Affirmation · 2026-08-03
The Annual Affirmation: What You're Actually Signing, and What Stands Behind Your Signature
Who signs the annual affirmation, what 32 CFR 170.22 makes them attest to, and what False Claims Act enforcement means for the evidence behind it.
Once a year, a senior official at your company must log into a federal system and attest, under their own name and title, that your company has implemented and will maintain every security requirement it claims to meet. That is the annual affirmation, codified at 32 CFR 170.22. It is not a renewal form or a checkbox. It is a standing representation to the United States government, and the False Claims Act is the statute that gives it teeth. This article explains who signs, exactly what the regulation makes them attest to, what the government has done when the attestation and reality diverged, and what real evidence behind a signature looks like.
What the regulation actually says
The affirmation requirement lives in 32 CFR 170.22. The mechanics are short enough to state in full:
- An Affirming Official must affirm the organization's continuing compliance after every assessment, including POA&M closeout, and annually thereafter. This applies whether you are a prime or a subcontractor.
- Affirmations are entered electronically in SPRS, the same system that holds your assessment score. The Department verifies that the affirmation is on file when checking contract eligibility.
- Each affirmation contains two things: the name, title, and contact information of the Affirming Official, and an attestation that the organization "has implemented and will maintain implementation of" all applicable security requirements for every information system in the assessment scope.
Read that attestation language again, because both verbs matter. Has implemented is a statement about the past and present: the requirements are in place today. Will maintain is a promise about the future: they will stay in place. You are not affirming that a snapshot was accurate on assessment day. You are affirming a continuing condition.
The companion contract clause, DFARS 252.204-7021, makes the affirmation an ongoing performance obligation: contractors must complete it annually and keep it current in SPRS for every applicable system, and must ensure their subcontractors do the same before subcontract award. An affirmation is considered current only if it is less than a year old and there have been no changes in compliance.
Who signs: the Affirming Official
The regulation defines the Affirming Official as the senior-level representative responsible for ensuring the organization's compliance, with the authority to affirm it. In a 40-person shop, that is the president, the owner, or a senior officer. Three things follow from the definition that are easy to miss.
It cannot be outsourced. Your MSP can implement controls and your consultant can write documents, but neither can be your Affirming Official. The signature comes from inside the company, from someone with actual authority over it.
It is personal. The affirmation carries a specific person's name, title, and contact information into a federal system of record. When a prime, a contracting officer, or an investigator looks at your compliance posture, a named individual stands next to it.
It recurs. After the initial assessment, after any POA&M closeout, and every year after that. The official who signs in year one will be asked to sign again in year two, about a company whose people, systems, and configurations have changed in the meantime.
What "continuing compliance" means in practice
The gap between assessment day and affirmation day is where compliance programs quietly fail. Evidence decays on a schedule: access reviews are quarterly, training records are annual, log retention rolls forward continuously, and personnel actions happen whenever they happen. A company that was genuinely compliant in March can drift out of compliance by October without anyone deciding anything. The machine that ran the old finishing line gets replaced. The office manager who ran offboarding leaves. The MSP migrates your file server.
The affirmation is the legal mechanism that makes this drift your problem. Because the attestation covers continuing compliance, the relevant question is not "was the score right when we posted it?" It is "is the statement still true today, and can we show it?" A signature backed by a binder assembled once, eighteen months ago, is a signature backed by a description of a company that no longer exists.
One more point that matters for every contractor reading this. Even before a CMMC clause appears in your contracts, the score you post in SPRS under DFARS 252.204-7019 is already a representation to the government, made in connection with claims for payment. The enforcement cases below all predate CMMC clauses entirely. The affirmation formalizes and personalizes an exposure that has existed since the SPRS posting requirement began.
The statute behind the signature: the False Claims Act
The False Claims Act (31 U.S.C. § 3729) imposes liability on anyone who knowingly submits, or causes to be submitted, false claims for payment to the federal government. Two features make it the most consequential statute in this space.
The damages are treble. A company found liable pays three times the government's damages, plus per-claim civil penalties. Settlements in this area have run from six figures to eight.
Private individuals can bring the case. Under the FCA's qui tam provisions, a whistleblower (the "relator," often a current or former employee) can file suit on the government's behalf and receive a share of any recovery, typically 15 to 30 percent. Your compliance representations can be tested in court by the person who administered your systems and knows exactly what was and was not implemented.
In October 2021, the Department of Justice launched its Civil Cyber-Fraud Initiative, announcing that it would use the FCA to pursue federal contractors who knowingly misrepresent their cybersecurity practices or fail to meet contractual cybersecurity requirements. The initiative has continued across administrations, and defense-contractor cybersecurity cases are now a recurring category of FCA settlement.
The enforcement record
These are settlements of alleged violations. Except where noted, the defendants did not admit liability, and settlement is not a finding of wrongdoing. The fact patterns are still the clearest available picture of what the government considers actionable.
Aerojet Rocketdyne (2022, $9 million). DOJ announced on July 8, 2022 that Aerojet agreed to pay $9 million to resolve allegations that it violated the FCA by misrepresenting its compliance with cybersecurity requirements in certain federal government contracts. The suit was brought and litigated by a former employee, Brian Markus, under the qui tam provisions; the parties settled on the second day of trial, and Mr. Markus received $2.61 million as his share of the recovery.
Pennsylvania State University (2024, $1.25 million). DOJ announced on October 22, 2024 that Penn State agreed to pay $1.25 million to resolve allegations that, between 2018 and 2023, it failed to comply with cybersecurity requirements in fifteen contracts or subcontracts involving DoD or NASA. Per the announcement, the government alleged that Penn State failed to implement contractually required controls and did not adequately develop and implement plans of action to correct the deficiencies it identified; that the assessment scores it submitted to DoD reflected the unimplemented controls but misrepresented the dates by which it would implement them, without pursuing the plans of action to do so; and that it used an external cloud provider that did not meet DoD's security requirements. The whistleblower, the former chief information officer of Penn State's Applied Research Laboratory, received $250,000.
MORSECORP Inc. (2025, $4.6 million). According to DOJ's announcement, the government alleged that between 2018 and 2023 the company had not fully implemented the NIST SP 800-171 controls its Army and Air Force contracts required, lacked a consolidated system security plan for its covered systems for part of that period, and in January 2021 posted a self-assessment score of 104 to SPRS. A third-party gap analysis later assessed the company's actual score as −142, and the score was not corrected in SPRS until mid-2023. The company subsequently remediated, reaching a reported 110 in 2024, and paid $4.6 million to resolve the allegations. The whistleblower received approximately $851,000.
Raytheon, RTX, and Nightwing (2025, $8.4 million). DOJ announced a settlement resolving allegations that, between 2015 and 2021, Raytheon performed unclassified work on 29 DoD contracts and subcontracts using an internal system that did not meet required cybersecurity controls, and developed and stored covered defense information on it. The suit was filed by a former Raytheon director of engineering under the qui tam provisions; the defendants denied the allegations. The relator received over $1.5 million.
Three patterns are worth naming without editorializing. First, the gap the government pursues is the gap between what was represented and what was implemented; none of these cases required a breach. Second, the entire SPRS submission is treated as a representation: the score itself in the MORSECORP allegations, and the projected implementation dates and plans of action behind the score in the Penn State allegations. Third, the relators were insiders. The people best positioned to compare your paperwork to your reality already work for you.
What evidence behind a signature looks like
If the affirmation is a personal attestation of a continuing condition, the practical question for the Affirming Official is simple: on the day I sign, what would I show someone who asked me to prove it? A defensible answer has four properties.
Coverage. Evidence exists for each requirement you claim as met, mapped to the assessment objectives of NIST SP 800-171A, not just to the requirement heading. "We do MFA" is a claim; enrollment reports, configuration screenshots, and the policy requiring it are evidence.
Freshness. Recurring artifacts are current on their own cycles. The quarterly access review from six quarters ago proves the process existed in 2024, not that it exists now.
Timestamps and attribution. Each artifact shows when it was captured and who captured it. Undated screenshots in a shared folder cannot reconstruct what was true on affirmation day, which is the date that matters.
Consistency. The SSP's implementation statements, the POA&M, the posted score, and the evidence all describe the same company. Contradictions among them are exactly what an assessor, a prime's questionnaire, or a relator's attorney goes looking for.
Before signing, an Affirming Official should be able to run one honest pass: every "met" requirement has current evidence, every gap is on the POA&M with a real date, and the SPRS score matches the arithmetic of the statuses. If any of those three checks fails, the signature is being asked to cover the difference.
This is the specific job Valontir exists to do. It keeps every requirement's status, implementation note, and evidence in one timestamped system, flags evidence that has aged past its refresh cycle, and computes the SPRS score from the official weights as statuses change, so that when your Affirming Official signs, the statement is checkable rather than hopeful. Sign your annual affirmation with evidence behind it.
FAQ
Who can be the Affirming Official? A senior-level representative of your own organization who is responsible for compliance and has the authority to affirm it, typically an owner, president, or senior officer. An outside consultant or MSP cannot fill the role.
How often is the affirmation required? After every assessment, including POA&M closeout, and annually thereafter, entered in SPRS. Under DFARS 252.204-7021 it must be less than a year old to be current.
Is the affirmation only a CMMC thing? The affirmation itself is defined in the CMMC program rule (32 CFR 170.22). But the underlying exposure is older: posting a self-assessment score to SPRS under DFARS 252.204-7019 is already a representation to the government, and the FCA settlements to date arose from that pre-CMMC framework.
Does a settlement mean those companies were guilty? No. Settlements resolve allegations; in most of these cases the defendants did not admit liability. The cases are cited here because their fact patterns show what the government alleges and pursues.
What if we discover we are out of compliance after affirming? That is a question for your attorney, and promptly. As a general matter, the enforcement record shows that the government has treated the speed and honesty of correction as relevant, and that stale misstatements left standing in SPRS are the aggravating pattern.
Valontir is a compliance workspace for small defense contractors: every 800-171 requirement, every piece of evidence, and your live SPRS score in one place, so your annual affirmation has evidence behind it. Book a demo or request access.
Sources: 32 CFR 170.22 (Affirmation) · DFARS 252.204-7021 · DFARS 252.204-7019 · 31 U.S.C. § 3729 (False Claims Act) · DOJ: MORSECORP settlement (Mar. 26, 2025) · DOJ: Raytheon/RTX/Nightwing settlement (2025) · DOJ: Penn State settlement (Oct. 22, 2024) · DOJ: Aerojet Rocketdyne settlement (July 8, 2022)