of CUI in transmission unless otherwise protected.
3.13.91Terminate network connections at the end of sessions or after a defined period of inactivity.
3.13.101Establish and manage cryptographic keys for the cryptography employed.
3.13.115 (partial 3)Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
3.13.121Prohibit remote activation of collaborative computing devices and show users when devices are in use.
3.13.131Control and monitor the use of mobile code.
3.13.141Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.
3.13.155Protect the authenticity of communications sessions.
3.13.161Protect the confidentiality of CUI at rest.

System and Information Integrity (SI)

RequirementPointsSummary
3.14.15Identify, report and correct system flaws in a timely manner.
3.14.25Provide protection from malicious code at designated locations.
3.14.35Monitor system security alerts and advisories and take action in response.
3.14.45Update malicious code protection mechanisms when new releases are available.
3.14.53Perform periodic scans of systems and real-time scans of files from external sources.
3.14.65Monitor systems, including inbound and outbound traffic, to detect attacks and indicators of potential attacks.
3.14.73Identify unauthorized use of systems.

Example responses

A paid verification of the sample package (report shortened), and the findings from a demo run of the sample with errors. Both generated by running the real endpoint code.

{
  "requestId": "7f3c2a1e-5b8d-4c6f-9e0a-1d2b3c4d5e6f",
  "api": "cmmc-self-assessment-validator",
  "mode": "paid",
  "charged": true,
  "priceCents": 2500,
  "balanceCents": 7500,
  "report": {
    "schemaVersion": 1,
    "status": "PASS",
    "level": 2,
    "asOf": "2026-10-05",
    "verifiedScore": 110,
    "maxScore": 110,
    "band": {
      "key": "final",
      "label": "Final Level 2 (Self) score",
      "reason": "All requirements MET or N/A: 110 of 110."
    },
    "claimedScore": {
      "provided": true,
      "matches": true
    },
    "counts": {
      "met": 108,
      "notMet": 0,
      "partial": 0,
      "notApplicable": 2,
      "assessed": 110,
      "required": 110,
      "pointsDeducted": 0
    },
    "deductions": [],
    "deductionsByFamily": {},
    "readiness": [
      {
        "item": "requirements",
        "label": "All 110 requirements assessed, once each",
        "status": "ready"
      },
      {
        "item": "ssp",
        "label": "System security plan in place (3.12.4)",
        "status": "ready"
      },
      {
        "item": "score",
        "label": "Score verified against the methodology",
        "status": "ready"
      },
      {
        "item": "poam",
        "label": "POA&M in place and allowed for every NOT MET requirement",
        "status": "ready"
      },
      {
        "item": "sprs",
        "label": "SPRS details: level, date, scope and CAGE codes",
        "status": "ready"
      },
      {
        "item": "affirmation",
        "label": "Affirmation by the Affirming Official",
        "status": "ready"
      },
      {
        "item": "status",
        "label": "Score reaches a Level 2 (Self) status",
        "status": "ready"
      }
    ],
    "findingCount": 0,
    "findingCounts": {
      "error": 0,
      "warning": 0
    },
    "ruleCounts": {},
    "methodology": {
      "name": "CMMC Level 2 Scoring Methodology",
      "regulation": "32 CFR 170.24, as in effect October 2026",
      "requirements": "NIST SP 800-171 Rev 2 (110 requirements), assessed with NIST SP 800-171A (June 2018)",
      "maxScore": 110,
      "minScore": -203,
      "conditionalMinimum": 88
    },
    "scope": "A verified score is arithmetic from the results you entered, checked against the published CMMC scoring methodology. It is not a CMMC certification or assessment, not legal or compliance advice, and a PASS does not mean your company meets NIST SP 800-171 or that DoD will accept the score.",
    "input": {
      "format": "json",
      "bytes": 5541
    },
    "inputSha256": "e1a4e2037578048573503b1d32820c6157e57a52bb6d19fa97565e9e4eef9019"
  }
}
[
  {
    "severity": "error",
    "ruleId": "CMMC-AFFIRM-BEFORE",
    "path": "/affirmation/affirmationDate",
    "message": "The affirmation is dated before the assessment. An affirmation is required at the time of each assessment.",
    "source": "cfr170.22"
  },
  {
    "severity": "error",
    "ruleId": "CMMC-AFFIRM-MISSING",
    "path": "/affirmation/statementAffirmed",
    "message": "The affirmation statement attests that all applicable CMMC requirements are implemented and will stay implemented. It has not been made.",
    "source": "cfr170.22"
  },
  {
    "severity": "error",
    "ruleId": "CMMC-CAGE-FORMAT",
    "path": "/assessment/cageCodes[1]",
    "message": "A CAGE code is five characters, letters and digits only.",
    "source": "dla-cage"
  },
  {
    "severity": "error",
    "ruleId": "CMMC-POAM-MISSING",
    "path": "/assessment/poamInPlace",
    "message": "There are NOT MET requirements, so a POA&M must be in place for each one (poamInPlace: true). A POA&M is not a substitute for a completed requirement, and the points stay deducted.",
    "source": "cfr170.24"
  },
  {
    "severity": "error",
    "ruleId": "CMMC-SCORE-MISMATCH",
    "path": "/assessment/claimedScore",
    "message": "The claimed score does not match the score recomputed from the requirement results. Post the verified score, or correct the results it came from.",
    "source": "cfr170.24"
  },
  {
    "severity": "warning",
    "ruleId": "CMMC-BAND-NONE",
    "path": "/score",
    "message": "This score does not reach a Level 2 (Self) status. It can still be posted, but a contract that requires Level 2 (Self) cannot be awarded on it.",
    "source": "cfr170.21"
  }
]

Errors

See the shared error table. Rejected with HTTP 400 and not charged: a body that is not a JSON object, no assessment object, a level other than 2, no requirement results, both or neither of requirements and requirementsCsv, a CSV without requirement and status columns, or wrong value types; on the demo endpoint, anything other than a sample package. Example (HTTP 400):

{
  "error": {
    "code": "input_error",
    "message": "assessment.level must be 2. Only CMMC Level 2 self-assessments are scored; Level 1 is MET or NOT MET in its entirety, with no score.",
    "requestId": "7f3c2a1e-5b8d-4c6f-9e0a-1d2b3c4d5e6f",
    "charged": false
  }
}

Code samples

curl -X POST "https://www.spreadrun.com/api/v1/cmmc-self-assessment-validator" \
  -H "Authorization: Bearer $SPREADRUN_API_KEY" \
  -H "Content-Type: application/json" \
  --data-binary @self_assessment.json