With third-party certification paused in 2026, the self-assessment is the CMMC obligation still squarely on your plate. It means scoring your environment against the 110 controls of NIST SP 800-171 Rev 2, documenting it in a System Security Plan, tracking gaps in a POA&M, and posting your score to SPRS. Here's how the pieces fit.
Book a 15-minute review →The scoring model is specific: NIST 800-171 uses a weighted scale starting at 110, subtracting points for each unmet control (some worth 1 point, some 3 or 5). A perfect score is 110; a negative score is common and correct when many controls are unmet. That number goes into the Supplier Performance Risk System (SPRS), where it conditions award under DFARS 252.204-7019.
Your System Security Plan (SSP) describes how each control is met - the single most important document an assessor (or your prime) will ask for. Your Plan of Action & Milestones (POA&M) lists the controls you haven't met yet and your plan to close them. Both need to reflect your real environment, not aspirations, because a future assessment will check.
The hard part isn't understanding the controls - it's producing evidence that they're actually operating, and keeping the SSP current as your environment changes. This is where most self-assessments quietly drift out of date the moment they're written.
MDRwatchdog generates your control matrix, SSP, POA&M, and SPRS score from live monitoring, and keeps them current automatically - so your self-assessment reflects what your systems are actually doing. Readiness and evidence, not certification, and not legal advice.
Yes. The July 2026 suspension paused third-party certification, but Phase 1 self-assessment, SPRS posting, and DFARS 252.204-7012 remain in force. You still self-assess against all 110 NIST 800-171 controls.
A perfect NIST 800-171 score is 110. Many organizations start negative because unmet controls subtract weighted points. The goal is to close gaps (tracked in your POA&M) to raise the score over time; some contracts expect a minimum or a credible improvement plan.
At minimum: a System Security Plan (SSP) describing how each control is met, a POA&M listing open gaps and your remediation plan, and a posted SPRS score. MDRwatchdog generates all three from live evidence.
MDRwatchdog provides security monitoring and compliance evidence to support readiness. It is not a certification and not legal advice. Certification and formal audits are performed by the appropriate authorized bodies (a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001).