CMMC Self-Assessment Score Validator API Reference
Beta. Verifies one CMMC Level 2 self-assessment: the score recomputed with the CMMC Level 2 Scoring Methodology in 32 CFR 170.24, the POA&M rules in 170.21, the SPRS details in 170.16 and the affirmation in 170.22. Product page and free test form.
Endpoint
| Paid | POST https://www.spreadrun.com/api/v1/cmmc-self-assessment-validator, API key required, $25.00 per completed verification |
|---|---|
| Demo | POST https://www.spreadrun.com/api/demo/cmmc-self-assessment-validator, no key, 10 runs per day. Runs the three published sample packages only (clean, conditional, errors); spacing and key order do not matter, any changed value does. Your own data goes to the paid endpoint. |
| Body | A JSON object, UTF-8, up to 256 KB. Text values up to 200 characters, except requirementsCsv; up to 300 requirement rows. |
Request
asOf | Optional. YYYY-MM-DD the dates are checked against. Default: today (UTC). |
assessment.level | Required. 2. Level 1 has no score and is not supported. |
assessment.assessmentDate | YYYY-MM-DD. Must not be in the future or three or more years old. |
assessment.claimedScore | Optional whole number: the score you plan to post. Compared with the verified score. |
assessment.cageCodes | List of every industry CAGE code associated with the systems in scope. Each is five letters or digits. |
assessment.scopeDefined | true when the CMMC Assessment Scope (every asset assessed) is defined. |
assessment.sspInPlace | true when a system security plan covers every system in scope. false means no score. |
assessment.poamInPlace | true when a POA&M is in place for every requirement not MET. |
assessment.statusDate | Optional. YYYY-MM-DD the result was posted in SPRS (the CMMC Status Date). Used for the 180-day POA&M closeout window. |
affirmation.affirmingOfficialIdentified | true when the Affirming Official is named. Do not send the name. |
affirmation.titleAndContactProvided | true when their title and contact information are included. |
affirmation.statementAffirmed | true when the affirmation statement has been made. |
affirmation.affirmationDate | YYYY-MM-DD of the latest affirmation. |
requirements | List of objects, one per requirement: id (3.1.1, or AC.L2-3.1.1) and status. Send this or requirementsCsv. |
requirementsCsv | CSV text with a header row naming a requirement column (requirement, requirement id, id or control) and a status column (status or result). Other columns are ignored. Up to 64 KB. |
Start from the sample package or the CSV template. The sample contractor is invented and uses the placeholder CAGE code 00000.
Requirement results
MET | All applicable assessment objectives are met. No deduction. Enduring exceptions and temporary deficiencies handled as the regulation describes count as MET. |
NOT MET | One or more objectives not met. The requirement's full value is deducted. |
NOT APPLICABLE | Also N/A or NA. Counts as MET. 3.12.4 can never be N/A. |
PARTIAL | 3.5.3 and 3.13.11 only, 3 points deducted instead of 5. 3.5.3: MFA is implemented only for remote and privileged users. 3.13.11: encryption is employed but is not FIPS-validated. |
Case and spacing do not matter: Not Met and NOT_MET both read as NOT MET.
How the score is computed
- Start at 110, the number of Level 2 requirements.
- For each requirement NOT MET, subtract its value: 5, 3 or 1 point (table below). PARTIAL subtracts 3 for 3.5.3 and 3.13.11. The lowest possible score is -203.
- 3.12.4, the system security plan, has no value: without an SSP the assessment cannot be completed and there is no score.
- Final Level 2 (Self): 110. Conditional Level 2 (Self): at least 88 (0.8 of 110), and every NOT MET requirement allowed on a POA&M, which means a 1-point requirement or 3.13.11 as PARTIAL, and never 3.1.20, 3.1.22, 3.10.3, 3.10.4, 3.10.5 or 3.12.4.
Report
| Field | Meaning |
|---|---|
status | FAIL if any error, WARN if only warnings, otherwise PASS. A conditional result is at least WARN. A PASS is not a certification and does not mean DoD will accept the score. |
verifiedScore, maxScore | The recomputed score, or null when the package is incomplete or has no SSP. |
band | key (final, conditional, none or not-scored), label and reason. |
claimedScore | provided and matches (true, false or null). Your number is never repeated. |
deductions, deductionsByFamily | Each requirement that cost points, with the points and whether partial credit applied, and the totals by family. |
readiness | The submission checklist: requirements, ssp, score, poam, sprs, affirmation and status, each ready, review or fix. |
findings | Errors first. Each has severity, ruleId, path, message, source and, where one applies, requirement. Findings never repeat a value from the input. |
counts, findingCount, findingCounts, ruleCounts | Totals. |
methodology, notChecked, sources, scope, input, inputSha256 | The method and version used, what the report does not cover, where the rules come from, what the verdict means, and a fingerprint of the request body. |
Rule IDs
| Rule | Severity | Meaning |
|---|---|---|
CMMC-REQ-MISSING | error | No result for a requirement. No score is given until all 110 have one. |
CMMC-REQ-UNKNOWN | error | A row that is not one of the 110 NIST SP 800-171 Rev 2 requirements, or has the wrong family prefix. |
CMMC-REQ-DUPLICATE | error | A requirement given more than once. |
CMMC-REQ-STATUS | error | A result other than MET, NOT MET, NOT APPLICABLE or PARTIAL. |
CMMC-REQ-PARTIAL | error | PARTIAL on a requirement other than 3.5.3 or 3.13.11. |
CMMC-SSP-MISSING | error | 3.12.4 not MET, marked N/A, or sspInPlace false. No score can be given. |
CMMC-SSP-CONFIRM | warning | sspInPlace not confirmed. |
CMMC-SCORE-MISMATCH | error | The claimed score differs from the verified score. |
CMMC-SCORE-RANGE | error | The claimed score is outside -203 to 110. |
CMMC-POAM-MISSING | error | Requirements are NOT MET and poamInPlace is not true. |
CMMC-POAM-INELIGIBLE | warning | A NOT MET requirement that may not be on a POA&M, so no Level 2 (Self) status is possible until it is MET. |
CMMC-BAND-NONE | warning | The verified score does not reach a Level 2 (Self) status. |
CMMC-BAND-CONDITIONAL | warning | Conditional, not Final: the POA&M must be closed out within 180 days of the CMMC Status Date. |
CMMC-STATUS-EXPIRING | warning | The 180-day closeout window ends within 30 days of asOf. |
CMMC-STATUS-EXPIRED | error | More than 180 days since the CMMC Status Date of a conditional result. |
CMMC-CAGE-MISSING | error | No CAGE code. |
CMMC-CAGE-FORMAT | error | A CAGE code that is not five letters or digits. |
CMMC-CAGE-DUPLICATE | warning | The same CAGE code listed twice. |
CMMC-SCOPE-MISSING | error | scopeDefined is not true. |
CMMC-DATE-MISSING | error | No assessment date. |
CMMC-DATE-FORMAT | error | Assessment date not in YYYY-MM-DD form. |
CMMC-DATE-FUTURE | error | Assessment date after asOf. |
CMMC-DATE-EXPIRED | error | Assessment three or more years before asOf. |
CMMC-AFFIRM-MISSING | error | One of the three affirmation items is not true. |
CMMC-AFFIRM-DATE | error or warning | Affirmation date missing (warning) or not a valid date (error). |
CMMC-AFFIRM-FUTURE | error | Affirmation date after asOf. |
CMMC-AFFIRM-BEFORE | error | Affirmation dated before the assessment. |
CMMC-AFFIRM-STALE | error | Latest affirmation a year or more before asOf. |
Source keys, as returned in every report:
cfr170.24 | 32 CFR 170.24, CMMC Scoring Methodology (Level 2 point values, partial credit, SSP, N/A) |
cfr170.21 | 32 CFR 170.21, Plan of Action and Milestones requirements (0.8 threshold, eligible requirements, 180-day closeout) |
cfr170.16 | 32 CFR 170.16, CMMC Level 2 self-assessment (SPRS contents, three-year cycle, affirmation) |
cfr170.22 | 32 CFR 170.22, Affirmation (Affirming Official, content, timing) |
cfr170.4 | 32 CFR 170.4, Definitions (MET, NOT MET, N/A, CMMC Status Date, Affirming Official) |
nist800-171 | NIST SP 800-171 Rev 2, the 110 CMMC Level 2 security requirements |
nist800-171a | NIST SP 800-171A (June 2018), assessment objectives (a requirement is MET only when all its applicable objectives are met) |
dla-cage | Defense Logistics Agency: the CAGE code is five characters |
- 32 CFR 170.24: CMMC Scoring Methodology
- 32 CFR 170.21: Plan of Action and Milestones requirements
- 32 CFR 170.16: CMMC Level 2 self-assessment and affirmation
- 32 CFR 170.22: Affirmation
- DFARS 252.204-7021: Contractor compliance with the CMMC level requirement
- NIST SP 800-171 Rev 2: Protecting CUI in nonfederal systems
- NIST SP 800-171A: Assessing security requirements for CUI
- DoD CIO: implementing the suspension of CMMC Phase 2
- DOJ: $4.6 million settlement over cybersecurity requirements (March 2025)
- DOJ: $507,144 settlement after a DoD assessment score of -170 (June 2026)
- DLA: the CAGE code is five characters
Not checked
- Whether each requirement is really MET. The score is recomputed from the results you entered; SpreadRun does not see your systems, evidence or SSP.
- Whether your assessment scope, asset categories and CAGE codes are the right ones for your contracts.
- Whether the CAGE codes are registered to your company. Only their format is checked.
- The SPRS entry itself, which you complete in SPRS.
- Level 1 and Level 3 assessments, and C3PAO certification assessments.
Point values
From 32 CFR 170.24(c)(2)(i)(B). Requirement wording is shortened from NIST SP 800-171 Rev 2.
Access Control (AC)
| Requirement | Points | Summary |
|---|---|---|
3.1.1 | 5 | Limit system access to authorized users, processes acting for them, and devices. |
3.1.2 | 5 | Limit system access to the types of transactions and functions that authorized users may execute. |
3.1.3 | 1 | Control the flow of CUI in accordance with approved authorizations. |
3.1.4 | 1 | Separate the duties of individuals to reduce the risk of malevolent activity without collusion. |
3.1.5 | 3 | Employ least privilege, including for specific security functions and privileged accounts. |
3.1.6 | 1 | Use non-privileged accounts or roles when accessing nonsecurity functions. |
3.1.7 | 1 | Prevent non-privileged users from executing privileged functions, and log the execution of such functions. |
3.1.8 | 1 | Limit unsuccessful logon attempts. |
3.1.9 | 1 | Provide privacy and security notices consistent with applicable CUI rules. |
3.1.10 | 1 | Use session lock with pattern-hiding displays after a period of inactivity. |
3.1.11 | 1 | Terminate a user session automatically after a defined condition. |
3.1.12 | 5 | Monitor and control remote access sessions. |
3.1.13 | 5 | Employ cryptographic mechanisms to protect the confidentiality of remote access sessions. |
3.1.14 | 1 | Route remote access through managed access control points. |
3.1.15 | 1 | Authorize remote execution of privileged commands and remote access to security-relevant information. |
3.1.16 | 5 | Authorize wireless access before allowing such connections. |
3.1.17 | 5 | Protect wireless access using authentication and encryption. |
3.1.18 | 5 | Control connection of mobile devices. |
3.1.19 | 3 | Encrypt CUI on mobile devices and mobile computing platforms. |
3.1.20 | 1 | Verify and control or limit connections to and use of external systems. |
3.1.21 | 1 | Limit use of portable storage devices on external systems. |
3.1.22 | 1 | Control CUI posted or processed on publicly accessible systems. |
Awareness and Training (AT)
| Requirement | Points | Summary |
|---|---|---|
3.2.1 | 5 | Make managers, administrators and users aware of the security risks of their activities and of applicable policies, standards and procedures. |
3.2.2 | 5 | Train personnel to carry out their assigned information security duties. |
3.2.3 | 1 | Provide security awareness training on recognizing and reporting potential indicators of insider threat. |
Audit and Accountability (AU)
| Requirement | Points | Summary |
|---|---|---|
3.3.1 | 5 | Create and retain system audit logs and records to enable monitoring, analysis, investigation and reporting of unlawful or unauthorized system activity. |
3.3.2 | 3 | Ensure the actions of individual users can be uniquely traced to those users. |
3.3.3 | 1 | Review and update logged events. |
3.3.4 | 1 | Alert in the event of an audit logging process failure. |
3.3.5 | 5 | Correlate audit record review, analysis and reporting processes. |
3.3.6 | 1 | Provide audit record reduction and report generation. |
3.3.7 | 1 | Compare and synchronize internal system clocks with an authoritative source for time stamps. |
3.3.8 | 1 | Protect audit information and audit logging tools from unauthorized access, modification and deletion. |
3.3.9 | 1 | Limit management of audit logging functionality to a subset of privileged users. |
Configuration Management (CM)
| Requirement | Points | Summary |
|---|---|---|
3.4.1 | 5 | Establish and maintain baseline configurations and inventories of systems. |
3.4.2 | 5 | Establish and enforce security configuration settings. |
3.4.3 | 1 | Track, review, approve or disapprove, and log changes to systems. |
3.4.4 | 1 | Analyze the security impact of changes before implementation. |
3.4.5 | 5 | Define, document, approve and enforce physical and logical access restrictions associated with changes. |
3.4.6 | 5 | Employ the principle of least functionality. |
3.4.7 | 5 | Restrict, disable or prevent the use of nonessential programs, functions, ports, protocols and services. |
3.4.8 | 5 | Apply deny-by-exception or permit-by-exception policy to prevent the use of unauthorized software. |
3.4.9 | 1 | Control and monitor user-installed software. |
Identification and Authentication (IA)
| Requirement | Points | Summary |
|---|---|---|
3.5.1 | 5 | Identify system users, processes acting for users, and devices. |
3.5.2 | 5 | Authenticate the identities of users, processes or devices before allowing access. |
3.5.3 | 5 (partial 3) | Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts. |
3.5.4 | 1 | Employ replay-resistant authentication for network access to privileged and non-privileged accounts. |
3.5.5 | 1 | Prevent reuse of identifiers for a defined period. |
3.5.6 | 1 | Disable identifiers after a defined period of inactivity. |
3.5.7 | 1 | Enforce a minimum password complexity and change of characters when new passwords are created. |
3.5.8 | 1 | Prohibit password reuse for a specified number of generations. |
3.5.9 | 1 | Allow temporary passwords for system logons only with an immediate change to a permanent password. |
3.5.10 | 5 | Store and transmit only cryptographically protected passwords. |
3.5.11 | 1 | Obscure feedback of authentication information. |
Incident Response (IR)
| Requirement | Points | Summary |
|---|---|---|
3.6.1 | 5 | Establish an operational incident-handling capability, from preparation to recovery and user response. |
3.6.2 | 5 | Track, document and report incidents to designated officials and authorities. |
3.6.3 | 1 | Test the incident response capability. |
Maintenance (MA)
| Requirement | Points | Summary |
|---|---|---|
3.7.1 | 3 | Perform maintenance on systems. |
3.7.2 | 5 | Control the tools, techniques, mechanisms and personnel used for system maintenance. |
3.7.3 | 1 | Sanitize equipment removed for off-site maintenance of any CUI. |
3.7.4 | 3 | Check media with diagnostic and test programs for malicious code before use. |
3.7.5 | 5 | Require multifactor authentication for nonlocal maintenance sessions, and end them when maintenance is complete. |
3.7.6 | 1 | Supervise maintenance by personnel without required access authorization. |
Media Protection (MP)
| Requirement | Points | Summary |
|---|---|---|
3.8.1 | 3 | Protect (physically control and securely store) system media containing CUI, paper and digital. |
3.8.2 | 3 | Limit access to CUI on system media to authorized users. |
3.8.3 | 5 | Sanitize or destroy system media containing CUI before disposal or release for reuse. |
3.8.4 | 1 | Mark media with necessary CUI markings and distribution limitations. |
3.8.5 | 1 | Control access to media containing CUI and keep accountability for it during transport outside controlled areas. |
3.8.6 | 1 | Use cryptography to protect CUI on digital media during transport unless otherwise protected by alternative physical safeguards. |
3.8.7 | 5 | Control the use of removable media on system components. |
3.8.8 | 3 | Prohibit portable storage devices that have no identifiable owner. |
3.8.9 | 1 | Protect the confidentiality of backup CUI at storage locations. |
Personnel Security (PS)
| Requirement | Points | Summary |
|---|---|---|
3.9.1 | 3 | Screen individuals before authorizing access to systems containing CUI. |
3.9.2 | 5 | Protect systems containing CUI during and after personnel actions such as terminations and transfers. |
Physical Protection (PE)
| Requirement | Points | Summary |
|---|---|---|
3.10.1 | 5 | Limit physical access to systems, equipment and operating environments to authorized individuals. |
3.10.2 | 5 | Protect and monitor the physical facility and support infrastructure. |
3.10.3 | 1 | Escort visitors and monitor visitor activity. |
3.10.4 | 1 | Maintain audit logs of physical access. |
3.10.5 | 1 | Control and manage physical access devices. |
3.10.6 | 1 | Enforce safeguarding measures for CUI at alternate work sites. |
Risk Assessment (RA)
| Requirement | Points | Summary |
|---|---|---|
3.11.1 | 3 | Periodically assess the risk to operations, assets and individuals from operating organizational systems and processing, storing or transmitting CUI. |
3.11.2 | 5 | Scan for vulnerabilities periodically and when new vulnerabilities are identified. |
3.11.3 | 1 | Remediate vulnerabilities in accordance with risk assessments. |
Security Assessment (CA)
| Requirement | Points | Summary |
|---|---|---|
3.12.1 | 5 | Periodically assess the security controls to determine whether they are effective. |
3.12.2 | 3 | Develop and implement plans of action to correct deficiencies and reduce or eliminate vulnerabilities. |
3.12.3 | 5 | Monitor security controls on an ongoing basis. |
3.12.4 | none (SSP) | Develop, document and periodically update system security plans. |
System and Communications Protection (SC)
| Requirement | Points | Summary |
|---|---|---|
3.13.1 | 5 | Monitor, control and protect communications at external and key internal boundaries. |
3.13.2 | 5 | Employ architectural designs, development techniques and engineering principles that promote effective security. |
3.13.3 | 1 | Separate user functionality from system management functionality. |
3.13.4 | 1 | Prevent unauthorized and unintended information transfer through shared system resources. |
3.13.5 | 5 | Implement subnetworks for publicly accessible components, separated from internal networks. |
3.13.6 | 5 | Deny network traffic by default and allow it by exception. |
3.13.7 | 1 | Prevent remote devices from connecting to organizational systems while also connecting to resources in external networks (split tunneling). |
3.13.8 | 3 | Use cryptography to prevent unauthorized disclosure of CUI in transmission unless otherwise protected. |
3.13.9 | 1 | Terminate network connections at the end of sessions or after a defined period of inactivity. |
3.13.10 | 1 | Establish and manage cryptographic keys for the cryptography employed. |
3.13.11 | 5 (partial 3) | Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. |
3.13.12 | 1 | Prohibit remote activation of collaborative computing devices and show users when devices are in use. |
3.13.13 | 1 | Control and monitor the use of mobile code. |
3.13.14 | 1 | Control and monitor the use of Voice over Internet Protocol (VoIP) technologies. |
3.13.15 | 5 | Protect the authenticity of communications sessions. |
3.13.16 | 1 | Protect the confidentiality of CUI at rest. |
System and Information Integrity (SI)
| Requirement | Points | Summary |
|---|---|---|
3.14.1 | 5 | Identify, report and correct system flaws in a timely manner. |
3.14.2 | 5 | Provide protection from malicious code at designated locations. |
3.14.3 | 5 | Monitor system security alerts and advisories and take action in response. |
3.14.4 | 5 | Update malicious code protection mechanisms when new releases are available. |
3.14.5 | 3 | Perform periodic scans of systems and real-time scans of files from external sources. |
3.14.6 | 5 | Monitor systems, including inbound and outbound traffic, to detect attacks and indicators of potential attacks. |
3.14.7 | 3 | Identify unauthorized use of systems. |
Example responses
A paid verification of the sample package (report shortened), and the findings from a demo run of the sample with errors. Both generated by running the real endpoint code.
{
"requestId": "7f3c2a1e-5b8d-4c6f-9e0a-1d2b3c4d5e6f",
"api": "cmmc-self-assessment-validator",
"mode": "paid",
"charged": true,
"priceCents": 2500,
"balanceCents": 7500,
"report": {
"schemaVersion": 1,
"status": "PASS",
"level": 2,
"asOf": "2026-10-05",
"verifiedScore": 110,
"maxScore": 110,
"band": {
"key": "final",
"label": "Final Level 2 (Self) score",
"reason": "All requirements MET or N/A: 110 of 110."
},
"claimedScore": {
"provided": true,
"matches": true
},
"counts": {
"met": 108,
"notMet": 0,
"partial": 0,
"notApplicable": 2,
"assessed": 110,
"required": 110,
"pointsDeducted": 0
},
"deductions": [],
"deductionsByFamily": {},
"readiness": [
{
"item": "requirements",
"label": "All 110 requirements assessed, once each",
"status": "ready"
},
{
"item": "ssp",
"label": "System security plan in place (3.12.4)",
"status": "ready"
},
{
"item": "score",
"label": "Score verified against the methodology",
"status": "ready"
},
{
"item": "poam",
"label": "POA&M in place and allowed for every NOT MET requirement",
"status": "ready"
},
{
"item": "sprs",
"label": "SPRS details: level, date, scope and CAGE codes",
"status": "ready"
},
{
"item": "affirmation",
"label": "Affirmation by the Affirming Official",
"status": "ready"
},
{
"item": "status",
"label": "Score reaches a Level 2 (Self) status",
"status": "ready"
}
],
"findingCount": 0,
"findingCounts": {
"error": 0,
"warning": 0
},
"ruleCounts": {},
"methodology": {
"name": "CMMC Level 2 Scoring Methodology",
"regulation": "32 CFR 170.24, as in effect October 2026",
"requirements": "NIST SP 800-171 Rev 2 (110 requirements), assessed with NIST SP 800-171A (June 2018)",
"maxScore": 110,
"minScore": -203,
"conditionalMinimum": 88
},
"scope": "A verified score is arithmetic from the results you entered, checked against the published CMMC scoring methodology. It is not a CMMC certification or assessment, not legal or compliance advice, and a PASS does not mean your company meets NIST SP 800-171 or that DoD will accept the score.",
"input": {
"format": "json",
"bytes": 5541
},
"inputSha256": "e1a4e2037578048573503b1d32820c6157e57a52bb6d19fa97565e9e4eef9019"
}
}[
{
"severity": "error",
"ruleId": "CMMC-AFFIRM-BEFORE",
"path": "/affirmation/affirmationDate",
"message": "The affirmation is dated before the assessment. An affirmation is required at the time of each assessment.",
"source": "cfr170.22"
},
{
"severity": "error",
"ruleId": "CMMC-AFFIRM-MISSING",
"path": "/affirmation/statementAffirmed",
"message": "The affirmation statement attests that all applicable CMMC requirements are implemented and will stay implemented. It has not been made.",
"source": "cfr170.22"
},
{
"severity": "error",
"ruleId": "CMMC-CAGE-FORMAT",
"path": "/assessment/cageCodes[1]",
"message": "A CAGE code is five characters, letters and digits only.",
"source": "dla-cage"
},
{
"severity": "error",
"ruleId": "CMMC-POAM-MISSING",
"path": "/assessment/poamInPlace",
"message": "There are NOT MET requirements, so a POA&M must be in place for each one (poamInPlace: true). A POA&M is not a substitute for a completed requirement, and the points stay deducted.",
"source": "cfr170.24"
},
{
"severity": "error",
"ruleId": "CMMC-SCORE-MISMATCH",
"path": "/assessment/claimedScore",
"message": "The claimed score does not match the score recomputed from the requirement results. Post the verified score, or correct the results it came from.",
"source": "cfr170.24"
},
{
"severity": "warning",
"ruleId": "CMMC-BAND-NONE",
"path": "/score",
"message": "This score does not reach a Level 2 (Self) status. It can still be posted, but a contract that requires Level 2 (Self) cannot be awarded on it.",
"source": "cfr170.21"
}
]Errors
See the shared error table. Rejected with HTTP 400 and not charged: a body that is not a JSON object, no assessment object, a level other than 2, no requirement results, both or neither of requirements and requirementsCsv, a CSV without requirement and status columns, or wrong value types; on the demo endpoint, anything other than a sample package. Example (HTTP 400):
{
"error": {
"code": "input_error",
"message": "assessment.level must be 2. Only CMMC Level 2 self-assessments are scored; Level 1 is MET or NOT MET in its entirety, with no score.",
"requestId": "7f3c2a1e-5b8d-4c6f-9e0a-1d2b3c4d5e6f",
"charged": false
}
}Code samples
curl -X POST "https://www.spreadrun.com/api/v1/cmmc-self-assessment-validator" \
-H "Authorization: Bearer $SPREADRUN_API_KEY" \
-H "Content-Type: application/json" \
--data-binary @self_assessment.json