The Cybersecurity Maturity Model Certification (CMMC) program is now a regulatory requirement. Defense contractors handling Controlled Unclassified Information (CUI) must pass formal third-party assessments. Those assessments can only be conducted by certified individuals working under an authorized C3PAO. If you want to be one of them, here’s exactly what the path looks like.
What a CMMC Assessor Actually Does
A CMMC Certified Assessor (CCA) evaluates defense contractors against the 110 security requirements in NIST SP 800-171. The assessment procedures are based on NIST SP 800-171A. Per 32 CFR §170, CCAs work only as part of a C3PAO’s official assessment team. They cannot operate independently or sign off on assessments outside that structure.
Every CMMC Level 2 certification assessment requires a Lead CCA, a CCA, and a third CCA in a quality assurance role. The Department of Defense projects that 76,598 organizations will need a Level 2 certification assessment every three years. That’s roughly 25,532 assessments annually during the rollout. The demand for qualified assessors is real, and it’s growing.
The Two-Step Certification Path To Become a CMMC Assessor
To become a CMMC assessor, you need to earn the CMMC Certified Assessor (CCA) credential through ISACA, the authorized CAICO for the program. The path has two stages. First, earn the prerequisite CMMC Certified Professional (CCP) certification by completing a course with an Approved Training Provider, passing the CCP exam, and obtaining a favorable DoD Tier 3 background investigation. Then move to the CCA itself.
According to the Cyber AB, the CCA requires an active CCP, three years of cybersecurity experience, one year of audit or assessment experience, and a baseline certification aligned to DoD Manual 8140.3 Work Role 612 (Security Control Assessor).
You must also complete CCA training through an Approved Training Provider, pass the CCA exam, hold US citizenship, and maintain a favorable DoD suitability determination. Once certified, you can conduct CMMC Level 2 assessments as part of a C3PAO assessment team. You cannot assess any organization you previously consulted for.
Step 1: Earn the CMMC Certified Professional (CCP)
The CCP is the foundation. Recommended preparation includes a college degree in a cyber or IT field, or at least two years of related experience. You should also have CompTIA A+ certification or equivalent knowledge. Complete the DoD Mandatory Controlled Unclassified Information (CUI) Training before applying.
To get the CCP credential, you must:
- Apply and stay in good standing with the CAICO (ISACA).
- Sign all required agreements and pay the application and renewal fees.
- Complete a CCP course through an Approved Training Provider (ATP).
- Pass the CCP examination.
- Obtain a favorable Tier 3 background investigation determination from the DoD.
The CCP fee structure is $200 registration plus a $275 exam fee. Annual renewal is $250. Once you upgrade to CCA, you renew only the CCA credential going forward.
A CCP with a favorable Tier 3 determination can participate in a Level 2 assessment, but only to verify Level 1 practices. CCPs cannot make final assessment determinations. That authority belongs to a CCA or Lead CCA.
Step 2: Earn the CMMC Certified Assessor (CCA)
Once your CCP is active, you can begin the CCA process. The requirements are more demanding because the role carries final assessment authority. Per the Cyber AB and 32 CFR §170.11, you must:
- Hold an active CCP certification.
- Have a favorable DoD Tier 3 background investigation determination.
- Apply through CAICO, sign the agreements, and pay the fees.
- Complete a CCA course from an Approved Training Provider.
- Pass the CCA examination.
- Have at least three years of cybersecurity experience.
- Have at least one year of audit or assessment experience.
- Hold a baseline certification aligned to DoD Manual 8140.3, Work Role 612.
CCA fees are $50 registration plus $350 for the exam. Annual renewal is $500. US citizenship is required for the CCA. You must also have or obtain a favorable DoD Suitability Determination, or hold a DoD-accepted clearance, to participate on assessment teams.
The DoD 8140 Baseline Certification Requirement
This is where many candidates get tripped up. You need one industry certification mapped to DoD Cyber Workforce Framework Work Role 612, Security Control Assessor, at the Intermediate or Advanced proficiency level.
Per the Cyber AB’s published list (as of September 2025), accepted certifications include:
Intermediate Proficiency Level:
- CompTIA SecurityX (formerly CASP+)
- (ISC)² CGRC (formerly CAP)
- CompTIA Cloud+
- CompTIA PenTest+
- CompTIA Security+
- GIAC GCSA
- GIAC GSEC
- Federal IT Security Institute FITSP-A
- Mile2 CISSO
Advanced Proficiency Level:
- (ISC)² CISSP
- (ISC)² CISSP-ISSEP
- ISACA CISA
- ISACA CISM
- EC-Council CCISO
- CompTIA CySA+
- GIAC GSLC
- GIAC GSNA
The DoD updates this list periodically. Always confirm current requirements against the DoD Cyber Exchange Work Role 612 page before investing in training.
The Background Investigation
A favorable Tier 3 determination is non-negotiable for both CCP and CCA. The investigation is conducted in accordance with DoD standards. If you already hold a valid clearance through DoD-accepted means (such as a National Agency Check), that may satisfy the requirement. Plan for this early. Investigations take time, and you cannot work on assessment teams without one.
How to Get the Required Experience
The three-year cybersecurity experience requirement is straightforward. Most candidates already have it through prior roles in security engineering, GRC, SOC operations, or IT security management. The one-year audit or assessment experience requirement is the harder gap to close for many practitioners.
Useful sources of audit experience include:
- Performing internal NIST SP 800-171 self-assessments
- Working on SOC 2, ISO 27001, or PCI DSS audits
- Supporting RMF assessments under NIST SP 800-37
- Conducting vulnerability assessments and security control reviews
Document this experience clearly. The CAICO will request evidence as part of your application.
Choosing an Approved Training Provider
Training must come from an Approved Training Provider listed on the Cyber AB Marketplace. ATPs deliver the official CCP and CCA curricula. Look for instructors with field experience as practicing assessors, not just academic credentials. Pricing varies, but expect to invest several thousand dollars across both courses.
Where the Job Takes You
Once certified, you’ll be listed on the CMMC Marketplace and can work as part of a C3PAO assessment team. You cannot assess organizations you’ve previously consulted for. That conflict-of-interest rule is strict. Many CCAs split their work between formal assessments and pre-assessment consulting for organizations not yet ready for certification.
The next step up is Lead CCA, which requires additional documented experience in assessment. Lead CCAs run assessment teams and carry primary responsibility for the engagement.
A Realistic Timeline
If you’re starting from scratch with a strong cybersecurity background:
- Months 1 to 3: Earn a qualifying 8140 baseline certification if you don’t already have one.
- Months 3 to 4: Complete CCP training and pass the CCP exam.
- Months 4 to 9: Submit your Tier 3 background investigation package. Wait for adjudication.
- Months 9 to 11: Complete CCA training and pass the CCA exam.
- Month 11 onward: Apply to join a C3PAO assessment team.
Candidates without the audit experience or 8140 baseline cert should add several months to that timeline. Application submissions expire after one year, so don’t apply until you’re ready to complete the process.
Apply Through ISACA
ISACA now handles all CCP, CCA, Lead CCA, and CCI registrations on behalf of the Cyber AB. Start your application at isaca.org/cmmc. Verify current requirements on the Cyber AB Assessing and Certification page before paying any fees.
The CMMC ecosystem needs qualified assessors. If you have the cybersecurity background, the audit experience, and the discipline to work through a multi-stage certification process, this is one of the most stable career paths in defense cybersecurity right now.



