1The Governing Bodies
The CMMC ecosystem has a clear hierarchy of authority, and four bodies sit above the assessors and advisers a contractor actually meets. Knowing which one does what makes the rest of the ecosystem legible.
The Department of Defense owns the program. It exercises that ownership through the CMMC Program Management Office within the office of the Chief Information Officer, which sets policy, writes the rules, and defines what an assessment must find. Everything below it operates under authority that traces back to that office.
The Cyber AB, formerly the CMMC Accreditation Body and rebranded under its current name in 2022, is the non-governmental accreditation body that supports the program under a direct contract with the CMMC Program Management Office. It authorizes and accredits the organizations that assess and advise, maintains the official Marketplace where a contractor can verify that a provider has been vetted, and runs the Registered Practitioner programs. It operates to the international accreditation standard ISO/IEC 17011, and it is not itself part of the Department of Defense.
ISACA holds the role of the CMMC Assessor and Instructor Certification Organization, the CAICO, having fully assumed it in April 2026. It administers the training, examinations, and certifications for the individual professionals in the ecosystem, while the Cyber AB continues to run the background investigations behind those credentials. The division is worth holding onto, because it explains who issues what: the Cyber AB accredits organizations, and ISACA certifies individuals.
The Defense Industrial Base Cybersecurity Assessment Center, DIBCAC, is the government's own assessment arm, part of the Defense Contract Management Agency. It conducts the Level 3 assessments, and it assesses the C3PAOs themselves, so that the organizations authorized to certify others have first been certified by the government against the same standard they will apply.
2The Ecosystem Roles
Below the governing bodies are the organizations and individuals a contractor works with directly, and they divide along a single line that runs through the whole program: preparing for an assessment, or conducting one. The organizations come first.
| Organization | What it does | Side of the line |
|---|---|---|
| C3PAO, CMMC Third-Party Assessment Organization | Conducts Level 2 certification assessments; authorized by the Cyber AB after passing its own DIBCAC assessment | Assess |
| RPO, Registered Practitioner Organization | Provides readiness and advisory services through employed Registered Practitioners, and does not conduct assessments | Advise |
| ATP, Approved Training Provider | Delivers CMMC training under the CAICO | Neither |
| APP, Approved Publishing Partner | Publishes approved CMMC training materials | Neither |
The individuals hold credentials that sit on one side of the same line or the other. The advising credentials come from the Cyber AB, and the assessing credentials come from ISACA as the CAICO.
| Credential | What it authorizes | Issued by |
|---|---|---|
| RP, Registered Practitioner | A trained adviser providing readiness and implementation guidance | Cyber AB |
| RPA, Registered Practitioner Advanced | The advanced Registered Practitioner designation, for deeper readiness and implementation work | Cyber AB |
| CCP, Certified CMMC Professional | The foundational certification; an assessment team member and adviser, and the prerequisite to becoming an assessor | ISACA (CAICO) |
| CCA, Certified CMMC Assessor | Conducts Level 2 assessment work as part of a C3PAO team | ISACA (CAICO) |
| LCCA, Lead Certified CMMC Assessor | Leads a Level 2 assessment team and delivers the final determinations | ISACA (CAICO) |
| CCI, Certified CMMC Instructor | Delivers CMMC training | ISACA (CAICO) |
The assessing credentials carry their own baseline. A Certified CMMC Assessor works within a C3PAO for official assessments, must hold a professional security certification at the level the government expects of a security control assessor, and, like a Certified CMMC Professional, must clear a Tier 3 background investigation that establishes eligibility rather than a security clearance.
The independence wall
The line between advising and assessing is not merely descriptive, it is a rule with teeth. A single company may hold more than one role, but it cannot both prepare a client and assess that same client for the same effort. A provider that helped an organization get ready, and the assessors that provider employs, cannot take part in that organization's certification assessment, with the separation measured in years rather than months. The logic is the same one that keeps an auditor from auditing their own work, because an assessment is worth only as much as its independence. This is why a readiness practice and an assessment organization are structurally different businesses, and why a contractor engages one party to prepare and a separate party to certify.
3The Glossary
A working glossary of the terms that recur across the program and this guide. The roles above are not repeated here; what follows is the vocabulary of the data, the documents, the scores, the assessment, and the rules.
Information and data
| Term | Meaning |
|---|---|
| FCI, Federal Contract Information | Information provided by or generated for the government under a contract and not intended for public release, excluding public and simple transactional information. Handling it triggers Level 1. |
| CUI, Controlled Unclassified Information | Information that a law, regulation, or governmentwide policy requires to be safeguarded, the sensitive category that triggers Level 2. Organized by the National Archives program and catalogued in the CUI Registry. |
| CUI Basic and CUI Specified | Basic follows the uniform baseline handling; Specified carries additional handling rules from the authority that created it. Both are CUI for CMMC. |
| CTI, Controlled Technical Information | Technical data with a military or space application that is subject to controls, a common form of CUI on a manufacturing floor, safeguarded under DFARS 252.204-7012. |
| DIB, Defense Industrial Base | The network of contractors and subcontractors that support the Department of Defense. |
Documents and records
| Term | Meaning |
|---|---|
| SSP, System Security Plan | The document describing the assessment scope and how each applicable requirement is met, by whom, and with what. Required and not deferrable. |
| POA&M, Plan of Action and Milestones | The companion document recording requirements not yet met and the plan to close them, limited by rule in what it may carry. |
| CRM, Customer Responsibility Matrix | The document dividing security responsibilities between a contractor and an external or cloud service provider. |
| Affirmation | The annual attestation of continuous compliance entered in SPRS, signed by a designated Affirming Official. |
Scores, statuses, and systems
| Term | Meaning |
|---|---|
| SPRS, Supplier Performance Risk System | The DoD system where assessment scores and affirmations are posted and where a contracting officer verifies status before award. |
| eMASS, Enterprise Mission Assurance Support Service | The DoD system, in its CMMC instantiation, where certification assessment results are recorded. |
| CMMC Status | The result of an assessment: Conditional, a passing score with permitted open items and a 180-day clock, or Final, a clean result valid three years with annual affirmation. |
| Conditional CMMC Status Date | The date results are posted, which starts the 180-day closeout clock. |
| CMMC UID | The unique identifier assigned to each assessment in SPRS, tied to a specific contractor information system. |
| CAGE Code | The Commercial and Government Entity code identifying a contractor facility, to which an assessment is tied. |
Assessment terms
| Term | Meaning |
|---|---|
| Assessment Scope | The set of assets that are within an assessment and the category into which each falls. |
| Asset categories | CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets, described in Core Concepts. |
| Assessment Objective | A determination statement from NIST SP 800-171A; a requirement is MET only when all of its objectives are met. |
| MET, NOT MET, Not Applicable | The three possible findings for a requirement in an assessment. |
| Adequacy and Sufficiency | The two standards for evidence: the right kind of evidence, and enough of it across the full scope. |
| Enclave | A small, deliberately separated environment built to hold CUI and nothing else, used to shrink the assessment scope. |
| OSA and OSC | Organization Seeking Assessment, for any assessment, and Organization Seeking Certification, for a C3PAO certification specifically. |
| CAP, CMMC Assessment Process | The Cyber AB's procedural playbook for Level 2 certification assessments, described in The Assessment. |
| CoPC, Code of Professional Conduct | The ethics and conflict-of-interest rules binding the ecosystem's organizations and professionals. |
| FedRAMP Moderate | The federal cloud authorization baseline a cloud service handling CUI must meet, or match through a documented equivalency. |
Regulations and standards
| Citation | Meaning |
|---|---|
| 32 CFR Part 170 | The CMMC Program rule, covering the levels, assessments, scoring, plan of action rules, and phase-in. |
| 48 CFR, with DFARS 252.204-7021 and 252.204-7025 | The acquisition rule and clauses that place CMMC into contracts, described in Foundations. |
| DFARS 252.204-7012 | The longstanding safeguarding and cyber incident reporting clause requiring NIST SP 800-171. |
| FAR 52.204-21, renumbered FAR 52.240-93 | The basic safeguarding requirements for FCI, and the source of Level 1. |
| NIST SP 800-171 Rev 2 | The 110 requirements underlying Level 2, to which CMMC is pinned. |
| NIST SP 800-171A | The assessment objectives and the examine, interview, and test methods. |
| NIST SP 800-172 | The enhanced requirements, a subset of which is added at Level 3. |
From the vocabulary to the work
Knowing the terms is the start; applying them to a specific environment, with its own scope, evidence, and gaps, is onsite readiness work. That is the practice behind this guide.
Start CMMC Readiness or call 802-335-26624Sources
- The Cyber AB, ecosystem roles and the official CMMC Marketplace. cyberab.org
- ISACA, in its role as the CMMC Assessor and Instructor Certification Organization (CAICO), for the individual credentials. isaca.org
- 32 CFR Part 170, CMMC Program, including the definitions at 32 CFR 170.4. ecfr.gov
- NIST SP 800-171 Rev 2 and NIST SP 800-171A, the requirements and the assessment objectives. csrc.nist.gov