• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us
cyber security

CMMC-AB Begins to Approve Third-Party Auditors

January 19, 2021 Posted by Kate Upton IT Security

The CMMC Accreditation Body (CMMC-AB) has approved just over 20 CMMC Third-Party Assessor Organizations (C3PAOs) and nearly 100 Provisional Assessors. While this development is a positive step towards getting organizations CMMC certified, it is not clear if the approved C3PAOs are currently performing CMMC certification assessments.

The Department of Defense (DoD) estimates that in 2021 only 15 DoD contracts will contain the requirement for a CMMC certification. The DoD believes that every prime contract is supported by 100 DoD contractors.  This means in 2021, no less than 1,500 CMMC assessments need to be successfully completed. If all organizations who put in a bid for a contract with the CMMC requirement also need a CMMC, that demand will be far greater. If just five prime contractors bid on each of the 15 contracts containing the CMMC requirement, each of the 100 existing Provisional Assessors will need to complete at least 75 assessments this year to meet industry demand.

For organizations bidding on the 15 impacted contracts, there is currently no mechanism to be front-loaded for CMMC certification by C3PAOs.  This can create a problem for those companies that would like to bid on a contract but have no way of knowing if they can achieve the certification at the time of contract award.

The approval of the initial 100 Provisional Assessors is certainly a step in the right direction getting the DIB CMMC certified, however, demand is sure to exceed supply in short order. 

Have a CMMC Compliance Question? Contact Us. We Can Help!

Tags: CMMC CertificationCMMC Readinessnist 800-171
Share
0
Kate Upton

About Kate Upton

Kate Upton is the IT Government Compliance Team Lead at OCD-Tech. Kate has been with the firm since May 2019. Before joining the firm, Kate received her Bachelor’s degree in Political Science & Legal Studies from the University of Maine and went on to earn a Master’s degree from Northeastern University in Strategic Intelligence. She dedicates her time at the firm to meeting the unique compliance needs of clients in the Defense Industrial Base with projects including CMMC, NIST 800-171, NIST 800-53, and DFARS rules. Kate lives in Portland, Maine with her dog Lucy.

You also might be interested in

DFARS Clause and NIST SP800-171 – Are You Covered?

Feb 27, 2017

Do you work with the Department of Defense (DoD)? Does[...]

DoD Rulemaking Update and Impact on Defense Contractors

DoD Rulemaking Update and Impact on Defense Contractors

Jan 18, 2023

DoD released its long-awaited Rulemaking Agenda for CMMC 2.0 last[...]

The CMMC DFARS Interim Rule Explained

The CMMC DFARS Interim Rule Explained

Jan 18, 2021

On September 30, 2020, the DoD revealed a new set of proposed clauses for the Defense Federal Acquisition Regulation Supplement-known as the DFARS-in an interim rule (DFARS Case 2019-D041).

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next