CMMC Assessment Ecosystem · 3 of 3

CMMC assessors, instructors and professionals

← All Insights

In short

  • Assessor, instructor and professional certifications last 3 years.
  • A Lead CCA needs 5 years of cybersecurity and management experience.
  • Assessors may use only the C3PAO’s equipment for assessment work.
Published10 October 2026
Last reviewed10 October 2026
Sources current as of10 October 2026

1. One certification organization

The people who assess and teach under the Cybersecurity Maturity Model Certification (CMMC) rule are trained and certified by a single body. The CMMC Assessor and Instructor Certification Organization (CAICO) is responsible for training, testing, authorizing, certifying and recertifying CMMC assessors, instructors and related professionals (32 CFR 170.10(a)). Only the CAICO may make decisions on examination certifications, including granting, maintaining, recertifying, expanding, reducing, suspending or withdrawing them under ISO/IEC 17024:2012. The program has a single CAICO at any one time.

The CAICO is bound by the conflict of interest, professional conduct and ethics policies set by the Accreditation Body (32 CFR 170.10(b)(1)). It must achieve and maintain ISO/IEC 17024 accreditation within 12 months of December 16, 2024. It keeps its documentation and records in English (32 CFR 170.10(b)(2)).

2. Examinations and training materials

The CAICO trains, tests and designates Provisional Instructors, and trains, tests, certifies and recertifies the professionals, assessors and instructors (32 CFR 170.10(b)(3)). Its instructor and assessor examinations must be certified under ISO/IEC 17024 by a recognized United States-based accreditor that is not a member of the Accreditation Body (32 CFR 170.10(b)(4)). That accreditor must be a signatory to the relevant International Laboratory Accreditation Cooperation or International Accreditation Forum mutual recognition arrangement.

The CAICO sets quality control policies for training products, instruction and testing materials, and oversees the quality of training and examination materials (32 CFR 170.10(b)(5) and 32 CFR 170.10(b)(6)). It must publish an appeals process for complaints and appeals, and resolve appeals on certification decisions through internal processes (32 CFR 170.10(b)(7) and 32 CFR 170.10(b)(8)).

3. Records, separation and confidentiality

The CAICO keeps records of all procedures, processes and actions under its requirements for six years and gives the Accreditation Body access to them (32 CFR 170.10(b)(9)). It must ensure separation of duties among the individuals involved in testing, training and certification activities (32 CFR 170.10(b)(11)). It must safeguard the confidentiality of applicant, candidate and certificate-holder information, and require its training support service providers to do the same (32 CFR 170.10(b)(12)).

All personally identifiable information must be encrypted and protected in CAICO systems and those of its training support service providers (32 CFR 170.10(b)(13)). Examinations must be secure and fairly administered (32 CFR 170.10(b)(14)). CMMC data or metrics on authorization or certification may be disclosed only to the Accreditation Body and the Defense Department, except as required by law (32 CFR 170.10(b)(15)). The CAICO must require retraining and recertification of certified professionals, assessors and instructors on a significant change to program requirements, as determined by the Defense Department or the CAICO (32 CFR 170.10(b)(16)).

4. CMMC Certified Assessors

A CMMC Certified Assessor (CCA) conducts Level 2 certification assessments in support of a CMMC Third-Party Assessment Organization (C3PAO) (32 CFR 170.11(a)). The assessments follow National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171A, the Level 2 assessment processes and the Level 2 scoping rules. A CCA must obtain and maintain CAICO certification, which is valid for 3 years from issuance (32 CFR 170.11(b)(1)). Each CCA must complete a Tier 3 background investigation for national security eligibility, or meet its equivalent if not eligible (32 CFR 170.11(b)(3) and 32 CFR 170.11(b)(4)).

A CCA must be a CMMC Certified Professional (CCP) with at least 3 years of cybersecurity experience and at least 1 year of assessment or audit experience (32 CFR 170.11(b)(6)). The CCA also needs at least one foundational qualification aligned to at least the Intermediate Proficiency Level of the Security Control Assessor (612) Work Role. The qualification comes from Department of Defense (DoD) Manual 8140.03, under the DoD Cyberspace Workforce Framework. A Lead CCA needs at least 5 years of cybersecurity experience, 5 years of management experience and 3 years of assessment or audit experience (32 CFR 170.11(b)(10)). The Lead CCA’s foundational qualification must be aligned to the Advanced Proficiency Level of the same work role.

5. Assessor information handling

For all assessment activities, a CCA may use only the information technology, cloud and cybersecurity services and end-point devices provided by the engaged C3PAO (32 CFR 170.11(b)(7)). That C3PAO must itself have undergone a Level 2 certification assessment by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) or higher. Individual assessors may not use any other information technology, including personally owned devices or cloud services, for assessment reports or related information. Reviewing evidence within the assessed organization’s environment, using its tools, is permitted.

A CCA must immediately notify the C3PAO of any breach or potential breach of security to assessment materials under the assessor’s purview (32 CFR 170.11(b)(8)). Information about an organization obtained during pre-assessment and assessment activities may not be shared with anyone outside that assessment, except as required by law (32 CFR 170.11(b)(9)).

6. Instructors

A CMMC Provisional Instructor (PI) teaches CCA and CCP candidates during the transitional period that ends 18 months after December 16, 2024 (32 CFR 170.12(a)). A CMMC Certified Instructor (CCI) teaches CCP, CCA and CCI candidates, and holds certifications valid for 3 years from issuance (32 CFR 170.12(b)). A CCI with a valid CCP certification may teach CCP candidates, while one with a valid CCA certification may teach CCP, CCA and CCI candidates. Delivering CCA training requires a CCA certification (32 CFR 170.12(c)(3)).

Instructors must give the Accreditation Body and the CAICO accurate information on their qualifications, training experience, affiliations and certifications every year (32 CFR 170.12(c)(6)). They may not provide CMMC consulting services while serving as instructors, though they may serve on an assessment team subject to the conduct and conflict policies (32 CFR 170.12(c)(7)). A CCI may not develop examination objectives or content, or act as an examination proctor, at the same time (32 CFR 170.12(c)(8)). Instructors keep trainee records and other training information confidential, except as required by law (32 CFR 170.12(c)(9)).

7. Certified Professionals

A CCP completes training on CMMC and the assessment process to give advice, consulting and recommendations to organizations seeking assessment (32 CFR 170.13(a)). CCPs are eligible to become CCAs. They may take part in Level 2 certification assessments with CCA oversight, where the CCA makes all final determinations. CCP certification is valid for 3 years from issuance (32 CFR 170.13(b)(1)). CCPs must also complete a Tier 3 background investigation, or meet its equivalent when not eligible for one (32 CFR 170.13(b)(3) and 32 CFR 170.13(b)(4)). The organizations that employ assessors are covered in what a C3PAO must be and do.

Key terms

CAICOThe single organization that trains, tests and certifies CMMC assessors, instructors and professionals.
CCAA certified assessor who conducts Level 2 certification assessments for a C3PAO.
Lead CCAA CCA with the added experience needed to lead an Assessment Team.
CCPA certified professional who advises organizations and may support assessments under CCA oversight.
CCIA certified instructor who teaches CCP, CCA and CCI candidates.

Every statement above links to the document behind it. The full source list for this piece is on the sources page.

This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.

How Sentfore supports this

Qualified people sit behind every CMMC status. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.