HomeBlogCMMC
CMMCFundamentals2026-07-25SecReadyNow

What is a C3PAO? CMMC Third-Party Assessors Explained

A C3PAO is the only organization authorized to give you an official CMMC Level 2 certification. There are about 100 of them for 100,000+ contractors - which is exactly why Phase 2 was suspended. Here is everything you need to know about how they work and what an assessment looks like.

When CMMC first launched, the question "what is a C3PAO?" was mostly asked by defense contractors who had just received a contract requirement they did not recognize. Now, with Phase 2 suspended and the program under review, the question carries a different weight: understanding what C3PAOs are, what they do, and why they matter tells you a lot about why Phase 2 ran into trouble - and what any restructured program will still need to accomplish.

The Short Version

A C3PAO is a Certified Third-Party Assessment Organization - a company authorized by the Cybersecurity Maturity Model Certification Accreditation Body (Cyber AB) to conduct official CMMC Level 2 assessments. When CMMC Phase 2 requires a third-party assessment, the assessment must be conducted by a C3PAO. You cannot hire just any cybersecurity consultant - they must be a C3PAO.

~100
C3PAOs authorized as of mid-2026
100,000+
Defense contractors needing Level 2 assessment
$30K-$100K+
Typical C3PAO assessment cost range
3-6 mo
Typical scheduling lead time

That ratio - 100 authorized assessors for 100,000+ contractors - is one of the primary reasons Phase 2 was suspended. The math genuinely does not work, and the DoD acknowledged it.

The Cyber AB Ecosystem: C3PAOs, RPOs, and RPAs

The CMMC ecosystem has several types of authorized organizations that are easy to confuse. Here is how they differ:

RoleWhat They DoCan Conduct Official Assessment?
C3PAO
Certified Third-Party Assessment Organization
Conducts official CMMC Level 2 assessments that result in a certification. Employs Certified CMMC Assessors (CCAs).Yes - this is their sole purpose
RPO
Registered Practitioner Organization
Provides CMMC consulting, gap assessments, remediation support, and documentation help. Cannot conduct official assessments.No
RPA
Registered Practitioner Advanced
Individual CMMC consultant with advanced Cyber AB credentials. Works through an RPO or independently.No
CCA
Certified CMMC Assessor
Individual assessor employed by a C3PAO who conducts the actual assessment activities.Only when employed by a C3PAO
DIBCAC
Defense Industrial Base Cybersecurity Assessment Center
DoD government organization that conducts High-confidence government-led assessments for the most sensitive programs.Yes - government assessments only

The practical implication: if someone tells you they can do your "CMMC certification" but they are an RPO, not a C3PAO, they can help you prepare for an assessment - but they cannot give you the certification. You will still need a C3PAO when Phase 2 requires it.

What the C3PAO Assessment Process Looks Like

A CMMC Level 2 assessment is not a questionnaire you fill out. It is a structured review process conducted over days or weeks by trained assessors. Here is roughly how it works:

1

Pre-Assessment / Scoping

The C3PAO reviews your System Security Plan and scopes the assessment. They establish which systems, locations, and personnel are in scope for CUI handling. Scoping errors here cost money - everything in scope gets assessed.

2

Document Review

Assessors review your SSP, policies, procedures, and evidence packages before the on-site visit. Gaps in documentation are flagged before the assessment begins. This is where being well-documented pays off - assessors make preliminary judgments from your documents.

3

Assessment Activities

On-site (or remote) assessment of technical controls: configuration reviews, system demonstrations, interview of key personnel, testing of specific practices. Assessors use NIST SP 800-171A as their guide - it defines exactly how each practice is assessed.

4

Draft Findings

The C3PAO produces a draft assessment report. You have an opportunity to provide additional evidence for any practices marked as "Not Met." This is your chance to produce evidence you missed in the document review phase.

5

Final Report and Score

The final report is submitted to CMMC eMASS. If all 110 practices are Met, you receive a CMMC Level 2 certification. Practices marked Not Met go on your POA&M with remediation timelines. Final disposition determines whether conditional certification is possible.

How to Find an Authorized C3PAO

The Cyber AB maintains the official marketplace at cybermarketplace.com. This is the authoritative source - if an organization is not listed there as a C3PAO, they are not authorized to conduct Level 2 assessments. Do not take anyone's word for it. Check the marketplace.

When evaluating C3PAOs, ask:

What About During the Phase 2 Pause?

While Phase 2 is suspended, mandatory C3PAO assessments are not required for new contracts. However:

The capacity problem has not been solved. The Phase 2 pause paused the mandate, not the assessor shortage. When the requirement returns, there will still be far more contractors than available C3PAOs. Organizations that are prepared will have shorter assessment timelines and lower costs than those scrambling to catch up.

Preparing for a C3PAO Assessment?

The CMMC Level 2 Certification Kit gives you everything assessors will ask for: SSP, POA&M, and all 12 domain policies. Start building your evidence package now.

View the Certification Kit - $299

Frequently Asked Questions

A C3PAO (Certified Third-Party Assessment Organization) is authorized by the Cyber AB to conduct official CMMC Level 2 assessments that result in certification. An RPO (Registered Practitioner Organization) is authorized to provide CMMC consulting and preparation services but cannot conduct official assessments. If you need an official CMMC Level 2 certification, you need a C3PAO - an RPO cannot provide that, no matter how qualified their consultants are.
C3PAO assessment costs vary significantly by organization size, scope complexity, and the specific C3PAO. Published estimates range from $30,000 to over $100,000 for a full CMMC Level 2 assessment. Larger organizations with more complex CUI environments and more systems in scope pay more. This cost estimate was a central factor in the DoD's decision to suspend Phase 2 - the aggregate cost for 100,000+ contractors was estimated at over $7 billion annually.
Check the Cyber AB marketplace at cybermarketplace.com. The Cyber AB maintains the authoritative list of authorized C3PAOs. An organization that claims to be a C3PAO but is not listed there is not authorized to conduct Level 2 assessments. Do not rely on an organization's own marketing claims.
Most C3PAOs do not provide pre-assessment consulting to organizations they also assess, to avoid conflicts of interest. Some Cyber AB guidance discourages C3PAOs from providing consulting and assessment to the same organization. If you want help preparing, engage an RPO for consulting - then hire a separate C3PAO for the actual assessment.
Not necessarily. During the Phase 2 pause (as of July 2026), mandatory C3PAO assessments are not required for most contracts. CMMC Phase 1 (Level 1 and the Level 2 self-assessment track) remains active. When Phase 2 resumes - with whatever modifications the CMMC Reform Task Force recommends - C3PAO assessments will be required for Level 2 contractors. Check your specific contract requirements for any existing C3PAO assessment clauses.

Related Resources

🔒

Get the Free CMMC Level 2 Practice Checklist

All 110 NIST SP 800-171 practices organized by domain - formatted for assessment prep. Free PDF, instant access.