Skip to main content

DEFENSE & CMMC

What Is C3PAO (CMMC Third-Party Assessment Organization)?

DEFINITION

A C3PAO (CMMC Third-Party Assessment Organization) is a company accredited under the CMMC ecosystem to conduct CMMC Level 2 certification assessments of defense contractors. C3PAO assessments were the centerpiece of CMMC Phase 2, which the Department of Defense suspended in July 2026 pending a Reform Task Force review, leaving self-assessments, SPRS scores, and affirmations as the operative requirements for now.

A C3PAO is an independent assessment firm authorized within the CMMC ecosystem, accredited through the CMMC Accreditation Body (the Cyber AB), to perform Level 2 certification assessments. In a certification assessment, the C3PAO's certified assessors examine evidence, interview staff, and test controls to verify that a contractor has implemented the 110 requirements of NIST SP 800-171 within its defined assessment scope. A passing assessment results in a CMMC status recorded in DoD systems; a conditional status is possible when remaining gaps are limited to requirements eligible for a POA&M.

C3PAO assessments matter to contractors whose contracts specify CMMC Level 2 with a certification assessment rather than a self-assessment, which the DoD has indicated will cover much of the CUI-handling supply chain over the program's phase-in.

The current status is important to state precisely. In July 2026, DoD memoranda suspended Phase 2, the phase that would have made C3PAO certification assessments a condition of new awards, pending a Reform Task Force review of the program. Phase 1 obligations continue unchanged. The prudent posture is to treat the suspension as schedule relief, not requirement relief: the underlying NIST SP 800-171 obligations under DFARS 252.204-7012 never paused. See CMMC Level 2 requirements for small business for what an assessment-ready posture looks like.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →