By The Defense Compliance Report Editorial Team · Last reviewed: August 2026 · Last verified: August 28, 2026
Educational research — not legal, contractual, employment, or compliance advice.
The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We are not affiliated with, endorsed by, or acting on behalf of the Cyber AB, ISACA/CAICO, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. We sell no training, and we earn nothing from any training provider or credentialing body named on this page.
CCP vs CCA certification is not a choice between two levels of the same credential. It's a choice between two different jobs. The CMMC Certified Professional (CCP) is the advisory credential — 32 CFR §170.13 defines the role around advice, consulting, and recommendations to client organizations. The CMMC Certified Assessor (CCA) is the assessment credential — §170.11 authorizes Level 2 certification assessment work in support of a C3PAO. Buy the CCP if you advise. Buy the CCA if you perform official assessments.
That's the short answer. Here's the part almost nobody has written down.
We read both sections of the rule line by line. The CCA section contains exactly four numbered requirements the CCP section does not: one CCA eligibility gate, two restrictions that control how assessment work is performed, and the Lead CCA qualification tier. The background investigation everyone assumes is the dividing line isn't one of them.
Then we read §170.9 and found the staffing rule that should change how you think about both credentials: a Level 2 certification assessment requires at least two CCAs on the Assessment Team, a separate CCA performing quality assurance, and zero required CCPs. That is three distinct CCA-credentialed people involved in completing one assessment — but it is not a three-person Assessment Team.
And one thing changes the buying case for everyone: on July 13, 2026, the Department of War suspended the planned CMMC Phase II transition. That paused Phase II’s planned expansion of Level 2 (C3PAO) requirements and its discretionary use of Level 3 requirements in applicable solicitations and contracts, which was set to begin November 10, 2026. Phase I self-assessments remain in force, and the underlying DFARS cybersecurity duties did not disappear.
We'll show you what each fact means before you spend the money.
Start here: which one fits your goal?
| Your situation | Buy | Why |
|---|---|---|
| You advise companies on getting assessment-ready | CCP | The rule defines the CCP around advice, consulting, and recommendations (32 CFR §170.13(a)) |
| You want to perform official Level 2 certification assessments | CCP, then CCA | CCAs conduct that work in support of a C3PAO, and CCP is a prerequisite (§170.11(a), (b)(6)) |
| You do not hold an active CCP yet | CCP | There is no route that skips it (§170.11(b)(6)) |
| You cannot identify a Work Role 612 qualification at Intermediate proficiency | CCP, and resolve that gate first | The 8140 qualification is required for the CCA, not the CCP |
| Your employer is paying and has a defined C3PAO role for you | CCA path | Reasonable — get the role, reimbursement, and timing in writing first |
| You are trying to get your own company certified | Neither | Training one person does not certify a business |
→ Skip to the full decision table (jump link — no signup)
What we actually verified for this comparison
Verified August 28, 2026. We read 32 CFR §170.11 (CCA), §170.13 (CCP), and §170.9(b)(12)–(13) (Assessment Team composition and quality assurance) in full on the federal eCFR, which displayed Title 32 as current through August 27, 2026. We checked the full CMMC Program Final Rule at 89 FR 83092; the instruction adding Part 170 appears on printed page 83214, with §170.1 continuing on page 83215. That is why both page numbers appear in CMMC citations. We also checked the current DFARS clauses, ISACA's CCP and CCA credential pages and exam outlines, the Cyber AB's CMMC Assessment Process and Marketplace requirements, the July 2026 Department memoranda, and the Cyber AB's July 15 ecosystem statement.
What we did not establish, and won't pretend to: salary figures for either credential, pass rates for either exam, an average Tier 3 adjudication time, a permanent list of accepted Work Role 612 qualifications, a universal start-to-certification timeline, or a reliable post-suspension hiring forecast.
⚠️ Are you a company, not a candidate?
If you landed here because your business received a CMMC requirement, you're in the right publication but the wrong article. Training an employee will not make your company compliant, and it will not substitute for an assessment.
Your solicitation or contract identifies the required CMMC level and assessment type. The provider category you need — a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave — then depends on whether you handle FCI or CUI, your current environment, your scope, and your deadline. Start with the CMMC levels explained and provider-category guide, or use Find My CMMC Path to map your situation before requesting quotes.
→ I need a provider for my company, not a credential — use Find My CMMC Path
Do not submit CUI, drawings, or sensitive contract details.
Everyone else — consultants, MSP and MSSP staff, DIB employees who just had CMMC added to their job description, auditors moving into federal work, veterans entering compliance — keep reading.
What's the difference between CCP and CCA certification?
The CCP (CMMC Certified Professional) is the foundational credential for advising organizations on CMMC readiness and participating on Level 2 certification assessment teams under CCA oversight. The CCA (CMMC Certified Assessor) authorizes an individual to conduct CMMC Level 2 certification assessments in support of a C3PAO and make assessment determinations. A CCP is a mandatory prerequisite for the CCA under 32 CFR §170.11(b)(6), so the two are sequential, not parallel.
Here is the part the sales pages blur. A CCP is not a junior CCA. It's a different role with different authority, aimed at different work, sold into a different market.
The regulation is unusually direct about this. Section 170.13(a) says a CCP completes training on CMMC and the assessment process “to provide advice, consulting, and recommendations” to OSA clients. That is a consulting job description written into federal regulation. Section 170.11(a) says CCAs, in support of a C3PAO, conduct Level 2 certification assessments using NIST SP 800-171A assessment procedures. That is an assessment job description.
Advisor and assessor. Two different professions that happen to share a body of knowledge.
| Comparison | CCP — CMMC Certified Professional | CCA — CMMC Certified Assessor |
|---|---|---|
| Governing section | 32 CFR §170.13 | 32 CFR §170.11 |
| What the rule authorizes | Advice, consulting, and recommendations to client organizations; participation on a Level 2 assessment team under CCA oversight | Conducting Level 2 certification assessments in support of a C3PAO; making assessment determinations |
| What it cannot do alone | Make final assessment determinations | Conduct an official certification assessment outside a C3PAO or issue a company certificate independently |
| Prerequisite credential | None in §170.13 | CCP — §170.11(b)(6); ISACA currently requires it to be active for CCA exam registration |
| Experience required by the regulation | None stated in §170.13 | At least 3 years cybersecurity plus at least 1 year assessment or audit |
| Current ISACA operational experience gate | Degree in a cyber or IT field, or 2+ years related education, or 2+ years related experience | Evidence supporting the regulatory CCA experience requirements |
| DoD 8140 Work Role 612 qualification | Not required by §170.13 | Required at Intermediate proficiency or higher |
| Tier 3 background investigation | Required — §170.13(b)(3) | Required — §170.11(b)(3), with the same operative language |
| Mandatory training | Yes, through an Approved Training Provider | Yes, through an Approved Training Provider |
| Exam | 170 questions, 6 domains | 150 questions, 4 domains |
| Exam fee | US$575 member / US$760 non-member | US$575 member / US$760 non-member |
| Application processing fee | US$200 | US$50 |
| Certification validity | 3 years | 3 years |
| Best fit | Readiness consultants, internal CMMC leads, MSP/MSSP staff, and candidates beginning the regulated path | Experienced cybersecurity and audit professionals with a real route to C3PAO assessment work |
Sources: 32 CFR §§170.11 and 170.13; current ISACA CCP and CCA credentialing and exam-outline pages. Fees and operational requirements were verified August 28, 2026 and can change.
Two more names you'll see, so they don't confuse you. Lead CCA (LCCA) is a qualification tier written into §170.11(b)(10); ISACA also presents LCCA within its credential ecosystem. The regulation requires five years of cybersecurity experience, five years of management experience, three years of assessment or audit experience, and a Work Role 612 qualification at Advanced proficiency. CCI is the instructor credential. Neither is the choice this page is resolving.
And a distinction that trips up a surprising number of people: a CCA is a person. A C3PAO is an organization. The authority to conduct the certification assessment and issue a Certificate of CMMC Status belongs to the C3PAO, not to an assessor acting alone.
The four requirements unique to the CCA section
Every numbered requirement listed for the CCP in 32 CFR §170.13(b) also appears in the CCA requirements at §170.11(b). The CCA section contains exactly four numbered requirements absent from the CCP section: the CCA eligibility gate, the C3PAO-equipment restriction, the breach-notification duty, and the Lead CCA qualification tier. The Tier 3 background investigation is required for both.
We built this by reading the two sections line by line. The result reframes the decision because it separates the actual regulatory delta from training-page shorthand.
| Requirement | CCP §170.13(b) | CCA §170.11(b) | Result |
|---|---|---|---|
| Obtain and maintain CAICO certification; valid 3 years | (1) | (1) | Same |
| Follow Accreditation Body conflict-of-interest, conduct, and ethics policies | (2) | (2) | Same |
| Complete Tier 3 investigation using SF-86; non-critical sensitive; “Moderate Risk” | (3) | (3) | Same operative language |
| Meet DoW-determined Tier 3 equivalent when ineligible for Tier 3 | (4) | (4) | Same in substance |
| Provide records and documentation in English | (5) | (5) | Same |
| Do not share OSC information outside that assessment except as required by law | (6) | (9) | Same |
| Be a CCP with ≥3 years cybersecurity, ≥1 year assessment/audit, and Work Role 612 at Intermediate | — | (6) | CCA only |
| Use the engaged C3PAO's IT, cloud, cybersecurity services, and endpoints for assessment activities; personal IT prohibited | — | (7) | CCA only |
| Immediately notify the responsible C3PAO of a breach or potential breach of assessment materials | — | (8) | CCA only |
| Lead CCA tier: ≥5 years cyber, ≥5 years management, ≥3 years assessment/audit, Work Role 612 at Advanced | — | (10) | CCA section only |
The CCA section adds one entry gate, two rules that control the work itself, and one higher qualification tier.
Five things fall out of that table that matter more than the table itself.
1. Tier 3 is required for both — and it is not what separates them
This is the single most repeated error on this topic. Many guides describe the Tier 3 background investigation as an assessor-only requirement. It isn't. Sections 170.13(b)(3) and 170.11(b)(3) use the same operative language: SF-86 initiation, non-critical-sensitive designation, “Moderate Risk,” no security clearance, and no government-employment purpose.
If you were hoping the CCP is the easy one because it skips the government paperwork — it doesn't. The least controllable gate in this process sits underneath both credentials.
2. Section 170.13 sets no experience minimum. None.
Read the CCP requirements again. There is no degree requirement, no years-of-experience floor, and no DoD 8140 requirement in §170.13.
That does not mean the current operational process has no experience gate. ISACA's CCP certification page currently requires a cyber/IT college degree, two or more years of related education, or two or more years of related experience. One layer is regulatory; the other is operational. Keep them straight, because they are controlled by different bodies and can change on different schedules.
The Work Role 612 requirement belongs to the CCA under §170.11(b)(6). It is not a CCP requirement in §170.13.
3. The device rule is a business-model decision, not a footnote
Section 170.11(b)(7) is the requirement almost nobody writes about, and it may be the most consequential one on the page for an independent consultant.
A CCA must use the IT, cloud services, cybersecurity services, and endpoint devices provided by the authorized or accredited C3PAO engaged for the assessment. Individual assessors are prohibited from using other IT — including personally owned devices and their own cloud services — to process, store, or transmit assessment reports or other CMMC assessment information. The regulation permits evaluation of evidence inside the OSC environment using OSC tools. It also requires the C3PAO-provided environment to be associated with a C3PAO that has undergone a DCMA DIBCAC Level 2 certification assessment or higher.
Translation: official assessment work happens through the C3PAO's controlled environment, under the C3PAO's terms. If your plan was to buy the CCA and run official assessments independently from your own laptop, the rule closes that door before you reach the exam. The CCP carries no equivalent device restriction.
4. The breach-notification duty is a real professional obligation
Section 170.11(b)(8) requires a CCA to immediately notify the responsible C3PAO of any breach or potential breach affecting CMMC assessment materials under the assessor's purview. There is no CCP equivalent. It's one line with a large implication: as a CCA, you are a custodian of another company's most sensitive assessment evidence, and the rule says so.
5. Neither section has been amended since December 16, 2024
As of our August 28, 2026 verification, the eCFR timeline for §170.11 and §170.13 showed the original December 16, 2024 effective-date entry and no later amendment to either section — including after the July 2026 Phase II suspension.
You can verify that yourself on the eCFR by opening either section and expanding the Timeline panel.
One honest limitation, before we go further
We can't tell you whether these two credentials will look the same eighteen months from now. The Department established a 60-day CMMC Reform Task Force on July 13, 2026, and the rule can be changed through the appropriate rulemaking process. Anyone who tells you the credential landscape is settled right now is guessing.
Here's why we'd still spend the money on the comparison, and probably on the CCP.
Of everything in this program, the credential sections have been among the most stable pieces. One eCFR effective-date entry each since December 2024. No amendment through a Phase II suspension that changed contracting instructions across the Department. The Cyber AB stated on July 15, 2026 that training, exams, professional certification, and voluntary C3PAO assessments remained operational.
The rules didn't move. The demand trigger did. Those are different problems, and only one of them is yours to solve today.
Not sure whether you clear the CCA gates? Do not start with a course checkout page. Start with the regulated sequence: active CCP, three years of cybersecurity experience, one year of assessment or audit experience, and a qualifying Work Role 612 credential at Intermediate proficiency.
→ Walk the complete CCA gate map before you pay
Do you need a CCP before a CCA?
Yes. 32 CFR §170.11(b)(6) requires a CCA to be a CCP, and ISACA currently requires an active CCP credential for CCA exam registration. There is no pathway that skips the CCP, and a discounted CCP-plus-CCA bundle does not change the sequence — it sells you both steps in order.
That's the whole answer. The order is set by federal regulation, not by a training vendor's curriculum.
Two practical notes. First, “active CCP” means certified — not merely “passed the CCP exam.” Those are different states, and we untangle them in the next section. Second, if you're already committed to the CCA path, the full sequence includes experience documentation, the 8140 qualification, application evidence, Tier 3, and an actual route to C3PAO work.
→ See the complete CCA requirements and step-by-step path
What each credential actually lets you do on an assessment team
Under 32 CFR §170.9(b)(12), a Level 2 certification Assessment Team must include at least two people: one Lead CCA and at least one other CCA. Section 170.9(b)(13) separately requires a quality-assurance function performed by a CCA who is not a member of the team being reviewed. Therefore, one assessment requires at least three distinct CCA-credentialed people to be involved — two on the Assessment Team and one outside it for quality assurance. CCPs are permitted, but none is required.
Read that carefully, because the distinction matters.
- 1 Lead CCA on the Assessment Team — required by §170.9(b)(12)
- + 1 additional CCA on the Assessment Team — required by §170.9(b)(12)
- + 1 separate quality-assurance CCA, who cannot sit on the team being reviewed — required by §170.9(b)(13)
- = 3 distinct CCA-credentialed people involved, minimum
- Assessment Team size required by the rule: 2 people minimum
- CCPs required: zero
If you are buying the CCP primarily to get onto assessment teams, understand what you're buying: a seat that the rule does not require a C3PAO to fill. A C3PAO must staff the two CCA team positions and a separate CCA quality-assurance function. It may add CCPs. It does not have to.
That sounds like bad news for the CCP. It isn't — it's the wrong frame. Go back to §170.13(a): the CCP role exists to provide advice, consulting, and recommendations. Assessment-team participation is permission, not the core purpose.
The CCP is an advisory credential that the rule permits on assessment teams. It is not an assessment credential with training wheels. Once you see it that way, the decision stops being “how high do I climb?” and starts being “which job do I actually want?”
This isn't theoretical — the DoD Inspector General audited the authorization process
DODIG-2025-056 was issued January 10, 2025. The DoD Office of Inspector General examined whether the DoD effectively implemented requirements for authorizing C3PAOs and found that the authorization process was not effectively implemented. Its recommendations addressed verification and quality-assurance controls in the ecosystem.
We're citing it for one reason: assessor staffing and quality-control qualifications are not decorative requirements. They are part of a federal oversight record. The report addressed authorization-process weaknesses at the time of the review; it was not a finding that every currently authorized C3PAO is noncompliant today.
What a legitimate CCP or CCA job should actually say
The two roles should produce visibly different job descriptions.
A CCP-oriented role should center on readiness: scope analysis, gap assessment, SSP and POA&M support, remediation planning, control implementation, self-assessment preparation, and advice to the client organization.
A CCA-oriented role should connect the candidate to a C3PAO and official Level 2 certification assessment work: assessment planning, evidence evaluation, NIST SP 800-171A procedures, CAP execution, findings, and assessment-team responsibilities.
If a posting calls the CCA an independent license to certify companies, it is wrong. If it still says the credential is issued by the Cyber AB without acknowledging ISACA's CAICO role, it may be stale. A job description is not a governing source, and it is a bad reason to make an expensive career decision without checking the current rule and issuer requirements yourself.
→ Compare your experience against the full CCA pathway
Exam eligible, credential eligible, work eligible: three different things
Passing a CMMC exam does not make you certified, and being certified does not assign you assessment work. There are three separate states — eligible to sit the exam, eligible to hold the credential, and positioned to perform the work — and buying training for a state you have not reached is how candidates waste money on this path.
This distinction is worth ninety seconds because it prevents two expensive mistakes on this path.
| State | What it means | What is still missing |
|---|---|---|
| Exam eligible | You completed mandatory training through an Approved Training Provider and entered the issuer's exam process. For the CCA, ISACA's current registration requirements also include an active CCP and an accepted 8140 qualification. | Exam, application, documented experience, fees, and Tier 3 or approved equivalent |
| Credential eligible | You passed, submitted the application and experience evidence, paid the application fee, accepted the ethics/CPE obligations, and received the required favorable Tier 3 determination or approved equivalent. | Nothing for certification itself — this is the active credential |
| Work positioned | You hold the credential and have a role that can use it. For official CCA work, that means a C3PAO engagement. For a public Cyber AB Marketplace listing, ISACA currently requires an active CCP, CCA, or LCCA plus completed Delta Training. | The credential qualifies you; it does not hire or assign you |
The Marketplace detail is a concrete commercial benefit of the CCP: an active credential plus Delta Training can support a public Cyber AB Marketplace listing. That gives a CCP a directory presence defense contractors can verify. It does not guarantee leads, employment, or revenue.
The trap runs the other direction. A candidate pays for CCA training before confirming the experience record or Work Role 612 qualification, then discovers the application gate after the money is gone. The course did not remove the gate. It only made the mistake more expensive.
CCP vs CCA exam: what's actually on each one?
The CCP exam has 170 questions across six job-practice domains; the CCA exam has 150 questions across four. The CCP's largest domain is CMMC model construct and implementation evaluation at 35%. The CCA's largest domain is assessing CMMC Level 2 practices at 40%. The most decision-relevant shift is from broad ecosystem and implementation knowledge toward formal Level 2 evidence judgment.
We pulled both official exam content outlines from ISACA on August 28, 2026 and converted the published percentages into approximate question counts.
| What's tested | CCP — 170 questions | CCA — 150 questions | The shift |
|---|---|---|---|
| CMMC Ecosystem | 5% ≈ 8–9 | Not a named domain | Dropped as a standalone domain |
| Code of Professional Conduct / Ethics | 5% ≈ 8–9 | Not a named domain | Tested explicitly at the foundation |
| CMMC Governance and Source Documents | 15% ≈ 25–26 | Not a named domain | Folded into assessor-level work rather than kept standalone |
| CMMC Model Construct and Implementation Evaluation | 35% ≈ 59–60 | — | Replaced by the two Level 2 rows below |
| Evaluating the OSC Against CMMC Level 2 | — | 15% ≈ 22–23 | New assessor domain |
| Assessing CMMC Level 2 Practices | — | 40% = 60 | Largest single domain in either exam |
| CMMC Assessment Process (CAP) | 25% ≈ 42–43 | 25% ≈ 37–38 | Same percentage; about five more raw questions on the CCP |
| Scoping | 15% ≈ 25–26; blueprint objective references FCI assets | 20% = 30; blueprint centers CUI assets | Same heading, different data and assessment stakes |
Source: ISACA CCP and CCA exam content outlines, verified August 28, 2026. Percentages are ISACA's; question counts are our arithmetic from the published totals.
Four findings are worth carrying into your study plan.
The CCP contains more CAP questions by raw count. CAP is weighted at 25% on both exams, but 25% of 170 is about 42 or 43 questions while 25% of 150 is about 37 or 38. That does not prove the CCP tests CAP “harder.” It means the foundational exam contains roughly five more CAP questions.
Scoping changes data type, not just weight. The CCP blueprint's scoping objective references FCI assets. The CCA blueprint asks candidates to analyze CUI scope using the Level 2 asset categories. Same heading. Different environment, different evidence, different consequences.
The CCP blueprint establishes a Level 1 practice floor; the CCA devotes 40% to Level 2 practice assessment. ISACA's CCP outline says candidates must, at minimum, be evaluated on CMMC Level 1 practices. That does not turn the entire CCP into a Level 1 exam. It does show why the CCA's sixty-question Level 2 practice domain is the clearer technical and judgment split.
Ethics is a named domain at the foundation. The Code of Professional Conduct is a standalone 5% CCP domain and is not a standalone CCA domain. The professional-conduct obligation still follows both credentials under the rule.
One practical note: as of our August 28, 2026 check, ISACA's CCP review manual, questions-and-explanations database, and online review course were listed as Coming Soon. Your Approved Training Provider's materials may therefore carry most of your preparation load. Ask exactly what is included before you pay.
Is the CCA harder? We won't tell you it is because no official pass rates were published for either exam, and fewer questions does not prove an easier test. What the blueprints do establish is that the CCA is narrower and more assessment-judgment-heavy: sixty of its 150 questions sit in the Level 2 practice-assessment domain.
CCP vs CCA cost in 2026: what you'll actually pay
The fixed, knowable fees are US$575 per exam for ISACA members or US$760 for non-members, a US$200 CCP application fee, a US$50 CCA application fee, and annual maintenance of US$45 per credential for members or US$85 for non-members. Mandatory Approved Training Provider training is separate, priced by the provider, and can become the largest variable line in the budget. Any page quoting one universal “all-in” CMMC credential cost is guessing.
Let's show cost reality now, because it should shape the decision rather than ambush it later.
The three-year administrative fee floor
These figures cover the published exam, application, and three annual maintenance fees over one three-year certification cycle. They exclude mandatory training, membership dues, retakes, travel, and your time.
| Scenario | Arithmetic | Three-year administrative floor |
|---|---|---|
| CCP only, non-member | $760 exam + $200 application + (3 × $85 maintenance) | $1,215 |
| CCP only, ISACA member | $575 exam + $200 application + (3 × $45 maintenance) | $910 + membership dues |
| CCP + CCA, non-member | (2 × $760 exams) + $200 + $50 applications + (6 × $85 maintenance) | $2,280 |
| CCP + CCA, ISACA member | (2 × $575 exams) + $200 + $50 applications + (6 × $45 maintenance) | $1,670 + membership dues |
Exam, application, and maintenance fees verified on ISACA's published pages August 28, 2026. Fees can change.
The membership break-even, computed so you can use it
Most pages tell you membership “might save money.” Here is the threshold.
- ISACA membership saves $185 per exam ($760 − $575)
- It saves $40 per credential, per year on maintenance ($85 − $45)
Over one three-year cycle:
- Holding one credential: $185 + (3 × $40) = $305 in fee savings
- Holding both credentials: (2 × $185) + (6 × $40) = $610 in fee savings
Membership pays for itself on these credential fees if your total membership and chapter dues over the same period are below $305 for the CCP alone, or below $610 if you plan to take both exams and maintain both credentials. Get the actual dues shown at checkout and compare them against those numbers.
What the fee floor does not include
Do not treat those totals as the full cost of certification. Excluded: mandatory ATP training, exam retakes, study materials, the cost of earning an accepted Work Role 612 qualification, travel for an in-person course, unbillable study time, and continuing professional education.
ISACA currently requires at least 20 CPE hours each year and 120 over each three-year reporting cycle for both CCP and CCA. Qualifying activity may count toward multiple ISACA credentials when it satisfies each credential's requirements, but you still have to document and report it correctly.
Also excluded, and worth naming: the CCA device rule means official assessment work runs through the engaged C3PAO's systems. That is not a personal equipment expense, but it is another reason the CCA is difficult to monetize without an employment or subcontract relationship.
Chosen your credential? The next decision is where to buy the training — and that's where the largest variable expense sits.
→ Compare current CCP and CCA training options and written fee terms
Is the Tier 3 background investigation a security clearance?
No. 32 CFR §170.11(b)(3) and §170.13(b)(3) both state that the Tier 3 background investigation will not result in a security clearance and is not being executed for government employment. It is a national-security-eligibility determination for the CMMC role, initiated with Standard Form 86 for a non-critical-sensitive position designated “Moderate Risk.”
Because the same operative language governs both credentials, this section applies whichever one you choose.
What it is: a background investigation initiated with SF-86 that produces an eligibility determination for the CMMC ecosystem role. The Department controls the eligibility determination; the result does not create classified access or federal employment.
What it isn't: a clearance for access to classified information. Do not describe yourself as cleared because you received a favorable CMMC Tier 3 determination.
Do you have to be a U.S. citizen? Neither §170.11 nor §170.13 creates a blanket citizenship bar. Both provide a path for a candidate who is not eligible for Tier 3 to meet a DoW-determined equivalent. That is not a promise that any particular foreign investigation will be accepted. The Department decides equivalence for CMMC purposes.
Can you train and test before Tier 3 completes? ISACA's CCA page states that Tier 3 does not have to be complete before CCA training or the exam. Its certification steps place the favorable determination before credential issuance. Do not confuse “exam taken” with “credential active,” and confirm the current account-level sequence before attaching money to a six-month exam window.
Which DoD 8140 Work Role 612 qualification counts for the CCA?
32 CFR §170.11(b)(6) requires a CCA to hold at least one foundational qualification aligned to at least the Intermediate proficiency level of the Security Control Assessor (612) Work Role in the DoD Cyberspace Workforce Framework under DoD Manual 8140.03. The Lead CCA tier requires Advanced proficiency under §170.11(b)(10). The CCP has no equivalent regulatory requirement.
This is an expensive gate to discover after buying the course.
Three things to get right:
It's 8140, not the retired 8570 baseline model. The current CCA rule points to DoD Manual 8140.03 and the DoD Cyberspace Workforce Framework. A guide built around old 8570 baseline lists is not a safe application source.
“Work role” is not a job title. Work Role 612 is the Security Control Assessor role in the DoD framework. Your business card does not satisfy it. The gate concerns an accepted qualification aligned to the required proficiency level.
The regulation and the issuer workflow are separate layers. The rule uses “foundational qualification” language. ISACA's current CCA registration process asks candidates to document a qualification accepted for Work Role 612 at the required level. Both layers have to be satisfied.
Our verification method is simple: check the current Work Role 612 qualification pathway on the DoD Cyber Exchange, check ISACA's current CCA registration instructions, and save a dated copy of both before relying on them.
We are deliberately not publishing a permanent “complete list” of accepted credentials. DoD and ISACA can update their operational materials. A copied list ages badly while continuing to look authoritative, and a stale list can cost a candidate a course fee and months of delay.
How long do you have to apply after passing the CCP or CCA exam?
ISACA's own public pages currently conflict. As of August 28, 2026, the step-by-step CCP and CCA application sections say candidates must apply within five years of passing. Lower on both certification pages, the requirements copy says candidates have two years. We are publishing the conflict instead of choosing a deadline the issuer has not presented consistently.
Picking the more convenient number is how someone misses an application window.
The application deadline. Treat the shorter published period as the risk boundary until ISACA resolves the copy or confirms your account-specific deadline in writing. Check MyISACA, save the displayed date, and retain the confirmation.
Active CCP versus Tier 3 sequencing. ISACA's CCA registration guidance requires an active CCP for CCA exam registration. Its CCA page also says candidates do not need Tier 3 before CCA training or the exam. The public copy does not explain how that statement interacts with §170.13(b)(3), which requires Tier 3 for the CCP credential itself. There may be account-level or transition sequencing that the public pages do not show. Confirm the live gate in MyISACA before you pay.
That's not an accusation. Program transitions produce exactly this kind of drift. ISACA was authorized as the CAICO in December 2025, with credentialing services transitioning by April 1, 2026. What matters is that you do not build an expensive plan on one sentence when another section of the issuer's own page says something different.
Does the July 2026 CMMC suspension change which one you should buy?
Yes — it changes the case for the CCA far more than the case for the CCP. On July 13, 2026, the Department of War suspended the CMMC Phase II transition that was scheduled for November 10, 2026. Phase I began November 10, 2025 and was originally scheduled to run through November 9, 2026. The suspension paused Phase II’s planned expansion of Level 2 (C3PAO) requirements and its discretionary use of Level 3 requirements, while Phase I self-assessment requirements and the underlying DFARS cybersecurity obligations remained.
The precise distinction matters: the suspension changed the government demand trigger for official assessment work. It did not erase the CMMC rule, NIST SP 800-171 duties, SPRS scoring, incident reporting, or the voluntary assessment ecosystem.
What actually happened
The Department's July 13 implementation memorandum directed program managers and requiring activities to use only CMMC Level 1 (Self) or Level 2 (Self) designations during the suspension. It directed amendments removing Level 2 (C3PAO) and Level 3 requirements from active solicitations. For existing contracts or agreements that already contain those requirements, contracting officers were directed to remove them by modification before the next option exercise or during the next scheduled administrative modification.
That last sentence matters. An existing clause does not disappear by magic on the date of a press release; the memorandum supplies a modification path.
The Department also established a 60-day reform review. The public RFI closed August 14, 2026. As of this page's August 28, 2026 verification date, the Department had not published the Task Force's final recommendations.
What did not change
32 CFR Part 170 remains in force. The suspension did not rescind the CMMC Program Rule.
CMMC Level 2 still uses NIST SP 800-171 Revision 2. The current rule incorporates the 110 Rev. 2 security requirements across 14 families. NIST withdrew Rev. 2 in May 2024 and superseded it with Revision 3, but Revision 3 does not control CMMC Level 2 under the current rule. DoW would have to amend the governing CMMC rule before treating Rev. 3 as the CMMC Level 2 control set.
The same version-control issue exists at Level 3. Part 170 identifies selected requirements from the February 2021 NIST SP 800-172. NIST withdrew that publication on May 13, 2026 and superseded it with SP 800-172 Rev. 3, but the CMMC rule still names the February 2021 version unless and until the Department changes the rule.
The DFARS clauses still do different jobs:
- DFARS 252.204-7012 requires safeguarding covered defense information and rapid cyber-incident reporting — “rapidly report” means within 72 hours of discovery.
- DFARS 252.204-7019 requires an offeror, when applicable, to have a current NIST SP 800-171 DoD Assessment and verify that the summary score is posted in SPRS.
- DFARS 252.204-7020 governs the assessment process, government access for Medium or High assessments, SPRS score handling, and subcontractor assessment obligations.
- DFARS 252.204-7021 governs CMMC status, annual affirmation, SPRS records, and flowdown when the CMMC clause is included.
Do not collapse those into “7012 requires an SPRS score.” The clauses work together, but they are not interchangeable.
The ecosystem remains operational. The Cyber AB stated on July 15 that voluntary C3PAO Level 2 assessments, CAICO training, professional exams, Registered Practitioner services, and DIBCAC assessments of C3PAOs remained available.
The suspension is not a universal prohibition on every private demand for certification. The Department instructed its procurement chain not to designate new Level 2 C3PAO or Level 3 requirements during the review and supplied a path to modify existing contracts. A prime contractor, teaming partner, customer, or corporate risk decision may still create voluntary or private demand. That is different from a Department-wide condition of award.
The asymmetry nobody had named
Put the two credentials against that picture and they land in different places.
| Decision factor | CCA | CCP |
|---|---|---|
| Core work | Formal Level 2 certification assessment work through a C3PAO | Readiness, advice, implementation support, and permitted assessment-team participation under CCA oversight |
| Effect of July 13 suspension | The scheduled government-wide Phase II demand trigger was suspended | The underlying readiness and self-assessment workload continued, but no contract clause requires a contractor to hire a CCP specifically |
| Still usable? | Yes — voluntary assessments and non-government demand can continue | Yes — advisory and readiness work continues wherever organizations need it |
| What the suspension did not create | A guaranteed assessor job | A regulatory monopoly on readiness work |
Our editorial read, stated as an editorial read: the suspension weakened the near-term demand case for buying the CCA on speculation. It did not erase the CCA role. If you already have a named C3PAO route, the credential may still make sense. If you are buying because someone promised a universal assessor shortage, the premise changed underneath the sales pitch.
The official ecosystem snapshot — and what it cannot tell you
The Cyber AB's July 15, 2026 statement reported:
- More than 1,000 CCAs
- 110 authorized C3PAOs
- More than 2,000 CCPs
- 52 Approved Training Providers
- Nearly 2,000 defense contractors with Final Level 2 status
Those are post-suspension official ecosystem counts. They replace the stale pre-suspension counts that still circulate in training content.
They do not tell you how many assessors are available for hire, how many are fully utilized, how many assessments one Lead CCA can oversee, or what your employment odds are. The CMMC Assessment Process permits a Lead CCA to oversee multiple Assessment Teams across concurrent assessments, while §170.9 requires the quality-assurance CCA to remain off the team being reviewed. That is why dividing the total number of CCAs by three does not produce a valid national concurrency ceiling.
The Department's July 13 release emphasized cost, barriers to entry, and the need to review the scheduled transition. The Cyber AB's July 15 statement emphasized the size and continued operation of the ecosystem. Those claims answer different institutional questions. Neither one is a personal job offer.
Where does that leave your timeline? Track what the Department has actually published, not what a training ad predicts.
→ Check the current CMMC Phase II review status
Which one should you buy?
Most candidates choosing between these two today should start with the CCP. It is required for the CCA anyway, the regulation ties it directly to advisory work, and an active credential plus Delta Training can support a Cyber AB Marketplace listing. The CCA is the right next purchase when you already clear the experience and Work Role 612 gates and have a specific route to assessment work through a C3PAO.
Find yourself in this table.
| You are… | Buy | Why | Your first step |
|---|---|---|---|
| A solo readiness consultant, or an RP today | CCP | §170.13(a) describes the advisory work and the credential can support a Marketplace listing | Confirm the ATP's current status and written terms |
| An MSP or MSSP owner credentialing staff | CCP for selected staff | Your revenue is readiness and managed compliance, not issuing assessment certificates | Credential the people who will actually use it |
| A DIB employee just handed CMMC as a duty | CCP | You need source-document and assessment-process fluency more than formal assessor authority | Ask the employer to fund it |
| An auditor with audit years but thin cybersecurity years | CCP now, CCA later | The three-year cybersecurity minimum is a hard CCA gate | Document security responsibilities, not just audit titles |
| A security engineer with cyber years but no assessment/audit year | CCP now | Implementing a control is not the same as assessing one under the rule | Build documented assessment or audit experience |
| Already passed the CCP exam and weighing CCA training | Finish the CCP first | “Passed” is not “active,” and active CCP is the current CCA registration gate | Complete the CCP application and Tier 3 sequence |
| A C3PAO employee directed to earn the CCA | CCA path | Your employer has a defined use for the credential and must staff CCA roles plus separate quality assurance | Get the reimbursement and work assignment in writing |
| A career changer with no cybersecurity foundation | Neither yet | No course substitutes for the CCA experience gates or basic security competence | Build the foundation before buying the credential |
| A business owner trying to certify the company | Neither | An individual credential does not certify an organization | Use Find My CMMC Path |
Don't buy anything until you know your first unmet gate
Before you open a checkout page, answer four questions:
- Do I want advisory work or official C3PAO assessment work?
- Do I already hold an active CCP?
- Can I document three years of cybersecurity and one year of assessment or audit experience?
- Can I identify a current Work Role 612 qualification at Intermediate proficiency that ISACA will accept?
Your first “no” is the next problem to solve. Paying for a later step does not remove it.
→ Walk the full CCA gate sequence
→ Compare current CCP and CCA training options
Who should not buy either credential right now
Neither the CCP nor the CCA is a good purchase for someone financing it on a demand forecast, someone without a security foundation hoping a course will substitute for experience, or someone whose actual problem is getting a company certified. Naming that plainly will save more people money than any discount code.
We'd rather lose you here than take you somewhere expensive that doesn't fit. Five groups should walk away today:
If you're a complete beginner. Neither credential is a substitute for foundational cybersecurity knowledge. The Registered Practitioner designation is a separate ecosystem path, not a prerequisite and not a replacement for security competence. → Start with how the provider categories work
If you're buying because someone promised an automatic assessor shortage windfall. The November 10, 2026 Phase II catalyst was suspended, and an ecosystem count is not a hiring forecast. Buy only when the role still makes sense without the sales projection. → Track the review status
If you cannot identify your Work Role 612 qualification. That is your first CCA gate, not the course. → Walk the full CCA gate map
If your real goal is certifying your business. Training one employee is not organizational compliance and does not replace a C3PAO assessment where one is required. → Use Find My CMMC Path
If you plan to consult for a client and then assess that same organization. Section 170.8(b)(17) bars an ecosystem member from participating in a Level 2 certification assessment for an organization the member helped prepare for a CMMC assessment within the previous three years. Readiness help and formal assessment have to stay separate. → See how assessment independence works
What we verified, what we couldn't, and how we work
This comparison separates three kinds of claims: regulatory facts tied to primary sources, current operational facts carrying a verification date, and editorial judgments derived from the two. That separation is the discipline of an independent trade publication on CMMC and DIB compliance, and it is why we tell you where our confidence stops.
Primary regulatory sources read for this review: 32 CFR §170.9, §170.11, §170.13, and §170.8(b)(17); the full CMMC Program Final Rule at 89 FR 83092; the current DFARS 252.204-7012, -7019, -7020, and -7021 text; NIST's publication records for SP 800-171 Rev. 2 and Rev. 3 and SP 800-172; the Cyber AB CMMC Assessment Process; and DODIG-2025-056.
Current operational facts verified August 28, 2026: ISACA's published exam and application fees; 170 CCP questions across six domains; 150 CCA questions across four domains; mandatory ATP training; six-month exam eligibility; 20 annual and 120 three-year CPE requirements; annual maintenance fees; Marketplace listing prerequisites; the conflicting two-year and five-year application language; and the CCP preparation products marked Coming Soon.
Current phase facts verified August 28, 2026: Phase I began November 10, 2025; Phase II was originally scheduled for November 10, 2026; the Department suspended that transition on July 13, 2026; active solicitations and existing contracts follow different amendment instructions; and the Cyber AB published a July 15 post-suspension ecosystem snapshot.
What we could not establish: salaries, pass rates, average Tier 3 duration, a permanent accepted-qualification list for Work Role 612, a universal completion timeline, or your likelihood of receiving paid assessment work.
Editorial judgments, labeled as such: that the suspension changes the CCA buying case more than the CCP buying case; that most undecided candidates should start with the CCP; and the persona recommendations in the decision table. We showed the facts underneath each so you can disagree intelligently.
Who wrote this: The Defense Compliance Report Editorial Team. We do not sell CMMC training and earn nothing from ISACA, the Cyber AB, or any Approved Training Provider named or linked on this page.
More on our process: Editorial Standards · Methodology · Corrections Policy · Editorial & Advertising Policy
Disclosure: The Defense Compliance Report may receive compensation for qualified introductions, sponsorships, or partner referrals where disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. This credential comparison routes to no paid training provider and carries no training-provider compensation.
CCP vs CCA certification: frequently asked questions
Who issues CCP and CCA certification now — ISACA or the Cyber AB?
ISACA administers professional CMMC credentialing as the CAICO, including CCP, CCA, Lead CCA, and CCI functions. ISACA was authorized in December 2025, with services transitioning by April 1, 2026. The Cyber AB remains the Accreditation Body, authorizes or accredits C3PAOs, and operates the Cyber AB Marketplace. Material that still describes the Cyber AB as the current professional credential issuer may be stale.
Can I skip the CCP and go straight to the CCA?
No. 32 CFR §170.11(b)(6) requires a CCA to be a CCP, and ISACA currently requires an active CCP for CCA exam registration. A bundled course does not change the sequence.
Can a CCP conduct a CMMC assessment?
A CCP may participate on a Level 2 certification Assessment Team with CCA oversight, where the CCA makes final determinations (32 CFR §170.13(a)). A CCP cannot make those determinations. Section 170.9(b)(12) requires a Lead CCA and at least one other CCA on the team; CCPs may participate, but none is required.
Does the CCP require a background investigation?
Yes. Section 170.13(b)(3) requires a Tier 3 background investigation resulting in a national-security-eligibility determination. Section 170.11(b)(3) applies the same operative requirement to the CCA. Tier 3 is not what separates the credentials.
Does a Tier 3 investigation give me a security clearance?
No. Both sections state that it will not result in a security clearance and is not being executed for government employment.
Do I have to be a U.S. citizen to earn a CCP or CCA?
Neither section imposes a blanket citizenship bar. Both provide for a DoW-determined equivalent when a candidate is not eligible for Tier 3. That does not guarantee that a particular foreign investigation will be accepted. Confirm the current process with ISACA before paying.
What's the difference between a CCA and a C3PAO?
A CCA is an individual credential. A C3PAO is an organization authorized or accredited by the Cyber AB to conduct Level 2 certification assessments and issue Certificates of CMMC Status. A CCA performs assessment work in support of a C3PAO and cannot certify a company independently.
How much do the CCP and CCA exams cost?
Each exam is US$575 for ISACA members and US$760 for non-members, verified August 28, 2026. The application processing fee is US$200 for the CCP and US$50 for the CCA. Mandatory ATP training is separate.
Can I self-study and skip the training course?
No. Both credentials require mandatory training through an Approved Training Provider. An unapproved course may teach useful material, but it does not satisfy the issuer's mandatory training gate.
Does passing the exam make me certified?
No. Passing is one gate. Certification also requires the application, documented experience where applicable, the processing fee, ethics and CPE commitments, and the required favorable Tier 3 determination or approved equivalent.
Do I need to become a Registered Practitioner before the CCP?
No. RP is a separate Cyber AB designation. It is not a prerequisite in the CCP or CCA path.
How long does it take to go from CCP to CCA?
There is no defensible universal answer. The timeline is set by your slowest unmet gate: active CCP status, documented experience, Work Role 612 qualification, Tier 3, the exam process, and a route to C3PAO work.
Is the CCP still worth it after the July 2026 Phase II suspension?
For candidates doing readiness and advisory work, the case is less affected than the CCA case because Phase I self-assessments and the underlying DFARS work continue. But no contract clause requires a company to hire a CCP specifically. The value still depends on whether clients or an employer recognize and use the credential.
Does NIST SP 800-171 Revision 3 control CMMC Level 2 now?
No. NIST has superseded Rev. 2 with Rev. 3 in its own publication catalog, but the current CMMC rule still incorporates NIST SP 800-171 Rev. 2 for Level 2. Rev. 3 does not become the CMMC-controlling version unless the Department amends the rule.
Does either credential certify my company?
No. Both are individual professional credentials. Organizational CMMC status is a separate process involving the required self-assessment, C3PAO assessment, or DIBCAC assessment type. Use Find My CMMC Path rather than buying a course to solve a company-assessment problem.
How long do I have to apply after passing the exam?
ISACA's current CCP and CCA pages conflict: the step-by-step application copy says five years, while lower requirements copy says two years. Verify the operative deadline in MyISACA and retain written confirmation. Do not plan around the longer number merely because it is more convenient.
Your next step depends on your first unmet gate
- No active CCP yet, and readiness is your work → start with the CCP path and verify the ATP in the Cyber AB Marketplace
- CCA is the goal, but experience or 8140 status is uncertain → walk the full CCA gate map before you pay
- Credential chosen, now comparing courses → compare current training options and written fee terms
- Verifying an ATP, CCA, or C3PAO → use the Cyber AB Marketplace verification guide
- Waiting to see what the Department changes → track the CMMC Phase II review
If you're here for your company, not your career
Start with the CMMC readiness checklist, understand who to hire first, and compare the real cost categories before requesting quotes.
Need help deciding what type of CMMC provider you need? Tell us your level, scope, and timeline, and we'll route you to source-checked provider categories.
Do not submit CUI, drawings, or sensitive contract details.
This is educational research, not legal, contractual, employment, or compliance advice. Confirm credential and application requirements with ISACA/CAICO, confirm Marketplace and Tier 3 workflow with the Cyber AB, and confirm contract-specific obligations with a qualified federal-contracts attorney or an appropriate CMMC professional. Your solicitation, contract clauses, assessment scope, and handling of FCI or CUI control the actual requirement — not a generic checklist.
Primary sources
- 32 CFR §170.3 — Applicability and phased implementation
- 32 CFR §170.9 — CMMC Third-Party Assessment Organizations — Assessment Team composition at (b)(12), quality assurance at (b)(13)
- 32 CFR §170.11 — CMMC Certified Assessor
- 32 CFR §170.13 — CMMC Certified Professional
- 32 CFR §170.8 — Accreditation Body — three-year conflict rule at (b)(17)
- CMMC Program Final Rule — 89 FR 83092, October 15, 2024
- CMMC acquisition final rule — 90 FR 43560, effective November 10, 2025
- Department of War — July 13, 2026 Phase II suspension release
- Department of War — Implementing Suspension of CMMC Phase II memorandum
- SAM.gov — Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base
- DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7019 — Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7021 — CMMC Level Requirements
- NIST SP 800-171 Rev. 2 — withdrawn by NIST but still incorporated into the current CMMC rule
- NIST SP 800-171 Rev. 3 — NIST's successor publication, not the current CMMC Level 2 control set
- NIST SP 800-171A, June 2018 — assessment procedures referenced by §170.11
- NIST SP 800-172, February 2021 — version identified by the current CMMC rule for selected Level 3 requirements
- NIST SP 800-172 Rev. 3 — NIST’s successor publication, not the version currently incorporated into CMMC Level 3
- DoD Manual 8140.03 — Cyberspace Workforce Qualification and Management Program
- DoD Cyber Exchange — Security Control Assessor, Work Role 612
- ISACA — CCP credential, fees, and certification steps
- ISACA — How to get CCP certified
- ISACA — CCP exam content outline
- ISACA — Maintain CCP certification
- ISACA — CCA credential
- ISACA — How to get CCA certified
- ISACA — CCA exam content outline
- ISACA — Maintain CCA certification
- Cyber AB — CMMC Assessment Process, Version 2.0
- Cyber AB Marketplace
- Cyber AB — official July 15, 2026 statement on the Phase II suspension, distributed via Business Wire
- DoD Office of Inspector General — DODIG-2025-056
Regulatory and current operational claims on this page were verified August 28, 2026. Program phases, issuer workflows, fees, and credential requirements can change. We update the visible verification date only after re-checking the underlying sources.
