The CMMC ecosystem's assessor-side credentials and the certifying body are defined in 32 CFR Part 170. The full ecosystem is summarized in the CMMC 101 (Nov 2025) brief.
The three credentials at a glance
| Credential | 32 CFR section | Role | What they do on a CMMC Level 2 certification engagement |
|---|---|---|---|
| CCP — CMMC Certified Professional | § 170.11 | Foundation credential | Supports assessment activities, often used for pre-assessment work, evidence review, and audit-team support roles. |
| CCA — CMMC Certified Assessor | § 170.12 | Working assessor | Performs per-practice assessment work, applies the Examine/Interview/Test methods, makes MET/NOT MET determinations against assessment objectives. |
| CCI — CMMC Certified Instructor | § 170.13 | Instructor | Teaches CMMC training to candidate CCPs and CCAs. Not a member of an assessment team in the assessor capacity. |
| Lead Assessor | n/a (additional qualification on top of CCA) | Team lead | Plans the assessment, leads team coordination, owns the final assessment report, signs off on the C3PAO's findings. |
The certification body: ISACA, the named CAICO
Per 32 CFR § 170.10, the Cybersecurity Assessor and Instructor Certification Organization (CAICO) is responsible for certifying CCPs, CCAs, and CCIs under ISO/IEC 17024. ISACA — the global IT governance, security, and audit professional association — has been named by the DoW as the CAICO for the CMMC program. ISACA defines the knowledge areas required for each credential, develops and administers the exams, and conducts quality control on training curriculum across the CMMC ecosystem.
For the authoritative source on credential prerequisites, exam content, scheduling, costs, and continuing-education requirements, visit ISACA's CMMC credentialing page: https://www.isaca.org/credentialing/cmmc.
How the credentials map to a real assessment team
A typical CMMC Level 2 certification team:
- 1 Lead Assessor — plans the engagement, leads the team, owns the final report.
- 1-2 CCAs — perform the per-practice work alongside the Lead Assessor.
- Sometimes a CCP — supports pre-assessment scoping, document review, evidence checking.
The team is employed by the C3PAO; the OSC contracts with the C3PAO, not with individual assessors.
What the credentials don't tell you
- The credentials don't measure sector experience. A CCA new to your DIB sector may meet the credential requirement but lack practical context. Ask about past engagements similar to yours.
- The credentials don't guarantee Lead Assessor capacity. Ask the C3PAO who specifically will lead your engagement, and confirm their availability against your timeline.
- The credentials don't speak to platform expertise. A CCA with credentials may not have deep GCC High or AWS GovCloud experience. If you're on either, ask explicitly.
Common errors
- Engaging an organization that isn't a C3PAO. Individual CCPs and CCAs cannot conduct certification assessments — only an accredited C3PAO can.
- Assuming any CCA can be the Lead. Lead Assessor is a separate qualification.
- Treating credentials as the only criterion. Sector and platform experience matter as much as credential level on real engagements.