CMMC Certified Professional (CCP) — Exam Prep

Blueprint-weighted study plan and practice exams. Reflects the ISACA/CAICO transition and 32 CFR Part 170 as of July 2026.

Start here

v4 · 8 tabs · all six domains

What changed in 2026

Anything you read from 2024–2025 about registering through the Cyber AB is out of date.

ISACA became the CMMC Assessor & Instructor Certification Organization (CAICO) on 1 April 2026. Training oversight, the exam, and the certification itself now run through ISACA. The Cyber AB remains the accreditation body for organizations (C3PAOs, ATPs) and still runs the Tier 3 background investigations. The old $200 Cyber AB registration and CPN number path is gone.

Practical effect: you buy the exam in MyISACA, sit it at PSI, and apply to ISACA for the credential. You still take mandatory training from an Approved Training Provider listed on the CyberAB Marketplace.

Logistics

Registration, step by step

Tick these off as you go — progress is saved in this browser.

1

Complete mandatory CCP training with an ATP

Required before you can be certified. Find providers in the CyberAB Marketplace catalog. Typically 30–40 contact hours, delivered as a 4–5 day bootcamp or 8–10 evening sessions. Budget roughly $2,000–$4,000. Training from a non-authorized source does not count.

2

Buy the exam in MyISACA

US$575 member / US$760 non-member. Membership costs roughly $135 plus chapter dues, so joining first is cheaper than not. Registration is continuous — no fixed windows. Eligibility runs six months from the date you register, and the fee must be paid in full before you can schedule. Make sure your ISACA account name exactly matches your government photo ID.

3

Schedule with PSI

Computer-based at a PSI test center or remotely proctored. You can book as early as 48 hours after payment; appointments only open 90 days out. Reschedule free at any point in your eligibility window if you do it at least 48 hours before the appointment. Run the PSI system compatibility check first if you plan to test remotely.

4

Sit the exam

170 questions across six domains. ISACA reports scaled scores; check the current Exam Candidate Guide for the passing scale rather than relying on the old Cyber AB threshold.

5

Apply for the certification

Passing is only one component. You also submit an application demonstrating experience, pay a US$200 application processing fee, agree to the Code of Professional Ethics and CPE policy, and obtain a positively adjudicated DoW Tier 3 background investigation. ISACA validates your experience and hands off to the Cyber AB to start the investigation. You have five years from the exam date to apply.

6

Get listed and stay current

A CyberAB Marketplace listing requires an active credential plus completed Delta Training. Maintenance is 20 CPE minimum per year and 120 over three years; at least 90 must relate to the certification, two of which must cover CMMC rules specifically. CPEs that satisfy another ISACA certification can be applied to both.

Cost summary

ItemAmountPaid to
ATP training~$2,000–$4,000Approved Training Provider
Exam registration$575 member / $760 non-memberISACA
ISACA membership (optional, pays for itself)~$135 + chapter duesISACA
Application processing$200ISACA
Annual maintenanceSet by ISACA; lower than the old modelISACA

Blueprint

Where the 170 questions come from

Domains 4 and 5 are 60% of the exam. Weight your study time accordingly.

5 5 15 35 25 15
WeightDomainWhat it actually tests
5%1 — CMMC EcosystemWho does what: DoW, Cyber AB, CAICO, C3PAO, ATP, RPO, DIBCAC, OSA/OSC
5%2 — Code of Professional ConductConfidentiality, objectivity, proper use of methods, professional conduct
15%3 — Governance and Source DocumentsFCI vs CUI, 32 CFR 170, DFARS clause chain, NIST source docs
35%4 — Model Construct and Implementation EvaluationApplying source docs to practices, assessment criteria, evidence adequacy and sufficiency. L1 practices guaranteed to appear.
25%5 — CMMC Assessment Process (CAP)Four phases, CCP role boundaries, planning, conducting, reporting, POA&M closeout
15%6 — ScopingAsset categories and their treatment, FCI scope at Level 1
The single biggest trap for experienced practitioners: this is a document-recall exam, not a judgment exam. Where "what a good CISO would do" diverges from "what the rule and the CAP say," the rule wins. Answer from the document.

Sources

What to read, in priority order

Tier 1 — know these cold

Tier 2 — know the shape and the specifics that get tested

Plan

Six-week study schedule

Roughly 8–10 hours per week. Slot the ATP bootcamp into weeks 1–2, or take it before week 3 if it is a block course.

Week 1 — Ecosystem, ethics, and the shape of the ruleDomains 1, 2
Week 2 — FCI, CUI, and the clause chainDomain 3
Week 3 — ScopingDomain 6, 15%
Week 4 — Practices and evidenceDomain 4, 35%
Week 5 — The assessment processDomain 5, 25%
Week 6 — Test conditionsAll domains

Cheat sheet

High-yield facts

Level 2 asset categories (32 CFR 170.19(c)(1) Table 3)

CategoryDefinitionTreatment
CUI AssetProcesses, stores, or transmits CUIAssessed against all applicable Level 2 requirements. Document in inventory, SSP, network diagram.
Security Protection AssetProvides security functions or capabilities to the assessment scope, regardless of whether it handles CUI (a SIEM, for example)Assessed against the requirements relevant to the protections it provides. Document in inventory, SSP, network diagram.
Contractor Risk Managed AssetCan, but is not intended to, process/store/transmit CUI, and is managed under the risk-based policyIn scope. Not assessed against all requirements — assessor performs a limited check for deficiencies. If the risk-based management is not evident, the assessor may assess it fully.
Specialized AssetGFE, IoT, IIoT, Operational Technology, Restricted Information Systems, Test EquipmentPart of the assessment scope. Documented in inventory, SSP, and network diagram and managed per the risk-based policy. Not assessed against the other CMMC requirements.
Out-of-Scope AssetCannot process/store/transmit CUI; physically or logically separatedNo documentation requirement.
Level 1 is different. At Level 1 there are no asset categories. Assets are simply in scope or out of scope depending on whether they process, store, or transmit FCI — and Specialized Assets are not part of the Level 1 scope and carry no documentation requirement at all. Mixing up the L1 and L2 treatment of Specialized Assets is one of the most reliable ways to lose points.

Scoring and POA&M (32 CFR 170.21, 170.24)

  • Level 2 maximum score is 110. Unmet requirements deduct 5, 3, or 1 point.
  • Conditional Level 2 requires score ÷ 110 ≥ 0.8, so a minimum of 88.
  • Only 1-point requirements may go on a POA&M. One exception: SC.L2-3.13.11 (CUI encryption) may be included if encryption is employed but not FIPS-validated, at a 3-point cost.
  • Six specific 1-point requirements are named in 170.21 as ineligible regardless: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, PE.L2-3.10.5.
  • Consequence: every 3-point and 5-point requirement must be MET at assessment. Roughly 63 of the 110 cannot be deferred.
  • POA&M closeout must happen within 180 days of the Conditional CMMC Status Date, or the status expires. For a certification assessment, an authorized C3PAO performs the closeout.
  • Level 1 permits no POA&M at all. All 15 requirements must be MET.

Levels and who assesses

LevelRequirementsAssessed byCadence
Level 1 (Self)15, from FAR 52.204-21The OSA itselfAnnual self-assessment + annual affirmation
Level 2 (Self)110, NIST SP 800-171 Rev 2The OSA itselfEvery 3 years + annual affirmation
Level 2 (C3PAO)110, NIST SP 800-171 Rev 2Authorized C3PAOEvery 3 years + annual affirmation
Level 3 (DIBCAC)24 selected from NIST SP 800-172DIBCAC. Requires Final Level 2 (C3PAO) first.Every 3 years + annual affirmation

The four CAP phases

  1. Plan and Prepare Assessment — conflict of interest checks, contracting, scope verification, readiness review, assessment plan, evidence agreements, team selection.
  2. Conduct Assessment — collect and examine evidence, score practices, daily checkpoints with the OSC, generate preliminary findings, deliver the closeout briefing.
  3. Report Assessment Results — final findings, quality assurance review, package delivery to the OSC, upload to CMMC eMASS and SPRS, records retention.
  4. Remediation of Outstanding Assessment Issues — the POA&M closeout assessment inside the 180-day window.

Your role boundary as a CCP

  • You may serve as an Assessment Team Member on a Level 2 certification assessment and verify Level 1 practices.
  • You may not make final determinations. That authority belongs to the CCA or Lead CCA.
  • Participation on assessment teams requires a favorable Tier 3 determination.
  • You may advise, consult, and support readiness work for organizations seeking certification — but not for an organization you are also assessing.

Evidence vocabulary

  • Adequacy — does this evidence actually address the assessment objective?
  • Sufficiency — is there enough of it, across enough of the in-scope population, to support the finding?
  • Methods — examine (artifacts), interview (people), test (mechanisms). Findings should be corroborated across methods.
  • Findings — MET, NOT MET, or NOT APPLICABLE. There is no partial credit at the objective level.
  • Enduring Exception — a special circumstance where remediation is not feasible; documented in the SSP, no POA&M required.
  • Temporary Deficiency — a correctable condition tracked in an operational plan of action. This is not the same thing as a CMMC POA&M and is not subject to the 180-day clock.