Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

C3PAO explained

C3PAO: A Clear Guide to Choosing a CMMC Assessor in 2026

A C3PAO — a CMMC Third-Party Assessment Organization — is the only body that can conduct a CMMC Level 2 certification assessment and issue a Certificate of CMMC Status. The rule that creates them, 32 CFR 170.9, is unusually specific about what they must be: authorized by the Accreditation Body, themselves assessed by DCMA DIBCAC at Level 2, staffed by people with Tier 3 background investigations, screened for foreign ownership, and bound by conflict-of-interest rules that stop them consulting for the organizations they assess. Since the Department of War suspended the Phase 2 transition on 13 July 2026, C3PAO assessments are no longer a contract condition — but they remain available, primes still ask for them, and the Cyber AB’s chief executive has called a C3PAO certificate “the best insurance policy against False Claims Act risk”. This guide explains what a C3PAO is required to be, how to choose one, what the assessment involves, and how the pause changes the decision.

C3PAO: what the rule requires and what to check before you sign
The C3PAO checklist: Accreditation Body authorization, a DIBCAC assessment of its own, cleared assessors, FOCI screening and a two-CCA team.

What a C3PAO is under 32 CFR 170.9

The rule’s role statement is one sentence: C3PAOs “are responsible for conducting Level 2 certification assessments and issuing Certificates of CMMC Status to OSCs based on the results”. The requirements that follow are what an organization seeking certification should verify before engaging one.

Requirement (32 CFR 170.9(b)) What it means for you
(1) Authorization or accreditation from the Accreditation Body (Cyber AB) Check the Cyber AB Marketplace listing; ‘candidate’ is not ‘authorized’
(2) Comply with Cyber AB conflict-of-interest, professional conduct and ethics policies; achieve ISO/IEC 17020:2012 compliance within 27 months of authorization An authorized C3PAO may still be working toward 17020 accreditation; ask where it is
(3)–(4) All personnel in the Level 2 process complete a Tier 3 background investigation (or DoD-determined equivalent) Assessment team and QA reviewer are cleared; the investigation is not a security clearance
(5) FOCI review: SF 328 to DCSA, national security review, non-disqualifying determination Foreign-owned or foreign-influenced assessors are screened out or conditioned
(6) Undergo a Level 2 certification assessment conducted by DCMA DIBCAC The assessor has passed the assessment it is about to run on you
(8)–(9) Submit planning material, reports and certificates to CMMC eMASS; retain records six years Your assessment record lives in a DoD system, not only the C3PAO’s files
(12) Assessment team of at least two: a Lead CCA plus at least one other CCA; CCPs may also participate Two certified assessors minimum; ask who leads
(13) A quality assurance function performed by a CCA who was not on the assessment team Independent QA before upload — a built-in second opinion

How to choose a C3PAO

1. Verify the listing, not the logo

Every authorized C3PAO appears on the Cyber AB Marketplace with its status. The rule requires authorization before an assessment counts. A firm advertising CMMC services is not a C3PAO unless it holds that status, and a firm listed as a candidate cannot issue a certificate.

2. Understand the conflict-of-interest line

An assessor cannot both build your program and assess it. The rule requires assessment organizations to comply with the Accreditation Body’s conflict-of-interest policy, and the retained-records requirement explicitly includes “organizations for whom consulting services were provided” — because those are the organizations it may not then assess. Many also operate consulting arms; the separation has to be real. If a firm helped write your SSP, it is your consultant, not your assessor.

3. Ask about the team

At least two CMMC Certified Assessors, one of them the Lead CCA. Ask how many assessments the lead has completed, whether the team has assessed your kind of environment — a cloud-hosted enclave, an OT-heavy plant, a managed-service dependency — and who performs the independent QA.

4. Ask about external service providers

If your CUI or security protection data sits with an ESP — a cloud provider, an MSP, an MSSP — the scoping rules put those services inside your assessment. An assessor experienced with ESP-heavy scopes will know what a customer responsibility matrix needs to show and whether the ESP’s own certification can be leveraged. One that is not will spend your assessment days discovering it.

5. Price the whole engagement

The assessor’s fee is one line. The published cost analysis behind the rule puts the assessor’s own fee for a Level 2 certification at roughly $31,000 within a three-year cost of about $105,000 for a small entity; the rest is the organization’s own preparation, evidence collection and remediation. Ask for the day rate, the estimated days for your scope, the cost of a POA&M closeout assessment, and what a rescheduled or failed assessment costs. Our guide to CMMC Level 2 certification cost sets out the full breakdown.

6. Check availability and lead time

Before the suspension, assessor capacity was the binding constraint on Phase 2 and lead times ran to months. The pause has freed capacity, which is an argument for engaging now if you intend to certify at all.

What a C3PAO assessment involves

The Level 2 certification assessment follows 32 CFR 170.17 and the CMMC Assessment Guide: the assessment team reviews the scope and SSP, examines evidence, interviews staff and tests controls against all 320 NIST SP 800-171A objectives for the 110 requirements, and scores under the methodology in 170.24. The outcome is Final Level 2 (C3PAO) if every requirement is MET, Conditional Level 2 (C3PAO) if the score is at least 80% and the open items qualify for a POA&M — no requirement worth more than one point except FIPS-validation of CUI encryption, and none of six named requirements — and a fail otherwise. A POA&M must be closed by a closeout assessment within 180 days. The assessor uploads the results to eMASS, which transmits to SPRS, and issues the Certificate of CMMC Status; the organization’s Affirming Official then affirms in SPRS and repeats annually. The certificate is valid for three years.

Preparation is what decides the outcome. An organization that has run its own Level 2 self-assessment against the 800-171A objectives, scored it honestly into SPRS and closed the gaps arrives with the evidence organized; one that has not is paying an assessor to discover its gaps at assessment day rates. Our guide to the SPRS score explains the scoring the assessor applies.

Does a C3PAO assessment still make sense during the suspension?

The Department of War’s July 2026 memo suspended the Phase 2 transition, at which third-party certification would have become a condition of award for Level 2 contracts, and directed that solicitations and contracts already carrying Level 2 (C3PAO) requirements be amended to remove them. Level 2 self-assessment and affirmation remain required. The Cyber AB stated on 15 July 2026 that “all CMMC program elements remain operational and available” — C3PAOs can still assess and certify, voluntarily.

Three reasons organizations are still doing it. Prime contractors can and do require third-party certification of subcontractors by contract, independent of DoD’s phase schedule. The certificate is third-party evidence that the self-attestation posted in SPRS is true, which matters under the False Claims Act, where DoD-affirmed compliance claims have already produced settlements. And whatever the program review produces, an organization certified against the same 110 requirements will be at the front of any queue. Our guide to the CMMC Phase 2 suspension tracks where the review stands.

Frequently asked questions

What does C3PAO stand for?
CMMC Third-Party Assessment Organization — a company authorized by the Cyber AB under 32 CFR 170.9 to conduct Level 2 certification assessments and issue Certificates of CMMC Status.

Can a C3PAO also consult for us?
Not on the same engagement. Assessment organizations are bound by the Accreditation Body’s conflict-of-interest policy and must record the organizations they have consulted for; a firm that built your program cannot then assess it.

How many assessors are sent?
At least two CMMC Certified Assessors — a Lead CCA and at least one other CCA — with an independent CCA performing quality assurance before the results are uploaded.

Is a third-party assessment required now?
Not as a contract condition. The Phase 2 transition was suspended on 13 July 2026 and existing third-party requirements are being removed from contracts. Assessments remain available and are still required by some primes.

How long is the certificate valid?
Three years, with an annual affirmation of continuing compliance by the organization’s Affirming Official in SPRS.

Where this leaves you

Choose one the way the rule defines it: authorized on the Marketplace, DIBCAC-assessed, cleared and FOCI-screened, a two-CCA team with independent QA, and no consulting relationship with you. Then decide whether to engage one now on the basis of your primes’ requirements and your False Claims Act exposure, not on DoD’s phase schedule — which, for the moment, does not exist.

References

More on CMMC

The SSP template, the CMMC Gap Analysis Workbook, the SPRS Score Calculation guide and the policies behind all 110 Level 2 requirements a C3PAO tests are in the CMMC Documentation Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.