The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

CMMC research & assessments · primary-sourced · last reviewed August 2026

CMMC Joint Surveillance Voluntary Assessment (JSVA): Does Yours Still Count in 2026?

Last updated:

Last verified: against 32 CFR Part 170, current DFARS, SPRS, DIBCAC, NIST, Cyber AB, and Department CMMC implementation materials.

Editorial illustration of a CMMC Joint Surveillance Voluntary Assessment record, verification checklist, and three-year status timeline

By The Defense Compliance Report Editorial Team · Last verified: August 29, 2026 · How we verify · Editorial standards · Corrections policy


If you completed a CMMC Joint Surveillance Voluntary Assessment (JSVA), a qualifying assessment was automatically converted into a CMMC Status of Final Level 2 (C3PAO) under 32 CFR § 170.20. The status is valid for three years from the date of the original DCMA DIBCAC High Assessment. Not three years from the rule. Not three years from Phase 2. From your assessment date.

That one distinction is why we wrote this page. Because if your assessment was in early 2023, your three years are already gone — and most of what you'll read about JSVA right now won't tell you that.

What changes the answer: the date and type of the original assessment, whether it reached a perfect 110 with no open Plan of Action and Milestones (POA&M), whether the accepted scope was identical to the DIBCAC High Assessment scope, whether your current environment still matches the boundary you rely on, and whether your Affirming Official has filed the required affirmation in the Supplier Performance Risk System (SPRS) and kept it current.

The answer at a glance

Your question — The direct answer
Your questionThe direct answer
Can I still get a JSVA that qualifies under § 170.20?No. The standards-acceptance route only covers qualifying DIBCAC High Assessments conducted before December 16, 2024.
Did my JSVA become a CMMC status?If it met every § 170.20 condition, yes — automatically. DCMA DIBCAC identifies qualifying assessments and verifies SPRS.
How long does it last?Three years from the original DIBCAC High Assessment date.
Did the July 13, 2026 Phase II suspension pause the conversion?No published suspension document says that. Section 170.20 remains in force and SPRS had already converted qualifying High Assessments.
What should I check first?The SPRS status, the original assessment date, the CMMC UID and scope, and the latest affirmation date.
When does the last possible § 170.20 status expire?December 15, 2027. That is the outer boundary under the rule as written today.

Which one are you?

  • You have a JSVA and need to know if it still counts → start with the four conversion gates and the annual eligibility requirement, then use the expiration table. That's about six minutes.
  • You're hoping to still get one → skip to Can I still get a JSVA in 2026? The standards-acceptance route is closed, and the replacement depends on your contract.
  • A prime asked about your JSVA and you inherited the folder → start with JSVA vs. DIBCAC High vs. C3PAO assessment vs. Level 3, then follow the SPRS verification steps.

The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining regulatory claims with primary-source citations and mapping a contractor's required level, CUI scope, assessment type, and timeline to the right provider category before the contractor pays for the wrong engagement.


Your situation changes the answer

The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The solicitation or contract requirement sets the CMMC status you need; a checklist does not. Because a general answer can't resolve those facts for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.

  • What it asks: your required CMMC level, FCI vs. CUI handling, assessment type, IT/cloud environment, and contract timeline
  • What you get: the provider category that fits your situation, and the questions to ask before requesting quotes
  • Educational triage only: free · about 2 minutes · no obligation · do not submit CUI, drawings, or sensitive contract details

Find My CMMC Path →


Does a CMMC Joint Surveillance Voluntary Assessment still count in 2026?

A qualifying CMMC Joint Surveillance Voluntary Assessment carries a CMMC Status of Final Level 2 (C3PAO) under 32 CFR § 170.20, valid for three years from the date of the original DCMA DIBCAC High Assessment. Four conditions govern the conversion: date, assessment type, a perfect score with no open POA&M, and identical scope. A separate SPRS affirmation — and annual affirmations after that — governs contractual eligibility. Participation alone did not create the status.

Here's the thing most JSVA holders get wrong, and it's an understandable mistake: they remember the assessment, not the rule. The assessment was the hard part — the week of interviews, the evidence packet, the DIBCAC team in the conference room. So when someone asks "are you CMMC certified?", the instinct is to point at the assessment.

But the assessment isn't what gives you the recognized CMMC status. § 170.20 is. And § 170.20 has conditions.

We read the section in full at the eCFR on August 29, 2026. It's short. Each sentence does a different job.

The four conversion gates — plus the annual eligibility requirement

# — Requirement — What § 170.20 says — What to check on your side
#RequirementWhat § 170.20 saysWhat to check on your side
1DateThe DCMA DIBCAC High Assessment must have been conducted before the rule's December 16, 2024 effective date.The date of the original High Assessment in the authoritative assessment record.
2Assessment typeIt must be a DCMA DIBCAC High Assessment aligned with CMMC Level 2 Scoping. Eligible assessments include ones conducted with Joint Surveillance under DCMA Manual 2302-01.Confirm that the record is a DIBCAC High Assessment — not merely a Basic or Medium score.
3Score and POA&MThe organization must have achieved a perfect score with no open POA&M. The final-rule preamble confirms that any Joint Surveillance POA&M had to be closed before standards acceptance.Pull the 110 score and any closeout evidence; do not decide from memory.
4Accepted scopeThe Level 2 certification assessment scope must be identical to the DCMA DIBCAC High Assessment scope.Compare the accepted boundary against the original High Assessment scope.
OngoingAffirmationThe organization must submit an affirmation in SPRS and annually thereafter to achieve contractual eligibility.Locate the Final CMMC Status Date and the most recent affirmation in SPRS.

Source: 32 CFR § 170.20, read in full August 29, 2026. The score-and-POA&M clarification appears in the final rule at 89 FR 83092.

Two things in that table deserve to be pulled out and said plainly, because they're the ones that surprise people.

Gate 2 is broader than the label “JSVA.” The rule's operative sentence covers qualifying DCMA DIBCAC High Assessments aligned with CMMC Level 2 Scoping, and then states that eligible assessments include those conducted with Joint Surveillance. SPRS later announced that NIST High On-Site Assessments had been converted to CMMC Level 2 (C3PAO) and were available for affirmation. If your folder says “DIBCAC High” rather than “JSVA,” do not assume you are excluded. Check the actual SPRS record.

Gate 3 is about the accepted end state, not whether a POA&M ever existed. The rule requires a perfect 110 with no open POA&M. The final-rule preamble says that if the Joint Surveillance assessment resulted in POA&M actions, the POA&M had to be closed before standards acceptance. Don't disqualify yourself from memory — pull the closeout record.

The affirmation is not another conversion gate. It is the ongoing eligibility requirement that can fail after the status exists. More on that below, because it deserves its own section.

An organization-specific fact, not a category fact

We can tell you what the rule requires. We cannot tell you what your record shows. Nobody writing a public page can, and you should be skeptical of anyone who implies otherwise — including a consultant who tells you over the phone that you're “definitely still covered.”

The answer to “does my JSVA still count?” lives in your organization's current SPRS record, reconciled against the original DIBCAC High Assessment documents, the CMMC UID and scope, and the current environment. Everything on this page is designed to get you to that lookup with the right questions in hand.


When does a JSVA-derived CMMC Level 2 status expire?

The three-year validity period runs from the date of the original DCMA DIBCAC High Assessment — not from December 16, 2024, not from a POA&M closeout date, not from an annual affirmation, and not from the start of any implementation phase. Because § 170.20 only accepts assessments conducted before December 16, 2024, the latest possible expiration date for any status created through this provision is December 15, 2027.

This is the section we'd keep if we could only keep one.

Every § 170.20 status has a three-year endpoint tied to its own original High Assessment date. As of August 29, 2026, any qualifying assessment completed on or before August 29, 2023 has reached that endpoint. The final eligible cohort reaches it no later than December 15, 2027.

The JSVA expiration window

Date-window analysis by The Defense Compliance Report. Calculated August 29, 2026 from the rule's effective-date cutoff and three-year validity period. Use the exact date in your own assessment record; the table is a planning view, not a substitute for SPRS.

If the original DIBCAC High Assessment was conducted... — The three-year period ended or ends... — Where that leaves you on August 29, 2026
If the original DIBCAC High Assessment was conducted...The three-year period ended or ends...Where that leaves you on August 29, 2026
On or before August 29, 2023On or before August 29, 2026The three-year period has ended. Verify whether a newer status exists and what the current contract requires.
August 30–December 31, 2023August 30–December 31, 2026Expiring within about four months. This is the immediate decision window.
January–June 2024January–June 2027Roughly four to ten months remain.
July 1–December 15, 2024July 1–December 15, 2027The final eligible cohort and the longest remaining runway.
December 16, 2024 or laterNever converted under § 170.20The standards-acceptance route does not apply.

Every eligible row assumes the other three conversion conditions were met and the required affirmation was submitted. Date alone does not create contractual eligibility.

Why December 15, 2027 is a hard boundary: the last day an assessment could have been conducted “prior to the effective date” was December 15, 2024. Add the three-year validity period the rule specifies. That's it. That is the outer edge of the standards-acceptance window under the rule as written today.

Three worked examples

A May 4, 2023 assessment. Three-year anniversary: May 4, 2026. That passed nearly four months ago. This company's § 170.20 validity period has run its course, and if nobody was watching the calendar, the organization may still be describing the status as current. That's the scenario worth catching today.

A September 20, 2023 assessment. Three-year anniversary: September 20, 2026. Three weeks out. Still inside the window — barely — and squarely in decision territory.

A January 10, 2025 assessment. After the effective date. This one never entered through § 170.20 at all, regardless of score. Different path entirely.

Does the annual affirmation extend the three years?

No. The affirmation maintains contractual eligibility inside the validity period. It does not create a new original assessment date and it does not restart the three-year clock.

The two clocks you need to track

A JSVA-derived record can show two dates that answer different questions:

Clock — Date that drives it — What it controls
ClockDate that drives itWhat it controls
Legacy standards-acceptance clockOriginal DCMA DIBCAC High Assessment dateThe three-year validity period created by § 170.20.
Annual affirmation clockFinal CMMC Status Date, followed by annual affirmationsWhether the affirmation is current for contractual eligibility under §§ 170.20, 170.22, and DFARS 252.204-7021.

That distinction is easy to miss because both records live in SPRS. It is also why the CMMC Status Date is not a substitute for the original DIBCAC High Assessment date when calculating a § 170.20 expiration.

Which “assessment date,” exactly?

Use the date identified in the authoritative record as the date of the original DCMA DIBCAC High Assessment. DFARS 252.204-7020 separately identifies the date the assessment was completed as an SPRS data element, while 32 CFR § 170.4 defines the CMMC Status Date as the date the status results were submitted to SPRS or CMMC eMASS. Those are not interchangeable for a legacy § 170.20 calculation.

If the original assessment report, the NIST High record, and the converted CMMC record do not reconcile, do not pick whichever date gives you more time. Treat the discrepancy as a record issue and resolve it through the appropriate SPRS/DCMA channel.


Calculate the date before you buy anything

Original DCMA DIBCAC High Assessment date + three calendar years = the outer expiration date under § 170.20.

Then check four separate facts in SPRS: the Final Level 2 (C3PAO) status, the CMMC UID and scope, the Final CMMC Status Date, and the latest annual affirmation. Our CMMC certification validity guide explains how the three-year cycle differs across assessment types.


What happens when a JSVA-derived CMMC status expires?

When the three-year period ends, the § 170.20 validity period has ended. The rule does not provide a JSVA-specific grace period, tolling rule, automatic extension, or renewal. What § 170.20 does not answer is whether you have a separate newer status, what a particular contract or solicitation requires today, or when the Government will require a new Level 2 (C3PAO) assessment after the Phase II suspension.

This is where the damaging admission belongs: § 170.20 sets the life of the accepted status, but it does not contain a special bridge for what comes next. Its remaining paragraphs, § 170.20(a)(2) and § 170.20(b), are both marked [Reserved].

We looked for a published JSVA-specific extension, freeze, grace period, or post-expiration bridge in the Federal Register, the eCFR, the DoW CIO's CMMC pages, SPRS notices, and the July 2026 suspension memorandum. We did not find one.

So if your three-year period has ended, one part is not ambiguous: you should not represent the legacy § 170.20 period as unexpired. The open questions are operational and contractual: whether SPRS shows another current status, whether your existing contract still carries a third-party requirement, whether an amendment or modification has changed it, and what assessment path makes sense next.

Here's why we're saying that instead of glossing over it: the two empty paragraphs do not create a fallback. A score below 110, an open POA&M that was never closed before acceptance, a post-cutoff assessment, or a non-identical scope does not become eligible because the rule is quiet elsewhere. The qualification rules are explicit. The missing piece is the post-expiration transition, not the original eligibility test.

And here's the part that should lower your blood pressure: you are not stuck. You can establish the date, the conversion conditions, the SPRS status, the CMMC UID and scope, and the affirmation this week without hiring anyone. Then you can separate a government-record problem from a contract question and a readiness problem. Those are three different jobs.

The question to put in writing

Send this to your contracting officer, or adapt it for your prime's supply-chain contact. Getting a documented answer is worth more than a dozen confident phone calls.

Subject: Request for clarification — CMMC requirement, [Contract/Solicitation Number]

We are reviewing our organization's CMMC posture in connection with [contract/solicitation]. Our systems were assessed under a DCMA DIBCAC High Assessment conducted with Joint Surveillance on [date], which we understand was addressed under 32 CFR § 170.20 standards acceptance.

To ensure our representations are accurate and current, we request written confirmation of:

  1. The CMMC level and assessment type, if any, currently required under this contract or solicitation;
  2. Whether an amendment or modification has been issued affecting a previously stated CMMC assessment requirement following the July 13, 2026 suspension of Phase II implementation; and
  3. The effective date of any such amendment or modification and the requirement that applies until it is effective.

We are not requesting an interpretation of our SPRS record. We are requesting confirmation of the contractual requirement so that our submissions and performance remain accurate.

[Name, title, company]

Use SPRS/DCMA support for a suspected government-record problem. Use the contracting officer for the contract. Copy the template, change the brackets, and keep the answer with the file.


“Your conversion is paused.” Here's what the rule actually says.

The July 13, 2026 suspension of CMMC Phase II limits which CMMC levels program managers and requiring activities may designate in procurement requirements during the review. It did not amend 32 CFR Part 170. Section 170.20 remains in force, and SPRS had already announced that NIST High On-Site Assessments were converted to CMMC Level 2 (C3PAO) and available for affirmation.

This is the correction we most want on the record, because the error is fresh, it's confident, and it's aimed directly at people in a vulnerable position.

Several pages published since the suspension describe JSVA conversion as a Phase II mechanism that is now paused. One current analysis says the conversion was “policy, not statute,” that a JSVA was a promise of a later certificate, and that there is no active pipeline for conversion while Phase II is suspended.

We're not naming the publisher, because the point isn't the publisher. The point is that a reader who accepts that framing will sit still — preserving paperwork, waiting for a task-force report — while a three-year clock they don't know is running runs out.

Here is what we checked, and how you can check it yourself.

Standards acceptance is in the Code of Federal Regulations, not in a policy memo. Section 170.20 is a codified provision of 32 CFR Part 170, sourced to the CMMC Program final rule at 89 FR 83092, published October 15, 2024 and effective December 16, 2024. It is not a press release or a signaled intention.

The rule does not condition standards acceptance on Phase II. It says a qualifying organization “will be given” a Final Level 2 (C3PAO) status, valid for three years from the original DCMA DIBCAC High Assessment date. There is no Phase II trigger in that sentence.

The conversion occurred in the government system. On April 30, 2025, SPRS announced: “NIST High On-Site Assessments have been converted to CMMC Level 2 (C3PAO) and are available for affirmation.” That is not a future promise. It is an official system notice describing completed conversion and the next required action.

The mechanism runs through DCMA DIBCAC and SPRS, not a C3PAO queue. The rule says DIBCAC identifies qualifying assessments and verifies that SPRS accurately reflects the CMMC Status. The final-rule preamble separately says a C3PAO may not read the old DIBCAC score and grant a certification from it.

And the section is textually untouched. The eCFR displayed Title 32 as current through August 27, 2026 and last amended August 17, 2026. Section 170.20 still contains the original standards-acceptance language and the same two reserved paragraphs.

What the suspension did change — and it matters

We're not arguing the suspension was minor. It wasn't.

The CMMC acquisition rule took effect on November 10, 2025. Under the original rollout, Phase 1 ran from November 10, 2025 through November 9, 2026, and Phase II was scheduled to begin November 10, 2026. On July 13, 2026, the Department suspended Phase II implementation and established a reform review. The current DoW CIO page says the program is paused in Phase 1.

During the suspension:

  • Program managers and requiring activities may designate only Level 1 (Self) or Level 2 (Self) in procurement documents.
  • They may not designate Level 2 (C3PAO) or Level 3 (DIBCAC) during the review.
  • For active solicitations carrying those requirements, amendments are to be initiated and issued as soon as practicable.
  • Existing contracts are to be modified before the next option exercise or during the next scheduled administrative modification.
  • The Department continues to enforce the underlying NIST SP 800-171 Revision 2 baseline through self-assessments and select government-led assessments, and DFARS 252.204-7012 remains in effect.

Both of these are true at the same time, and holding them together is the whole skill here:

  1. Your organization may hold a Final Level 2 (C3PAO) status under § 170.20.
  2. During the suspension, program managers and requiring activities may not designate Level 2 (C3PAO) or Level 3 in procurement requirements.

Those answer different questions. One is about your record. The other is about the requirement in front of you. Confusing them is what produces both false panic and false comfort.

Four records, four different questions

Almost every bad JSVA answer comes from using one record to answer another record's question. This is the fix.

The question you're actually asking — The record that answers it
The question you're actually askingThe record that answers it
What could a qualifying historical DIBCAC High or JSVA receive?32 CFR § 170.20, the Federal Register final rule, and the April 30, 2025 SPRS conversion notice.
What may the acquisition team designate during the suspension?The July 13, 2026 implementation memorandum and any later official implementation direction.
What status does my organization actually hold?Your current SPRS record — Final status, CMMC UID, Final Status Date, scope, and affirmation.
What does this specific deal require?The solicitation, contract, amendment, or modification, plus written contracting-officer confirmation where needed.

A procurement implementation memorandum did not rewrite an organization-specific status created under a regulation. Check all four. In that order.


Your SPRS score is not your CMMC status

A NIST SP 800-171 assessment score and a CMMC Status are different records in SPRS. A score of 110 was a qualifying condition for § 170.20 standards acceptance. The Final Level 2 (C3PAO) status is the recognized CMMC result. Confirming a 110 does not confirm that the converted status exists, remains inside its three-year period, carries a current affirmation, or covers the information system you intend to use.

This distinction sounds academic until it costs you an award.

Plenty of JSVA holders log into SPRS, see a 110, and stop. The 110 is real and it's meaningful — it was the price of admission. But it answers “how did we score,” not “what does the Government currently recognize for this information system?”

A NIST SP 800-171 score tells you — A CMMC status record tells you
A NIST SP 800-171 score tells youA CMMC status record tells you
The recorded result against the 110 Revision 2 requirementsThe recognized CMMC level and assessment type
The assessment date, scope information, and score recorded under the NIST assessment processThe Final CMMC Status Date and the CMMC UID for the assessed information system
Whether the score gate may have been satisfiedWhether standards acceptance is reflected as Final Level 2 (C3PAO)
Nothing by itself about the annual affirmationWhether the related CMMC record has an affirmation that can be checked for currency

One more distinction matters: a CAGE code is not the CMMC assessment boundary. SPRS states that contracting officers verify CMMC using the UID supplied by the offeror, and that the CMMC UID must contain the scope covering the assessment. CAGE codes support access, metrics, and organization administration; they do not replace the UID and scope.

So change the question you ask your team. Not “did we pass the JSVA?” Ask:

“What Final CMMC Status does SPRS show, for which CMMC UID and scope, what is the original High Assessment date, what is the Final Status Date, and when was it last affirmed?”

That's the sentence that finds the problem.


The annual affirmation: the requirement that fails quietly

Under § 170.20, the organization must submit an affirmation in SPRS and annually thereafter to achieve contractual eligibility. Section 170.22 requires the affirmation after the Final CMMC Status and annually following the Final CMMC Status Date. DFARS 252.204-7021 treats a Final Level 2 (C3PAO) status as current only when the applicable age, continuing-compliance, and affirmation conditions are met.

If there's one thing we'd check first after confirming the converted status exists, it's this.

Look at the asymmetry the rule creates. The conversion was government-entered — DIBCAC identified qualifying assessments and SPRS converted the records. The contractor did not create that converted status by paying a C3PAO or filing a conversion application.

But the affirmation is not automatic. A named senior representative inside the organization must submit it in SPRS and do it again annually.

And the consequence isn't cosmetic. Section 170.17(b) makes both the applicable CMMC Status and a submitted affirmation prerequisites before award of a contract requiring Level 2 (C3PAO). DFARS 252.204-7021 requires an affirmation of continuous compliance not older than one year and requires annual affirmations for each applicable CMMC UID. A status can look impressive in a screenshot and still fail the contractual-currentness test.

Who has to sign it

The Affirming Official must be a senior representative from within your organization who is responsible for CMMC compliance and has authority to attest on the company's behalf under 32 CFR § 170.22. This cannot be outsourced to your MSP, your RPO, or your consultant. They can prepare the evidence. They cannot be the organization's Affirming Official.

That matters more than it sounds, because the affirmation includes the official's name, title, and contact information and attests that the organization has implemented and will maintain the applicable requirements across the relevant assessment scope.

If you've never filed one

Don't spiral. Do this instead, in order:

  1. Check SPRS first. The converted record was made available for affirmation, and someone may have completed it without your current team recognizing the label.
  2. If it is genuinely missing, determine whether your Affirming Official can truthfully attest today. Do not treat this as a clerical click-through.
  3. Submit the current affirmation if the official can truthfully make it, then document the discovery and correction. A late filing documents the current representation; it does not backdate an earlier gap or answer whether contractual eligibility existed during that gap.
  4. Do not backdate anything. An affirmation is a representation to the Government. Treat it with exactly that seriousness.
  5. If the official cannot honestly attest today, stop treating this as a paperwork problem. It is a remediation and scope problem, and that is the right time to bring in qualified help.

We'll be blunt about the stakes, because you deserve the real reason for the caution. The Department of Justice's Civil Cyber-Fraud Initiative has produced settlements involving cybersecurity representations to DoD, including Georgia Tech Research Corporation's $875,000 settlement announced September 30, 2025. DOJ alleged, among other things, that an SPRS score had been submitted for an environment other than the one actually handling the data. The settlement resolved allegations only; there was no determination of liability, and the defendants disputed the allegations.

The point is not that the case predicts your outcome. It is that environment-specific SPRS representations are material enough to become the center of federal litigation, and a CMMC affirmation is attached to a named senior official.


Don't let the next anniversary arrive unannounced

Download the CMMC readiness checklist →

It maps the annual affirmation and three-year reassessment cadence alongside the 110 Revision 2 requirements, with owners and evidence fields. It's free, it needs no CUI, and if you've just discovered a gap, it's the fastest way to hand your team a plan instead of a panic.


Your JSVA-derived scope is the environment that was assessed

Section 170.20 states that the Level 2 certification assessment scope is identical to the DCMA DIBCAC High Assessment scope. A JSVA-derived status does not automatically expand to systems, sites, cloud tenants, or CUI flows introduced after the original assessment.

This one catches good companies. Not sloppy ones — good ones, the kind that kept investing after the assessment.

Think about what a typical DIB contractor may have done between a 2023 assessment and today. Migrated from commercial Microsoft 365 to GCC High. Stood up a CUI enclave to shrink scope. Acquired a division and changed the operating environment. Moved CAD or PLM to a new platform. Opened a second facility. Every one of those can be a good decision. None of them is automatically covered just because the organization once held a JSVA-derived status.

Your status describes the boundary that was accepted. Not every boundary you have today.

What to actually do about it

We're deliberately not telling you that any change automatically voids your status — the rule doesn't say that, and we won't put words in it. What we can tell you is what a careful contractor does:

  1. Pull the original assessment scope description — the boundary, asset inventory, SSP version, sites, external services, and supporting records.
  2. Locate the current CMMC UID and its scope in SPRS. Do not use a CAGE hierarchy as a substitute; SPRS says CAGE codes are not the CMMC boundary.
  3. Map where CUI lives today. Not where it's supposed to live. Where it is.
  4. Mark every material difference. New tenant, enclave, subsidiary, system category, external service, site, or CUI flow.
  5. Treat a material divergence as a finding, document it, and get qualified review before you represent the old status as covering the changed environment.

There's a second reason to care. DFARS 252.204-7021 conditions a current Final Level 2 status on there being no changes in compliance with 32 CFR Part 170 since the Final CMMC Status Date, along with a current affirmation. A changed environment is not automatically fatal. It is automatically something you must evaluate.

If step 3 is where you get stuck — and for a lot of contractors it is — that's a scoping problem, and scoping is what readiness providers do every week. Our CMMC scoping guide walks the asset categories first, before you spend anything.


How to verify your JSVA status in SPRS

SPRS is the official store for CMMC statuses. Section 170.20 requires DCMA DIBCAC to identify qualifying assessments and verify that SPRS accurately reflects the status. A JSVA letter, an old 110 score, an assessment report, or a consultant's recollection is not enough by itself.

Ten minutes. No vendor required. Here's the sequence.

What to pull before you log in:

  • The original DCMA DIBCAC High Assessment report and completion date
  • Joint Surveillance documentation and the participating C3PAO, if applicable
  • The final 110 score and any POA&M closeout evidence
  • The original assessment scope description, SSP version, and supporting boundary records
  • The CMMC UID, if it has already been provided to a contracting officer or prime

What to locate in SPRS:

  • A CMMC Status of Final Level 2 (C3PAO)
  • The CMMC UID assigned to the assessed information system
  • The Final CMMC Status Date
  • The scope associated with the UID
  • The most recent annual affirmation date and Affirming Official
  • The separate NIST SP 800-171 High Assessment date and score

Then reconcile four things:

  1. Expiration: original DIBCAC High Assessment date + three years.
  2. Affirmation: Final CMMC Status Date and the latest annual affirmation.
  3. Scope: the CMMC UID's scope against the environment that will process, store, or transmit FCI or CUI.
  4. Continuing compliance: whether material changes since the status date affect the requirements you are affirming.

Write down what doesn't line up.

A practical note: SPRS field labels and navigation change over time. Rather than reproduce every screen label, we've listed the records you need conceptually. Contracting officers verify CMMC status using the UID supplied by the offeror; SPRS expressly says CAGE codes do not define the assessment boundary.

For a screen-by-screen companion, use our guide to verifying a company CMMC status in SPRS.

If the record is missing or inconsistent

Work it in this order, and notice that the first three steps cost nothing:

  1. Confirm you have the right SPRS role, organization access, and CMMC UID. Do not assume a CAGE hierarchy will reveal the assessed boundary.
  2. Reconcile the evidence against the four conversion conditions and the affirmation requirement. Date, assessment type, score and POA&M, accepted scope, affirmation.
  3. Contact the original C3PAO for assessment documentation if it participated — the records, not a promise of status. It cannot alter the government record.
  4. Use the appropriate SPRS/DCMA support route for a suspected conversion or record issue.
  5. Ask the contracting officer in writing about any procurement-specific conflict. The template is above.
  6. Engage an RP/RPO or qualified federal-contracts attorney where scope, representations, or applicability need interpretation.

One thing to be clear about, because it gets sold: a C3PAO cannot read your old DIBCAC score and issue a new certification from it. The final-rule preamble says so directly. Under § 170.17(c)(1), a C3PAO must perform a Level 2 certification assessment in accordance with NIST SP 800-171A and the CMMC scoping rules. Standards acceptance runs through § 170.20 and DCMA DIBCAC — not through a paid re-issue.


Five situations, five different next steps

The correct next step depends on which of five situations applies: a status that appears current, an eligible assessment with a missing status, a three-year period that has ended, a conversion condition that was never met, or a contract that still appears to require Level 2 (C3PAO) during the suspension. Only some of those situations involve hiring anyone.

This is where most pages send everyone to the same place. We're not going to, because the right answer genuinely differs.

A. SPRS shows a status that appears current

Good. Protect it.

Calculate the three-year endpoint from the original DIBCAC High Assessment date. Confirm the latest affirmation is no more than one year old. Confirm the CMMC UID and assessed scope still match the information system you rely on. Preserve the assessment evidence somewhere that isn't one person's inbox. Then set reminders before the next affirmation and before the three-year endpoint and get on with your quarter.

Do not rush to buy a replacement assessment because of suspension headlines. During the review, program managers and requiring activities may not designate Level 2 (C3PAO) or Level 3 in procurement requirements. Buy a formal assessment only when a real requirement, prime-customer demand, risk decision, or future plan justifies it.

B. The assessment looks eligible, but the status is missing

Assemble the evidence for the four conversion conditions, confirm the correct SPRS access and organization record, and pursue clarification through the authoritative support channel.

What not to do: pay a readiness provider to “fix” a government record it has no ability to alter. A provider can help you assemble and interpret evidence. Only the Government maintains the record. If someone quotes you a fee to correct SPRS, ask precisely which system they will be logging into and what authority lets them change it.

C. The three-year period has ended

First, verify there isn't a newer assessment or CMMC status you are unaware of.

Then answer the only question that determines immediate urgency: what does the current contract, solicitation, amendment, or prime flowdown actually require? During the Phase II suspension, new procurement requirements may designate only Level 1 (Self) or Level 2 (Self), but an existing contract term does not disappear until the appropriate amendment or modification takes effect.

Meanwhile, keep implementing. DFARS 252.204-7012 did not pause. NIST SP 800-171 Revision 2 remains the CMMC Level 2 control set under 32 CFR Part 170, and an expired CMMC status does not reduce the safeguarding obligation by one requirement.

Category fit: readiness — an RPO, a CMMC-focused MSP or MSSP, or a vCISO. Not a C3PAO yet, unless a formal assessment is genuinely the next decision.

D. A conversion condition was never met

Score below 110. An open POA&M that was never closed before standards acceptance. An assessment after December 15, 2024. A non-High assessment. A scope that was not identical. Any of these means the § 170.20 route is not yours, and forcing it wastes time.

Reset to the current question: what does your contract require, what information do you handle, what does your environment look like, and what's your timeline? That's a normal CMMC path decision, not a JSVA question.

E. A contract still appears to require Level 2 (C3PAO)

Check for an amendment or modification first. Then ask the contracting officer in writing, citing the July 13, 2026 implementation direction.

And until it is modified, the clause on your contract is the clause on your contract. Do not stop performing against a requirement because you read an article — including this one. Track the modification; don't infer it. If bid eligibility, payment, performance, or contractual rights are genuinely at stake, that is a conversation for qualified federal-contracts counsel.


Not sure which of the five you're in?

Get matched with source-checked provider options →

Tell us your required level, whether you handle FCI or CUI, your assessment status, your environment, and your timeline. The CMMC Path Framework maps that to a provider category — an RPO, an MSSP, a GRC platform, a CUI enclave, or a C3PAO — not a named provider, not a score, and not a compliance determination.

Do not submit CUI, drawings, SSP content, network diagrams, contract numbers, or credentials.

And if you don't need us, don't use us. If the three-year period has more than a year left, the affirmation is current, the scope still matches, and nobody is asking — you do not need to hire anyone today. Set the reminders and close the tab. We'd rather you come back when a real decision exists than spend money this week you didn't need to spend.


JSVA vs. DIBCAC High vs. C3PAO assessment vs. Level 3

A Joint Surveillance Voluntary Assessment was a way to conduct a DCMA DIBCAC High Assessment with C3PAO participation before the CMMC Program Rule took effect. It is not a Level 2 self-assessment, not the same process as a current C3PAO certification assessment, and it does not produce Level 3 status. A Final Level 2 (C3PAO) status is, however, a prerequisite to undergo a Level 3 certification assessment under § 170.18.

The terminology around this is genuinely messy, and the mess causes real errors. Here's the map.

Path or record — Who performs it — What it establishes — Relationship to JSVA
Path or recordWho performs itWhat it establishesRelationship to JSVA
Level 2 self-assessmentThe contractor, with an internal Affirming OfficialConditional or Final Level 2 (Self) against the 110 NIST SP 800-171 Revision 2 requirementsNot a JSVA. Different assessment type and status.
DCMA DIBCAC High AssessmentDCMA DIBCACA government High Assessment under the NIST SP 800-171 DoD Assessment MethodologyThe underlying assessment type accepted by § 170.20 when all conditions are met.
Joint SurveillanceDCMA DIBCAC with C3PAO participationA DIBCAC High Assessment conducted with Joint SurveillanceOne included form of eligible High Assessment under § 170.20.
§ 170.20 standards acceptanceIdentified by DCMA DIBCAC and reflected in SPRSFinal Level 2 (C3PAO), valid three years from the original High Assessment dateThe regulatory provision that converted qualifying legacy assessments.
Current Level 2 certification assessmentAn authorized or accredited C3PAOConditional or Final Level 2 (C3PAO) after an assessment under § 170.17The current formal path. The CMMC Assessment Process v2.0 is the official procedural guide for C3PAO Level 2 assessments.
Level 3 certification assessmentDCMA DIBCACLevel 3 status against 24 selected NIST SP 800-172 Feb2021 requirementsJSVA does not produce Level 3. Final Level 2 (C3PAO) for the Level 3 scope is a prerequisite.

Definitions, once: a C3PAO is a CMMC Third-Party Assessment Organization authorized or accredited through the Cyber AB to perform Level 2 certification assessments. DCMA DIBCAC is the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center. SPRS is the Supplier Performance Risk System, where CMMC statuses are officially stored. CMMC eMASS is the CMMC instantiation of the Enterprise Mission Assurance Support Service, where C3PAO and DIBCAC results are submitted for automated transmission to SPRS.

The version-control trap: Revision 3 did not silently replace Revision 2 for CMMC

NIST has published newer revisions of SP 800-171 and SP 800-172. That does not make those newer revisions the controlling CMMC requirements by itself.

The CMMC final rule defines Level 2 as the 110 requirements in NIST SP 800-171 Revision 2, organized across 14 requirement families, and Level 3 as 24 selected requirements from NIST SP 800-172 Feb2021. The final-rule preamble states directly that NIST SP 800-171 Revision 3 is not currently applicable to the rule. A change to the incorporated CMMC standards requires the appropriate rulemaking or other legally effective change; a NIST publication update does not rewrite 32 CFR Part 170 on its own.

That is why this page says Revision 2 even though NIST's publication page shows a newer revision. On this question, “newer” and “controlling” are not the same word.

What the Cyber AB CAP does — and does not do

The Cyber AB's CMMC Assessment Process (CAP) v2.0, effective December 16, 2024, is the official procedural guide for C3PAOs conducting current Level 2 certification assessments. It applies to those current C3PAO assessments; it is not the legal mechanism that created a legacy § 170.20 status.

The CAP also requires C3PAOs to manage impartiality and conflicts of interest and prohibits contractual guarantees or promises about the assessment result. A provider may help you prepare. A C3PAO may assess. Neither may guarantee the status before the evidence is tested.

Say it precisely

Accurate: “Our DCMA DIBCAC High Assessment conducted with Joint Surveillance on [date] was recognized under 32 CFR § 170.20 as a CMMC Status of Final Level 2 (C3PAO), subject to the recorded scope, the three-year validity period, continuing compliance, and our annual affirmation.”

Not accurate, and we've heard all of these: “Our 110 is our certificate.” “We're grandfathered forever.” “The suspension cancelled everybody's status.” “Our C3PAO can just reissue it.” “Revision 3 automatically replaced the CMMC control set.”

That first sentence is longer. It's also the one that survives a prime's supply-chain review.


Can I still get a JSVA in 2026?

No — not as a new assessment that can receive standards acceptance under § 170.20. An assessment conducted on or after December 16, 2024 cannot receive a CMMC status through that provision, regardless of score.

Short section, because you need fifteen seconds, not five hundred words.

We did not find a published Department notice giving a separate administrative date when Joint Surveillance stopped accepting requests. We do not need to invent one. The legally effective cutoff is in the rule: only qualifying High Assessments conducted before December 16, 2024 can enter through § 170.20.

It doesn't matter what a service page still calls an offering. A post-cutoff assessment cannot be turned into a legacy § 170.20 status.

What replaces it, given where things stand today:

  • A Level 2 self-assessment with the applicable SPRS record and annual affirmation, when the contract or solicitation designates Level 2 (Self). During the suspension, Level 1 (Self) and Level 2 (Self) are the only levels program managers and requiring activities may designate in procurement requirements.
  • A voluntary Level 2 certification assessment by a C3PAO. The Cyber AB stated on July 15, 2026 that C3PAO Level 2 assessments remain operational. A voluntary assessment may matter to a prime, customer, internal risk decision, or anticipated future requirement. It does not change the July 13 restriction on what acquisition teams may designate during the review.

A current C3PAO assessment is a new assessment under § 170.17 and the CAP. It is not a JSVA, not a reissue, and not a way to reset the old clock by paperwork.

Which route applies to you is a contract and scope question. Our Level 2 self-assessment vs. C3PAO guide walks that branch. No sales pitch here — this isn't automatically your buying moment, and pretending otherwise would waste your time.


What we actually verified

This guide was built by reading the operative CFR sections, the final-rule preamble, the current DFARS clauses, the official SPRS notices and FAQs, NIST's version records, the Cyber AB CAP, and the July 13, 2026 Phase II implementation memorandum. We cannot inspect a reader's SPRS record, interpret a specific contract, or confirm that an organization's current environment still matches its assessed scope.

Who created this: The Defense Compliance Report Editorial Team. We are an independent trade publication on CMMC and DIB compliance. No individual CMMC Subject Matter Advisor is represented as having formally reviewed this page.

Why it exists: because the current published answer to this question is split between service pages written for a legacy path and post-suspension analyses that describe a codified, already-implemented standards-acceptance provision as a future conversion promise. Both can leave a contractor sitting still while a real clock runs.

Verified August 29, 2026

  • Read 32 CFR § 170.20 in full, including § 170.20(a)(2) and § 170.20(b), both marked [Reserved]
  • Confirmed that § 170.20 requires a qualifying pre-effective-date DIBCAC High Assessment, a perfect score with no open POA&M, identical scope, and an SPRS affirmation with annual affirmations thereafter
  • Confirmed in the final-rule preamble that Joint Surveillance POA&M actions had to be closed before standards acceptance and that qualifying 110-scored High Assessments would be automatically converted in SPRS
  • Confirmed the CMMC Program final rule's correct citation: 89 FR 83092, published October 15, 2024 and effective December 16, 2024
  • Confirmed the December 15, 2027 outer boundary by applying § 170.20's pre-effective-date cutoff and three-year validity period
  • Read § 170.4 for the CMMC Status, CMMC Status Date, C3PAO, and Affirming Official definitions
  • Read §§ 170.17, 170.18, and 170.22 for Level 2 certification assessment, Level 3 prerequisite, assessment-investigation, contract-eligibility, and affirmation requirements
  • Confirmed that NIST SP 800-171 Revision 2 remains the CMMC Level 2 set of 110 requirements and that the final rule says Revision 3 is not currently applicable
  • Confirmed that CMMC Level 3 uses 24 selected requirements from NIST SP 800-172 Feb2021, not every requirement in a newer SP 800-172 revision
  • Read DFARS 252.204-7012 for the continuing safeguarding and incident-reporting baseline
  • Read DFARS 252.204-7019 and 252.204-7020 for the separate NIST SP 800-171 DoD Assessment requirement and High Assessment record elements
  • Read DFARS 252.204-7021 for current CMMC status, CMMC UID, annual affirmation, and continuing-compliance conditions
  • Confirmed the April 30, 2025 SPRS notice that NIST High On-Site Assessments had been converted to Level 2 (C3PAO) and were available for affirmation
  • Confirmed in the SPRS FAQ that contracting officers verify CMMC using the UID supplied by the offeror and that CAGE codes do not define the CMMC assessment boundary
  • Confirmed the original Phase 1 window of November 10, 2025 through November 9, 2026, the scheduled November 10, 2026 Phase II start, and the July 13, 2026 suspension that left the program paused in Phase 1
  • Confirmed that the suspension memorandum limits designations during the review to Level 1 (Self) and Level 2 (Self), directs action on active solicitations and existing contracts, and does not amend § 170.20
  • Read the Cyber AB CMMC Assessment Process v2.0, effective December 16, 2024, including its Level 2 scope, conflict-of-interest requirements, and prohibition on guaranteed assessment results
  • Confirmed the Cyber AB's July 15, 2026 statement that voluntary C3PAO Level 2 assessments remain operational

What we could not verify, and did not turn into fact

  • A definitive total count of completed Joint Surveillance assessments. We found no authoritative total and did not estimate one.
  • A separate administrative date when Joint Surveillance stopped accepting requests. We use the December 16, 2024 legal cutoff because that is what § 170.20 controls.
  • A JSVA-specific grace period, tolling rule, automatic extension, or post-expiration bridge. We found none in the published sources reviewed.
  • A reader's exact SPRS status, CMMC UID, scope, affirmation, or contract requirement. Those are organization- and record-specific facts.
  • Permanent SPRS screen labels. We describe the records to locate rather than freeze navigation text that can change.

Primary sources we read

Found something that changes this analysis? Use our corrections contact. We update when the rule, official implementation direction, or verification method changes — and we date the change.


Frequently asked questions

Is the CMMC Joint Surveillance Voluntary Assessment program still available?

Not as a new path to § 170.20 standards acceptance. Only qualifying DCMA DIBCAC High Assessments conducted before December 16, 2024 can receive a CMMC status through that provision.

How long is a JSVA-derived CMMC status valid?

Three years from the date of the original DCMA DIBCAC High Assessment. The period is not measured from the rule's effective date, a POA&M closeout, an affirmation, the converted CMMC Status Date, or an implementation-phase date.

Did my JSVA automatically become CMMC Level 2 (C3PAO)?

If the underlying DIBCAC High Assessment met every § 170.20 condition, the rule required DCMA DIBCAC to identify it and verify that SPRS reflected Final Level 2 (C3PAO). SPRS announced on April 30, 2025 that NIST High On-Site Assessments had been converted and were available for affirmation. Your own answer still depends on the organization-specific SPRS record.

What score did a JSVA need for standards acceptance?

A perfect score of 110 with no open POA&M. The final-rule preamble clarifies that if the Joint Surveillance assessment produced POA&M actions, the POA&M had to be closed before standards acceptance.

Did the July 13, 2026 Phase II suspension cancel or pause the converted status?

The suspension memorandum does not say that. It limits which levels acquisition teams may designate during the review. It does not amend § 170.20, and SPRS had already announced completed conversions in April 2025.

Does the suspension extend or freeze my three-year clock?

No published instrument we found extends, tolls, or freezes the § 170.20 validity period. Under the rule as written, it still runs from the original DIBCAC High Assessment date.

Do I still need an annual affirmation?

Yes. Section 170.20 requires an affirmation in SPRS and annually thereafter for contractual eligibility. Section 170.22 ties annual affirmations to the Final CMMC Status Date, and DFARS 252.204-7021 requires the affirmation to remain current.

Does an annual affirmation restart the three-year period?

No. It maintains the affirmation requirement inside the status period. It does not create a new original High Assessment date.

Who is allowed to be the Affirming Official?

A senior representative from within the organization who is responsible for CMMC compliance and has authority to affirm continuing compliance. An external MSP, RPO, or consultant cannot be the organization's Affirming Official.

Is a 110 SPRS score the same as a CMMC Status?

No. The score is the NIST SP 800-171 DoD Assessment result. The CMMC Status is the recognized level and assessment type for the assessed information system, identified through its CMMC UID and scope.

Does a straight DIBCAC High Assessment qualify, or only Joint Surveillance?

Section 170.20 covers qualifying DCMA DIBCAC High Assessments aligned with CMMC Level 2 Scoping and says eligible assessments include those conducted with Joint Surveillance. The official SPRS conversion notice referred broadly to NIST High On-Site Assessments. Check the actual record rather than relying only on the label in the folder.

What if our environment or scope changed after the assessment?

The accepted Level 2 scope under § 170.20 is identical to the original DIBCAC High Assessment scope. New systems, sites, cloud tenants, external services, or CUI flows are not automatically covered. Reconcile the current environment against the CMMC UID and assessed boundary before representing that the status covers it.

Is a CAGE code the CMMC assessment boundary?

No. SPRS says contracting officers verify CMMC status using the CMMC UID supplied by the offeror, and that CAGE codes are not used to define the assessment boundary. The UID must carry the scope that covers the assessment.

Can a C3PAO issue a certification by reading my old DIBCAC score?

No. The final-rule preamble says a C3PAO may not simply read the DIBCAC score and grant a completed Level 2 certification assessment. A current C3PAO status requires a current assessment under § 170.17.

Does a JSVA give me CMMC Level 3?

No. Standards acceptance produces Final Level 2 (C3PAO), not Level 3. A Final Level 2 (C3PAO) status for the Level 3 scope is a prerequisite to undergo the Level 3 assessment, which DCMA DIBCAC performs against 24 selected NIST SP 800-172 Feb2021 requirements.

Does NIST SP 800-171 Revision 3 control CMMC Level 2 now?

No. The CMMC final rule still incorporates the 110 requirements in NIST SP 800-171 Revision 2, and the rule's preamble says Revision 3 is not currently applicable. NIST publishing a newer revision does not amend 32 CFR Part 170 by itself.

How many requirements and families are in the CMMC Level 2 baseline?

The controlling Level 2 baseline is 110 NIST SP 800-171 Revision 2 requirements organized across 14 requirement families. Do not confuse the 110 requirements with 110 equally weighted points under every assessment methodology.

Do I need to hire a C3PAO immediately when the three-year period ends?

Not automatically. First determine what the current solicitation, contract, amendment, modification, or prime flowdown requires. Readiness work and a formal certification assessment are separate engagements. Buy the formal assessment when it solves a real requirement or business decision, not because the old date passed in isolation.

What happens the day the JSVA-derived period expires?

The § 170.20 validity period has ended. The rule supplies no JSVA-specific grace period or automatic extension. Verify whether another current status exists, confirm the actual contract requirement, and separate any SPRS record issue from the readiness and procurement decisions.

Can DCMA DIBCAC reassess us even with a current status?

Yes. Under § 170.17(a)(1)(iv), DoD reserves the right to conduct a DCMA DIBCAC assessment. If the later government assessment shows that the Part 170 requirements were not achieved or maintained, those results take precedence over the pre-existing CMMC Status.


Need help deciding what type of CMMC provider you need?

Tell us your level, scope, assessment position, and timeline, and we'll route you to the provider category that fits the decision.

Find My CMMC Path → · Request source-checked options → · Compare provider categories → · See who to hire first → · Download the readiness checklist →

The CMMC Path Framework routes to a provider category, not a compliance determination. Matching is not an endorsement, legal opinion, assessment result, or certification guarantee. Do not submit CUI, drawings, SSP content, network diagrams, contract numbers, or credentials.


Related reading


Disclosure: The Defense Compliance Report is an independent trade publication on CMMC and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category framework, or verification of Cyber AB marketplace status.

The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense or Department of War, DCMA DIBCAC, NIST, SPRS, or any U.S. government agency. This page is educational research and is not legal, contractual, assessment, or compliance advice. Confirm organization-specific scope and applicability with a qualified CMMC practitioner and use qualified federal-contracts counsel when contractual rights, representations, or bid eligibility are at stake.

Last verified: August 29, 2026. Next scheduled review: October 2026, or sooner if the CMMC Reform Task Force or another official source changes the implementation direction.