Your CMMC journey has a few really tough parts that are an absolute must.
- Documenting who, what, were, and why CUI is stored, processed, and transmitted
- What type or category of CUI your being entrusted with
- Creating your System Security Plan (CA.L2.3.12.4)
- Performing your Self-Assessment (CA.L2.3.12.1) and 32CFR 170
This document is going to focus on how to perform and document your self-assessment.
First step is to locate the DoD/DoW Chief Information Officer CMMC page. At the time of this document creation, it can be located at this URL:
https://dowcio.war.gov/CMMC/Resources-Documentation/
This URL can unfortunately change from time to time, but use your favorite search engine and search for “DoD CMMC program”, and only accept an official page from the DoD/DoW CIO .gov page as the source of truth. Every service, assessors, RP, RPO, C3PAO must follow the guidance created from this source.
There are several key documents that you should gather and store as part of your evidence collection during your self assessment.
- The CyberAB CMMC Assessment Process (CAP)
- The CMMC Level 1 Self-Assessment Guide
- The CMMC Level 2 Self-Assessment Guide (if you need to be CMMC Level 2)
- NIST SP800-171r2A
- Your System Security Plan (yes, I suggest you create an SSP even if you only have to attest to a CMMC Level 1)
What is helpful is to review the CMMC FAQ document, also found on the DoD/DoW CIO CMMC Page. These are commonly asked questions and mostly helps clarify questions that you may have, but it may also cause you to rethink what you may have done in the past.
What is an Self-Assessment?
An Self-Assessment is the minimum annual requirement regardless of the CMMC level you are required to have. I and others in this field strongly suggest this become an quarterly task whether you assess all the objectives or just a portion of them, but annually all practices and objectives for your CMMC level will need to be assessed and documented.
The self-assessment is where you will take your SSP (CA.L2.3.12.4) and validate that your organization is doing exactly what is documented within your SSP for each practice and objective. As part of this assessment, you will also validate your SSP and determine if modifications need to be made as defined by CA.L2.3.12.1.
Your going to need to create a repository where you will keep the artifacts or evidence of each finding. Pictures, documented notes (signed or initial), policies, processes, etc., are all forms of demonstrating that you have performed due diligence. But remember, your SSP is considered a protected document and will need to adhere to the same standards as your CUI.
Why do I use SP800-171r2A over SP800-171r2?
171r2 defines the practices, but 171r2A provides how to assess each objective of each practice, it works better for me and hopefully you as well.
Preform the assessment
I am not going to go through each practice as eventually I will provide a document per each practice, but let\’s walk through 3.1.1 and how you have to think like an auditor instead of a implementor.

So lets take a look at the objectives
3.1.1(a): Its simply asking you if you have documented each and every person that has access (digital or physical) to anywhere that stores, processes or transmits FCI or CUI (yes, 3.1.1 is a L1 practice that is required for both CMMC levels 1, 2, and 3. Your evidence is that documentation.
3.1.1(b): Have you documented technology systems that have a service account, but uses the identity of an authorized person to authorize access to the system.
3.1.1(c): Your asset inventory of devices, including the categorization and classification of those systems, that connect to networks and systems where FCI/CUI is stored, processed or transmitted. Include SaaS or other hosted systems !!
3.1.1(d): Demonstrate how you are preventing a person or technology from access anything where FCI or CUI is stored. Include manufacturing areas, door locks, filing cabinets, file shares, email boxes, offices, applications. An security group and policy should do the trick.
3.1.1(e): Ensure that service accounts or hosted systems that are using your identity to authorize you is properly working. A screenshot of an authorization fail for a non authorized account should do the trick.
3.1.1(f): Demonstrate that an unauthorized system cannot access any system, including your network. Show how a network access control is preventing a system from connecting to the system or how your preventing someone from moving a network cable on a switch.
The next section is the three means of demonstrating compliance to each objective, and each practice will give a few hints on how compliance can be achieved.
- Examine: review the policy or process that to see if that can demonstrate compliance against the objective
- Interview: discussion with the system owner to ensure their understanding matches the SSP and each objective
- Test: A prove it statement. Prove that the control is working as expected
The self-assessment is within the top 5 hardest things an organization has to complete and not only is it difficult, the folks that you will have to work with to demonstrate compliance may not have the same thought on how to solve.
Rule of thumb is to keep this simple, straightforward and for the love of god, do not over think the practices and their objectives. You should have a Policy, Process or a combination of the two defined for each objective; Also remember a policy won’t work unless there is a mechanism to enforce it.
