The Affirming Official is the senior company representative who certifies that a CMMC assessment is accurate. Under 32 CFR Part 170, every contractor names an Affirming Official and re-affirms compliance each year in the Supplier Performance Risk System (SPRS). That signature is a statement of fact to the government, and it carries personal exposure under the False Claims Act.
Who can be the Affirming Official?
The rule requires someone with the authority to affirm the organization's compliance on its behalf. In practice that is the CEO, CIO, CISO, or another senior executive who owns the security program. It is not a role a compliance analyst can hold. The person who signs has to be able to stand behind every control statement in the System Security Plan, because when the assessment is questioned, their name is on it.
What does the affirmation certify?
The Affirming Official attests that:
- Every NIST SP 800-171 Rev 2 requirement is implemented, or covered by a valid Enduring Exception with a working compensating control.
- The System Security Plan describes the environment as it actually is.
- Any Plan of Action and Milestones (POA&M) items meet the CMMC scoring thresholds and the 180-day remediation window.
- Evidence exists and can be produced on demand.
What is the False Claims Act exposure?
31 U.S.C. 3729, the False Claims Act, creates liability for any false statement material to a federal contract payment. A CMMC affirmation is exactly that: a statement made to obtain or keep contract eligibility. The bar is not intent to defraud. Reckless disregard or deliberate ignorance is enough.
Penalties run to treble damages plus per-claim fines. Since launching its Civil Cyber-Fraud Initiative in 2021, the Department of Justice has pursued cybersecurity FCA cases directly on this theory. Settlements have turned on misrepresented NIST SP 800-171 compliance, audit logs that were never captured, and vulnerabilities left unremediated. The 2022 Aerojet Rocketdyne settlement (23.7 million dollars) put the industry on notice that these cases get prosecuted.
Why does the Affirming Official role matter for OT environments?
An Affirming Official cannot sign for compensating controls they have not verified. For OT assets running under an Enduring Exception, the real question is whether the compensating mechanism is technically deployed and produces usable evidence, not whether a policy document says so. A written procedure with no operating control behind it does not satisfy the affirmation, and it does not survive a C3PAO assessment.
Related terms
How Access Gate helps
Access Gate produces the evidence an Affirming Official needs to verify OT compensating controls before signing: policy exports, session logs, and audit records tied to identity. See CMMC Enduring Exceptions for OT.

