Subcontractor CMMC Tracker
Findings · finding 9 of 12

Subcontractor holds ISO 27001 or SOC 2 but has no SPRS score

A subcontractor that holds ISO 27001, SOC 2, NIST CSF, FedRAMP Moderate or CIS v8 may be able to reuse some of that evidence toward a NIST SP 800-171 self-assessment. The counts are reuse candidates from our crosswalk, high and medium confidence shown apart, with the number that has no candidate and needs CMMC-specific evidence; every one of the 110 is still assessed on its own evidence.

What the register reads

a question

Send the subcontractor its starting sheet and ask for a self-assessment date.

The rule sentences behind it

2 cited
32 CFR 170.16(a)(1)codified text, eCFR current to 24 Sep 2026

To maintain compliance with the requirements for a CMMC Status of Level 2 (Self), the OSA must conduct a Level 2 self-assessment every three years and submit the results in SPRS, within three years of the CMMC Status Date associated with the Conditional Level 2 (Self).

Threshold read: Level 2 (Self) assessment: every three years. Source
32 CFR 170.24(c)(2)codified text, eCFR current to 24 Sep 2026

For each requirement NOT MET, the associated value of the security requirement is subtracted from the maximum score, which may result in a negative score.

Threshold read: the score runs from -203 to 110 (the values in 170.24 add to 313). Source

The clauses behind it

CMMC L2 CA.L2-3.12.4System Security Plan 0 points in the score

Develop, document and periodically update a system security plan describing system boundaries, the operating environment, how each requirement is implemented, and connections to other systems.

What an assessor asks to see: Current system security plan covering boundary, environment, implementation and interconnections; Version history showing periodic update; Approval record for the current version
Where subcontractors usually fall short: Plan describes intent rather than actual implementation; Boundary and interconnections omitted or stale; No defined update trigger or cadence
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)

A line that raises it

invented

Tessera Software | 2TS77 | | | none yet | | yes | no | no | ISO 27001; SOC 2

See it in the specimen