C3PAO selection is the most consequential vendor decision in your CMMC journey. The accreditation requirement is set in 32 CFR § 170.9; only Cyber AB-accredited C3PAOs can conduct Level 2 certification assessments.
Where to find authorized C3PAOs
The single authoritative source is the Cyber AB Marketplace at cyberab.org/Catalog. The Marketplace lists every accredited C3PAO and their accreditation status. Anyone who is not on the Marketplace cannot lawfully issue a Level 2 (C3PAO) certification.
Selection criteria
| Criterion | What to ask |
|---|---|
| Sector experience | Has the C3PAO conducted assessments for organizations similar in size and DIB sector? Aerospace, manufacturing, IT services, etc., have different operating contexts. |
| Cloud and platform experience | If your CUI environment is in GCC High, does the C3PAO have direct GCC High experience? If you're using AWS GovCloud or Azure Government, the same. |
| Assessment team composition | Who will be the Lead Assessor on your engagement? What are their credentials? How many CCAs will support them? You want named individuals, not abstract "team" assignments. |
| Schedule availability | What is the realistic earliest assessment date? If your contract requires Final Level 2 (C3PAO) status by a date, the schedule must work backward from that — including the time needed for any closeout assessment. |
| Pricing transparency | Is the price fixed, time-and-materials, or scope-dependent? What does the price include (pre-assessment document review, on-site days, report production, POA&M closeout assessment within the 180-day window)? |
| References | Will the C3PAO connect you with two or three prior clients similar in scope to yours? |
| Scope methodology | Will they walk through your asset inventory, your network diagram, and your scoping decisions before signing the SOW? A C3PAO that signs without scope review is one that will find scoping problems mid-assessment. |
Engagement model
Per 32 CFR § 170.9, the C3PAO is contracted directly by the OSC. The C3PAO employs the Lead Assessor and CCAs (each certified by CAICO under § 170.11/12), submits the assessment report through CMMC eMASS, and issues the CMMC certificate.
Common errors
- Picking the cheapest C3PAO without scope review. A cheap engagement that surfaces a scoping mistake mid-assessment becomes the most expensive engagement.
- Engaging a C3PAO without experience in the kind of environment you have. Whether your CUI environment runs in GCC High, AWS GovCloud, Azure Government, an on-premises stack, an Infrastructure-as-Code-managed cloud, or a hybrid — the platform's nuances materially affect how an assessor evaluates implementations. Ask the C3PAO directly about their experience with assessments in environments like yours.
- Treating C3PAO selection as a procurement exercise. The Lead Assessor's judgment will determine your CMMC Status. Treat the selection as you would the selection of an outside auditor.
- Booking too late. Confirm scheduling availability with the C3PAO early — a contract with a near-term CMMC requirement and no booked C3PAO is already at risk.