April 26, 2025
3
min read
OCD Tech

CMMC-AB Begins to Approve Third-Party Auditors

Editor
OCD Tech
Category
Cybersecurity
Date
April 26, 2025

The CMMC Accreditation Body (CMMC-AB) has approved just over 20 CMMC Third-Party Assessor Organizations (C3PAOs) and nearly 100 Provisional Assessors. While this development is a positive step towards getting organizations CMMC certified, it is not clear if the approved C3PAOs are currently performing CMMC certification assessments.

The Department of Defense (DoD) estimates that in 2021 only 15 DoD contracts will contain the requirement for a CMMC certification. The DoD believes that every prime contract is supported by 100 DoD contractors. This means in 2021, no less than 1,500 CMMC assessments need to be successfully completed. If all organizations who put in a bid for a contract with the CMMC requirement also need a CMMC, that demand will be far greater. If just five prime contractors bid on each of the 15 contracts containing the CMMC requirement, each of the 100 existing Provisional Assessors will need to complete at least 75 assessments this year to meet industry demand.

For organizations bidding on the 15 impacted contracts, there is currently no mechanism to be front-loaded for CMMC certification by C3PAOs. This can create a problem for those companies that would like to bid on a contract but have no way of knowing if they can achieve the certification at the time of contract award.

The approval of the initial 100 Provisional Assessors is certainly a step in the right direction getting the DIB CMMC certified, however, demand is sure to exceed supply in short order.

Have a CMMC Compliance Question? Contact Us. We Can Help!

Please enable JavaScript in your browser to complete this form.Name *FirstLastEmail *CompanyQuestions / CommentsComment Submit

Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

OCD Tech

25 BHOP, Suite 407, Braintree MA, 02184

844-623-8324

https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
SOC 2 ® Readiness Assessment
SOC 2 ®
SOC 3 ®
SOC for Cybersecurity ®
IT Advisory Services
IT Vulnerability Assessment
Penetration Testing
Privileged Access Management
Social Engineering
WISP
General IT Controls Review
IT Government Compliance Services
CMMC
DFARS Compliance
FTC Safeguards vCISO

Industries

Financial Services
Government
Enterprise
Auto Dealerships

CMMC-AB Begins to Approve Third-Party Auditors

By  
OCD Tech
January 19, 2021
3
min read
Share this post

The CMMC Accreditation Body (CMMC-AB) has approved just over 20 CMMC Third-Party Assessor Organizations (C3PAOs) and nearly 100 Provisional Assessors. While this development is a positive step towards getting organizations CMMC certified, it is not clear if the approved C3PAOs are currently performing CMMC certification assessments.

The Department of Defense (DoD) estimates that in 2021 only 15 DoD contracts will contain the requirement for a CMMC certification. The DoD believes that every prime contract is supported by 100 DoD contractors. This means in 2021, no less than 1,500 CMMC assessments need to be successfully completed. If all organizations who put in a bid for a contract with the CMMC requirement also need a CMMC, that demand will be far greater. If just five prime contractors bid on each of the 15 contracts containing the CMMC requirement, each of the 100 existing Provisional Assessors will need to complete at least 75 assessments this year to meet industry demand.

For organizations bidding on the 15 impacted contracts, there is currently no mechanism to be front-loaded for CMMC certification by C3PAOs. This can create a problem for those companies that would like to bid on a contract but have no way of knowing if they can achieve the certification at the time of contract award.

The approval of the initial 100 Provisional Assessors is certainly a step in the right direction getting the DIB CMMC certified, however, demand is sure to exceed supply in short order.

Have a CMMC Compliance Question? Contact Us. We Can Help!

Please enable JavaScript in your browser to complete this form.Name *FirstLastEmail *CompanyQuestions / CommentsComment Submit

Share this post
OCD Tech