Subcontractor CMMC Tracker
Findings · finding 3 of 12

CMMC affirmation older than one year: what 32 CFR 170.22 says

The affirming official affirms after every assessment and annually thereafter (32 CFR 170.22(a)); 252.204-7021 reads a status as current only with an affirmation not older than 1 year, for each system that processes, stores or transmits FCI or CUI.

What the register reads

a date to chase

Ask for the date of the latest annual affirmation in SPRS, and who made it.

The rule sentences behind it

4 cited
32 CFR 170.22(a)codified text, eCFR current to 24 Sep 2026

An Affirming Official from each OSA, whether a prime or subcontractor, must affirm the continuing compliance of their respective organizations with the specified security requirement after every assessment, including POA&M closeout, and annually thereafter.

Threshold read: affirmation after every assessment and annually thereafter. Source
32 CFR 170.22(a)(1)codified text, eCFR current to 24 Sep 2026

The Affirming Official is the senior level representative from within each Organization Seeking Assessment (OSA) who is responsible for ensuring the OSA's compliance with the CMMC Program requirements and has the authority to affirm the OSA's continuing compliance with the specified security requirements for their respective organizations.

Threshold read: the affirmation is made by the affirming official. Source
DFARS 252.204-7021, "current" (2)(ii)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official

Threshold read: Final Level 2: not older than 3 years, affirmation not older than 1 year. Source
DFARS 252.204-7021, "current" (2)(i)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Not older than 1 year for Final Level 1 (Self), with (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official

Threshold read: Final Level 1: not older than 1 year. Source

The clauses behind it

CMMC L2 CA.L2-3.12.3Security Control Monitoring 5 points in the score

Monitor security controls continuously so their effectiveness is known on an ongoing basis rather than only at assessment time.

What an assessor asks to see: Continuous monitoring strategy naming controls, metrics and frequency; Monitoring output such as dashboards or periodic reports; Records of action taken when monitoring shows degradation
Where subcontractors usually fall short: Monitoring limited to the annual assessment; Metrics collected but not evaluated against expectations; Degradation detected without follow up
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)

A line that raises it

invented

Lumen Mesh Systems | 6LM20 | 92 | 2024-08-19 | Level 2 (Self) | 2025-08-19 | yes | no | yes

See it in the specimen