CMMC Assessment Ecosystem · 1 of 3
The CMMC Accreditation Body and its overseer
In short
- The PMO may have DIBCAC assess an organization whose status is questioned.
- There is only one Accreditation Body at a time.
- C3PAOs must meet ISO/IEC 17020 within 27 months of authorization.
1. Defense oversight
The Cybersecurity Maturity Model Certification (CMMC) rule also governs the private businesses and other entities that make up its assessment and certification ecosystem (32 CFR 170.3(a)(2)). Oversight sits with the Office of the Deputy Chief Information Officer for Cybersecurity within the Office of the Defense Department Chief Information Officer (CIO) (32 CFR 170.6(a)). That office sets CMMC assessment, accreditation and training requirements and develops and updates program policies and guidance. The CMMC Program Management Office (PMO) monitors the Accreditation Body’s performance of its assigned roles and acts as needed to address problems (32 CFR 170.6(b)).
The PMO keeps, for the Deputy CIO, the right to review the Accreditation Body’s decisions and to evaluate any alleged conflicts of interest affecting its objectivity (32 CFR 170.6(c)). It sponsors the Defense Counterintelligence and Security Agency (DCSA) work needed for ecosystem members, including foreign ownership, control or influence (FOCI) risk assessments and Tier 3 background investigations (32 CFR 170.6(d)).
2. Investigating a status
The PMO investigates and acts on indications that an active CMMC status has been called into question (32 CFR 170.6(e)). Reports may come from the Accreditation Body, a CMMC Third-Party Assessment Organization (C3PAO) or anyone with knowledge of the organization’s security processes. Investigations may include reviewing assessment information and having the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) conduct its own review of the organization under Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7020.
Where DIBCAC finds the required status was not achieved or not kept, its results prevail over any status recorded in the Supplier Performance Risk System (SPRS) (32 CFR 170.6(f)). The Department updates SPRS to show the organization is out of compliance. If the organization is working on an active contract requiring CMMC compliance, standard contractual remedies apply.
3. One Accreditation Body
The Accreditation Body is responsible for authorizing and ensuring the accreditation of C3PAOs under the international standard ISO/IEC 17020:2012 and all applicable requirements (32 CFR 170.8(a)). It sets the C3PAO authorization requirements and accreditation scheme and submits both to the PMO for approval. At any given point in time, there will be only one Accreditation Body for the program.
The body must be based in the United States and be a member in good standing of the Inter-American Accreditation Cooperation (32 CFR 170.8(b)(1)). It must become a signatory of the International Laboratory Accreditation Cooperation mutual recognition arrangement, with a scope of ISO/IEC 17020. It must also be a member in good standing of the International Accreditation Forum, with signatory status covering ISO/IEC 17024 (32 CFR 170.8(b)(2)). Within 24 months of Defense approval, it must fully comply with ISO/IEC 17011:2017 and complete a peer assessment by other signatories (32 CFR 170.8(b)(3)).
4. Authorization before accreditation
Until it achieves that full compliance, the body authorizes C3PAOs that meet all the rule’s requirements, and its administrative requirements, to conduct Level 2 certification assessments and issue Certificates of CMMC Status (32 CFR 170.8(b)(3)(i)(A)). It must require all C3PAOs to meet ISO/IEC 17020 within 27 months of authorization (32 CFR 170.8(b)(3)(i)(B)). The body accredits C3PAOs under ISO/IEC 17020 that meet all the rule’s requirements (32 CFR 170.8(b)(3)(ii)).
5. Vetting and foreign interests
The body’s board, professional, information technology and accreditation staff, and independent CMMC Certified Assessor staff must complete a Tier 3 background investigation resulting in a determination of national security eligibility (32 CFR 170.8(b)(4)). That investigation does not produce a security clearance and is not for government employment. It starts with Standard Form 86 and is processed by DCSA through Washington Headquarters Services. The positions are designated non-critical sensitive with a moderate risk designation.
The body must complete Standard Form 328, the certificate pertaining to foreign interests, submit it to DCSA and undergo a national security review on protecting controlled unclassified information (32 CFR 170.8(b)(5)(i)). It must receive a non-disqualifying eligibility determination from the PMO to be recognized. It must resubmit the form within 15 business days of any change, and a disqualifying determination based on the change ends its authorization or accreditation (32 CFR 170.8(b)(5)(ii)). It must identify prospective C3PAOs to the PMO, which sponsors their own FOCI risk assessments by DCSA (32 CFR 170.8(b)(5)(iii)).
6. Duties, data and policies
The body must obtain a Level 2 certification assessment by DIBCAC every three years, which meets all Final Level 2 (C3PAO) requirements but does not give it that status (32 CFR 170.8(b)(6)). It must provide all documentation and records in English, and keep a single public website listing authorized and accredited C3PAOs (32 CFR 170.8(b)(7) and 32 CFR 170.8(b)(8)). It provides C3PAO data, with authorization and accreditation dates, to the PMO through the CMMC instance of the Enterprise Mission Assurance Support Service (32 CFR 170.8(b)(9)). It must encrypt and protect all information about individuals in its systems, and give the PMO all plans for revenue, such as fees, licensing and memberships (32 CFR 170.8(b)(12) and 32 CFR 170.8(b)(13)).
The body gives the Defense Department aggregate statistics on the ecosystem, including the authorization and accreditation status of C3PAOs (32 CFR 170.8(b)(10)). It provides inputs for assessor supplemental guidance to the PMO and supports Defense-led working groups (32 CFR 170.8(b)(11)). It must ensure that the CMMC Assessor and Instructor Certification Organization complies with ISO/IEC 17024:2012 (32 CFR 170.8(b)(14)). Training products, instruction and testing materials must be of high quality and subject to that organization’s quality control policies (32 CFR 170.8(b)(15)).
The body must keep an internal appeals process and give a final decision on all elevated appeals (32 CFR 170.8(b)(16)). Its conflict of interest, professional conduct and ethics policies must be approved by the PMO before they take effect, and apply to the body and to some ecosystem members (32 CFR 170.8(b)(17)). Those members are the ones who provide assessments, instruction, training materials or certificates on its behalf. The conflict policy requires disclosure of actual, potential or perceived conflicts to the PMO, and a one-year cooling off period for employees, directors and committee members who leave (32 CFR 170.8(b)(17)(i)). The C3PAOs the body authorizes are covered in what a C3PAO must be and do.
Key terms
| CMMC PMO | The program office that monitors the Accreditation Body and investigates questioned statuses. |
|---|---|
| Accreditation Body | The single body that authorizes and accredits C3PAOs. |
| ISO/IEC 17020 | The standard under which C3PAOs are accredited, within 27 months of authorization. |
| Tier 3 investigation | A background investigation for national security eligibility, not a clearance. |
| Standard Form 328 | The certificate pertaining to foreign interests, reviewed by DCSA. |
Every statement above links to the document behind it. The full source list for this piece is on the sources page.
This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.
How Sentfore supports this
Assessment integrity matters to everyone who relies on a status. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.