Working on a government contract is a big deal for many businesses. It's also frequently the culmination of months (if not years) of effort in building, architecting, defining, and securing systems meant to handle the sensitive information the government needs you to handle.
It would be miserable to miss a step and fail at the finish line, but it's surprisingly not too uncommon that it happens. When there are a million and one details to handle, getting a million right still leaves that one last one to trip you up.
CMMC UIDs are a key part of the new paradigm of CMMC, so knowing how they work and what you need to do with them is very important. It's also a relatively recent change (as of about a year ago), so businesses with older and established compliance might run into questions. So, let's talk about it.
BLUF - Bottom Line Up Front
Government contracts need CMMC compliance. SPRS is the DoD database that tracks contractor cyber scores. Each CMMC assessment creates a unique CMMC UID tied to one system scope. Submit assessment results to SPRS via PIEE; the AO must sign to finalize the UID. Keep and protect UIDs and full records for six years. Share UIDs up the contract chain; do not use CAGE codes as proof of authorization.
What is the SPRS?
SPRS is the Supplier Performance Risk System. You can think of it as a kind of database the Department of Defense uses to track all of the contractors they work with throughout the defense industrial base, at least as far as those that handle sensitive information.

The DoD, prime contractors, and others that need to use a procurement process to outsource operations, and who need to make sure their subcontractors are properly secured, can use the SPRS to evaluate risks.
Any business or contractor that achieves certification with CMMC can submit their score to the SPRS and be part of the database, so they can be found by those procurement processes. The SPRS also maintains other information, such as product quality and delivery classifications, which can be further used to make informed decisions.
Obviously, it's important that you be represented in the SPRS accurately. The CMMC UID is part of that.
What is a CMMC UID?
You likely understand how hard it can be to keep track of individual entities in a world where names can be anything and version control can be spotty. How often do you see the same paperwork or form, the same system, the same entity, with different versions and different iterations? How hard is it to figure out which is the most updated, most relevant version when you need it? If you have a pile of the same thing from different sources, how do you associate them with their origins?
The solution to this problem, whenever it comes up, tends to be a unique identifier. This can be an ID number similar to how a Social Security number works, or it could be the hidden unique ID number that each app and version on your phone carries, or whatever other example you can think of. Any time that each entity in a system is given a unique character string to serve as their official identifier, it's a form of UID.

This has always existed in CMMC. Until September of 2025, it was called the DoD Unique Identifier. With the Final Rule issued in 2025, the name was changed to the CMMC UID.
What Does the CMMC UID Do?
The CMMC UID is a unique identifier for your business's assessment score submission. Or, rather, not your business specifically, but your "assessment scope." Everything within a boundary of a system, assessed together under one assessment, has one CMMC UID for that assessment.

This CMMC UID covers one information system within a boundary. This means if you're using an enclave strategy and you have multiple enclaves within your organization, each one will have its own assessments and its own lists of CMMC UIDs.
Basically, whenever you have an assessment under CMMC, whether it's a self-assessment for Level 1 or Level 2, or a C3PAO assessment under Level 2 or Level 3, you need to submit the results of that assessment to SPRS. When you do, an associated CMMC UID is generated.
You can think of it kind of like a unique confirmation code or receipt for when you submit your assessment results to SPRS.
How to Submit to SPRS
Submitting your assessment results to SPRS is the final step of the assessment process. Until you submit the assessment results, the government has no idea that the assessment has happened at all.

Every CMMC assessment needs to be submitted to the SPRS. If it's a level 1 self-assessment, you submit it yourself. If it's a C3PAO level 2 assessment, the C3PAO submits it, and you validate it. Level 3 DoD-led assessments have their own additional record-keeping involved, but that's a discussion for your DoD contact, not a blog online.
The process for submission is fairly easy. You log into your PIEE portal and access the SPRS. You find your company's CAGE code and run the Cyber Reports system. You find the CMMC assessments tab for your assessment level, and click to add a new assessment. You upload all of the relevant data, including the assessment date, compliance scores, scope, and description of the environment.
If you are the Affirming Official for your organization, you can then sign off on the submission, generate the official record, and finalize the generation of the CMMC UID for this assessment. If you are not the Affirming Official, there's a button to "transfer to AO", which sends the record to your AO for them to log in and submit the final record.
If a C3PAO is doing the assessment and handling the submission, they will still need to transfer the sign-off to your AO for the final submission.
Common Mistakes with CMMC SPRS Submission and UIDs
There are a bunch of ways all of this can go wrong if you aren't properly tracking all of the details. Here are some of the most common mistakes you need to watch out for.
Assuming the C3PAO Does Everything
When you perform a level 1 self-assessment, you need to submit your assessment results, generate your CMMC UID, and validate submission in SPRS. When you undergo a C3PAO level 2 assessment, the C3PAO does most of the work for the submission for you, though your AO still needs to sign off on it for the final submission.
The mistake here is that some organizations fail to realize their AO needs to perform this final step. If you don't have your AO log in and submit the assessment results, the assessment may as well not exist.
Your AO will also need to check over the submission and look for delays, glitches, or errors, and it's your job to make sure that your submission has gone through and is valid. Your Affirming Official should log into SPRS via the PIEE (Procurement Integrated Enterprise Environment), open your cyber reports tab, and use the CMMC UID to search for your assessment record.
This will show you what your assessment status is. An old, expired, or superseded assessment will be identified, while a current will be labeled in green as final.
Note that the CMMC UID is unique per assessment. You cannot use an old assessment CMMC UID to look up a new assessment's information, even if the same C3PAO performed it. If your C3PAO has not given you the CMMC UID from your most recent assessment, you will need to get it from them.

It can also take up to 30 days for a new submission to be validated in the SPRS. Checking the day after your C3PAO submits your assessment might show it as pending; this doesn't mean it's invalid, just that it hasn't been fully processed yet.
Not Maintaining Records of CMMC UIDs
Each assessment submitted to the SPRS generates a unique CMMC UID, which is associated with your assessed in-scope information system and your business. You need to maintain all of this information for your records. This isn't a receipt you hold onto for a few weeks and then toss; it's part of your records that you are required to maintain for FCA liability reasons.

CMMC UIDs, alongside all of the assessment results, all of the artifacts and proof that goes into the assessment, and all of the other data, must be maintained for two assessment cycles. Since these assessments have a three-year certification cycle, that means the FCA statute of limitations requires that you hold onto it all for six years.
The important date is the CMMC status date, which you can find by looking up the CMMC UID in the SPRS, as mentioned above. One additional common mistake (though not one that typically has significant consequences) is accidentally purging records a little too early, because you operated on the assessment date rather than the CMMC Status Date.
Not Securing CMMC UIDs and Assessment Data
While it might not seem like it, it's a surprisingly easy mistake to make to store the CMMC UID somewhere it shouldn't be.

The CMMC UID, your SPRS scores, the assessment data, and other information are mostly themselves considered CUI. While you are free to access and use the information within your company, it should be treated as CUI for anyone not in your organization or part of the government.
Giving Your CMMC UIDs to the Wrong People
If someone asks you to prove your certification with CMMC, other than listing in the Cyber-AB Marketplace, your CMMC UID is the official proof. You need to submit your assessment data to SPRS, and the CMMC UID to the person above you up the chain towards the DoD.

For Prime Contractors, it means you will need to submit your CMMC UIDs to your government contracting officer. This serves as proof that your operations are secured to government standards and you can continue working on your contracts.
For subcontractors, you will need to submit your CMMC UIDs to the contractor above you. However, even if you know what contract you're part of and what DoD contracting officer is in charge, you do not submit your CMMC UID directly to the DoD.
Instead, Prime Contractors are responsible for gathering and maintaining the CMMC UIDs of their subcontractors, and those below them, down the chain. As far as CUI goes down, CMMC UIDs must flow back up.
This rule serves two purposes. First, it ensures that the prime contractor takes responsibility for those below them in the chain. Second, it alleviates some of the burden of record-keeping and data tracking that a contracting officer would otherwise need to do.
If you're sending your CMMC UID to a contracting officer when you shouldn't be, you're both sharing CUI you shouldn't be, and putting an unnecessary burden on an official you don't need to.
Other CMMC UID Mistakes
There are other mistakes that can happen in specific situations, but aren't as common as those expounded upon above.

For example, if you're soliciting for subcontractors and you require a level 2 authorization, you need to make sure to get CMMC UIDs from potential subcontractors that refer to level 2 assessments; accepting a level 1 assessment is invalid.
Some companies also mistake a CMMC UID as a company-wide authorization marker, when it really just refers to one specific information system. For smaller companies, this can be the same thing, but it's not universally true.
There's also the potential issue of mixing up CMMC UIDs with CAGE codes. CAGE codes are 5-digit identifiers that refer to your company as a whole and don't change. These are issued by the Defense Logistics Agency and are the Commercial and Government Entity Codes. CMMC UIDs are unique to each information system and each assessment; one company will have one CAGE code but many CMMC UIDs. A CAGE code does not indicate authorization or successful assessments, so you shouldn't use it as proof.
How We Can Help
Here at Ignyte, we can help in a variety of ways. The Ignyte Assurance Platform is one great way to ensure that you're keeping track of all of your data, including CMMC UIDs, properly. Our experts can answer questions you may have about CMMC and SPRS scores, and our blog is full of useful information and answers to these and many more questions. Additionally, we're a C3PAO for CMMC and can perform the assessments you need, if that's what you're looking for.

All you need to do to get the help you need for CMMC is reach out. We're also experienced in and can help with other frameworks as well, including HIPAA, ISO 27001, FedRAMP, and more.

Dan Page is a seasoned Cybersecurity and Risk Management Executive known for advancing security programs aligned with complex regulatory frameworks and critical business objectives. With over 12 years in information security, his expertise began in the U.S. Army Signal Corps, where he led global communications and secured classified networks supporting Special Operations missions. Post-military, he specializes in security architecture for CUI, ITAR data, and federal cloud workloads. Currently, as Senior Cybersecurity Manager at Ignyte Assurance Platform, Dan guides organizations through compliance with CMMC, FedRAMP, ISO 27001, PCI, and NIST standards. A CISSP, CRISC, CISM, PMP, and ITIL-certified professional, he is also a cybersecurity lecturer and community volunteer advocating workforce development.