A CMMC Third-Party Assessment Organization is not simply a cybersecurity vendor you hire; it is an entity the government has separately vetted, and its authorization has a defined scope, a defined lifespan, and defined limits. Those terms are set out in 32 C.F.R. §§ 170.8 and 170.9, the sections of the CMMC Program rule that govern the Accreditation Body and the C3PAOs it authorizes. Reading them turns assessor selection from a procurement guess into a checklist.
"Authorized" and "Accredited" Are Not the Same Word
The rule creates two distinct states, and marketing material frequently blurs them. Before the Accreditation Body itself achieves full ISO/IEC 17011:2017(E) compliance, it may authorize C3PAOs that meet the § 170.9 requirements to conduct Level 2 certification assessments and issue Certificates of CMMC Status. Separately, it accredits qualifying C3PAOs in accordance with ISO/IEC 17020:2012(E). A C3PAO must "achieve and maintain compliance with ISO/IEC 17020:2012(E) ... within 27 months of authorization."
So an authorized-but-not-yet-accredited C3PAO is operating lawfully — but it is inside a clock. If you are selecting an assessor for a multi-year relationship, when that 27-month window opened is a fair question to ask, and the answer is knowable: § 170.8(b)(8) requires the Accreditation Body to maintain "an up-to-date list of authorized and accredited C3PAOs on a single publicly accessible website," and § 170.8(b)(9) requires it to give the CMMC Program Management Office the dates associated with each C3PAO's authorization and accreditation. The public list is the record you check — not the firm's own website.
What the Government Already Vetted
Three of the § 170.9 requirements amount to a government screening of the assessor, and they are worth understanding because they explain both cost and scheduling.
Personnel. Every C3PAO employee participating in the Level 2 certification assessment process — the Assessment Team and the quality assurance individual — must complete a Tier 3 background investigation resulting in a determination of national security eligibility, initiated on Standard Form 86. The rule is explicit that this "will not result in a security clearance and is not being executed for the purpose of government employment." Personnel not eligible for a Tier 3 investigation must meet a DoD-determined equivalent.
Foreign ownership. A C3PAO must submit SF 328, Certificate Pertaining to Foreign Interests, to DCSA on request and undergo a National Security Review under the FOCI factors and procedures at 32 C.F.R. § 117.11(b) and (c). It must receive a non-disqualifying eligibility determination from the CMMC PMO before it can proceed to its own assessment, must report any SF 328 change within 15 business days, and a later disqualifying determination "will result in the C3PAO losing its authorization or accreditation."
The assessor gets assessed. Under § 170.9(b)(6), a C3PAO must itself undergo a Level 2 certification assessment meeting all requirements for a Final Level 2 (C3PAO) — conducted by DCMA DIBCAC, not by another C3PAO — though it does not receive a CMMC Status or a certificate for it. The Accreditation Body's parallel obligation under § 170.8(b)(6) is to repeat that process every three years.
The Conflict Line Contractors Trip Over
The rule bars a member of the CMMC ecosystem from participating in a Level 2 certification assessment for an organization it "previously served as a consultant to prepare ... for any CMMC assessment within 3 years." That is a three-year look-back, and it is the single most common structural problem in assessor selection: the firm that ran your readiness engagement, wrote your System Security Plan, or remediated your gaps is disqualified from certifying the result. Separating the readiness partner from the assessor early avoids discovering the conflict after you have paid a deposit.
The same policy framework requires ecosystem members to "represent themselves and their companies accurately," including not misrepresenting CMMC authorization status or exaggerating the services they are authorized to deliver. An assessor claiming accreditation it has not achieved is not merely puffery — it is a reportable Code of Professional Conduct issue, and the Accreditation Body must notify DoD of new investigations in writing within 72 hours and report outcomes within 15 business days.
Team Composition, Certificates, and Appeals
Three practical details from § 170.9 that contractors should confirm in the engagement letter:
Team size. An Assessment Team must include at least two people — a Lead CCA and at least one other CCA. Additional CCAs and CCPs may participate.
Quality assurance. The individual performing quality assurance must be a CCA and cannot be a member of the Assessment Team being reviewed. A one-person "QA" review by a team member does not satisfy the rule.
What the certificate says. A Certificate of CMMC Status must include, at minimum, all industry CAGE codes associated with the information systems within the assessment scope, the C3PAO name, the assessment unique identifier, the organization's name, and the CMMC Status date and level. If your certificate omits a CAGE code you expected covered, your assessment scope — not the paperwork — is what needs revisiting.
Appeals. Appeals arising from assessment activities go to the C3PAO first; if either the contractor or the C3PAO is unsatisfied, the matter may be elevated to the Accreditation Body for final determination. C3PAOs must also retain assessment records for six years, which is worth knowing if a dispute or a government inquiry surfaces well after the engagement ends.
Why This Still Matters During the Reform Review
The Department of War suspended the Phase 2 transition in July 2026 and stood up a reform task force, and the shape of third-party assessment is genuinely under review — we covered that suspension and its scope. But 32 C.F.R. Part 170 remains codified, existing certifications remain valid on their terms, and contractors pursuing or maintaining a Level 2 certification are still selecting assessors today. Whatever the task force recommends, the diligence questions above — is this firm on the public list, authorized or accredited, and free of a three-year consulting conflict with us — will survive the redesign in some form.
For where third-party assessment fits among your other obligations, start with Find My Requirements and the frameworks reference; to sequence the work, see Build a Program.
Key Takeaways
- Check the Accreditation Body's public list, not the vendor's brochure. The rule requires a single publicly accessible list of authorized and accredited C3PAOs, and requires authorization and accreditation dates to be reported to the CMMC PMO — so "authorized" versus "accredited," and when the 27-month ISO/IEC 17020 clock started, are verifiable facts.
- Your readiness consultant cannot be your assessor. The three-year look-back on CMMC consulting work disqualifies the firm that prepared you from certifying you. Decide the split before you sign anything.
- Read the certificate against your scope. The certificate must name every CAGE code tied to the assessed systems, the assessment unique identifier, and the status date and level — and the C3PAO must keep the underlying records for six years.