Start here
v4 · 8 tabs · all six domains
What changed in 2026
Anything you read from 2024–2025 about registering through the Cyber AB is out of date.
ISACA became the CMMC Assessor & Instructor Certification Organization (CAICO) on 1 April 2026. Training oversight, the exam, and the certification itself now run through ISACA. The Cyber AB remains the accreditation body for organizations (C3PAOs, ATPs) and still runs the Tier 3 background investigations. The old $200 Cyber AB registration and CPN number path is gone.
Logistics
Registration, step by step
Tick these off as you go — progress is saved in this browser.
Complete mandatory CCP training with an ATP
Required before you can be certified. Find providers in the CyberAB Marketplace catalog. Typically 30–40 contact hours, delivered as a 4–5 day bootcamp or 8–10 evening sessions. Budget roughly $2,000–$4,000. Training from a non-authorized source does not count.
Buy the exam in MyISACA
US$575 member / US$760 non-member. Membership costs roughly $135 plus chapter dues, so joining first is cheaper than not. Registration is continuous — no fixed windows. Eligibility runs six months from the date you register, and the fee must be paid in full before you can schedule. Make sure your ISACA account name exactly matches your government photo ID.
Schedule with PSI
Computer-based at a PSI test center or remotely proctored. You can book as early as 48 hours after payment; appointments only open 90 days out. Reschedule free at any point in your eligibility window if you do it at least 48 hours before the appointment. Run the PSI system compatibility check first if you plan to test remotely.
Sit the exam
170 questions across six domains. ISACA reports scaled scores; check the current Exam Candidate Guide for the passing scale rather than relying on the old Cyber AB threshold.
Apply for the certification
Passing is only one component. You also submit an application demonstrating experience, pay a US$200 application processing fee, agree to the Code of Professional Ethics and CPE policy, and obtain a positively adjudicated DoW Tier 3 background investigation. ISACA validates your experience and hands off to the Cyber AB to start the investigation. You have five years from the exam date to apply.
Get listed and stay current
A CyberAB Marketplace listing requires an active credential plus completed Delta Training. Maintenance is 20 CPE minimum per year and 120 over three years; at least 90 must relate to the certification, two of which must cover CMMC rules specifically. CPEs that satisfy another ISACA certification can be applied to both.
Cost summary
| Item | Amount | Paid to |
|---|---|---|
| ATP training | ~$2,000–$4,000 | Approved Training Provider |
| Exam registration | $575 member / $760 non-member | ISACA |
| ISACA membership (optional, pays for itself) | ~$135 + chapter dues | ISACA |
| Application processing | $200 | ISACA |
| Annual maintenance | Set by ISACA; lower than the old model | ISACA |
Blueprint
Where the 170 questions come from
Domains 4 and 5 are 60% of the exam. Weight your study time accordingly.
| Weight | Domain | What it actually tests |
|---|---|---|
| 5% | 1 — CMMC Ecosystem | Who does what: DoW, Cyber AB, CAICO, C3PAO, ATP, RPO, DIBCAC, OSA/OSC |
| 5% | 2 — Code of Professional Conduct | Confidentiality, objectivity, proper use of methods, professional conduct |
| 15% | 3 — Governance and Source Documents | FCI vs CUI, 32 CFR 170, DFARS clause chain, NIST source docs |
| 35% | 4 — Model Construct and Implementation Evaluation | Applying source docs to practices, assessment criteria, evidence adequacy and sufficiency. L1 practices guaranteed to appear. |
| 25% | 5 — CMMC Assessment Process (CAP) | Four phases, CCP role boundaries, planning, conducting, reporting, POA&M closeout |
| 15% | 6 — Scoping | Asset categories and their treatment, FCI scope at Level 1 |
Sources
What to read, in priority order
Tier 1 — know these cold
Tier 2 — know the shape and the specifics that get tested
Plan
Six-week study schedule
Roughly 8–10 hours per week. Slot the ATP bootcamp into weeks 1–2, or take it before week 3 if it is a block course.
Cheat sheet
High-yield facts
Level 2 asset categories (32 CFR 170.19(c)(1) Table 3)
| Category | Definition | Treatment |
|---|---|---|
| CUI Asset | Processes, stores, or transmits CUI | Assessed against all applicable Level 2 requirements. Document in inventory, SSP, network diagram. |
| Security Protection Asset | Provides security functions or capabilities to the assessment scope, regardless of whether it handles CUI (a SIEM, for example) | Assessed against the requirements relevant to the protections it provides. Document in inventory, SSP, network diagram. |
| Contractor Risk Managed Asset | Can, but is not intended to, process/store/transmit CUI, and is managed under the risk-based policy | In scope. Not assessed against all requirements — assessor performs a limited check for deficiencies. If the risk-based management is not evident, the assessor may assess it fully. |
| Specialized Asset | GFE, IoT, IIoT, Operational Technology, Restricted Information Systems, Test Equipment | Part of the assessment scope. Documented in inventory, SSP, and network diagram and managed per the risk-based policy. Not assessed against the other CMMC requirements. |
| Out-of-Scope Asset | Cannot process/store/transmit CUI; physically or logically separated | No documentation requirement. |
Scoring and POA&M (32 CFR 170.21, 170.24)
- Level 2 maximum score is 110. Unmet requirements deduct 5, 3, or 1 point.
- Conditional Level 2 requires score ÷ 110 ≥ 0.8, so a minimum of 88.
- Only 1-point requirements may go on a POA&M. One exception:
SC.L2-3.13.11(CUI encryption) may be included if encryption is employed but not FIPS-validated, at a 3-point cost. - Six specific 1-point requirements are named in 170.21 as ineligible regardless:
AC.L2-3.1.20,AC.L2-3.1.22,CA.L2-3.12.4,PE.L2-3.10.3,PE.L2-3.10.4,PE.L2-3.10.5. - Consequence: every 3-point and 5-point requirement must be MET at assessment. Roughly 63 of the 110 cannot be deferred.
- POA&M closeout must happen within 180 days of the Conditional CMMC Status Date, or the status expires. For a certification assessment, an authorized C3PAO performs the closeout.
- Level 1 permits no POA&M at all. All 15 requirements must be MET.
Levels and who assesses
| Level | Requirements | Assessed by | Cadence |
|---|---|---|---|
| Level 1 (Self) | 15, from FAR 52.204-21 | The OSA itself | Annual self-assessment + annual affirmation |
| Level 2 (Self) | 110, NIST SP 800-171 Rev 2 | The OSA itself | Every 3 years + annual affirmation |
| Level 2 (C3PAO) | 110, NIST SP 800-171 Rev 2 | Authorized C3PAO | Every 3 years + annual affirmation |
| Level 3 (DIBCAC) | 24 selected from NIST SP 800-172 | DIBCAC. Requires Final Level 2 (C3PAO) first. | Every 3 years + annual affirmation |
The four CAP phases
- Plan and Prepare Assessment — conflict of interest checks, contracting, scope verification, readiness review, assessment plan, evidence agreements, team selection.
- Conduct Assessment — collect and examine evidence, score practices, daily checkpoints with the OSC, generate preliminary findings, deliver the closeout briefing.
- Report Assessment Results — final findings, quality assurance review, package delivery to the OSC, upload to CMMC eMASS and SPRS, records retention.
- Remediation of Outstanding Assessment Issues — the POA&M closeout assessment inside the 180-day window.
Your role boundary as a CCP
- You may serve as an Assessment Team Member on a Level 2 certification assessment and verify Level 1 practices.
- You may not make final determinations. That authority belongs to the CCA or Lead CCA.
- Participation on assessment teams requires a favorable Tier 3 determination.
- You may advise, consult, and support readiness work for organizations seeking certification — but not for an organization you are also assessing.
Evidence vocabulary
- Adequacy — does this evidence actually address the assessment objective?
- Sufficiency — is there enough of it, across enough of the in-scope population, to support the finding?
- Methods — examine (artifacts), interview (people), test (mechanisms). Findings should be corroborated across methods.
- Findings — MET, NOT MET, or NOT APPLICABLE. There is no partial credit at the objective level.
- Enduring Exception — a special circumstance where remediation is not feasible; documented in the SSP, no POA&M required.
- Temporary Deficiency — a correctable condition tracked in an operational plan of action. This is not the same thing as a CMMC POA&M and is not subject to the 180-day clock.
Practice exams
Drill the whole blueprint or one domain at a time
Each trial draws questions you have not yet mastered. Get one right and it retires from the pool; get it wrong and it comes back next time. Keep going until nothing is left.
Progress
Mastery by domain
A question counts as mastered once you answer it correctly. Miss a mastered question later and it goes straight back into the pool.
Your record
Trial history
CCP Domain 5 — CMMC Assessment Process
Assessment process
Click any step, gate, or outcome
Each one opens what happens there, how the exam samples it, and the specific wrong answer it is built to attract. Dashed amber boxes are decision gates.
What Domain 5 actually asks of you
25% of a 170-question paper is roughly 43 items. Together with Domain 4 that is 60% of the exam. The blueprint splits Domain 5 across five tasks: 5.1 planning, 5.2 conducting, 5.3 reporting, 5.4 POA&M evaluation, and 5.5 applying the whole sequence to a Level 2 scenario.
| Task | Blueprint statement | What that means on exam day |
|---|---|---|
| 5.1 | Choose the appropriate roles of the CCP when developing the assessment plan — Phase 1, plan and prepare. | Validation criteria for evidence, analysing requirements, what the plan contains, and the readiness review. The heaviest single block. |
| 5.2 | Apply CAP requirements to the CCP's role as a team member while conducting the assessment — Phase 2. | The three methods, scoring at objective level, interviewing and observing tests, rating and validating preliminary results. |
| 5.3 | Comprehension of the CCP role in preparing the assessment report — Phase 3. | Who drafts, who scores, who delivers, who submits, and why the package is archived. |
| 5.4 | Comprehension of the CCP role in evaluating outstanding POA&M items — Phase 4. | Minimum score, qualifying items, the 180-day clock, and who performs the closeout. Densest testable block in the domain. |
| 5.5 | Given a scenario, determine the appropriate phases and steps for a Level 2 assessment. | Sequencing items. Fast once the four phases and their gates are automatic. |
A preparation order that works
Phase detail
Four phases, each with a gate. Know the activities by name — the exam samples the activity list, not just the phase title.
| Phase | Purpose | Key output |
|---|---|---|
| 1 — Plan and Prepare | Agreements and NDAs, conflict-of-interest checks, scope verification against the asset inventory / SSP / network diagram, team composition and qualification, requirement analysis, logistics and site access, evidence approach, communication and escalation. | Approved assessment plan; readiness go / no-go |
| 2 — Conduct | Collect and examine evidence through Examine, Interview and Test; score each requirement at objective level; daily checkpoints; validate preliminary results with the OSA; maintain evidence integrity. | Preliminary findings, validated with the OSA |
| 3 — Report Recommended Results | Assemble evidence and findings; the Lead Assessor drafts and scores final findings, delivers recommended results, and submits through the C3PAO review process; package and archive. | Final assessment report and archived record |
| 4 — Remediation of Outstanding Issues | Track and close POA&M items; confirm closure by a closeout assessment within the window. | Final CMMC status, or an expired conditional status |
What a CCP may and may not do
| A CCP may | A CCP may not |
|---|---|
| Assist in analysing requirements | Lead the assessment team |
| Assist in developing the assessment plan | Make the final determination on a requirement |
| Assist in verifying readiness | Make the readiness go / no-go decision |
| Collect and examine evidence, interview, observe tests | Draft and score the final findings |
| Assist in scoring and validating preliminary results | Sign or submit the assessment report |
| Assist in delivering recommended results | Represent themselves as an assessor |
Scoring and the POA&M rules
The densest testable block in Domain 5, set out in 32 CFR §170.21. Learn the shape first, then the exceptions.
Scoring
POA&M eligibility
| Situation | Rule |
|---|---|
| Level 1 self-assessment | A POA&M is not permitted at any time. |
| Level 2 score condition | Assessment score ÷ total Level 2 requirements ≥ 0.8. |
| Point value | No requirement on the POA&M may have a point value greater than 1. Every 3-point and 5-point requirement must be MET at assessment. |
| The one exception | SC.L2-3.13.11 CUI Encryption may be on a POA&M where encryption is employed but is not FIPS-validated, which scores 3 points. |
| Six named exclusions | AC.L2-3.1.20 External Connections · AC.L2-3.1.22 Control Public Information · CA.L2-3.12.4 System Security Plan · PE.L2-3.10.3 Escort Visitors · PE.L2-3.10.4 Physical Access Logs · PE.L2-3.10.5 Manage Physical Access. All 1-point, all ineligible. |
| Level 3 exclusions | IR.L3-3.6.1e · IR.L3-3.6.2e · RA.L3-3.11.1e · RA.L3-3.11.4e · RA.L3-3.11.6e · RA.L3-3.11.7e · SI.L3-3.14.3e, with the same 0.8 ratio. |
| Closeout window | 180 days from the Conditional CMMC Status Date. Miss it and the conditional status expires — there is no extension. |
| Who closes out | Level 2 self → the OSA, in the same manner as the initial self-assessment. Level 2 certification → an authorized or accredited C3PAO. Level 3 → DCMA DIBCAC. |
| What is reassessed | Only the NOT MET requirements identified with a POA&M in the initial assessment. Not the full scope. |
Trap deck
Twenty-six things the exam is built to catch. Confirmed is traceable to 32 CFR Part 170 or the CAP. Inferred is a training convention or my own derivation — verify before you rely on it. Doc lag flags where older material disagrees with the current rule.
Recall cards
Twenty-eight prompts for the facts worth holding verbatim. Click a card to reveal the answer.
Question set
Forty-two Domain 5 items across Tasks 5.1 to 5.5, weighted toward 5.4 where the memorisable rules concentrate. Explanations name the trap each item is testing.
Certification study · current to Dec 2025 rule state
The CMMC Ecosystem
Who owns what, who certifies whom, and the rollout dates the exam leans on. Read the guide, drill the cards, then test yourself. Progress saves in this browser.
The three-tier authority structure
Most ecosystem questions are really "who owns what." Get this hierarchy cold and half the domain answers itself.
DoD — the program owner
Owns the CMMC program and sets policy through the rules. The DoD CIO office and the CMMC Program Management Office (PMO) run it; DCMA's DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) performs the Level 3 assessments. DoD does not certify individuals or accredit assessor organizations — it delegates that.
The Cyber AB — the accreditation body
Formerly the CMMC-AB, rebranded to "The Cyber AB" in June 2022 (same legal entity). Sole official DoD partner for accreditation and oversight of the ecosystem. It accredits organizations and, after the December 2025 transition, retains oversight of C3PAOs, the Marketplace, the RP/RPA/RPO programs, and Tier 3 background checks.
The CAICO — the credentialing body
Cybersecurity Assessor and Instructor Certification Organization: trains, examines, and certifies individuals. ISACA assumed the CAICO role on 16 Dec 2025, expecting full capacity around April 2026. The CAICO must hold ISO/IEC 17024 accreditation (the personnel-certification standard).
Recent change — old slides show the Cyber AB running certification itselfRoles — organizations
| Role | What it is | Key rule |
|---|---|---|
| OSA | Organization Seeking Assessment — umbrella term (32 CFR) for any contractor pursuing any CMMC status. | Broadest term |
| OSC | Organization Seeking Certification — specifically one getting a C3PAO certification assessment. | Subset of OSA |
| C3PAO | Certified Third-Party Assessment Organization — the only entity authorized to run Level 2 certification assessments. | Separation of duties |
| RPO | Registered Provider Organization — consulting/prep firm. Not an assessor. | Advisory only |
Roles — individuals
| Role | Scope |
|---|---|
| CCP | Certified CMMC Professional — foundational. Prep, gap analysis, evidence; with a favorable Tier 3 determination can verify Level 1 practices and sit on a Level 2 assessment team. |
| CCA | Certified CMMC Assessor — conducts Level 2 assessments, serves on a C3PAO team, and makes final compliance determinations. |
| Lead CCA | The CCA leading an assessment team. |
| RP | Registered Practitioner — entry-level advisory individual (under an RPO). Consulting, not assessing. |
| RPA | Registered Practitioner Advanced — higher advisory tier. |
| Instructor | Certified / Provisional Instructor — delivers CAICO-approved training. "Provisional" designations were the bootstrap-era roles. |
Training-body terminology — a live trap
The provider names are mid-transition; the exam may show either set. Know both pairs, and that they now sit under the CAICO (ISACA), not the Cyber AB.
- LTP (Licensed Training Provider) → ATP (Approved Training Provider)
- LPP (Licensed Publishing Partner) → APP (Approved Publishing Partner)
The rule backbone — don't conflate the two
- 32 CFR Part 170 — the program rule. Defines CMMC policy, the levels, controls, roles, waivers, and assessment parameters. In effect since December 2024.
- 48 CFR (DFARS) — the acquisition rule. Implements the contract language — the DFARS 252.204-7021 clause — that lets contracting officers require CMMC. Published in the Federal Register 10 Sep 2025; effective 10 Nov 2025.
The four-phase rollout
All keyed off the 10 Nov 2025 effective date, over three years.
- Phase 1
Nov 2025 – Nov 2026Level 1 and Level 2 self-assessments as a pre-award condition on applicable new contracts. DoD may, at its discretion, require a Level 2 C3PAO assessment on select high-priority acquisitions. - Phase 2
from Nov 10 2026Level 2 third-party (C3PAO) certification required on applicable contracts. The date contractors circle in red. - Phase 3
from Nov 10 2027Level 3 (DIBCAC) requirements phase in. - Phase 4
by Nov 10 2028Full implementation across all applicable contracts.
The traps that catch people
- Accredit vs certify: the Cyber AB accredits organizations; the CAICO certifies individuals.
- OSA vs OSC: OSA is the umbrella; OSC is certification-specific.
- Level 3 is DoD/DIBCAC, not a C3PAO.
- Since Dec 2025 the Cyber AB no longer certifies individuals — ISACA does, as CAICO.
Domain 3 · current to the Dec 2024 rule & the standing Rev 2 deviation
Governance & Source Documents
FCI vs CUI, the 32 CFR rules, the DFARS clause chain, and the NIST source stack — with the revision trap that catches most candidates. Read, drill, test. Progress saves in this browser.
The foundational distinction — FCI vs CUI
Almost every governance question starts here: which information type you hold decides which level, clause, and standard apply.
Federal Contract Information
Information provided by or generated for the Government under a contract to develop or deliver a product or service, not intended for public release.
Excludes information the Government provides to the public (e.g., a public website) and simple transactional information (e.g., to process payments).
Controlled Unclassified Information
Information the Government creates or possesses — or that an entity creates or possesses for or on behalf of the Government — that law, regulation, or Government-wide policy requires be safeguarded.
Categories are listed in the NARA CUI Registry; the CUI program itself is defined by 32 CFR Part 2002.
The governance rule stack — keep the two "32 CFRs" apart
| Authority | What it governs |
|---|---|
| FAR 52.204-21 | Basic safeguarding of covered contractor information systems — 15 requirements protecting FCI. Basis for CMMC Level 1. |
| 32 CFR Part 2002 | The CUI Program rule. NARA is the CUI Executive Agent; defines CUI categories, marking, and handling. Not CMMC-specific. |
| 32 CFR Part 170 | The CMMC Program rule (published 15 Oct 2024; effective Dec 2024). Defines levels, assessment methodology, and roles; anchors Level 2 to NIST 800-171 Rev 2 (§170.14(c)); flow-down at §170.23. |
| 48 CFR (DFARS) | The acquisition rule — the contract clauses that actually impose the requirements below. |
The DFARS clause chain
Four clauses, each with a distinct job. The exam loves to swap what 7019, 7020, and 7021 do.
- 252.204-7012Safeguarding + reportingSafeguarding Covered Defense Information and Cyber Incident Reporting. Requires NIST 800-171 (Rev 2 via class deviation), 72-hour incident reporting to DIBNet, media preservation, cloud (FedRAMP-equivalent), and flow-down. In effect since Dec 2017.
- 252.204-7019Post your scoreNotice of NIST 800-171 DoD Assessment Requirements. The offeror must have a current self-assessment score posted in SPRS (not older than 3 years) to be eligible for award.
- 252.204-7020Grant accessNIST 800-171 DoD Assessment Requirements. The contractor must grant DoD (DIBCAC) access to conduct Medium/High assessments, and flow the requirement down.
- 252.204-7021CMMC itselfCMMC Requirements. The contractor must achieve and maintain the required CMMC level for the life of the contract, and flow it down.
NIST source documents
| Document | Role in CMMC |
|---|---|
| SP 800-171 R2 | The 110 security requirements across 14 families ("3.x.x" identifiers), Feb 2020. Basis for Level 2. |
| SP 800-171A | Assessment procedures for 800-171 — methods (examine, interview, test) and determination statements. Level 2 is assessed against this. |
| SP 800-172 | Enhanced requirements for advanced persistent threats. A selected subset is the basis for Level 3. |
| SP 800-172A | Assessment procedures for 800-172. |
| SP 800-53 | The parent control catalog for federal systems. 800-171 is a tailored subset of it. |
| SP 800-37 | The Risk Management Framework (RMF) — the process backdrop. |
| FIPS 199 / 200 | 199: security categorization of information/systems. 200: minimum security requirements for federal systems. |
| CUI Registry | NARA's authoritative list of CUI categories and subcategories (export control, privacy, proprietary, etc.). |
The revision trap — Rev 2 vs Rev 3
- 32 CFR Part 170 codifies Revision 2 (Feb 2020) as the Level 2 standard.
- DoD Class Deviation 2024-O0013 keeps DFARS 7012 pointing to Rev 2 (7012 otherwise says "most current version").
- A Rev 3 transition (RIN 0790-AM01) is on the regulatory agenda but not yet in force.
- Exam answer today: Revision 2. Rev 3 is the direction of travel, not the assessed standard.
Most-tested traps, gathered
- FCI → Level 1 (FAR 52.204-21); CUI → Level 2 (NIST 800-171). Don't cross them.
- CMMC uses 800-171 Rev 2, not the newer Rev 3.
- 800-171 is a tailored subset of 800-53, not a standalone invention.
- 7012 requires 800-171; 7021 requires CMMC — different clauses, different jobs.
- 7019 = post the SPRS score; 7020 = grant DoD assessment access.
- Level 3 uses a subset of 800-172, not the entire publication.
- 32 CFR 2002 (CUI/NARA) ≠ 32 CFR 170 (CMMC/DoD).
- You assess against 800-171A, you implement 800-171.
CCP Domain 4 — CMMC Model Construct & Implementation Evaluation
What Domain 4 actually asks of you
The blueprint splits 35% of the exam across three tasks. Task 4.1 is recall-heavy (architecture, levels, numbering, domains). Task 4.2 is applied (criteria and methodology against a specific requirement). Task 4.3 is judgment (is this evidence adequate, and is there enough of it). The blueprint carries an explicit floor: at minimum you will be tested on Level 1 requirements.
| Task | Blueprint statement | What that means on exam day |
|---|---|---|
| 4.1 | Given a scenario, apply the appropriate CMMC source documents as an aid to evaluate the implementation/review of CMMC practices. Covers model architecture, levels (cumulative nature, characteristics, which level a contract needs), practices (numbering scheme, objectives, assessment methods and objects), and the 14 domains. | Know the identifier anatomy cold, know which of the 14 domains appear at Level 1, and know which guide answers which question. Most "which document do I open" items live here. |
| 4.2 | Apply knowledge of the CMMC assessment criteria and methodology to the appropriate practices: the definition of each requirement, the assessment objectives, the three methods (examine, interview, test), what to look for in the discussion, and the key references. | Scenario stems ending in MET / NOT MET / N/A. Also "which method best gathers sufficient and accurate evidence for this objective." |
| 4.3 | Analyze the adequacy and sufficiency around the location, collection, quality, and usage of evidence. | Two questions, always: is this the right kind of evidence (adequacy), and is there enough of it across the in-scope population (sufficiency). Draft artifacts fail adequacy outright. |
Full blueprint weighting, for time allocation
| # | Domain | Weight | Approx. items of 170 |
|---|---|---|---|
| 1 | CMMC Ecosystem | 5% | ~9 |
| 2 | Code of Professional Conduct (Ethics) | 5% | ~9 |
| 3 | Governance and Source Documents | 15% | ~26 |
| 4 | Model Construct and Implementation Evaluation | 35% | ~60 |
| 5 | CMMC Assessment Process (CAP) | 25% | ~43 |
| 6 | Scoping | 15% | ~26 |
Source documents Domain 4 draws on
- 32 CFR Part 170
- The program rule. §170.14 model construct, §170.15 Level 1 self-assessment, §170.19 scoping, §170.21 POA&M and status, §170.24 scoring and findings definitions.
- CMMC Model Overview
- Architecture, levels, domain list, identifier scheme.
- CMMC Assessment Guide – Level 1
- The 15 Level 1 requirements, their objectives, methods, discussion, further discussion, key references. Your Task 4.1/4.2 workhorse.
- CMMC Assessment Guide – Level 2
- Same structure across all 110 requirements.
- NIST SP 800-171 Rev. 2
- Requirement statements and the Discussion text.
- NIST SP 800-171A
- The assessment objectives. Determination statements, methods, objects. This is the criteria source — not 800-171 itself.
- FAR 52.204-21
- The 15 basic safeguarding requirements Level 1 aligns to.
- DoD Assessment Methodology
- The 110-point weighted scoring for Level 2 (5 / 3 / 1).
Model architecture
Three levels, cumulative. Fourteen domains at Level 2 and above; six of them at Level 1. No process or maturity practices exist in the current model — that was CMMC 1.0.
Levels
| Level | Requirements | Source | Protects | Assessment |
|---|---|---|---|---|
| 1 Foundational | 15 | FAR 52.204-21 | FCI | Annual self-assessment + annual affirmation. No POA&M, no conditional status. |
| 2 Advanced | 110 | NIST SP 800-171 Rev. 2 | CUI | Self-assessment or C3PAO certification assessment, triennial, plus annual affirmation. |
| 3 Expert | Level 2 + 24 selected | NIST SP 800-172 | CUI, highest-priority programs | DCMA DIBCAC assessment. Requires a Final Level 2 (C3PAO) status first. |
AC.L2-3.1.1, not AC.L1-b.1.i) with CUI in scope rather than FCI.Identifier anatomy — the renumbering that trips people
| Format | Anchored to | Example | Status |
|---|---|---|---|
DD.L1-b.1.i | FAR 52.204-21(b)(1) subparagraphs, lowercase roman | AC.L1-b.1.i | Current per 32 CFR 170.14(c) |
DD.L2-3.x.y | NIST SP 800-171 requirement number | AC.L2-3.1.1 | Current |
DD.L1-3.x.y | Legacy CMMC 2.0 model, NIST-anchored at Level 1 | AC.L1-3.1.1 | Superseded — still appears in the 2022 blueprint text |
The 15 Level 1 requirements and their objective counts
Objective counts matter. "How many assessment objectives does X have" and "which requirement has the most objectives" are both fair game, and the counts drive the all-or-nothing finding logic.
| Identifier | Short name | Requirement (abbreviated) | Obj. |
|---|---|---|---|
AC.L1-b.1.i | Authorized Access Control | Limit system access to authorized users, processes acting on their behalf, and devices. | 6 |
AC.L1-b.1.ii | Transaction & Function Control | Limit access to the types of transactions and functions authorized users may execute. | 2 |
AC.L1-b.1.iii | External Connections | Verify and control/limit connections to and use of external systems. | 6 |
AC.L1-b.1.iv | Control Public Information | Control information posted or processed on publicly accessible systems. | 5 |
IA.L1-b.1.v | Identification | Identify system users, processes acting on behalf of users, and devices. | 3 |
IA.L1-b.1.vi | Authentication | Authenticate or verify identities as a prerequisite to access. | 3 |
MP.L1-b.1.vii | Media Disposal | Sanitize or destroy media containing FCI before disposal or release for reuse. | 2 |
PE.L1-b.1.viii | Limit Physical Access | Limit physical access to systems, equipment, and operating environments. | 4 |
PE.L1-b.1.ix | Manage Visitors & Physical Access | Consolidated: escort visitors, monitor visitor activity, maintain physical access audit logs, and control/manage physical access devices. | 6 |
SC.L1-b.1.x | Boundary Protection | Monitor, control, and protect communications at external and key internal boundaries. | 8 |
SC.L1-b.1.xi | Public-Access System Separation | Implement subnetworks for publicly accessible components, physically or logically separated. | 2 |
SI.L1-b.1.xii | Flaw Remediation | Identify, report, and correct system flaws in a timely manner. | 6 |
SI.L1-b.1.xiii | Malicious Code Protection | Provide protection from malicious code at designated locations. | 2 |
SI.L1-b.1.xiv | Update Malicious Code Protection | Update malicious code protection mechanisms when new releases are available. | 1 |
SI.L1-b.1.xv | System & File Scanning | Periodic system scans plus real-time scans of files from external sources. | 3 |
SC.L1-b.1.x at 8 objectives.
Smallest: SI.L1-b.1.xiv at 1. Derived The 59 is a straight sum
of the published objectives — recount it once yourself from the Level 1 guide so you own the number.The 14 domains
| Abbr. | Domain | At L1? | Note |
|---|---|---|---|
AC | Access Control | Yes (4) | Largest domain at L2 — 22 requirements. |
AT | Awareness and Training | No | Common distractor as a Level 1 domain. |
AU | Audit and Accountability | No | Physical access logs at L1 sit under PE, not AU. |
CM | Configuration Management | No | |
IA | Identification and Authentication | Yes (2) | |
IR | Incident Response | No | Note DFARS 252.204-7012 reporting duties exist independently of CMMC level. |
MA | Maintenance | No | |
MP | Media Protection | Yes (1) | |
PS | Personnel Security | No | Abbreviation is PS, not PE. |
PE | Physical Protection | Yes (2) | Abbreviation is PE, not PP. |
RA | Risk Assessment | No | |
CA | Security Assessment | No | CA, not SA. Holds the SSP and plan-of-action requirements. |
SC | System and Communications Protection | Yes (2) | |
SI | System and Information Integrity | Yes (4) |
Anatomy of a requirement description in the Assessment Guide
| Section | Sourced from | What it is for |
|---|---|---|
| Requirement number, name, statement | 32 CFR 170.14(c) | The identifier, the short name (quick reference only), the full requirement text. |
| Assessment Objectives | NIST SP 800-171A | The determination statements. All must be MET or N/A. |
| Potential Assessment Methods and Objects | NIST SP 800-171A | Examine / interview / test, against specifications, mechanisms, activities, individuals. |
| Discussion | NIST SP 800-171 Rev. 2 | NIST's own explanatory text. At Level 1, modified to reference FCI. |
| Further Discussion | CMMC-authored | Extra guidance, worked examples with objective letters in brackets, assessment considerations. Not prescriptive, not comprehensive. |
| Key References | FAR / NIST | The identical FAR 52.204-21 safeguarding requirement and the pertinent 800-171 Rev. 2 requirement. |
Assessment criteria and methodology
Task 4.2. This is the highest-yield page in the workbench: the finding rules here generate most of the scenario items, and they are fully deterministic once you know them.
Three methods, four object types
Methods (exactly three)
Interview — hold discussions with individuals or groups.
Test — exercise objects under specified conditions to compare actual behavior with expected.
Objects (exactly four)
Mechanisms — hardware, software, firmware safeguards.
Activities — protection-related actions involving people.
Individuals — the people applying the above.
What each method is actually worth
| Method | What it establishes | Weakness |
|---|---|---|
| Interview | What staff believe to be true. | Belief is not implementation. Never sufficient on its own for a technical objective. |
| Examine | That policy, procedure, or configuration exists in final form. | A signed policy does not prove the control operates. |
| Test | What has or has not actually been done. | A single test proves one instance, not a population. |
Findings — three outcomes, defined in 32 CFR 170.24
| Finding | Rule | What makes it appear on the exam |
|---|---|---|
| MET | All applicable objectives satisfied based on evidence, and all evidence is in final form. | Includes the two special cases below. |
| NOT MET | One or more objectives not satisfied. | All-or-nothing. There is no partial credit at the requirement level. |
| NOT APPLICABLE | The requirement and/or objective does not apply at the time of assessment. Record why. | An objective assessed N/A is equivalent to MET during the assessment. |
The two "looks like a failure but scores MET" cases
Enduring Exception
Temporary Deficiency
The finding logic, as a decision path
| Step | Question | Consequence |
|---|---|---|
| 1 | Is the objective applicable in this scope? | No → N/A, which counts as MET. Record the rationale. |
| 2 | Is the supporting evidence in final form? | Draft, working paper, or unapproved policy → not usable → objective fails. |
| 3 | Does the evidence address the determination statement itself? | Adjacent evidence does not count. Adequacy failure. |
| 4 | Does it cover the in-scope population? | One host out of a fleet → sufficiency failure. |
| 5 | Any objective NOT MET? | The entire requirement is NOT MET. |
Where satisfaction can come from
A requirement is MET if adequate evidence shows that another part of the enterprise or an External Service Provider implements the objectives. ESPs include cloud service providers, managed service providers, MSSPs, and cybersecurity-as-a-service providers. Outsourcing does not make a requirement N/A and does not make it NOT MET — it moves where you go to collect the evidence.
Level 1 vs Level 2 evaluation differences boundary with Domains 5 & 6
| Level 1 | Level 2 | |
|---|---|---|
| Scoring | Pass/fail. Every requirement MET or N/A. | 110-point weighted score; 5 / 3 / 1 deductions per the DoD Assessment Methodology. |
| POA&M permitted | No. | Yes, subject to eligibility rules in 32 CFR 170.21, with a 180-day closeout. |
| Objectives reference | 800-171A with [FCI] substituted for CUI. | 800-171A as written, CUI. |
| Who assesses | OSA itself (a third party may assist; it is still a self-assessment). | OSA self-assessment or a C3PAO certification assessment. |
| Partial-credit controls | None. | Two built-in: MFA (3.5.3) and FIPS crypto (3.13.11) deduct 5 or 3 depending on extent. |
Evidence: adequacy and sufficiency
Task 4.3 is only two blueprint lines but it drives a disproportionate number of scenario items, because every MET/NOT MET stem is secretly an evidence question.
Adequate — is it the right evidence?
Approved and official, not pending signature.
Current, not expired or superseded.
Maps to this determination statement, not an adjacent one.
From an authoritative location within the assessment scope.
Sufficient — is there enough of it?
Covers the in-scope population, not one convenient host.
Corroborated across methods where the objective is technical.
Consistent — the interview, the document, and the test tell the same story.
Acceptable document types
The Level 1 guide names four categories, and states the list is neither exhaustive nor prescriptive: policy/process/procedure documents; training materials; plans and planning documents; and system, network, and data flow diagrams.
Disqualifying conditions — memorize this list
| Condition | Why it fails |
|---|---|
| Draft policy | Not final, still subject to change. Explicitly named as unacceptable. |
| Working papers | Explicitly named as unacceptable. |
| Unofficial or unapproved policy | Explicitly named as unacceptable. Verbal approval is not approval. |
| Evidence describing intent only | "We plan to" describes a future state, not implementation. |
| Evidence from outside the assessment scope | Right control, wrong system. |
| Single-instance evidence for a population objective | Adequate but not sufficient. |
Worked judgments
SI.L1-b.1.xii — Flaw Remediation, objective [a]: "the time within which to identify system flaws is specified"
SC.L1-b.1.xi — Public-Access System Separation
MP.L1-b.1.vii — Media Disposal
AC.L1-b.1.i — Authorized Access Control, six objectives
Blueprint's four evidence dimensions
| Dimension | Question to ask |
|---|---|
| Location | Where does this artifact live, and is that system in the assessment scope? |
| Collection | How was it obtained, and can it be reproduced or re-verified? (Hashing supports this.) |
| Quality | Final, approved, current, and on point for the determination statement? |
| Usage | Which objectives does it actually support, and are we over-claiming its reach? |
Trap deck
Twenty-six things the exam is built to catch. Confirmed is traceable to the rule, the guides, or 800-171A. Inferred is a training convention or my own derivation — verify before you rely on it. Doc lag flags places where the 2022 blueprint text disagrees with the current model.
Question set
Fifty-eight Domain 4 items, weighted roughly 40 / 40 / 20 across Tasks 4.1, 4.2, and 4.3 — the same shape as the domain itself. Explanations name the trap each item is testing.
Certification study · Domain 6 · 15% of the exam · keyed to 32 CFR §170.19
Scoping
Asset categories, specialized assets, external service providers, and the separation rules that decide what gets assessed. Scoping questions are almost all scenario questions — you are handed an environment and asked which bucket an asset lands in. Read the guide, drill the cards, then test yourself. Progress saves in this browser.
What comes in the exam, and how to prepare
Domain 6 is 15% of a 170-question paper — roughly 26 questions. It is the most mechanical domain on the exam: the rules are tabular, finite, and reward memorisation more directly than anything else in the blueprint.
| What to expect | |
|---|---|
| Question form | Almost entirely scenario. You are given an environment and an asset, and asked which category it lands in, or what the assessor does about it. |
| Heaviest sub-areas | The five Level 2 asset categories and their treatment; Specialized Assets; External Service Providers. |
| Reliable trap sources | Level 1 versus Level 2 treatment of the same asset; the two-part out-of-scope test; whether a vendor even meets the ESP definition. |
| Pacing | Stems are short and the answer is usually a single lookup. These are the questions to bank time on for Domains 4 and 5. |
A preparation order that works
- Draw the five-category table from memory, on paper, until it is automatic. Category, definition, what the OSA documents, what the assessor does. Four columns, five rows. If you can reproduce it, you have most of the domain.
- Then the ESP matrix. Three rows — CUI, SPD without CUI, neither — by two columns, CSP and not-CSP. Six cells, and the bottom row collapses into one answer. Learn it as a grid, not as prose.
- Then the six Specialized Assets, and immediately the Level 1 versus Level 2 split in how they are treated. That single distinction is worth several marks.
- Then the out-of-scope test — both conditions, and the fact that anything in an in-scope category cannot be out of scope.
- Finally, read 32 CFR §170.19 itself. It is short, it is the authority, and the tables in it are the tables the questions are written from.
Two questions decide every scoping answer
Scoping scenarios look varied but almost always reduce to the same pair of questions asked in the same order. Ask them in the wrong order and you will talk yourself into the wrong bucket.
Which level are we scoping?
Level 1 has two outcomes: in scope, or out of scope. Level 2 has five asset categories. Level 3 has four. The same physical device lands in different places depending on the level, and the exam exploits that.
Does it process, store or transmit the protected data?
FCI at Level 1, CUI at Level 2 and 3. This is the primary test. Only after answering it do you ask the secondary questions: does it provide a security function, could it touch CUI without being intended to, and is it a specialized asset type.
Organizational scoping
Before assets come organizations. The CAP asks you to draw the organizational boundary first, because it determines whose assets you are about to categorize.
| Term | What it means |
|---|---|
| Organization | The legal entity seeking the assessment — the OSA or OSC as a whole. The outermost boundary of the conversation. |
| Host Unit | The part of the organization that owns the environment being assessed and where the assessment is centred. The Host Unit's assets are the core of the scope. |
| Supporting Units | Parts of the organization that provide services or capabilities to the Host Unit's in-scope environment — shared IT, a corporate SOC, a central helpdesk. If they touch the protected data or protect it, they come into scope with it. |
| Coordinating Unit | The unit that organizes and coordinates the assessment logistics. Frequently the same as the Host Unit, but it does not have to be. |
Level 1 scoping
Simpler than Level 2 in every respect, and the differences are exactly where the traps sit.
- In scope: OSA information systems that process, store or transmit FCI. Self-assessed against the applicable requirements.
- Out of scope: systems that do not process, store or transmit FCI. There are no documentation requirements for out-of-scope assets at Level 1.
- Specialized Assets are NOT part of the Level 1 assessment scope and are not assessed against CMMC security requirements — even though they can process, store or transmit FCI.
- VDI carve-out: an endpoint hosting a VDI client configured to allow nothing beyond keyboard, video and mouse traffic is out of scope.
- Scoping considerations: people, technology, facilities and External Service Providers within the environment that process, store or transmit FCI.
The five Level 2 asset categories
Four are in the assessment scope, one is not. Know the assessment treatment as well as the definition — scenario questions usually ask what the assessor does, not what the asset is.
| Category | Definition | What the assessor does |
|---|---|---|
| CUI Assets | Process, store or transmit CUI. | Assess against all Level 2 security requirements. |
| Security Protection Assets | Provide security functions or capabilities to the assessment scope — whether or not they touch CUI. A SIEM, a hosted VPN, a cloud security service. | Assess against the Level 2 requirements relevant to the capabilities provided — not all 110. |
| Contractor Risk Managed Assets | Can, but are not intended to, process, store or transmit CUI, because of the policies, procedures and practices in place. Not required to be separated from CUI assets. | Review the SSP. If sufficiently documented, do not assess against other requirements. If the documentation or other findings raise questions, the assessor may conduct a limited check, assessed against CMMC requirements, which must not materially increase assessment duration or cost. |
| Specialized Assets | Can process, store or transmit CUI but are unable to be fully secured. Six named types, listed below. | Review the SSP. Do not assess against other CMMC security requirements. |
| Out-of-Scope Assets | Cannot process, store or transmit CUI and do not provide security protections for CUI Assets. Physically or logically separated from CUI assets. | None. But the OSA must be prepared to justify the asset's inability to process, store or transmit CUI. |
The six Specialized Assets
A closed list. Memorise it — questions are built by offering a seventh thing that sounds plausible.
| Type | Typical example |
|---|---|
| Government Furnished Equipment (GFE) | A laptop or instrument issued by the government under the contract. |
| Internet of Things (IoT) | Networked cameras, smart building sensors, badge readers. |
| Industrial Internet of Things (IIoT) | Instrumented plant equipment reporting telemetry. |
| Operational Technology (OT) | PLCs, SCADA, CNC machines on the shop floor. |
| Restricted Information Systems | Systems configured to a specific contractual or statutory requirement that constrains how they may be secured. |
| Test Equipment | Oscilloscopes, spectrum analysers, calibration rigs with embedded computers. |
External Service Providers
The highest-yield table in the domain, and the one that changed most under the final rule. Two questions produce the answer: is the provider a CSP, and does it handle CUI, SPD, or neither?
| The ESP handles… | …and is a CSP | …and is not a CSP |
|---|---|---|
| CUI (with or without SPD) | The CSP must meet the FedRAMP requirements in DFARS 252.204-7012. | The services are in the OSA's assessment scope and are assessed as part of the OSA's assessment. |
| SPD, without CUI | The services are in the OSA's scope and are assessed as Security Protection Assets. | The services are in the OSA's scope and are assessed as Security Protection Assets. |
| Neither CUI nor SPD | The provider does not meet the CMMC definition of an ESP at all. | |
- Security Protection Data is data stored or processed by Security Protection Assets and used to protect the assessed environment — security-relevant information that would help an attacker if disclosed. Configuration data for a security tool is the standard example.
- Not every vendor is an ESP. An HR or accounting SaaS that touches neither CUI nor SPD does not meet the definition, however important it is to the business.
- Documentation: the use of the ESP, its relationship to the OSA, and the services provided must be in the OSA's SSP, supported by the ESP's service description and customer responsibility matrix (CRM), which allocates responsibility for each requirement between the two parties.
- Voluntary certification: an ESP may choose to undergo its own CMMC certification assessment to reduce the effort it imposes during the OSA's assessment. The minimum assessment type for the ESP is dictated by the OSA's DoD contract requirement.
- Accountability does not transfer. Outsourcing the capability never outsources the obligation. The OSA remains responsible for demonstrating the requirements are met.
Level 3 scoping, briefly
- Four categories, not five. Contractor Risk Managed Assets disappear as a separate category — at Level 3 assets that can but are not intended to process CUI are folded into CUI Assets.
- The Level 3 scope must be equal to or a subset of the Level 2 scope — typically a hardened enclave inside the Level 2 boundary.
- Any Level 2 POA&M items must be closed before a Level 3 certification assessment begins.
- DIBCAC may check any Level 2 requirement on any in-scope asset. If one is found NOT MET, the Level 3 assessment may be paused for remediation, placed on hold, or terminated outright.
- Specialized Assets at Level 3 get a limited check against Level 2 and are assessed against Level 3 requirements; intermediary devices are permitted to help a specialized asset meet requirements.
Separation, and when scope changes
- Separation may be physical or logical. Physical separation means no connection at all, wired or wireless. Logical separation is achieved by configuration — but it has to actually hold, and the OSA must be prepared to justify it.
- Maximise what is out of scope. Good scoping is a design activity, not a paperwork exercise: every asset legitimately excluded is one not assessed against 110 requirements.
- A new assessment is required for significant architectural or boundary changes — network expansion, mergers and acquisitions.
- Operational changes inside the existing boundary that follow the existing SSP — adding or removing resources — do not require a new assessment and are covered by the annual affirmation.
Traps worth memorising
- Level 1 has no asset categories. In scope or out. CRMA and SPA options in a Level 1 scenario are automatically wrong.
- Specialized Assets: Level 1 versus Level 2. Not in scope at Level 1. In scope but not assessed against other requirements at Level 2. Different answers to a near-identical question.
- CRMAs are not required to be separated from CUI assets. That is what distinguishes them from out-of-scope assets, which must be.
- Out-of-scope has two conditions, not one. Cannot process, store or transmit CUI and does not provide security protections. A device that touches no CUI but supplies a security function is a Security Protection Asset.
- Security Protection Assets are not assessed against all 110. Only the requirements relevant to the capabilities they provide.
- The limited check on a CRMA is bounded. It must not materially increase assessment duration or cost — and what it does check is assessed against CMMC requirements.
- A provider handling neither CUI nor SPD is not an ESP. The instinct to sweep every vendor into scope is the error the question is testing.
- A CSP handling CUI points to FedRAMP, not to a CMMC assessment of the CSP. A non-CSP handling CUI is assessed as part of the OSA's own assessment.
- The VDI carve-out is narrow. Keyboard, video and mouse only. Allow a file transfer or clipboard through and the endpoint is back in scope.
- Only out-of-scope assets escape the documentation duty. All four in-scope categories go in the asset inventory, the SSP and the network diagram.
Certification study · Domain 2 · 5% of the exam · the cheapest marks on the paper
Code of Professional Conduct
Confidentiality, objectivity, proper use of methods, professionalism — plus the ISO/IEC standards behind the ecosystem and the DoD obligations that sit on every credential holder. Small domain, easy marks, and one reliable heuristic that answers most of them. Read the guide, drill the cards, then test yourself. Progress saves in this browser.
What comes in the exam, and how to prepare
Domain 2 is 5% of a 170-question paper — roughly 8 or 9 questions. It is the smallest domain and the easiest to score full marks on, because the questions follow a pattern and the pattern has a tell.
| What to expect | |
|---|---|
| Question form | Almost always “a CCP observes X — what should they do?” A short situation, four courses of action, one correct. |
| Heaviest sub-areas | Conflicts of interest and objectivity; confidentiality; proper use of methods; the duty to report. |
| Also examinable | The ISO/IEC standards behind the ecosystem, DoD obligations such as the background investigation, intellectual property, and NDAs. |
| Pacing | Stems are short. These should take well under a minute each and bank time for Domains 4 and 5. |
A preparation order that works
- Read the Code of Professional Conduct end to end once. It is short. Nothing else in the blueprint has this ratio of pages to marks.
- Learn the principle headings and be able to sort a scenario under one of them before choosing an answer. Naming the principle usually names the answer.
- Memorise the ISO/IEC mapping — three standards, three bodies. It is a single flat fact and it appears.
- Drill conflicts of interest until the separation-of-duties rule is reflexive.
Who the Code binds
Not just assessors. The Code applies across the ecosystem, and the exam likes to test whether you know a CCP is already bound before ever sitting on an assessment team.
- Credentialed individuals — CCP, CCA, CCI, Provisional roles, RP and RPA.
- Accredited and registered organizations — C3PAOs, RPOs, LTPs and LPPs.
- Candidates — obligations attach from application, including the exam non-disclosure agreement, before any credential is issued.
- It survives the engagement. Confidentiality and intellectual property obligations do not end when the assessment or the employment does.
The guiding principles
Confidentiality
Information obtained about an OSA or OSC is used only for the purpose for which it was obtained, and disclosed only where authorised or legally required. This covers assessment findings, evidence, system details, vulnerabilities and commercial information. Practical consequences: no using one client's environment as a war story with another, no retaining evidence beyond what the process requires, and no disclosure to a parent company or a subcontractor without authorisation.
Objectivity & conflicts of interest
Judgment must be free from bias, financial interest and undue influence. Conflicts must be identified and disclosed, and where they cannot be managed, the individual or organization steps aside. Separation of duties: a firm that consulted on or prepared an environment cannot then assess it. Financial stakes, family relationships, recent employment and gifts or gratuities all bear on objectivity.
Proper use of methods
Follow the defined process. Use the approved methods, the approved materials and the evidence requirements as written. Schedule pressure, cost pressure and client preference are never a justification for substituting one method for another or for shortening the evidence required. Results must not be misrepresented, and a credential must not be used to imply an authority it does not carry.
Professionalism
Competence within the limits of your role, courteous and non-discriminatory conduct, accurate representation of your own credentials, and no marketing that implies DoD endorsement. A CCP describing themselves as an assessor, or a firm implying government sponsorship, breaches this.
Information integrity
Evidence and findings are recorded accurately and completely. No falsification, no selective omission, no alteration of an artifact, no post-hoc adjustment of a finding to suit a party. Where evidence conflicts, it is resolved and documented — not smoothed over.
Lawful practice & intellectual property
Comply with applicable law and contract. Respect copyright in CMMC materials and third-party content — training materials are licensed to LTPs and LPPs, and reproducing them without licence is a breach. Exam content is under NDA: discussing questions, reconstructing them, or using recalled items is a violation regardless of intent.
ISO/IEC standards behind the ecosystem
Three standards, three bodies. A flat fact that appears in this domain and occasionally in Domain 1.
| Standard | Governs | Applies to |
|---|---|---|
| ISO/IEC 17011 | Requirements for accreditation bodies accrediting conformity assessment bodies | The Cyber AB, as the accreditation body |
| ISO/IEC 17024 | Requirements for bodies operating certification of persons | The CAICO, which certifies individuals |
| ISO/IEC 17020 | Requirements for bodies performing inspection | C3PAOs, which perform assessments |
DoD obligations on credential holders
- Background investigation. Participation in assessment activities requires a positively adjudicated Tier 3 background investigation. It establishes eligibility to participate — it is not a security clearance, and describing it as one is a distractor.
- CUI handling. Credential holders are expected to complete DoD CUI awareness training and to handle CUI encountered during an engagement in accordance with the applicable marking, handling and dissemination rules.
- Contractual obligations. Non-disclosure agreements with the OSA sit alongside, not instead of, the Code. Where a client NDA and the Code both apply, both must be satisfied.
- No authority to bind the government. A credential holder does not speak for the DoD, cannot grant waivers, and cannot promise an assessment outcome.
When something goes wrong
- Complaints and alleged violations are raised through the established ethics reporting process, and credential holders are expected to cooperate with an investigation.
- Outcomes range from advisory guidance and a warning through to suspension or revocation of the credential or accreditation, and removal from the Marketplace.
- Disagreement with an assessment finding is not an ethics matter — it goes through the dispute and appeal path with the C3PAO and the Cyber AB. Do not confuse the two channels; questions sometimes offer the wrong one.
Traps worth memorising
- A private word is not a report. The duty is to report through the established process.
- Schedule pressure never justifies a method substitution. Any option offering an interview in place of a required test because time is short is wrong.
- Consulting bars assessing. Different teams inside the same firm does not cure it — the prep firm and the C3PAO must be different companies.
- Confidentiality does not expire with the engagement, the contract or the employment.
- Tier 3 background investigation, not a clearance.
- Exam content is under NDA. Sharing recalled questions is a violation even when the motive is to help others study.
- The Code binds candidates, not only credential holders. Obligations attach on application.
- Findings disputes go to appeal, not to ethics. Ethics is for conduct, not for disagreement about a determination.
- Accurate credentials. A CCP is not an assessor and must not be presented as one, however experienced.