Learn about CyberAB, Lead Assessor, CCA, CCP, Provisional Assessor, RPO, RP, RPA, difference between an RPO and a C3PAO, and more, through the Frequently Asked Questions (FAQs) below. If you are looking for certified CMMC Professionals and a customized solution for your organization, please schedule a free consultation.
Table of Contents
What is the Cyber AB (CMMC Accreditation Body) and what is its role?
The Cyber AB, headquartered in Washington, D.C., is the nonprofit organization officially designated by the DoD to manage the CMMC assessor ecosystem, authorizing, training, credentialing, and overseeing C3PAOs, Registered Practitioner Organizations (RPOs), individual assessors, and training providers who operate within the CMMC program.
The Cyber AB’s core functions include: authorizing C3PAOs to conduct CMMC Level 2 assessments; credentialing Certified CMMC Assessors (CCAs), Certified CMMC Professionals (CCPs), Provisional Assessors (PAs), Registered Practitioners (RPs), and Registered Practitioner Advisors (RPAs); maintaining the Cyber AB Marketplace as the authoritative directory of all authorized CMMC ecosystem entities; overseeing quality and ethics compliance within the ecosystem; and developing training curricula and standards for all credential levels.
The Cyber AB operates under a memorandum of understanding with the DoD and is the single authoritative source for confirming whether any entity claiming CMMC credentials is legitimately authorized. Contractors can access the Cyber AB Marketplace at cyberab.org to verify credentials and find service providers.
What is a Certified CMMC Assessor (CCA) and what are they authorized to do?
A Certified CMMC Assessor (CCA) is an individual credentialed by the Cyber AB who has completed required CMMC training, passed the CCA examination, and met background check requirements, and who is authorized to lead CMMC Level 2 certification assessments as a member of a C3PAO assessment team.
CCAs are the licensed professionals who conduct the actual CMMC assessment work on behalf of a C3PAO. They lead the Examine, Interview, and Test evaluation activities across all 110 NIST SP 800-171 Rev 2 controls and 320 assessment objectives, determine MET and NOT MET findings, and compile the assessment report submitted to eMASS. A CCA must be formally affiliated with an authorized C3PAO, they cannot conduct CMMC assessments independently.
CCAs are subject to strict independence requirements: a CCA who has provided consulting or advisory services to an organization cannot participate in that organization’s assessment. The Cyber AB tracks CCA credentials and compliance status; individuals with revoked or lapsed credentials cannot legally conduct CMMC assessments.
What is a Certified CMMC Professional (CCP) and what are they authorized to do?
Summary: A Certified CMMC Professional (CCP) is a Cyber AB-credentialed individual who has completed CMMC training and passed the CCP examination, and who is authorized to participate as a non-lead member of a C3PAO assessment team and to provide CMMC consulting and advisory services to organizations seeking compliance.
CCPs serve dual functions in the CMMC ecosystem. In an assessment context, they support Certified CMMC Assessors (CCAs) on assessment teams, conducting portions of the Examine, Interview, and Test activities under CCA supervision but not serving as the assessment lead. In a consulting context, CCPs can provide advisory services, gap analyses, SSP development, remediation planning, and compliance program management, for organizations preparing for CMMC certification.
The CCP examination spans approximately 3.5 hours with 170 multiple-choice questions, and candidates must score 500 or higher (on a 200–800 scale) to pass. A CCP who has provided consulting services to an organization cannot participate in that same organization’s C3PAO assessment due to independence requirements. CCPs must be affiliated with either an RPO for consulting work or a C3PAO for assessment work, they cannot operate independently as unaffiliated CMMC professionals.
What is a Lead Assessor (LA) and how do they differ from a CCA?
A Lead Assessor (LA) in the CMMC ecosystem is a highly credentialed individual, typically a senior CCA, who has been authorized by the Cyber AB to lead complex CMMC assessments, mentor other assessors, and in some contexts participate in quality review of assessment findings submitted to eMASS.
The Lead Assessor designation represents the top tier of individual assessor credentialing in the CMMC program. While all CCAs can lead Level 2 assessments, LAs have typically demonstrated additional experience, completed advanced training, and may hold subject matter authority in specific domains or technical environments. In the assessment team structure, the LA serves as the team lead ultimately responsible for the quality, accuracy, and completeness of the assessment findings submitted to eMASS.
Organizations undergoing complex assessments, large enterprises with multiple locations, contractors with sophisticated cloud environments, or those with extensive ESP arrangements, benefit from a C3PAO that assigns a Lead Assessor rather than a standard CCA, as the LA’s additional experience and quality oversight typically results in more accurate and defensible assessment outcomes.
What is a Provisional Assessor (PA) in the CMMC ecosystem?
A Provisional Assessor (PA) is a Cyber AB-credentialed individual who has met interim credentialing requirements established during the early phases of the CMMC program, allowing them to participate in assessment activities while working toward full Certified CMMC Assessor (CCA) credentialing status.
The PA credential was created by the Cyber AB to address the acute shortage of fully credentialed CCAs during the initial CMMC program rollout, allowing individuals who had completed required training but not yet passed the full CCA examination to participate in assessment teams under CCA supervision. PAs can perform specific assessment activities assigned by the assessment team lead but cannot independently lead assessments or serve as the primary signatory on assessment findings submitted to eMASS.
The PA credential is intended as a transitional status, PAs are expected to progress to CCA credentialing. Defense contractors selecting a C3PAO should confirm the credentials of the specific assessment team proposed for their engagement. An assessment team composed primarily of PAs without experienced CCA oversight may carry higher risk of finding inconsistencies or requiring rework.
What is a Registered Practitioner Organization (RPO)?
A Registered Practitioner Organization (RPO) is an organization authorized by the Cyber AB that employs or contracts with Registered Practitioners (RPs) and/or Registered Practitioner Advisors (RPAs) to provide CMMC compliance consulting, advisory, and implementation services to defense contractors preparing for certification, but that is not authorized to conduct formal CMMC certification assessments.
RPOs occupy a critical position in the CMMC ecosystem: they are the organizations that defense contractors engage to prepare for certification. RPO services include conducting gap analyses against NIST SP 800-171 Rev 2, developing System Security Plans (SSPs), implementing security controls, preparing policy and procedure documentation, providing security awareness training, conducting mock assessments, and managing the overall compliance program.
RPOs are subject to Cyber AB oversight and code of conduct requirements. Because RPOs provide consulting services rather than certification services, they can work more closely with contractors over time without the independence constraints that restrict C3PAOs. RPOs and C3PAOs must be separate organizations for the same contractor’s preparation and assessment, the same entity cannot serve both roles. Databrackets operates as both an authorized RPO and an authorized C3PAO, maintaining strict separation between these roles for individual client engagements in full compliance with 32 CFR Part 170 independence requirements.
What is a Registered Practitioner (RP) and what services can they provide?
A Registered Practitioner (RP) is a Cyber AB-credentialed individual who has completed required CMMC training, passed the RP examination, and met code of conduct requirements, and who is authorized to provide CMMC compliance advisory and consulting services to defense contractors on behalf of a Registered Practitioner Organization (RPO).
RPs are the primary delivery personnel for RPO consulting engagements. Their authorized services include: conducting gap analyses against NIST SP 800-171 Rev 2 and CMMC requirements; advising on security control implementation strategies; developing System Security Plans (SSPs), policies, and procedures; assisting with SPRS score calculations and submissions; providing compliance roadmap guidance; and supporting audit preparation activities.
RPs are not authorized to conduct formal CMMC certification assessments, that function belongs exclusively to CCAs within authorized C3PAOs. An RP can provide substantive advisory support throughout an organization’s entire compliance journey, including right up to the point where the C3PAO assessment begins. When an RP engages with an organization in a consulting capacity, neither the RP nor their affiliated RPO can then participate in or conduct the formal certification assessment for that organization.
What is a Registered Practitioner Advisor (RPA)?
A Registered Practitioner Advisor (RPA) is a senior-level Cyber AB-credentialed individual who has demonstrated expertise in CMMC and cybersecurity policy and is authorized to provide CMMC advisory services at a strategic level, including program design, policy development, and senior leadership guidance for defense contractors and their RPO engagements.
The RPA credential represents a senior advisory tier within the RPO ecosystem. RPAs typically possess extensive cybersecurity backgrounds, often including CISSP, CISA, CISM, or equivalent certifications, and may hold the Certified CMMC Assessor (CCA) credential in addition to the RPA designation. In practice, RPAs often serve in senior advisory roles for complex, multi-site, or enterprise-scale CMMC programs, providing strategic direction and technical oversight to the RPO team.
Like RPs, RPAs are prohibited from participating in the formal certification assessment for any organization to which they have provided substantive consulting services. The RPA credential is particularly relevant when evaluating the seniority and expertise of an RPO’s leadership, organizations should seek RPOs whose senior advisors hold both deep technical credentials and current Cyber AB credentialing.
What is the difference between an RPO and a C3PAO?
Summary: An RPO (Registered Practitioner Organization) provides CMMC compliance consulting and preparation services to help defense contractors implement security controls and prepare for certification, while a C3PAO (Certified Third-Party Assessment Organization) independently assesses whether those controls are actually implemented and issues the formal CMMC Level 2 certification, the two roles are mutually exclusive for the same contractor at the same time.
The clearest way to understand the distinction is: the RPO is your coach, the C3PAO is the referee. The RPO helps build your compliance program, close gaps, develop documentation, and prepare for the assessment. The C3PAO independently evaluates your program against the CMMC standard and issues a finding.
Due to the independence requirement in 32 CFR Part 170, the same organization cannot play both roles for the same contractor. If an organization approaches you offering to both prepare you and certify you, this violates CMMC program rules and would produce an invalid certification. Contractors must maintain two separate relationships: one with an RPO for preparation support and one with a C3PAO for the certification assessment. The RPO and C3PAO can share no organizational affiliation in the contractor’s engagement.
Can the same organization provide CMMC compliance consulting and conduct the certification assessment?
Summary: The same organization cannot legally provide CMMC compliance consulting services and conduct the certification assessment for the same contractor. This independence requirement is codified in 32 CFR Part 170 and enforced by the Cyber AB to ensure that assessors evaluate work objectively rather than validating their own prior recommendations.
The prohibition is categorical: if an organization provided substantive CMMC advisory services, including gap analysis, SSP development, control implementation guidance, mock assessments, or remediation planning, to a contractor, that same organization cannot conduct the formal C3PAO certification assessment for that contractor. This applies to the organization as a whole, not just to individual personnel.
Violations of this rule can result in the Cyber AB invalidating the assessment and revoking the C3PAO’s authorization. Defense contractors who receive offers from a single provider promising to both prepare them and certify them should decline and report the offer to the Cyber AB. The only legitimate offering is for a provider to do one or the other for a given client, not both.
What credentials and certifications should I look for when hiring a CMMC consultant or RPO?
Summary: When evaluating a CMMC consultant or RPO, the minimum credential requirement is a current Registered Practitioner (RP) or Registered Practitioner Advisor (RPA) designation listed in the Cyber AB Marketplace, supplemented by technical cybersecurity credentials such as CISSP, CISA, or CISM, and demonstrated experience in CMMC assessments and defense contracting environments.
Credential checklist for CMMC consultant selection: (1) Cyber AB Marketplace listing, verify the RPO appears as an Authorized RPO in the current Marketplace; (2) Individual RP/RPA credentials, confirm that the specific practitioners who will work on your engagement hold active RP, RPA, CCA, or CCP credentials in good standing; (3) Technical security credentials, CISSP, CISA, CISM, or equivalent; (4) Industry experience, defense contracting background, NIST SP 800-171 implementation experience, and familiarity with the specific DoD information types your organization handles.
Also evaluate: (5) References, verifiable references from defense contractors successfully guided through CMMC preparation; and (6) CMMC-specific assessment experience, practitioners who have participated in actual CMMC assessments as CCPs on C3PAO teams bring direct insight into what assessors evaluate. Be wary of consultants who cannot produce a current Cyber AB Marketplace listing, as unaffiliated practitioners operating without RPO authorization are not accountable to Cyber AB ethics and conduct standards.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties