Subcontractor holds ISO 27001 or SOC 2 but has no SPRS score
A subcontractor that holds ISO 27001, SOC 2, NIST CSF, FedRAMP Moderate or CIS v8 may be able to reuse some of that evidence toward a NIST SP 800-171 self-assessment. The counts are reuse candidates from our crosswalk, high and medium confidence shown apart, with the number that has no candidate and needs CMMC-specific evidence; every one of the 110 is still assessed on its own evidence.
What the register reads
a questionSend the subcontractor its starting sheet and ask for a self-assessment date.
The rule sentences behind it
2 cited32 CFR 170.16(a)(1)codified text, eCFR current to 24 Sep 2026To maintain compliance with the requirements for a CMMC Status of Level 2 (Self), the OSA must conduct a Level 2 self-assessment every three years and submit the results in SPRS, within three years of the CMMC Status Date associated with the Conditional Level 2 (Self).
32 CFR 170.24(c)(2)codified text, eCFR current to 24 Sep 2026For each requirement NOT MET, the associated value of the security requirement is subtracted from the maximum score, which may result in a negative score.
The clauses behind it
CMMC L2 CA.L2-3.12.4System Security Plan 0 points in the scoreDevelop, document and periodically update a system security plan describing system boundaries, the operating environment, how each requirement is implemented, and connections to other systems.
A line that raises it
inventedTessera Software | 2TS77 | | | none yet | | yes | no | no | ISO 27001; SOC 2