Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

What Is a C3PAO? The Plain-English Guide to CMMC Assessors

August 11, 2026
hero-what-is-a-c3pao-1.png

A C3PAO, short for Certified Third-Party Assessment Organization, is a firm authorized to run official CMMC Level 2 assessments. It issues a company’s Certificate of CMMC Status. Under the CMMC Program final rule, C3PAOs are one of only two entities allowed to perform third-party CMMC assessments.

The other authorized assessor is DIBCAC, which handles CMMC Level 3. Say your company handles Controlled Unclassified Information (CUI) on a Department of War contract. If that contract requires third-party certification, a C3PAO checks your work.

A C3PAO is not a consultant and not a badge you buy. It is the independent auditor that verifies your cybersecurity controls actually work, then reports the result to the government.

Why Do C3PAOs Exist?

Not every defense contractor needs a C3PAO. CMMC has three levels, and each one calls for a different kind of check. The level assigned to your contract decides whether self-assessment is enough or a third-party assessor has to sign off.

LevelWho It Applies ToHow It’s VerifiedFrequency
Level 1 (Foundational)Companies that only handle Federal Contract Information (FCI)Self-assessmentAnnual
Level 2 (Advanced)Companies that handle CUISelf-assessment (Level 2 Self) or C3PAO third-party assessment, depending on the contractSelf: annual. C3PAO: every 3 years
Level 3 (Expert)Highest-priority programs handling CUIGovernment-led assessment by DIBCACSet by the Department of War

Which path applies is a contract term, not a company preference. DFARS 252.204-7021 writes the CMMC requirement into the contract itself. The solicitation or contract language tells you which level and which path apply.

The difference between the two Level 2 paths comes down to who’s checking. For a self-assessment, your own IT team checks the boxes. For a C3PAO assessment, an independent outside party checks them instead. That party reports the results directly to the government. That is why the requirement exists at all: for the CUI that matters most, the Department of War doesn’t want a company grading its own homework.

How Does a Company Become a C3PAO?

Becoming a C3PAO is not simple paperwork. The Cyber AB runs that accreditation chain. A firm has to clear every step before it can assess anyone.

Becoming a C3PAO
  1. Hold its own CMMC Level 2 certification first. The firm has to meet the same bar it will later assess others against.
  2. Obtain ISO/IEC 17020 accreditation as a conformity-assessment body. This is the same standard used to accredit inspection bodies in other regulated industries.
  3. Pass foreign ownership, control, or influence (FOCI) screening. This check keeps the assessment ecosystem free of foreign influence.
  4. Staff assessments with Certified CMMC Assessors (CCAs), the credentialed individuals who lead assessments on the firm’s behalf.

Each step is designed to answer a different question. The Level 2 certification proves the firm can meet the standard it’s grading others on. The ISO 17020 accreditation proves it runs its assessments the way a real conformity-assessment body should. The FOCI screening proves it isn’t compromised by foreign ownership or influence before it ever gets near a defense contractor’s CUI.

Authorization is not permanent either. It can change. A firm’s current standing is always worth checking before you sign anything.

C3PAO vs. CCA vs. CCP vs. RP/RPO: What’s the Difference?

These four terms get used interchangeably online. That is a mistake. Each one means something different. Only one of them can actually assess you.

RoleWhat It IsCan It Assess or Certify You?
C3PAOThe accredited firm authorized to conduct a CMMC Level 2 third-party assessmentYes, it’s the organization performing the assessment
CCA (Certified CMMC Assessor)The individual credentialed to lead an assessment on the C3PAO’s behalfYes, as the lead assessor working for the C3PAO
CCP (Certified CMMC Professional)A related credential for staff who support assessmentsNo, supports the assessment but does not lead or certify it
RP / RPO (Registered Practitioner / Registered Provider Organization)A consultant or firm that helps a company prepare for assessmentNo, cannot conduct an assessment or certify compliance

The distinction that trips people up most is the last row. An RP or RPO can be enormously useful getting your systems ready. It just cannot be the one that signs off on you.

That confusion isn’t harmless. A company that treats its prep consultant as if it were also its assessor can walk into an actual C3PAO engagement thinking it’s further along than it is. The two roles are built to be separate on purpose. One helps you get ready. The other independently checks whether you actually are.

What Does a C3PAO Assessment Actually Involve?

A C3PAO assessment is not a conversation. It’s a structured review of documented evidence.

Assessors don’t just ask if you have a control. They verify it works, on your actual systems. That’s the biggest difference from a self-assessment, where your own team checks its own boxes.

A typical C3PAO assessment digs into:

  • Access control and authentication, including multifactor authentication (MFA)
  • Encryption of CUI at rest and in transit
  • Centralized audit logging
  • Configuration management and patching
  • Security awareness training records
  • Incident response planning
  • Documentation, including the System Security Plan (SSP) and, where applicable, a Plan of Action and Milestones (POA&M)

Each item gets checked against evidence, not a verbal answer. If you want the step-by-step prep roadmap for this list, see how to prepare for a CMMC Level 2 assessment.

The controls above map directly to NIST SP 800-171, the standard Level 2 is built on. A C3PAO is checking whether you actually implemented those 110 requirements, not whether you can describe them.

When Is a C3PAO Assessment Required?

Level 2 has two paths, and your contract picks one for you. It’s not a preference call.

Self-Assessment vs C3PAO

Some contracts accept Level 2 Self, an annual self-assessment your own team performs. Others require a full C3PAO assessment instead. A C3PAO-issued Certificate of CMMC Status stays valid for three years. A self-assessment affirmation has to be renewed every year.

There’s a related requirement worth knowing about, even though it’s separate from CMMC itself. A score below 110 means you need a POA&M on file.

Not sure which level applies to you, or what the number itself measures? See what is an SPRS score and CMMC levels explained in depth for the full breakdown.

Where C3PAOs Don’t Fit In: Level 1 and Level 3

C3PAOs only operate at Level 2. That surprises a lot of people.

Level 1 covers companies that only handle Federal Contract Information (FCI), not CUI. Verification is self-assessment, done annually, with no third-party involvement at all.

Level 3 sits at the other end. Assessment there is government-led, run by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), not a C3PAO.

This trips up manufacturers more than most. A shop that assumes it only needs Level 1 is often wrong, because build-to-print work usually involves technical drawings and specs that count as CUI. That pushes the requirement to Level 2, not Level 1. CMMC for Manufacturers walks through that distinction in more detail.

How to Find and Vet a C3PAO

Start with the Cyber AB Marketplace, the official public catalog of accredited C3PAOs. It’s the only reliable source for who’s currently authorized.

Don’t stop at “they’re listed.” Authorization status can change. A firm can lose accreditation, get suspended, or let its own certification lapse. Check current status close to when you actually engage them, not months earlier.

Supply is tight right now, and that matters for planning.

Small Business Administration](https://www.sba.gov/article/2026/07/13/sba-commends-us-department-wars-suspension-cmmc-phase-ii-small-defense-contractors), July 2026).

That suspension, announced July 13, 2026, paused the Phase II third-party certification timeline that was set to start November 10, 2026. It did not touch Level 1 or Level 2 Self self-assessment obligations, which remain in effect right now. If a C3PAO assessment is still on your roadmap, plan around that limited assessor pool early. Waiting until a contract deadline is close is a real risk with this few assessors available.

See Where You Stand

Before you ever schedule a C3PAO assessment, it helps to know where your gaps actually are. Answer a few plain-English questions about your systems and CUI exposure and get your readiness level, no sign-up required to see the result.

Take the free 2-minute CMMC Risk-Check

How LeadingIT Helps You Get Ready

LeadingIT is not a C3PAO. It doesn’t perform CMMC assessments, and it doesn’t issue a Certificate of CMMC Status. What it does is get you ready for the company that will.

For manufacturers working toward Level 1 or Level 2, LeadingIT builds and runs the technical backbone an assessment actually checks. That means access control with MFA, encryption of CUI, audit logging, patching, security awareness training, and incident response planning, all as part of ongoing managed IT.

LeadingIT also helps scope which systems actually touch CUI, so your compliance boundary doesn’t balloon into the whole company. That scoping work alone often saves significant assessment time and cost. It maintains the evidence trail, including the SSP, that an assessor or a prime’s flow-down audit will ask to see.

Want to talk through your specific CUI footprint before you ever call a C3PAO? Contact us and we’ll walk through where you stand.

Frequently Asked Questions

Those figures come from federal compliance-cost analysis, not a fixed price list. Get a specific quote from a C3PAO directly once you know your scope.</p> </details>

A Certificate of CMMC Status issued by a C3PAO is valid for three years. A self-assessment affirmation, by contrast, has to be renewed every year. Which cycle applies to you depends on which Level 2 path your contract requires.

No. A consultant is usually a Registered Practitioner (RP) or Registered Provider Organization (RPO), and can help you prepare. A C3PAO is the accredited firm that independently assesses and certifies you. An RP or RPO cannot conduct your assessment or sign off on your compliance.

Nobody outside your own company. Level 1 only covers Federal Contract Information, not CUI, and it’s verified by annual self-assessment. C3PAOs are not involved at Level 1 at all.

The Defense Industrial Base Cybersecurity Assessment Center, or DIBCAC, handles Level 3. That’s a government-led assessment for the highest-priority programs, not a C3PAO engagement.

The Cyber AB runs the official public marketplace of accredited C3PAOs. Search it directly and confirm the firm’s current authorization status before you sign anything, since status can change over time.

No, and be wary of anyone who suggests otherwise. Becoming a C3PAO requires its own CMMC Level 2 certification, ISO/IEC 17020 accreditation, and FOCI screening. A managed IT provider like LeadingIT can get your systems assessment-ready, but it cannot also be the independent party that certifies you.

Ready to Get Assessment-Ready?

Getting ready for a C3PAO is technical work, and it’s easy to underscope or overscope it. LeadingIT’s IT compliance services for CMMC build the controls an assessor will check, before you ever schedule the assessment itself.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.