CMMC ANSWER ENGINE

What's the difference between a CCP, CCA, and Lead Assessor?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14

The CMMC ecosystem's assessor-side credentials and the certifying body are defined in 32 CFR Part 170. The full ecosystem is summarized in the CMMC 101 (Nov 2025) brief.

The three credentials at a glance

Credential32 CFR sectionRoleWhat they do on a CMMC Level 2 certification engagement
CCP — CMMC Certified Professional§ 170.11Foundation credentialSupports assessment activities, often used for pre-assessment work, evidence review, and audit-team support roles.
CCA — CMMC Certified Assessor§ 170.12Working assessorPerforms per-practice assessment work, applies the Examine/Interview/Test methods, makes MET/NOT MET determinations against assessment objectives.
CCI — CMMC Certified Instructor§ 170.13InstructorTeaches CMMC training to candidate CCPs and CCAs. Not a member of an assessment team in the assessor capacity.
Lead Assessorn/a (additional qualification on top of CCA)Team leadPlans the assessment, leads team coordination, owns the final assessment report, signs off on the C3PAO's findings.

The certification body: ISACA, the named CAICO

Per 32 CFR § 170.10, the Cybersecurity Assessor and Instructor Certification Organization (CAICO) is responsible for certifying CCPs, CCAs, and CCIs under ISO/IEC 17024. ISACA — the global IT governance, security, and audit professional association — has been named by the DoW as the CAICO for the CMMC program. ISACA defines the knowledge areas required for each credential, develops and administers the exams, and conducts quality control on training curriculum across the CMMC ecosystem.

For the authoritative source on credential prerequisites, exam content, scheduling, costs, and continuing-education requirements, visit ISACA's CMMC credentialing page: https://www.isaca.org/credentialing/cmmc.

How the credentials map to a real assessment team

A typical CMMC Level 2 certification team:

  • 1 Lead Assessor — plans the engagement, leads the team, owns the final report.
  • 1-2 CCAs — perform the per-practice work alongside the Lead Assessor.
  • Sometimes a CCP — supports pre-assessment scoping, document review, evidence checking.

The team is employed by the C3PAO; the OSC contracts with the C3PAO, not with individual assessors.

What the credentials don't tell you

  • The credentials don't measure sector experience. A CCA new to your DIB sector may meet the credential requirement but lack practical context. Ask about past engagements similar to yours.
  • The credentials don't guarantee Lead Assessor capacity. Ask the C3PAO who specifically will lead your engagement, and confirm their availability against your timeline.
  • The credentials don't speak to platform expertise. A CCA with credentials may not have deep GCC High or AWS GovCloud experience. If you're on either, ask explicitly.

Common errors

  • Engaging an organization that isn't a C3PAO. Individual CCPs and CCAs cannot conduct certification assessments — only an accredited C3PAO can.
  • Assuming any CCA can be the Lead. Lead Assessor is a separate qualification.
  • Treating credentials as the only criterion. Sector and platform experience matter as much as credential level on real engagements.

Sources

  • 32 CFR Part 170 — §§ 170.10 (CAICO), 170.11 (CCP), 170.12 (CCA), 170.13 (CCI) — link
  • ISACA — CMMC Credentialing (named CAICO for the CMMC program) — link
  • CMMC 101 Brief (Nov 2025) — CMMC Ecosystem — link
  • Cyber AB Marketplace — link
Rulebook version: CMMC 2.0 Final Rule (32 CFR 170); CMMC 101 Nov 2025 brief
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.