Skip to main content
Remindax
AI SmartDoc NEW Pricing

Login Signup Free
Document Tracking

Track CMMC certification, affirmation, and SPRS dates

CMMC decides whether a defense contractor is even allowed to compete — and the level required is set by the contract, not by you. A certification is issued once and then held up by a yearly affirmation, an SSP, POA&M close-out dates, and a score posted in SPRS. Remindax tracks those dates and reminds you far enough ahead that you're at level before the solicitation, not after it.

  • GDPR-ready
  • Forever-free plan
  • iOS & Android App
  • Trusted by 30,000+ teams

CMMC is a phased, evolving program — confirm current requirements with DoD or your assessor. General information, not cybersecurity or legal advice.

Staff working at desks in a busy contractor office, one on a desk phone amid paperwork, with a cyber security shield graphic on one of the monitors
The security work happens in rooms like this one. The dates don't — a certification, a yearly affirmation, and an SPRS posting are calendar obligations, and the level you'll need is set by a contract you haven't won yet.

Most compliance obligations are about the work you already have. This one is about the work you haven't won yet. CMMC is the Department of Defense program that requires contractors handling certain federal information to demonstrate a level of cybersecurity before they're eligible for the contracts that call for it — and the level required is written into the solicitation by a customer you don't control. That single fact changes the shape of the problem. Your own operations don't set the bar; the next opportunity does. A company can be perfectly compliant for the contract it's performing today and ineligible for the one it wants to bid on next month, without anything about the company having changed at all.

And the gap can't be closed in a hurry. Where a higher level calls for a third-party assessment, that has to be scheduled with a limited pool of authorized assessors — on a timeline that has no relationship to a proposal deadline. By the time a solicitation tells you what you needed, the window to become it has usually already closed.

Underneath sits the paperwork that has to stay true in between: the System Security Plan describing the environment, any plan-of-action items with close-out dates attached, and a score posted in SPRS — which, unlike almost anything else in your compliance file, a prime or a contracting officer can look up about you without asking. And a certification, once issued, is kept meaningful by a yearly affirmation that a named senior official has to sign. Here's how CMMC works to track, and how to be at level before you need to be.

CMMC is a phased, evolving program — the specifics below are general information and are still settling. Confirm what currently applies to you with DoD or your assessor. This is not cybersecurity or legal advice.

Section 01

1. What is CMMC?

CMMC — the Cybersecurity Maturity Model Certification — is the Department of Defense framework requiring contractors that handle federal contract information or controlled unclassified information to demonstrate a required level of cybersecurity in order to be eligible for DoD contracts. The level is tiered to the contract and the data involved, with lower levels commonly met by self-assessment and higher ones requiring a third-party assessment. Eligibility is then held in place by an ongoing yearly affirmation and by supporting documents that have to stay current. Remindax helps you track those dates and reminds you before each. It does not assess, certify, remediate, or manage cybersecurity, and it is not a GRC platform or an authorized assessor.

The part worth sitting with is who decides. Nothing about your company determines your obligation on its own — not your headcount, not your revenue, not the sensitivity you'd assign to your own systems. The requirement arrives attached to an opportunity, and it can arrive at a different height each time. That makes CMMC a forward-looking obligation in a way most dated records aren't: the useful question isn't "is our certification current?" but "will we be at the level the next thing we want to bid on asks for, by the time it asks?"

A level your customer sets vs. a level your own business sets

This is the line that separates this page from its closest structural sibling. PCI DSS validation is also tiered, and it also splits between self-assessment and an assessor-led route — but the tier there follows from your own card volume. It's a fact about your business that you already know, it moves slowly, and it applies to everything you do at once. CMMC's level is assigned from outside, per opportunity, and can differ between two contracts you're pursuing in the same quarter. One is a cadence you settle into. The other is a bar that can be raised on you by someone else's paperwork.

1.1 What keeps you eligible

Four things carry dates, and only the first looks like a certificate:

  • The certification level — tiered to the contract and the information it involves. Lower levels are commonly self-assessed; higher levels generally call for a third-party assessment, which has to be scheduled rather than simply performed.
  • Assessment validity — a CMMC assessment commonly carries a multi-year validity, around three years, after which it has to be redone rather than extended.
  • The annual affirmation — a yearly submission by a named senior official confirming that the requirements are still being met in between assessments.
  • Supporting documents — the System Security Plan, any POA&M items with close-out deadlines, and the score posted in SPRS.

Each is governed by rules that are still phasing in, so treat every specific here as a starting point for a conversation with your assessor rather than a settled fact. What isn't likely to change is the structure: a level someone else chooses, a certification obtained on a long lead time, and a set of records underneath it that have to keep saying true things about an environment that keeps moving.

Section 02

2. Does CMMC certification expire?

Quick answer — evolving program, confirm the specifics
The assessment has a multi-year validity

A CMMC assessment is commonly valid for around three years, then has to be redone.

The affirmation is due every year in between

A named senior official submits it annually, confirming the requirements are still being met.

The certificate is issued; the affirmation keeps it true

An unexpired certification with a missed affirmation can still leave your eligibility in question.

The supporting records have their own dates

A current SSP, POA&M close-out deadlines, and a posted SPRS score sit underneath it.

So a CMMC certification expiration date is a real thing you can write down — it just isn't the only date that decides whether the certification still counts for anything. The distinction that matters here is between a validation and an affirmation, because they do different jobs. An assessment is the event that produces the certification — the examination itself, at the level required, self-performed or assessor-led depending on where you sit. The annual affirmation isn't a smaller version of that. It's a signature: a named senior official personally stating that a certification already in hand still describes reality. Nobody re-examines anything. Somebody takes responsibility for the claim.

That's why the yearly date is the one that slips. The assessment is expensive, scheduled far ahead, and owned by a project team — it has everyone's attention by construction. The affirmation is one submission by one person on a date that arrives without ceremony, in a year when nothing else about CMMC is happening. It looks administrative, and it's the thing standing between a certificate and its meaning. A contractor holding a certification that hasn't expired can still find its position weakened because the signature that was supposed to accompany it never went in.

A rising bar, not a repeating one

Recurring compliance usually means doing the same thing again: the same review, the same filing, the same audit, once a cycle. CMMC has that element, but it also has one most dated obligations don't — the requirement itself can go up. A contractor pursuing work at a higher level than the one it holds isn't repeating last year's exercise on a fresh date; it's undertaking a different and larger project, with an outside assessor's calendar in the middle of it. Tracking the renewal date alone will tell you when today's certification runs out. It won't tell you that the pipeline has started asking for something you don't have.

Section 03

3. Why tracking CMMC dates matters

Four properties combine to make this an unusually easy obligation to be quietly wrong about:

3.1

The bar is set by work you haven't won

The level comes from the solicitation, so your obligation is defined by opportunities still in the pipeline — not by anything visible inside the company today.

3.2

Closing a gap takes longer than a bid window

Where a third-party assessment is required, it has to be booked with a limited pool of authorized assessors — a schedule that no proposal deadline can compress.

3.3

The yearly signature is the quiet date

The annual affirmation is one submission by one senior official, on a date in a year when nothing else is due — and an unaffirmed certification is a weaker thing than it looks.

3.4

Part of your file is readable from outside

A score posted in SPRS can be looked up by a prime or a contracting officer directly. A stale posting says something about you before anyone asks you anything.

Individually, none of these is hard to handle. Together they produce a specific and recognizable failure: the contractor who is genuinely compliant, believes it, and is right — for the contract it happens to be performing. Everything on the current job is in order. The certification hasn't expired. And the reason a bid didn't go anywhere last quarter never quite gets traced back to a level, a lapsed affirmation, or a score that hadn't been refreshed since the environment changed. Nothing announced itself, so nothing got fixed.

Being registered vs. being qualified

Federal eligibility is layered, and the layers fail differently. An active SAM.gov registration is the administrative baseline — you renew it yourself, it's the same requirement for everyone, and letting it lapse costs you awards and payments across the board until you reactivate. CMMC sits a layer above: it doesn't ask whether you're registered to do business with the government, it asks whether you're qualified for this particular piece of it. That's why a lapse here doesn't produce a company-wide stop. It narrows the set of things you're allowed to pursue, quietly, one solicitation at a time.

Section 04

4. Who needs to track CMMC dates

The dates are usually split across people who don't share a calendar, which is most of the problem:

The recurring pattern is a handoff that never happens. Capture reads a requirement and files it as a bid consideration. IT owns the environment and the plan describing it. One executive owns a signature. Nobody owns the sentence that would join them — "the thing we intend to pursue in the spring needs a level we don't currently hold, and getting there starts now." That sentence only exists if the dates and the level live somewhere both sides look.

Section 05

5. What happens when a CMMC date lapses

Nobody tells you. That's the whole difficulty, and it's worth stating plainly because it's so unlike the way compliance failures usually behave. An expired permit stops work. A failed inspection tags out a machine. A lapsed professional license means somebody can't sign something, today, and everyone finds out immediately. A CMMC shortfall produces none of that. Your systems keep running, your current contract keeps being performed, your staff keep working, and no notice arrives to say a threshold was crossed.

What changes is what you're allowed to go after. Because the requirement is written into individual solicitations, falling short doesn't remove you from the market — it removes you from a subset of it, and the subset is invisible from where you're standing. Opportunities you'd have been competitive for simply aren't ones you can pursue. There's no rejection letter for a bid you never submitted, and no line item anywhere in the business for revenue that never had the chance to exist. A defense-focused company can lose a meaningful part of its addressable pipeline this way and experience it only as a slow quarter.

The specific ways it happens are unglamorous. A certification runs to the end of its multi-year validity and the reassessment wasn't booked early enough, so there's a gap between one and the next. The annual affirmation date passes in a quiet year and the certification carries on looking valid while quietly resting on nothing. The SSP still describes an environment the company has since moved off. A POA&M item's close-out deadline arrives with the item not closed. Or the SPRS score reflects a posture from before the last round of changes — and because a prime or a contracting officer can read that directly, it's the one failure that speaks for you in your absence.

And the recovery is slow in a way the calendar doesn't warn you about. A gap discovered inside a bid window generally can't be closed inside that bid window — a third-party assessment isn't something you can arrange because a deadline is pressing. That inverts the usual logic of a renewal reminder. Knowing the date something expires is useful. Knowing it early enough to have done something about it is the entire point.

⚠ The failure that files no complaint

Most lapses generate an event: a letter, a fine, a stop-work, an angry phone call. Falling short on CMMC generates a non-event. You are not competing for something, and nothing in the business is structured to notice an absence. That's precisely what makes it a tracking problem rather than an operational one — no part of the company will raise its hand, so the dates have to do it, far enough ahead to matter.

Section 06

6. How Remindax keeps your CMMC dates current

Your security team and your assessor do the work; your senior official signs the affirmation. What's left over is a coordination problem — knowing what's due, who owns it, and getting warned early enough that a long lead time is still available to you. That's the part Remindax does:

📂

Certification and affirmation side by side

The assessment validity and the yearly affirmation held together with the SSP, POA&M close-outs, and SPRS dates — status at a glance, in one register.

🔔

Warnings with runway, not notice

Staged alerts by Email, SMS, and WhatsApp, set far enough ahead of a CMMC assessment renewal that an assessor's calendar is still open to you — and routed to the person who actually owns each date.

👤

The affirmation reaches its signer

The yearly submission belongs to one named senior official, so its reminder goes to them directly rather than into a shared inbox that assumes somebody will pick it up.

🏢

Every unit tracked separately

Business units or enclaves each with their own level, dates, and reminders — so one unit being current is never mistaken for the group being current.

Two honest limits

Remindax tracks dates and reminds the right people. It does not assess, certify, remediate, or manage cybersecurity, does not calculate or post a score, is not an authorized assessor, and is not a GRC platform — that work stays with you and your assessor. And because the program is still phasing in, confirm what currently applies to you with DoD or your assessor rather than with a page on the internet. For teams carrying this beside every other dated obligation, see compliance tracking software — tracking and reminders, not governance — and certification tracking software.

Section 07

7. Why spreadsheets fail for CMMC tracking

A spreadsheet built to hold CMMC compliance dates almost always contains one row: the certification and the date it runs out. That row is the least dangerous thing on the whole list. It's the expensive, scheduled, project-managed item that nobody was going to forget anyway — and having captured it, the tracker feels complete.

What it leaves out is everything that actually goes wrong. It has no row for the yearly affirmation, because an affirmation isn't a document with an expiry printed on it. It has no way to hold a POA&M close-out deadline, or to know that the SSP no longer matches the environment, or that the posted score is older than the last three changes to the network. And it certainly has no column for the requirement that hasn't arrived yet — the level a pursuit in next year's plan is going to ask for, which is the only entry that would have given anyone time to act.

Then there's the silence. A spreadsheet will hold a date perfectly and never once mention that it passed. For an obligation whose failure mode is already invisible — where nothing stops, nobody writes, and the cost is work you never got to bid on — a silent tracker isn't a partial solution. It's a second layer of the same problem.

Manual spreadsheet
  • Usually holds only the certification date — the one item nobody was going to forget
  • No row for a yearly affirmation, because it isn't a document with an expiry on it
  • POA&M close-outs, SSP currency, and the posted score have nowhere to live
  • Silent — it will never volunteer that a reassessment needed booking last quarter
  • Says nothing about the level an upcoming pursuit will require
Automated tracking
  • Assessment validity, yearly affirmation, and supporting dates in one register
  • The affirmation reminder goes to the named senior official who has to sign it
  • POA&M close-out deadlines and SPRS refresh dates carried as first-class entries
  • Alerts staged far enough ahead that an assessor's calendar is still available
  • Each business unit or enclave held separately, with its own level and dates
Section 08

8. Key takeaways

  • CMMC gates eligibility for DoD contracts involving protected information — and the level required is set by the contract, not by anything inside your own business.
  • That makes it a forward-looking obligation: the bar is defined by opportunities you haven't won yet, and can differ between two pursuits in the same quarter.
  • A CMMC assessment commonly carries a multi-year validity, while a yearly affirmation by a named senior official is what keeps an issued certification meaningful in between.
  • The SSP, POA&M close-out deadlines, and the SPRS score carry their own dates — and the posted score is the part a prime or contracting officer can read without asking you.
  • A shortfall produces no notice and no stop-work; it just narrows what you can pursue, and it can't be fixed inside a bid window — so warning has to arrive with runway. Remindax tracks the dates; it doesn't assess, certify, or remediate.

Never lose eligibility between assessments

Track your CMMC certification and annual affirmation — automatically. Hold the assessment validity, the yearly submission, and the SSP, POA&M, and SPRS dates in one place, and Remindax reminds the people who own them early enough to still act.

GDPR-ready · AWS secure cloud · Encrypted storage · Setup in under 5 minutes

CMMC is a phased, evolving program — confirm current requirements with DoD or your assessor.

Section 09

9. Frequently Asked Questions

A CMMC assessment typically carries a multi-year validity, commonly around three years, after which it has to be redone. But eligibility also depends on an annual affirmation submitted in between, so an unexpired certification with a missed affirmation can still leave your position in question. CMMC is a phased, evolving program - confirm the current rules with DoD or your assessor.

A yearly submission by a named senior official confirming that the company is still meeting the requirements of its CMMC level, made in between assessments. It is not a re-examination - nobody reassesses anything. It is a signature taking responsibility for a certification already in hand.

The level is tiered to the contract and the type of information involved, so it is set by the solicitation rather than by anything inside your own business. Two contracts you are pursuing at the same time can require different levels, and the requirement can be higher than the level you currently hold.

Typically a System Security Plan describing the environment, any plan-of-action-and-milestones (POA&M) items with close-out deadlines, and a score posted in SPRS. Each carries dates of its own, and the SPRS posting is the part a prime or contracting officer can look up directly.

Nothing stops and no notice arrives - which is what makes it hard to catch. You simply become ineligible for the DoD contracts that require CMMC at that level until it is restored, so the cost shows up as work you were never able to pursue rather than as a penalty.

Both are tiered and both split between self-assessment and an assessor-led route, but the tier is set differently. PCI DSS follows from your own card volume - a fact about your business that moves slowly and applies to everything at once. A CMMC level is assigned from outside, per contract, and can be raised on you by a solicitation you did not write.

No. SAM.gov registration is the administrative baseline for doing business with the federal government at all - one annual renewal, the same for everyone. CMMC sits above it and asks whether you are qualified for a particular piece of that work, so a shortfall narrows what you can pursue instead of stopping awards outright.

Usually not, where a third-party assessment is required - that has to be scheduled with a limited pool of authorized assessors, on a timeline unrelated to a proposal deadline. This is why the useful date is the one that gives you runway, not the one that tells you a deadline has arrived.

No - Remindax tracks the certification, affirmation, and related dates and reminds you. Assessment, certification, remediation, and posting a score are handled by you and authorized assessors. Remindax is not an assessor and not a GRC platform.

Yes - each entity or enclave gets its own level, assessment date, annual affirmation, and supporting dates in one place, each with its own reminders, so one unit being current is never mistaken for the group being current.

Yes - a forever-free plan, no credit card required.