It's 4:45 on a Friday. Someone from compliance sets a folder in front of the CEO and says, "Just needs your signature, we're good to go." One page in, buried between routine paperwork, sits the CMMC affirmation. A few sentences, submitted into a government database called SPRS. Easy to sign without a second read.
That signature is a sworn statement that the company has implemented, and will keep implementing, every required security control. Under 32 CFR § 170.22, the person who signs it is putting their own name behind that claim, not just the company's.
Legal Disclaimer: This article is provided for compliance support and informational purposes only and does not constitute legal advice. Organizations and individuals should consult qualified legal counsel regarding their specific CMMC obligations and potential legal exposure.
What the Affirmation Actually Is
The CMMC affirmation is a sworn statement, submitted by a senior company official into the Supplier Performance Risk System (SPRS), that the organization has implemented and will maintain every applicable CMMC security requirement. The obligation comes directly from 32 CFR § 170.22.
It isn't a one-time form filed at certification and forgotten. For Level 1, the affirmation is required annually, with the reaffirmation tied to the annual date. Level 2 organizations also submit an annual reaffirmation and must submit another affirmation when a Plan of Action and Milestones is closed out. Each submission is a fresh, current statement of fact, not a renewal of the last one.
SPRS is the only place this status officially exists. Contracting officers and primes check it before award, not the assessment paperwork sitting in a file somewhere.
Also Read: What Is CMMC and Do You Need It?
Who Signs It: The Affirming Official
The Affirming Official is a senior company representative with the actual authority to commit the organization to a compliance claim. In practice, this may be someone such as a CEO, CISO, or Facility Security Officer, depending on the organization's structure. The regulation focuses on the official's authority to bind the organization rather than requiring a specific job title.
The regulation isn't just about title. It requires someone who can legally bind the company and who has been personally briefed on the real state of compliance before signing, not someone repeating what a report told them. Delegating the signature to someone without that authority or that knowledge doesn't reduce liability. It just means the wrong person is now exposed.
In practice, this means the Affirming Official needs direct answers on three things before signing: what's actually implemented, what evidence backs it up, and what's still open. Anything less turns the signature into a guess.
What Signing Actually Commits You To
The affirmation states that the organization "has implemented and will maintain implementation" of every applicable security requirement. That phrasing matters. It isn't a claim about a point in time, it's an ongoing commitment that stays true for as long as the affirmation stands, not just on the day it was signed.
This is where the False Claims Act enters the picture. When a company certifies compliance as a condition of contract award or payment, and that certification turns out to be false, the government can pursue treble damages and per-claim penalties, and it doesn't need to prove intent to defraud. Reckless disregard is enough.
The Department of Justice's Civil Cyber-Fraud Initiative has already tested this theory against real contractors. In 2022, Aerojet Rocketdyne agreed to pay $9 million to settle allegations that it misrepresented its cybersecurity compliance on DoD and NASA contracts, a case that reached trial before it settled. The settlement included no admission of liability.
The Aerojet case illustrates that alleged cybersecurity misrepresentations can result in False Claims Act exposure for a contractor. It does not establish individual liability for the person who signed a CMMC affirmation. The personal accountability of the Affirming Official is a separate issue tied to the named individual's role in making the affirmation under 32 CFR 170.22.
Also Read: CMMC Level 1 vs Level 2: Which Does Your Contract Require?
What Happens the Following Year: The Reaffirmation Cycle
The affirmation doesn't expire quietly and get renewed like a subscription. Every year, the same Affirming Official has to make the same claim again, current as of that new date, not a repeat of what was true twelve months earlier.
For Level 1, the reaffirmation trigger is the annual date. Level 1 does not permit POA&Ms. For Level 2, reaffirmation is required annually and again when a Plan of Action and Milestones is closed out. A year of operations, a few new hires, a vendor swap, a system upgrade, all of it has to hold up against the applicable requirements before that signature goes in again.
Miss the deadline, and the consequence isn't a warning letter. A lapsed affirmation means the company's CMMC status is no longer current in SPRS, and without a current status, it isn't eligible for award on contracts that require it. Contracting officers check the record, not intentions. For an Affirming Official, that turns the calendar date itself into part of the compliance program, not an administrative afterthought.
Common Mistakes Around the Affirmation
Most of the exposure Affirming Officials carry doesn't come from a hidden technicality. It comes from a handful of habits that show up in almost every case DOJ has pursued so far:
- Signing without a real briefing: Being told "we're good to go" isn't the same as reviewing actual evidence. A signature based on someone else's summary is still the signer's personal liability.
- Treating it as a one-time task: The affirmation isn't a certificate earned once. It's a claim that has to stay true every day it's on file, through staff changes, new systems, and everything in between.
- No evidence trail behind "Met": If a requirement is marked Met, there should be something concrete behind it, a screenshot, a config, a policy, a date. Memory isn't documentation.
- Assuming the Phase 2 suspension lowers the stakes: With third-party assessment paused for Level 2, more of the burden sits on self-assessment accuracy, not less. The affirmation carries more weight right now, not less.
Moving Ahead
The CMMC affirmation looks like paperwork until it's read closely. It's a personal, recurring claim that someone in the organization is willing to stand behind, backed by real evidence, not a summary from someone else. The signature itself takes a minute. What it commits you to lasts until the next one replaces it.