This is the main content of the page.

 
 

Ecosystem ProfessionsAssessing and Certification

CMMC Assessors

Thank you for your interest in joining the CMMC ecosystem. Becoming a DoD CMMC Level 2 Assessor is an opportunity to contribute to the defense of our nation, as well as a personal opportunity to expand your skills in cybersecurity and assessing.

Before you start your Assessor journey it’s important to understand the process and requirements for becoming an Assessor. First, there are two roles the CMMC Certified Professional (CCP) and the CMMC Certified Assessor (CCA), you must become a certified CCP before pursuing CCA training and certification.

To begin, start by pursuing your CMMC Certified Professional certification. To be successful in this program, below is the recommended educational and/or experience for the CCP program:

To achieve your certification and to receive your CCP badge and be listed on The Cyber AB Marketplace, all of the following requirements must be met.

Note: You may not be planning to become a CMMC Assessor but find obtaining your CCP is important for demonstrating your CMMC knowledge. Therefore, if you successfully complete your CCP training and pass your CCP examination, you will receive a certificate from the CAICO to demonstrate this achievement to others.

Certification Requirements for CCP:

  1. Apply and Remain in good standing with the CAICO; and
    • Sign and Comply with agreements as part of the application process
    • Pay Fees (initial application and annual renewal fees)
  2. Complete CMMC Certified Professional class/course offered by an Approved Training Provider (ATP), formerly referred to as a Licensed Training Provider (LTP); and
  3. Pass CMMC Certified Professional Examination; and
  4. Obtain or have a Tier 3 determination from DoD.

Note: As a CCP holding a favorable Tier 3 determination, you can participate on a CMMC Level 2 Assessment, only to verify Level 1 practices. As a CCP, you cannot make any final determinations on a CMMC assessment. Those final determinations can only be made by a CCA or a Lead CCA.

Once you have achieved your CCP certification, you’re ready to start the process to become a CMMC Certified Assessor (CCA) who can participate on CMMC Level 2 assessments for the DoD.

To achieve your certification and to receive your CCA badge and be listed on The Cyber AB Marketplace, all of the following requirements must be met.

Note: You may not be planning to become a CMMC Assessor but find obtaining your CCA is important for demonstrating your CMMC knowledge. Therefore, if you successfully complete your CCA training and pass your CCA examination, you will receive a certificate from the CAICO to demonstrate your achievement to others.

Certification Requirements for CCA:

  1. Hold an active CMMC Certified Professional (CCP) Certification; and
  2. Obtain or have a Tier 3 determination from DoD; and
  3. Apply & Remain in good standing with the CAICO; and
    • Sign and Comply with agreements as part of the application process
    • Pay Fees (initial application and annual renewal fees)
  4. Complete CMMC Certified Assessor class/course offered by an Approved Training Provider (ATP), formerly referred to as a Licensed Training Provider (LTP); and
  5. Pass CMMC Certification Assessor examination; and
  6. Have at least three (3) years of cybersecurity experience; and
  7. One (1) year of assessment or audit experience; and
  8. Hold at least one baseline certification aligned to the Intermediate and/or Advanced Proficiency Level for the Career Pathway Certified Assessor 612 from the DoD Manual 8140.3 Cyberspace Workforce Qualification & Management Program. https://public.cyber.mil/dcwf-work-role/security-control-assessor/

Note: please check this site as the DoD may update qualifying certifications on this page. Below is a table of qualifying certifications for CCAs as of October 2024.

8140.3 – 612 Certifications

Intermediate

Advanced

  • (ISC)2 CGRC/CAP or
  • CompTIA CASP+ or
  • CompTIA Cloud+ or
  • CompTIA PenTest+ or
  • CompTIA Security+ or
  • GIAC GSEC
  • ISACA CISM or
  • United American Technologies, LLC dba Mile2 CISSO or
  • United American Technologies, LLC dba Mile2 CPTE or
  • CompTIA CySA+ or
  • Federal IT Security Institutes FITSP-A or
  • GIAC GCSA or
  • ISACA CISA or
  • (ISC)2 CISSP or
  • (ISC)2 CISSP-ISSEP or
  • GIAC GSLC or
  • GIAC GSNA

 

Please review the Requirements Grid below to begin the process. For more detailed requirements click here.

To review registration and testing information for the CMMC Certification Examinations  click here.

Requirements Grid

CMMC Certified Professional (CCP)
Registration DurationMeet prerequisites (CCP blueprint), then approximately 1 week
Fee*$200 Registration (one time, CPN) + $275 Exam Fee
Renewal Terms$250 Annual renewal fee. Note: Once you are certified in CCA you will only be annually renewing your CCA.
Background Check RequirementsAchieve a favorable Tier 3 investigation determination or equivalent conducted by DMCA

CMMC Certified Assessor (CCA)
Registration DurationMeet prerequisites (CCA blueprint). Then, approximately 1 week
Fee*$50 Registration fee + $350 Exam Fee
Renewal Terms$500 Annual renewal fee
CitizenshipUS Citizenship Required. Have or gain a favorable DoD Suitability Determination, or Possess a NAC (National Agency Check) or other DoD accepted clearance (require to participate on CMMC assessment teams).

CMMC Third-Party Assessment Organization (C3PAO)
Registration DurationApproximately 4 months, including suitability check
Fee*$6,000 Application
$15,000 Authorization/Re-authorization fee.
Renewal TermsThese fees will be updated soon

Candidate
Registration Duration
Fee*
Renewal Terms
Background Investigation Requirements
CMMC Certified Professional (CCP)
Meet prerequisites (CCP blueprint), then approximately 1 week
$200 Registration + $275 Exam Fee
$250 Annual renewal fee. Note: Once you are certified in CCA you will only be annually renewing your CCA.
Achieve a favorable Tier 3 investigation determination or equivalent conducted by DMCA, or Possess a NAC (National Agency Check) or other DoD accepted clearance
CMMC Certified Assessor (CCA)
Meet prerequisites (CCA blueprint). Then, approximately 1 week
$50 Registration fee + $350 Exam Fee
$500 Annual renewal fee
Achieve a favorable Tier 3 investigation determination or equivalent conducted by DMCA, or Possess a NAC (National Agency Check) or other DoD accepted clearance
CMMC Third-Party Assessment Organization (C3PAO)
Approximately 4 months, including suitability check
$6,000 Application
$15,000 Authorization/Re-authorization
Annual renewal and Accreditation fees will be posted soon
Pass an Experian financial review and FOCI review conducted by the Cyber AB, and pass an SF-328 investigation conducted by DCMA

 

* Please be advised application submissions have a one (1) year expiration period. If you do not take the next steps to complete the process, for example training and testing, for the related to which you applied,your application will expire one (1) year from applying. You will lose any fees paid and will have to re-apply to start the application process over.

*All fees are inclusive of application processing and membership registration which are non-refundable (please see Refund Policy). Schedule does not include any training, testing or examination fees.

Upon successful completion of the process, all candidates will be presented with additional information to include the authorized use of digital credentials in business materials, listing in the CMMC Central Marketplace and access to the Cyber AB's community updates.

CMMC Certified Professional (CCP)

An individual

CCP Enroll Here

A CCP is a person seeking to become responsible for the assessment, examination, verification, and review of an organization for compliance to a respective level of CMMC standards. They will utilize compliance checklists prescribed by the CMMC standard to control scope and ensure fairness in applied criteria. Assessors may work for a C3PAO or be independent.

As a CCP holding a favorable Tier 3 determination, you can participate on a CMMC Level 2 Assessment, only to verify Level 1 practices. As a CCP, you cannot make any final determinations on a CMMC assessment. Those final determinations can only be made by a CCA or a Lead CCA.

A CCP is eligible to become CMMC Certified Assessor (CCA), participates up to CMMC Level 2 assessments, and holds a valuable credential reflecting the training to understand the CMMC requirements for a Defense supplier.

CMMC Certified Assessor (CCA)

An individual

CCA Enroll Here

Upon passing the CCP examination, the individual will be able to begin the CCA process. Again, the candidate will need to find an Approved Training Provider (ATP) on The Cyber AB Marketplace to take their CCA training.

Once a candidate becomes a certified CCA they are then qualified to work on CMMC Level 2 assessments as part of a Certified Third-Party Assessment Organization (C3PAO) assessment team. The C3PAOs employ Assessors who are responsible for conducting the assessments for the Organizations Seeking Certification (OSC).

CCA candidates who have participated in any capacity with an organization preparing for CMMC cannot participate on an assessment team for that same organization.

CMMC Third-Party Assessment Organization (C3PAO)

An organization

C3PAO Enroll Here

A C3PAO is an organization that has successfully passed a rigorous series of requirements to become acknowledged by the CMMC Accreditation Body, on behalf of the DoD, as being objective and competent to perform assessments of OSCs. C3PAOs adhere to assessment criteria that must be consistent, unbiased, and follows a prescribed approach that is utilized similarly across all C3PAOs. They are certified to assess based on the CMMC standard; only Cyber-AB recognized assessors utilized by the C3PAO may conduct authorized assessments.

Want to become a Member?

Membership into the CMMC-AB community, and visibility within the CMMC marketplace, is reserved for those organizations and individuals which successfully complete and pass their respective application and onboarding process, which includes formal review and authorization by the CMMC-AB.

Please click on the appropriate enrollment button above to start the process.