CMMC control families
CMMC Security Assessment (3.12 CA): 4 requirements, SSP, POA&M and SPRS
Four requirements, and the family where a supplier has to be loudest about its limits. We are not an assessor, a C3PAO or an RPO, we hold no CMMC level, and nothing we sell — hardware, license or service — produces an SSP, a POA&M or an SPRS score.
- Family
- 3.12 — Security Assessment
- Requirements
- 4 of the 110 Level 2 requirements
- Level 1
- Not in Level 1 — appears at Level 2
- Boundary
- The capability behind the control — never a certification we hold
The family that produces the paperwork everything else is judged against
Security assessment carries four requirements: periodically assess the security controls in your systems to determine whether they are effective (3.12.1); develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities (3.12.2); monitor the controls on an ongoing basis (3.12.3); and develop, document and periodically update system security plans that describe boundaries, environments, how requirements are implemented and the relationships to other systems (3.12.4). Between them they produce the two documents the whole program runs on — the SSP and the POA&M — and the score that goes into SPRS. None of it is purchasable, and this is the page where saying so matters most.
What each level asks of this family
Security assessment is a Level 2 family. It is not one of the six Level 1 touches. That does not mean Level 1 contractors escape the paperwork: a Level 1 self-assessment is performed annually against the 15 FAR 52.204-21 requirements with a senior-official affirmation posted in SPRS, and no POA&Ms are permitted at Level 1 — a requirement is met or it is not.
At Level 2 all four apply, and the assessment route depends on the solicitation: self-assessment or a C3PAO assessment, against the 110 requirements and their 320 objectives. Level 2 allows a limited, time-bound plan of action for certain requirements where Level 1 allows none. Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.
The tooling can be quoted. The assessment never can.
Uniqcli is not a C3PAO, an RPO, an RPA or an assessor of any kind. We hold no CMMC level ourselves, we do not write system security plans, build POA&Ms, perform self-assessments or compute SPRS scores, and we do not offer assessment-readiness services. Anyone selling you a certification outcome is selling something that does not exist — CMMC certifies organizations, never products, and no purchase — hardware, license or service — confers certification on its own.
It is worth being exact about the tooling too, because this is the family where a supplier is most tempted to blur it. Governance, risk and compliance platforms — the software some programs use to track control status and assemble evidence — are not in our catalog. We are not going to invent an adjacency to fill this page. The one genuinely adjacent line already appears one family over: the vulnerability-scanning subscription that feeds 3.11.2 is quotable, and it stays a scanner rather than an assessment.
What we do is downstream of this family, not inside it. We quote against the SSP you already have, not a generic bundle: send the section, the POA&M line you are closing or the enclave bill of materials, and the estimate is built against that document — hardware, licensing and the integration work around them. That is the whole of our role, and it is the honest one.
Assessment, SSP and SPRS questions
What is the difference between a self-assessment and a C3PAO assessment?
A self-assessment is performed by the contractor and affirmed by a senior official in SPRS; a C3PAO assessment is performed by an accredited third-party assessment organization. Which one applies at Level 2 depends on what the solicitation specifies. Level 1 is always self-assessed, annually, with no POA&Ms permitted. Uniqcli performs neither — we are not an assessor.
How is the SPRS score calculated?
Under the DoD Assessment Methodology, a full implementation of all 110 NIST SP 800-171 requirements scores 110, and unmet requirements are subtracted at weights of 5, 3 or 1 points depending on their impact, with the scale bottoming out at -203. The score is a snapshot of implementation, not a grade — and it is your organization's to compute, affirm and keep current.
What goes in an SSP and a POA&M?
3.12.4 asks the system security plan to describe the system boundary, the operating environment, how each requirement is implemented, and the relationships with or connections to other systems. 3.12.2 asks the plan of action to record the deficiencies and how they will be corrected. Both are living documents that get updated, and both are what an assessment is actually conducted against.
What happens if you fail a CMMC assessment?
That depends on the level and the route, and it is a question for your assessor or your contracting officer rather than for a supplier. In broad terms Level 2 allows a limited, time-bound plan of action for certain requirements while Level 1 permits none, so an unmet Level 1 requirement is simply unmet. We do not advise on assessment outcomes and would be out of our lane if we did.
Get a CMMC estimate — CMMC Security Assessment (3.12 CA)
Nothing in this family is a purchase, and the page above says so. Tell us where to reach you and a Uniqcli specialist follows up by email about the parts of your program that do have a line behind them — the hardware, software licensing and integration work the rest of your SSP calls for, quoted against the plan you already have.
An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.
The solutions atlas
Every solution, one accountable partner.
UniQ platforms
By technology
By customer
- TAA & NDAA-889 Compliance Screening
- CMMC & CUI Solutions
- Federal & DoD
- State, Local & Education
- Healthcare
- Enterprise
- Rapid Procurement & GPC Buys
- Multi-Vendor Integration Projects
- eProcurement & Custom Catalogs
- FISMA Modernization
- CJIS-Compliant Justice Cloud & Local AI
- Federal Storage Modernization
- Government ERP & Business Systems Infrastructure
- Managed Procurement
- Secure AV & Conferencing
- Fiber Network Infrastructure
- Satellite & Resilient Connectivity
- Wavelength & Optical Transport
- Decentralized Data Centers
- Data Center Design & Build
Already have the SSP? Send the section.
We do not write assessment documents, run assessments or certify anything. What we do is quote against the plan you already have — send the SSP section, the POA&M line you are closing or the enclave bill of materials, and a Uniqcli specialist replies with an estimate built against it, covering the hardware, the licensing and any integration work the fix actually needs.