Skip to content

CMMC Renewal and Reassessment

 

Learn about what triggers an out-of-cycle CMMC reassessment, impact of a merger or infrastructure change, losing certification status, and more, through the Frequently Asked Questions (FAQs) below. If you are looking for certified CMMC Professionals and a customized solution for your organization, please schedule a free consultation.

Table of Contents

How often must a CMMC Level 1 self-assessment be renewed? 

 

CMMC Level 1 self-assessments must be conducted and results submitted to SPRS annually, once every 12 months, along with an affirmation by the senior company Affirming Official confirming the accuracy of the submitted results. 

The annual cycle begins from the date of the initial Level 1 self-assessment submission. Organizations must conduct a new assessment of all 17 FAR 52.204-21 safeguarding requirements against all 59 assessment objectives before the 12-month anniversary of their most recent submission. If any requirement was NOT MET during the annual review, the deficiency must be remediated before a compliant SPRS submission can be made. 

The SPRS system tracks submission dates, and contracting officers can determine whether a Level 1 entry is within its valid annual period. An expired Level 1 entry, where more than 12 months have passed since the last submission, means the contractor’s CMMC status shows as no current certification, which affects contract eligibility. Organizations should build the annual Level 1 self-assessment into their calendar as a recurring compliance event with a designated owner responsible for timely completion. 

 

How often must a CMMC Level 2 C3PAO assessment be renewed? 

 

A CMMC Level 2 C3PAO certification assessment must be renewed every three years, the triennial cycle requires a new full C3PAO assessment before the three-year certification period expires, with annual affirmations of continued compliance required in SPRS in Year 1 and Year 2 between assessments. 

The three-year certification period begins from the date of the Final Findings Briefing issued by the C3PAO, not from the date the certification appears in SPRS or eMASS. Organizations should record this date carefully and build their reassessment planning around it. Given current C3PAO scheduling lead times of 3 to 12 months, organizations should begin the C3PAO engagement for their triennial renewal approximately 9 to 12 months before the three-year expiration date. 

A lapsed Level 2 C3PAO certification, where the three-year period expires before a renewal assessment is completed, results in no valid CMMC status in SPRS, creating contract eligibility risk. The triennial C3PAO assessment is a full independent evaluation of all 110 controls and 320 assessment objectives, not an abbreviated review of changes since the last assessment. 

 

What must an organization do in the years between C3PAO triennial assessments? 

 

Summary: In the years between C3PAO triennial assessments, a CMMC Level 2 certified organization must maintain continuous compliance with all 110 NIST SP 800-171 Rev 2 controls, submit annual affirmations of compliance in SPRS (Year 1 and Year 2 of the certification cycle), and update the System Security Plan (SSP) to reflect any material changes to the assessed environment. 

Specific between-assessment obligations include: conducting an annual self-review of control implementation to verify that the security posture remains consistent with the C3PAO’s findings; updating the SSP whenever the organizational environment changes materially; maintaining continuous monitoring activities (vulnerability scanning, log review, patching); providing security awareness training annually to all personnel; submitting annual affirmations in SPRS before the 12-month and 24-month anniversaries of the certification date; maintaining and updating the evidence library so artifacts remain current; and responding appropriately to security incidents including cyber incident reporting obligations. 

Organizations that maintain their compliance program as an active operational capability, rather than going dormant between assessments, consistently achieve smoother and less costly triennial renewals because they have not allowed controls to decay. 

 

What triggers an out-of-cycle CMMC reassessment? 

 

Summary: An out-of-cycle CMMC reassessment is triggered by significant changes to the organizational environment that materially affect the CMMC assessment scope or the implementation status of security controls, including major technology changes, security incidents resulting in CUI compromise, corporate restructuring, or discovery of material misrepresentation in a prior assessment. 

Specific triggers include: migration to a new cloud service provider for CUI handling; deployment of new information systems handling CUI not covered by the existing assessment scope; significant changes to the network architecture that alter the assessment boundary; merger, acquisition, or divestiture affecting the certified entity; replacement of a major ESP in the compliance environment; discovery of a significant security incident in which CUI was compromised; or receipt of a DoD contracting officer’s request for a new assessment based on audit findings. 

The program’s intent is clear: the CMMC certification represents the security posture as assessed at a specific point in time, and material changes that would produce different assessment results make the certification outdated. Organizations should consult with their C3PAO when significant changes occur to determine whether a delta assessment or a full reassessment is required. 

 

How does a merger, acquisition, or significant infrastructure change affect CMMC certification status? 

 

Summary: A merger, acquisition, or significant infrastructure change does not automatically extend or invalidate a CMMC certification but requires the certified organization to evaluate whether the change materially affects the assessment scope, and in most cases to engage the C3PAO for a scope review and potentially a delta or full reassessment. 

In a merger or acquisition scenario, the key question is whether the acquired entity’s systems are integrated into the certified environment. If they are: the acquired systems were not part of the original assessment and may be handling CUI without the required CMMC controls; this represents a compliance gap, and the combined environment must be assessed. If the acquired entity operates as a completely separate legal entity with its own CAGE code, IT systems, and CMMC status with no integration of CUI-handling systems, the existing certifications may remain valid independently. 

For significant infrastructure changes, such as migrating from on premises to cloud, the change typically alters the assessment scope, the applicable Shared Responsibility Matrix, and the specific technical implementations for multiple controls, warranting at minimum a scope review with the C3PAO and SSP update. CAGE code changes, legal name changes, and changes in organizational ownership affecting FOCI status must be reported and assessed for program implications. Organizations undergoing M&A should engage their CMMC consultant or RPO early in the transaction process to assess CMMC implications before closing.

 

Can an organization lose its CMMC certification and what causes this? 

 

Summary: An organization can lose its CMMC Level 2 certification through four primary mechanisms: expiration of the Conditional 180-day POA&M window, expiration of the three-year certification period without renewal, voluntary or involuntary revocation triggered by a significant security incident or material misrepresentation, and administrative lapse due to failure to submit required annual affirmations. 

180-day POA&M lapse: Conditional certification lapses automatically if all POA&M items are not verified closed within 180 days of the Final Findings Briefing. Three-year expiration: The certification period expires three years from the Final Findings Briefing date; if the renewal C3PAO assessment is not completed before expiration, the certified status lapses in SPRS. 

Revocation for cause: If an organization provides materially false information to a C3PAO during assessment, has a significant security incident that calls into question the accuracy of the certification, or is found to have materially misrepresented its compliance posture in a DoD investigation, the Cyber AB or DoD may revoke the certification. Annual affirmation failure: Failure to submit the required annual affirmation within the specified window results in the certification status being flagged in SPRS as unaffirmed, potentially triggering contracting officer review. Organizations should maintain calendar reminders for all CMMC status milestones and treat them as contract-critical obligations. 

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Med First Primary and Urgent Care
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties