Understanding the regulatory requirements behind NIST SP 800-171A, evidence collection, and proper Level 2 self-assessments under 32 CFR Part 170.

By Dr. Thomas Graham

Introduction

I want to focus specifically on the Level 2 self-assessment (L2 Self), because it is the piece most organizations misunderstand. Regardless of the pause of Phase 2 of CMMC, organizations are still accountable for this process and the evidence collection that is required.

Table of Contents

What the Regulation Actually Requires

The L2 Self sounds self-explanatory, but an organization that does not fully understand the requirement can end up on the wrong side of regulatory compliance at best, and faces the Department of Justice (DoJ) at worst. Setting penalties aside for a moment, there is a genuine amount of confusion about what the L2 Self actually requires an organization to do each year. Getting clear on the specifics will help organizations cut through the noise and stay on the right side of the line.

The L2 Self requirements are documented in 32 CFR Part 170.16. Many organizations are familiar with the general implications of 32 CFR Part 170, but the nuance, and the risk, lives in the details.

Look at the first section, 170.16(a). The second sentence states that “an OSA conducts a Level 2 self-assessment as detailed in paragraph (c) of this section.” Straightforward enough. All the Organization Seeking Assessment (OSA) has to do is go to paragraph (c) and it will know what to do, right?

Paragraph (c) identifies the procedures an OSA must follow to properly conduct an L2 Self, and this is where the trouble starts. In 170.16(c)(1), the very first sentence states that “the OSA must conduct a Level 2 self-assessment in accordance with NIST SP 800-171A Jun 2018 (incorporated by reference, see § 170.2) and the CMMC Level 2 scoping requirements set forth in §§ 170.19(a) and (c).”

Notice what it does not say. It does not point to the assessment guide, and it does not simply cite NIST 800-171r2. It specifically requires NIST SP 800-171A, and it requires the L2 Self to be scoped per the CMMC Level 2 Assessment Guide. That means scoring each item as if the OSA were going through an actual third-party assessment. It also means that if any item is scored “Not Met,” the OSA must conduct a POA&M close out self-assessment as well, using the methods described in NIST SP 800-171A, and within the 180-day limitation.

Bringing Cloud and External Service Providers into Scope

The scope of the L2 Self extends to any Cloud Service Providers (CSPs) or External Service Providers (ESPs) in the environment. 32 CFR Part 170.16(c)(2) and 170.16(c)(3) lay out the procedures for evaluating each. A useful rule of thumb: if a provider stores, processes, or transmits CUI, it is a CSP for these purposes.

Under 170.16(c)(2), a CSP is brought into the L2 Self under any of the following circumstances:

  • The CSP is FedRAMP Moderate or higher and listed on the FedRAMP Marketplace
  • The CSP is not FedRAMP Authorized but meets requirements equivalent to the moderate baseline or higher
  • A Customer Responsibility Matrix (CRM) is documented or referenced in the OSA’s System Security Plan (SSP)

Evidence Retention and Where Most OSAs Fall Short

All the artifacts collected during the L2 Self must be retained for six years from the assessment date.

This is where many OSAs fall short. When they conduct their L2 Self, they either collect no artifacts at all, or they collect them in a way that does not follow NIST SP 800-171A. That means the score ultimately affirmed in SPRS is not accurate, and the OSA has not met the regulatory requirement. An illegitimate affirmation can cost a contract award, or worse, open the door to False Claims Act (FCA) allegations. A solid working knowledge of NIST SP 800-171A pays off twice over: it protects the organization from that exposure, and it confirms the requirements were actually implemented in the first place.

The Three Methods for Collecting Evidence

NIST SP 800-171A, identifies three Methods for collecting evidence (artifacts) to support the L2 Self:

  1. Examine: documentation such as the SSP, policies, and procedures, along with screenshots and diagrams that must be reviewed and retained
  2. Interview: talking directly with the people responsible for implementing each requirement and documenting what they say
  3. Test: confirming implementation through a live demonstration, such as a live screenshare of a configuration

This last method, Test, is the one most often missing from the online commentary about the pause. NIST SP 800-171A details each method with examples.

Objectives Come from NIST, Not the Assessment Guide

To properly self-assess a requirement, each requirement objective must be scored “Met.” Some posts have suggested that the CMMC L2 Assessment Guide introduced these objectives. It did not. The objectives, and the evidence expectations tied to them, come directly from NIST SP 800-171A. Unless an OSA is actually collecting evidence to support each objective as “Met,” the L2 Self score uploaded into SPRS will not be accurate.

Coverage and Depth: Why Partial Evidence is Not Enough

When self-assessing requirements and objectives, OSAs also have to satisfy the coverage and depth (adequacy and sufficiency) requirements in NIST SP 800-171A as well. What this means is that for each system, or service, in play for a particular objective, evidence must be collected that is accurate for the objective AND covers all systems/services in scope for that objective. This includes ANY ESP such as CSPs, MSPs, MSSPs, etc. Specifically for these third-party services, they are broken out in 32 CFR Part 170.19(c)(2) and included here for convenience:

By now it should be clear that conducting an L2 Self is not a “check the box” exercise.

Getting Help

If you are an OSA and any part of this feels murky, reach out for help. It is also worth taking the official CMMC Certified Professional (CCP) course, which covers each requirement in depth and provides the context, history, and rationale behind them. Spoiler: You cannot simply write “N/A” and move on. ISACA maintains a list of approved training providers, and in my experience, organizations where at least the person responsible for the scoped environment has completed this training tend to move through their independent third-party assessments far more smoothly.

Closing Thoughts

At the end of the day, there is a real shortage of posts explaining what an OSA is actually required to do. Without understanding the mechanics, both the OSA and the individual affirming the score (the Affirming Official) may be exposing themselves to real risk.

What’s changed: On July 20, 2026, the House of Representatives voted unanimously to pass the Expanding Whistleblower Protections for Contractors Act, which would extend anti retaliation protections to government contractors, subcontractors, grantees, and their employees, and companion legislation already cleared the Senate earlier this year. [1] Enforcement mechanisms like the FCA and government inspectors remain very active. Flagging a shortcut or inaccurate statement on a L2 Self gained broader protection with this legislation, for those affirming their organization’s SPRS scores, take notice.