CMMC Assessment Ecosystem · 2 of 3
What a C3PAO must be and do
In short
- C3PAO assessment personnel need a Tier 3 investigation.
- An Assessment Team includes at least two CCAs.
- Assessment records are kept for six years.
1. What a C3PAO does
Under the Cybersecurity Maturity Model Certification (CMMC) rule, a CMMC Third-Party Assessment Organization (C3PAO) conducts Level 2 certification assessments. It issues Certificates of CMMC Status to organizations seeking certification based on the results (32 CFR 170.9(a)). Every C3PAO must be accredited or authorized by the Accreditation Body. It must obtain that authorization or accreditation under the authorization and accreditation provisions at 32 CFR 170.8(b)(3) (32 CFR 170.9(b)(1)).
A C3PAO must comply with the Accreditation Body’s conflict of interest, professional conduct and ethics policies (32 CFR 170.9(b)(2)). It must also achieve and maintain compliance with the international standard ISO/IEC 17020:2012 within 27 months of authorization.
2. Personnel vetting
All C3PAO personnel taking part in the Level 2 certification assessment process need a Tier 3 background investigation that results in a national security eligibility determination (32 CFR 170.9(b)(3)). This covers the CMMC Assessment Team and the quality assurance individual. The investigation does not result in a security clearance and is not carried out for government employment. It is started with Standard Form 86, and the positions carry a non-critical sensitive designation at moderate risk.
Personnel who are not eligible for a Tier 3 investigation must meet the equivalent of a favorably adjudicated Tier 3 investigation (32 CFR 170.9(b)(4)). The Defense Department determines that equivalence for use with the CMMC Program only.
3. Foreign ownership, control or influence
A C3PAO must complete and submit the Certificate Pertaining to Foreign Interests (Standard Form 328) on request from the Defense Counterintelligence and Security Agency (DCSA) (32 CFR 170.9(b)(5)(i)). It then undergoes a national security review focused on the protection of controlled unclassified information, based on the factors in 32 CFR 117.11(b).
A non-disqualifying eligibility determination is then needed from the CMMC Program Management Office (PMO), based on the foreign ownership, control or influence (FOCI) risk assessment (32 CFR 170.9(b)(5)(ii)). Only then may it proceed to its own Level 2 assessment as part of authorization and accreditation. Any change to the information on its Standard Form 328 must be reported by resubmitting the form to DCSA within 15 business days of the change taking effect (32 CFR 170.9(b)(5)(iii)). A disqualifying determination based on the change results in the C3PAO losing its authorization or accreditation.
4. Its own Level 2 assessment
Each C3PAO must undergo a Level 2 certification assessment meeting all requirements for a Final Level 2 (C3PAO) status, under the procedures for Level 2 certification (32 CFR 170.9(b)(6)). Two exceptions apply. The assessment is conducted by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). And the assessment does not result in a Level 2 (C3PAO) status or a Certificate of CMMC Status.
5. Records, data and security
A C3PAO must provide all documentation and records in English (32 CFR 170.9(b)(7)). It submits pre-assessment and planning material, final assessment reports and certificates into the CMMC instance of the Enterprise Mission Assurance Support Service (eMASS) (32 CFR 170.9(b)(8)). All assessment data uploaded into eMASS must comply with the CMMC assessment data standard in the eMASS CMMC Assessment Import Templates (32 CFR 170.9(b)(17)).
Unless the PMO authorizes otherwise, a C3PAO keeps all assessment-related records for six years (32 CFR 170.9(b)(9)). These include materials and working papers generated during assessments, and records on the training, skills and authorization of assessment personnel. They also include contractual agreements with organizations seeking certification, and records of organizations for which consulting services were provided.
A C3PAO must provide any requested audit information to the Accreditation Body, including information outside the ISO/IEC 17020 cycle (32 CFR 170.9(b)(10)). It must ensure that all personally identifiable information is encrypted and protected in all its information systems and databases (32 CFR 170.9(b)(11)). It must maintain the facilities, personnel and equipment in scope of its own Level 2 assessment and comply with the security requirements and procedures the Accreditation Body prescribes (32 CFR 170.9(b)(16)).
6. Teams, quality assurance and scope
An Assessment Team must include at least two people, a Lead CMMC Certified Assessor (CCA) and at least one other CCA (32 CFR 170.9(b)(12)). Additional CCAs and CMMC Certified Professionals (CCPs) may also take part. A C3PAO must implement a quality assurance function that checks the accuracy and completeness of assessment data before upload into eMASS (32 CFR 170.9(b)(13)). The quality assurance individual must be a CCA and may not be a member of the Assessment Team being reviewed. That individual manages quality assurance reviews and the appeals process, under ISO/IEC 17020 and ISO/IEC 17011.
Quality assurance reviews are conducted for each assessment, including observing the Assessment Team’s conduct and its management of assessment processes (32 CFR 170.9(b)(14)). All Level 2 certification assessment activities must be performed on the information system within the CMMC Assessment Scope (32 CFR 170.9(b)(15)).
7. Certificates and appeals
A Certificate of CMMC Status must include, at a minimum, all industry Commercial and Government Entity (CAGE) codes associated with in-scope information systems (32 CFR 170.9(b)(18)). It must also show the C3PAO name, the assessment unique identifier, the name of the organization, and the CMMC status date and level.
The C3PAO must address all appeals by organizations arising from its Level 2 certification assessments (32 CFR 170.9(b)(19)). If either side is not satisfied with the result, the organization or the C3PAO may elevate the matter to the Accreditation Body for final determination. The C3PAO submits assessment appeals, review records and appeal decisions to the Defense Department through eMASS (32 CFR 170.9(b)(20)).
8. Conduct policies set through the Accreditation Body
The professional conduct policy requires the Accreditation Body to inform the Defense Department in writing of new investigations within 72 hours (32 CFR 170.8(b)(17)(ii)). It must report the outcome of completed investigations within 15 business days. The policy must prohibit ecosystem members from taking part in a Level 2 certification assessment for an organization they served as a consultant, to prepare it for any CMMC assessment, within 3 years. It must also require them to keep customer and government data confidential and to report assessment results objectively, completely, clearly and accurately.
The ethics policy requires ecosystem members to report to the Accreditation Body within 30 days any conviction, guilty plea or no contest plea for fraud, misrepresentation, perjury or similar offenses (32 CFR 170.8(b)(17)(iii)). It also requires a satisfactory record of integrity and business ethics. The people who serve on C3PAO teams are covered in CMMC assessors, instructors and professionals.
Key terms
| C3PAO | An organization that conducts Level 2 certification assessments and issues Certificates of CMMC Status. |
|---|---|
| Assessment Team | At least a Lead CCA and one other CCA, with optional CCPs. |
| Quality assurance individual | A CCA, outside the team, who checks assessment data before upload. |
| Standard Form 328 | The foreign interests certificate, resubmitted within 15 business days of a change. |
| Three-year consulting bar | The rule against assessing an organization within 3 years of consulting for it. |
Every statement above links to the document behind it. The full source list for this piece is on the sources page.
This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.
How Sentfore supports this
The choice of assessor affects the timing of a status. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.