Editor
Michael Hammond
Category
Cybersecurity
Date
April 26, 2025

As of today, January 26, 2020, there is no possible way to get CMMC certified; no way to get a CMMC audit. The CMMC Accreditation Body (CMMC-AB https://www.cmmcab.org/) has not created nor released the requirements or training for audit firms to begin the certification process. Beware of shady firms saying they can perform the audit now. Or worse, perform the audit now and then once the rules are released, immediately issue the certification. The CMMC-AB is building the C3PAO accreditation process with formal adoption and approval by the CMMC AB in the coming months.  No C3PAOs are yet formally designated nor accredited by the CMMC-AB.

What you can do is get ready for the certification by performing readiness assessments against the most recent CMMC standards, currently draft v0.7. https://www.acq.osd.mil/cmmc/index.html

It is expected that RFP's in Sept 2020 will indicate what CMMC level will be required for bid. With the amount of time it will take to become compliant, never-mind that NIST 800-171 was required back in 2017, there is no time to wait. Get compliant today and certified as soon as the board releases the information for creating C3PAOs.

Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

OCD Tech

25 BHOP, Suite 407, Braintree MA, 02184

844-623-8324

https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
SOC 2 ® Readiness Assessment
SOC 2 ®
SOC 3 ®
SOC for Cybersecurity ®
IT Advisory Services
IT Vulnerability Assessment
Penetration Testing
Privileged Access Management
Social Engineering
WISP
General IT Controls Review
IT Government Compliance Services
CMMC
DFARS Compliance
FTC Safeguards vCISO

Industries

Financial Services
Government
Enterprise
Auto Dealerships

You cannot get a CMMC audit. There are no CMMC auditors, yet

By  
Michael Hammond
January 26, 2020
8
min read
Share this post

As of today, January 26, 2020, there is no possible way to get CMMC certified; no way to get a CMMC audit. The CMMC Accreditation Body (CMMC-AB https://www.cmmcab.org/) has not created nor released the requirements or training for audit firms to begin the certification process. Beware of shady firms saying they can perform the audit now. Or worse, perform the audit now and then once the rules are released, immediately issue the certification. The CMMC-AB is building the C3PAO accreditation process with formal adoption and approval by the CMMC AB in the coming months.  No C3PAOs are yet formally designated nor accredited by the CMMC-AB.

What you can do is get ready for the certification by performing readiness assessments against the most recent CMMC standards, currently draft v0.7. https://www.acq.osd.mil/cmmc/index.html

It is expected that RFP's in Sept 2020 will indicate what CMMC level will be required for bid. With the amount of time it will take to become compliant, never-mind that NIST 800-171 was required back in 2017, there is no time to wait. Get compliant today and certified as soon as the board releases the information for creating C3PAOs.

Share this post
Michael Hammond