April 26, 2025
3
min read
Michael Hammond

C3PAO

Editor
Michael Hammond
Category
Cybersecurity
Date
April 26, 2025

OCD Tech, the IT Audit & Security division of O’Connor & Drew P.C., a Braintree MA CPA firm has been selected as a Candidate Cybersecurity Maturity Model Certification (CMMC) Third-Party Assessor Organization (C3PAO) by the CMMC Accreditation Body. Only C3PAOs are authorized to conduct CMMC assessments.  While OCD Tech has the Candidate C3PAO designation, until the DoD performs their own Level 3 audit of our firm, we cannot conduct the assessment as an Authorized C3PAO for the Organization Seeking Certification (OSC).   As of this writing, no C3PAOs are currently authorized to perform this level of work.

“I’m proud of everything the team here has done to get us ready for this important step in the rollout of the framework.  Especially all the work Kate Upton, IT Security Analyst, put in to make sure OCD Tech was ready to meet the strict requirements for this designation,” OCD Tech Partner Michael Hammond said. 

Definitions from the AB

  • Applicant C3PAO - Companies that have APPLIED to be a C3PAO, but has not yet been cleared by the CMMC AB
  • Candidate C3PAO - Companies that are CLEARED by the AB, and sent to DOD for CMMC Assessment scheduling
  • Authorized C3PAO - Companies that have successfully completed a CMMC ML3 assessment
  • Accredited C3PAO - Companies that have successfully completed the ISO 17020 Audit by the CMMC AB

About OCD Tech

OCD Tech is the IT Audit & Security division of O’Connor & Drew, P.C., a licensed CPA firm. The company has been providing assurance and advisory services for over 70 years. The IT Audit division provides assurance on SOC2, ISO 27001, other regulatory IT frameworks, including C3PAO for the CMMC framework. OCD Tech is headquartered in Braintree Massachusetts.  For more information about OCD Tech’s CMMC related services, visit ocd-tech.com/cmmc

Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

OCD Tech

25 BHOP, Suite 407, Braintree MA, 02184

844-623-8324

https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
SOC 2 ® Readiness Assessment
SOC 2 ®
SOC 3 ®
SOC for Cybersecurity ®
IT Advisory Services
IT Vulnerability Assessment
Penetration Testing
Privileged Access Management
Social Engineering
WISP
General IT Controls Review
IT Government Compliance Services
CMMC
DFARS Compliance
FTC Safeguards vCISO

Industries

Financial Services
Government
Enterprise
Auto Dealerships

C3PAO

By  
Michael Hammond
April 30, 2021
3
min read
Share this post

OCD Tech, the IT Audit & Security division of O’Connor & Drew P.C., a Braintree MA CPA firm has been selected as a Candidate Cybersecurity Maturity Model Certification (CMMC) Third-Party Assessor Organization (C3PAO) by the CMMC Accreditation Body. Only C3PAOs are authorized to conduct CMMC assessments.  While OCD Tech has the Candidate C3PAO designation, until the DoD performs their own Level 3 audit of our firm, we cannot conduct the assessment as an Authorized C3PAO for the Organization Seeking Certification (OSC).   As of this writing, no C3PAOs are currently authorized to perform this level of work.

“I’m proud of everything the team here has done to get us ready for this important step in the rollout of the framework.  Especially all the work Kate Upton, IT Security Analyst, put in to make sure OCD Tech was ready to meet the strict requirements for this designation,” OCD Tech Partner Michael Hammond said. 

Definitions from the AB

  • Applicant C3PAO - Companies that have APPLIED to be a C3PAO, but has not yet been cleared by the CMMC AB
  • Candidate C3PAO - Companies that are CLEARED by the AB, and sent to DOD for CMMC Assessment scheduling
  • Authorized C3PAO - Companies that have successfully completed a CMMC ML3 assessment
  • Accredited C3PAO - Companies that have successfully completed the ISO 17020 Audit by the CMMC AB

About OCD Tech

OCD Tech is the IT Audit & Security division of O’Connor & Drew, P.C., a licensed CPA firm. The company has been providing assurance and advisory services for over 70 years. The IT Audit division provides assurance on SOC2, ISO 27001, other regulatory IT frameworks, including C3PAO for the CMMC framework. OCD Tech is headquartered in Braintree Massachusetts.  For more information about OCD Tech’s CMMC related services, visit ocd-tech.com/cmmc

Share this post
Michael Hammond