By The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Last verified: August 28, 2026
How to become a CCP in 2026: verify eligibility, complete official ATP training, pass the ISACA exam, apply for certification, and satisfy Tier 3 or the applicable equivalent—without confusing an exam pass with an active credential.
Program status strip: Current credential administrator: ISACA, authorized as the CAICO in December 2025; CAICO services fully transitioned in April 2026 · CMMC Phase 1 began November 10, 2025 and remains the active implementation phase · CMMC Phase 2 was suspended July 13, 2026, with pending and future implementation milestones held in abeyance
The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We are not affiliated with the Cyber AB, ISACA, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. We sell no training, we run no exam prep, and we earn nothing from any training provider mentioned or linked on this page.
Here is how to become a CCP in 2026, in one paragraph.
Confirm you can document ISACA's certification eligibility. Complete mandatory CMMC Certified Professional training through a current Approved Training Provider. Pass the 170-question CCP exam through PSI, which costs $575 for ISACA members and $760 for non-members. Pay a $200 application processing fee. Submit your education or experience evidence. Then obtain a positively adjudicated Tier 3 background investigation. Your certification is valid for three years under 32 CFR § 170.13. ISACA's published exam and application fees total $775 for a member and $960 for a non-member. Provider tuition is separate in the pathway, but a quoted course may or may not include an exam voucher—so never add both without checking the bundle.
That is the whole path. Six steps, two of which most people don't know exist until they've already spent money.
What changes that answer: if you have no IT, security, audit, or compliance background, this is the wrong first certification and we'll tell you why below. If your employer sent you here, note that certifying a person does not give a company—or any of its in-scope systems—a CMMC Status. And if you're trying to get your business CMMC-ready rather than yourself, you're on the wrong page entirely — we'll route you in about ninety seconds.
One more thing before you scroll. There is a single number in this process that ISACA currently publishes two different ways on its own website, on the same page. It governs how long you have to convert a passing exam score into an actual certification. Get it wrong and you risk losing the value of an exam registration that costs up to $760. We captured both statements on August 28, 2026, we'll show you both, and we'll tell you exactly what to do about it. That section is What happens after you pass.
The six-step path at a glance
| Step | What happens | Current published fee |
|---|---|---|
| 1 | Confirm you can document certification eligibility | $0 |
| 2 | Complete mandatory training through an Approved Training Provider | Provider-variable |
| 3 | Register through ISACA, schedule and pass the exam through PSI | $575 member / $760 non-member |
| 4 | Pay the certification application processing fee | $200 |
| 5 | Submit your application and experience evidence | Included above |
| 6 | Obtain a positively adjudicated Tier 3 determination, or applicable equivalence | No separate candidate fee published by ISACA or Part 170 |
| Ongoing | Maintain the credential | $45 member / $85 non-member annually, plus CPE |
Exam fee, application fee, process order, and annual maintenance fee verified against ISACA's published CCP pages on August 28, 2026.
Is this page for you?
Keep reading if: you work in IT, security, GRC, audit, or MSP delivery · you support or want to support Defense Industrial Base clients · your employer told you to "go get CMMC certified" · you hold Security+, CISA, or CISSP and want the government-adjacent next step · you're mapping a path toward the assessor credential.
Leave now if: you're looking for the Certified Compensation Professional (WorldatWork) or the Certified Cost Professional (AACE). Different credentials, different bodies, nothing on this page applies to you.
And read this carefully if you're a company, not a candidate. Training one employee will not make your business CMMC-ready, and it will not substitute for an assessment.
The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The solicitation provision and resulting contract clause set the required CMMC Status for the in-scope system, not a checklist. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.
→ I'm choosing a provider for my company, not training. Map my company's CMMC path
The CMMC Path Framework routes contractors to a provider category, not a named provider. It is not a score, a ranking, or compliance advice.
Everyone else, keep going.
What we actually verified for this guide
Read on August 28, 2026: 32 CFR Part 170, including §§ 170.8 through 170.14 · DFARS 252.204-7012, -7019, -7020, -7021, and 252.204-7025 · the current ISACA CCP credential, certification, maintenance, membership, transition, and exam-outline pages · NIST SP 800-171 Rev. 2, Rev. 3, and the NIST SP 800-172 publication record · the Cyber AB CMMC Assessment Process v2.0 · the official SPRS materials · and the Department's July 13, 2026 Phase II suspension release and implementation documents.
Captured with a date on August 28, 2026: the $575/$760 exam fee · the $200 application processing fee · the $45/$85 annual maintenance fee · the current $145 professional membership price plus local chapter dues · the 170-question exam structure and all six domain weights · the six-month exam eligibility window · the 90-day appointment horizon · the CyberAB Marketplace listing requirements · the conflicting application-window statements · the fact that NIST has superseded Rev. 2 while 32 CFR Part 170 still incorporates Rev. 2 as the CMMC Level 2 standard.
Carried as a dated market snapshot, not represented as current quotes: public Approved Training Provider course prices captured June 29, 2026.
Claims we deliberately did not publish: the exam duration, the passing score, the pass rate, a universal Tier 3 processing time, a guaranteed end-to-end completion timeline, the CMMC Delta Training price, a current count of active CCPs, or any salary figure. None of those were verifiable to a current official source in this pass. We would rather leave a gap than fill it with a number you might budget against.
That last paragraph may be the most useful thing on this page. When a guide tells you the CCP "typically takes two to six months," ask where that came from. We looked. There is no official service level for the part of the process you don't control.
How to become a CCP: the six steps, and who actually controls each one
Answer capsule: Becoming a CMMC Certified Professional (CCP) requires six sequential steps: documenting certification eligibility, completing the mandatory CCP training through an Approved Training Provider (ATP), passing the 170-question CCP exam administered through PSI, paying a $200 application processing fee, submitting an education-or-experience application to ISACA, and receiving a positively adjudicated Tier 3 background investigation or DoD-determined equivalent. Certification is valid for three years under 32 CFR § 170.13.
Most guides give you those six steps as a numbered list and stop. That's not where people lose money.
People lose money because they don't know who controls each step, which steps carry a hard deadline, and which evidence they were supposed to be collecting the whole time. So here is the version we wish someone had handed us.
The 2026 CCP Pathway Control Matrix
| Stage | What you must do | Who controls it | Fixed cost | Official clock | Evidence to keep | Where people lose money |
|---|---|---|---|---|---|---|
| 1. Confirm fit and eligibility | Decide whether CCP serves your actual goal, and confirm you can document a qualifying education or experience route | You, against ISACA's published requirements | $0 | None | Transcripts, employment dates, role descriptions, military records | Paying for training before checking whether you can ever certify |
| 2. Mandatory training | Complete the official CCP curriculum through a current Approved Training Provider | ISACA sets the current pathway; the ATP delivers it | Provider-variable | The provider's schedule | Enrollment record, receipt, completion confirmation, course version | Buying a general "CMMC awareness" course that never unlocks the exam |
| 3. Register and schedule | Register and pay through ISACA, then schedule through PSI | ISACA and PSI | $575 member / $760 non-member | Six months from registration; appointments visible only 90 days out | Payment receipt, eligibility dates, ID name match | Registering early "to lock in the price" and burning the six-month window |
| 4. Pass the exam | Sit the 170-question exam across six domains | ISACA and PSI | Included in registration | Must fall inside the eligibility window | Score notice, account record | Studying the 110 Level 2 requirements and skipping Level 1 and the CAP |
| 5. Apply for certification | Submit the application, education-or-experience evidence, and fee | ISACA | $200 | ISACA currently publishes two conflicting windows | Application copy, evidence, receipt, written deadline confirmation | Assuming a passing score is the same as a certification |
| 6. Tier 3 or equivalence | Obtain a positively adjudicated Tier 3 determination, or the applicable equivalence | The Department background-investigation or equivalence process, with credential-path handoff | No separate candidate fee published | No universal processing time published | Follow official instructions; never retain SF-86 content in an ordinary project folder | Treating Tier 3 as a security clearance, or promising an employer a start date |
| Post-certification: get listed | Satisfy current CyberAB Marketplace listing requirements, including Delta Training | ISACA and the Marketplace | Current Delta price not verified | Tied to active credential status | Credential record, Delta completion, listing screenshot | Assuming certification automatically produces a public listing |
| Ongoing: maintain | Earn CPE, pay the annual fee, follow the ethics rules | ISACA | $45 member / $85 non-member per year | 20 CPE hours per year, 120 per three-year cycle | CPE certificates and supporting records | Treating a three-year credential as permanent |
Assembled by The Defense Compliance Report from ISACA's published CCP training, examination, certification, maintenance, and Marketplace instructions and from 32 CFR §§ 170.10 and 170.13. Current-state facts verified August 28, 2026.
Passing the exam is not the same as being certified
This trips up more candidates than anything else on this page, so let's be blunt about it. There are seven distinct statuses on this path, and four of them get called "getting your CCP" in casual conversation:
- Enrolled in training
- Training completed
- Exam passed
- Application submitted
- Tier 3 or equivalence satisfied
- Active CCP certification
- Listed on the CyberAB Marketplace
Status 3 is not status 6. Status 6 is not status 7. If a recruiter asks whether you're a CCP, the honest answer at status 3 is: "I've passed the CCP exam. I am not yet certified."
Which parts of the clock can you actually control?
| You control | Your training provider controls | The external process controls |
|---|---|---|
| Evidence collection, provider selection, study schedule, when you register, application completeness | Course schedule, delivery format, completion reporting, refund and transfer terms | Tier 3 or equivalence processing and final credential issuance |
That third column is why we refuse to publish a total timeline. Any guide that gives you one is quoting the first two columns and guessing at the third.
You now know the process. The next question is whether it's worth putting your own money into.
→ Build your CCP cost and deadline plan in the worksheet below — copy your provider quote, exact MyISACA eligibility date, application evidence, and maintenance obligations onto one page. Do not enter CUI, contract data, Social Security numbers, or SF-86 information.
Do I qualify to become a CMMC Certified Professional?
Answer capsule: The CCP exam is open to anyone who completes mandatory training through an Approved Training Provider, but ISACA requires documented education or experience for the certification itself: a college degree in a cyber or information technical field, or 2+ years of related education experience, or 2+ years of related experience including military service in a cyber, information technology, or assessment field. You can pass the exam and still be unable to certify.
Read that twice, because the internet gets it wrong constantly.
ISACA's own language is that the exam "is open to anyone who is interested in the CMMC ecosystem," provided you complete the mandatory ATP course. But on the certification application page, the same organization states that the education or experience minimum "is required for certification."
Two different gates. Two different bars. Nobody tells you that before you swipe the card.
The finding that costs candidates the most
Here's something we haven't seen published anywhere else, and it comes straight from reading the regulation next to the certifying body's own instructions.
The work experience requirement does not appear in 32 CFR § 170.13 at all.
The numbered requirements in 32 CFR § 170.13(b) are exactly six: maintain CAICO certification (valid three years), comply with the Accreditation Body's conflict of interest, code of conduct and ethics policies, complete a Tier 3 background investigation, meet an equivalent where Tier 3 isn't available, provide documentation in English, and keep assessment information confidential.
That's it. No degree. No two years. No $200 fee. The regulation does require successful CCP training and testing, but it does not say the course must be bought from an ATP or that self-study can never qualify; those are current ISACA pathway rules.
| Requirement you'll be told about | Where it actually comes from | What that means for you |
|---|---|---|
| Successful CCP training and testing | 32 CFR § 170.13(a) | Federal regulation |
| Training through an ATP; self-study alone does not unlock the exam | Current ISACA certification pathway under the CAICO structure | Binding for the current process, but the ATP delivery rule is not written into § 170.13 |
| Degree or 2+ years of related education or experience | ISACA certification policy | Binding for certification, but not in the regulation |
| $200 application processing fee | ISACA policy | Binding for the current process, subject to change without rulemaking |
| Tier 3 background investigation, initiated using SF-86 | 32 CFR § 170.13(b)(3) | Federal regulation |
| Three-year certification term | 32 CFR § 170.13(b)(1) | Federal regulation |
| Conflict-of-interest and ethics compliance | 32 CFR § 170.13(b)(2), referencing § 170.8(b)(17) | Federal regulation |
| Confidentiality about assessment information | 32 CFR § 170.13(b)(6) | Federal regulation |
| Retraining and recertification after a significant program change | 32 CFR § 170.10(b)(16) | Federal regulation when DoD or the CAICO determines the change is significant |
Source: 32 CFR §§ 170.10 and 170.13, read August 28, 2026, alongside ISACA's current CCP certification requirements.
Why does this distinction matter to you and not just to lawyers? Because policy requirements can change faster than regulatory ones. The two-year experience bar could be adjusted by ISACA. The Tier 3 requirement cannot be, short of amending 32 CFR Part 170. When you're planning an 18-month career move, knowing which is which is worth something.
The evidence to collect before you enroll, not after
Start a folder today. You'll need some or all of this at the application stage:
- Degree documentation or transcripts, if you're using the education route
- Dates and descriptions of related education, if you're using that route
- Employment dates, role descriptions, and a verifier for each relevant position
- Military documentation (military experience counts explicitly under ISACA's wording)
- Legal name consistency across your ISACA account and your government-issued ID
- A written note to yourself recording which eligibility route you intend to claim
That last one sounds trivial. It isn't. Candidates who float between "I have a degree" and "I have two years" tend to assemble a weak application from both instead of a strong one from either.
What if your experience is close but not obviously qualifying?
Get it in writing from ISACA before you spend money. Not from a training provider's admissions rep, who has an obvious incentive, and not from a forum. A borderline eligibility read is exactly the situation where a $3,000 course purchase turns into a $3,000 education with no credential at the end.
We're not going to tell you that generic IT helpdesk experience will qualify. It might. The wording is specific and the decision isn't ours.
Is CCP the right credential for what you're actually trying to do?
Answer capsule: The CCP is the foundational individual credential in the CMMC ecosystem and the required first credential on the CMMC Certified Assessor (CCA) path. It fits professionals doing CMMC readiness work, advising Defense Industrial Base clients, joining a Level 2 certification assessment team under supervision, or building toward the assessor path. It is not a CMMC Status for an organization's in-scope systems, not a security clearance, and not authority to make final assessment determinations.
Match your goal to the path before you match your wallet to a course.
| What you actually want | The honest next step |
|---|---|
| Understand CMMC well enough to do your job | Training alone may be enough. You don't have to sit the exam |
| Run or support your employer's CMMC readiness program | CCP fits well, especially if the role is being formalized |
| Provide readiness or implementation consulting | CCP strengthens your credibility; RP/RPO registration is a separate track |
| Serve on a Level 2 certification assessment team | CCP, working under CCA oversight |
| Make final assessment determinations yourself | That's CCA authority, not CCP authority |
| Build toward assessor work | CCP is the required first rung |
| Appear in the CyberAB Marketplace | Active certification plus Delta Training. See below |
| Obtain a CMMC Status for your employer's in-scope system | Not this. You need the right provider category and assessment path, not an employee course |
What a CCP can do, and what a CCP cannot do
Answer capsule: Under 32 CFR § 170.13(a), a CMMC Certified Professional provides advice, consulting, and recommendations to client organizations, and may participate on a Level 2 certification assessment team with CCA oversight, where the CCA makes all final determinations. A CCP cannot independently issue a CMMC Status or Certificate of CMMC Status, cannot make final assessment determinations, and holds an individual credential that is separate from any organization's CMMC status.
The regulation is unusually plain here. A CCP "completes rigorous training on CMMC and the assessment process to provide advice, consulting, and recommendations." On assessments, CCPs "participate as a CCP on Level 2 certification assessments with CCA oversight where the CCA makes all final determinations."
Note the word order. Advice and consulting come first in the regulation. Assessment participation comes second, and it's supervised. Training pages tend to reverse that emphasis because "become a CMMC assessor" sells better than "become a well-qualified consultant." The regulation disagrees with the marketing.
A CCP can:
- Advise organizations on CMMC requirements, readiness, and implementation
- Support Level 1 self-assessment preparation
- Serve as an assessment team member on a Level 2 certification assessment, under a CCA
- Use the credential as the mandatory first step toward the CCA
A CCP cannot:
- Make final Level 2 certification assessment determinations
- Issue or determine a company's CMMC Status by virtue of holding the credential
- Represent the credential as a government endorsement or affiliation
- Treat the Tier 3 determination as a security clearance
- Promise any organization that it will pass a CMMC assessment
How the CCP sits next to the other roles
| Role | What it is | Individual or organization? | Final Level 2 determination or status authority? | Defined in 32 CFR Part 170? |
|---|---|---|---|---|
| CCP (CMMC Certified Professional) | Foundational credential; advice, consulting, supervised assessment participation | Individual | No | Yes, § 170.13 |
| CCA (CMMC Certified Assessor) | Certified assessor performing Level 2 certification assessments | Individual | A CCA makes final assessment determinations within the authorized assessment structure | Yes, § 170.11 and § 170.13(a) |
| Lead CCA | A CCA who satisfies the additional experience and qualification requirements in § 170.11(b)(10) and oversees an assessment team for a C3PAO | Individual | Oversees the assessment team; certificate issuance remains a C3PAO function | Yes, § 170.11(b)(10); it is a qualified CCA role, not a separate Part 170 section |
| CCI (CMMC Certified Instructor) | Teaches CCP, CCA and CCI candidates within the credential rules | Individual | No | Yes, § 170.12 |
| RP / RPO (Registered Practitioner / Registered Practitioner Organization) | Cyber AB–registered readiness and implementation roles | Individual / Organization | No | No — these are ecosystem registrations, not credentials created by the Program Rule |
| C3PAO (CMMC Third-Party Assessment Organization) | The authorized or accredited organization that conducts Level 2 certification assessments and issues Certificates of CMMC Status | Organization | Yes, through its authorized personnel and quality process | Yes, § 170.9 |
That last column is a distinction almost nobody draws, and it matters. CCP, CCA and CCI are creatures of the federal regulation. RP and RPO are not. They're registrations administered within the Cyber AB ecosystem. If someone tells you an RP designation is "regulated the same way" as a CCP, they haven't read Part 170.
One naming note, since you'll see it both ways: 32 CFR § 170.9 uses "CMMC Third-Party Assessment Organization." Much of the market, including plenty of serious firms, writes "Certified Third-Party Assessment Organization." Same entity. The regulation's version is the one we use.
Did the July 2026 CMMC suspension just make the CCP worthless?
Answer capsule: No, but the reason to earn a CCP has changed. Phase I began November 10, 2025 and, under the original one-year phase-in schedule, was scheduled to run through November 9, 2026. On July 13, 2026 the Department suspended Phase II and placed pending and future implementation milestones in abeyance, pausing the third-party assessment expansion that had been scheduled for November 10, 2026. The Department says Phase I self-assessment requirements remain during the suspension. Separately, where the governing solicitation, contract, option, or subcontract requires them, DFARS safeguarding duties, SPRS records, CMMC Status requirements, and annual affirmations continue.
Here's the part most pages on this topic won't say out loud, so we will.
The demand story you were sold is on hold. If you were told to get a CCP because a wall of mandatory C3PAO assessments was arriving on November 10, 2026, that wall has been postponed indefinitely. Two memoranda issued July 13, 2026 under publication case 26-P-1023 — a policy memo from the Department CIO and implementation procedures for acquisition personnel — suspended Phase II and froze the remaining implementation milestones. Program offices were directed to amend active solicitations that still required Level 2 (C3PAO) or Level 3, and contracting officers were directed to remove those requirements from existing contracts by modification before the next option exercise or during the next scheduled administrative modification.
We're not going to soften that. If your entire business case for this credential was the November 2026 deadline, your business case changed in July.
Now here's why we still think this is a reasonable credential to pursue, and why we'd argue the case got more interesting rather than less.
First, CCP work was never mostly assessment work. Go back to the regulation. Advice, consulting and recommendations come first in § 170.13(a). Readiness work did not disappear, because the underlying duties did not disappear. Where DFARS 252.204-7012 applies, contractors still have to safeguard covered defense information using the contractually controlling standard. Where a Level 2 CMMC Status applies, the assessment basis remains the 110 security requirements of NIST SP 800-171 Rev. 2 across 14 families. Somebody still has to scope the environment, build the evidence, reconcile the SSP and POA&M, and keep the right records current.
The SPRS language gets blurred constantly, so separate these two records:
| SPRS record | Controlling source | What the record represents |
|---|---|---|
| NIST SP 800-171 DoD Assessment result | DFARS 252.204-7019 and -7020, when applicable | A Basic, Medium, or High NIST DoD Assessment result and score |
| CMMC self-assessment/status and affirmation record | 32 CFR Part 170 and DFARS 252.204-7021; DFARS 252.204-7025 is the solicitation-stage notice that checks current SPRS status and affirmation before award | The CMMC level, status, scope, date, and current affirmation for the in-scope system |
Those are related records. They are not interchangeable, and a CCP candidate who cannot explain the difference is not ready to advise a contractor.
Second, the government's stated reason for pausing was capacity and burden, not excess assessor supply. The July 13 release said the program had created prohibitive compliance costs and bureaucratic burdens, and the Department launched a top-to-bottom review aimed at lowering barriers for small, medium, and non-traditional businesses. The program did not pause because the credentialed workforce had become too large.
Third, nothing about the controlling CMMC standard changed. 32 CFR Part 170 remains in effect. It took effect December 16, 2024 and has not been withdrawn. A policy memo changes implementation direction. It does not repeal a rule.
Revision 3 is current at NIST. It is not the CMMC-controlling version.
NIST superseded SP 800-171 Rev. 2 with Rev. 3 in May 2024, and it superseded the original SP 800-172 with Rev. 3 in May 2026. That publication history does not silently rewrite CMMC.
| Question | NIST library status on August 28, 2026 | CMMC-controlling source today |
|---|---|---|
| Level 2 | NIST SP 800-171 Rev. 3 is NIST's current edition | 32 CFR Part 170 still incorporates NIST SP 800-171 Rev. 2, all 110 requirements |
| Level 3 | NIST SP 800-172 Rev. 3 is NIST's current edition | Part 170 still uses selected requirements from the February 2021 SP 800-172, on top of Level 2 |
Implementing Rev. 3 may be a deliberate forward-looking choice. It is not a substitute for the version currently written into Part 170 or the version your contract, clause, deviation, or assessment path requires. Rev. 3 becomes CMMC-controlling only when the controlling legal or contractual instrument changes.
And now the honest forward risk, because you deserve it before you spend.
A CMMC Reform Task Force is conducting a top-to-bottom review. Its request for information closed August 14, 2026, and its report was due to the CIO within 60 days of July 13 — roughly mid-September 2026. As of our verification date, no report had been published.
If that review produces a change that DoD or the CAICO determines is significant, 32 CFR § 170.10(b)(16) requires retraining and recertification of CCPs, CCAs and CCIs. That trigger is the regulation's own text. Which means a credential you buy this quarter could carry an unbudgeted retraining cost next year. We'll come back to this in the maintenance section, because the current Marketplace listing rule creates a separate training obligation candidates also miss.
Who should wait: if you have no employer funding, no current CMMC-adjacent role, and you were pursuing this purely on the strength of the November 2026 date, the rational move is to wait for the Task Force report. Against the Department's stated 60-day reporting clock, that is a weeks-scale decision, not a years-scale one.
→ See exactly what CMMC still requires today, and what the suspension did and didn't change
What training do I need before the CCP exam?
Answer capsule: Official CCP training through a current Approved Training Provider (ATP) listed on the CyberAB Marketplace is mandatory under ISACA's current pathway. Self-study alone does not satisfy that training requirement. Confirm in writing how and when the ATP reports completion before you register.
There is no way around this one. Not a cheaper way, not a faster way, not a "I already know 800-171" way.
If a course is not official CCP training from a listed ATP, it will not unlock the exam, no matter how good it is or how much it costs. This is the single most expensive mistake on the path, and it happens because the terminology changed and stale pages are everywhere.
Old advice versus the current process
This table is the fastest way to tell whether the page you're reading was written before or after the ISACA transition. If a guide contains anything in the left column, treat everything else on it as suspect.
| What an older page will tell you | What is actually true in 2026 | How to spot the stale page |
|---|---|---|
| "The Cyber AB administers the CCP exam" | ISACA was authorized as the CAICO in December 2025 and fully transitioned CAICO services in April 2026. The Cyber AB remains the Accreditation Body | Any instruction to register for the CCP exam through the Cyber AB |
| "Find a Licensed Training Provider (LTP)" | The current term is Approved Training Provider (ATP) | LTP terminology used as current, not historical |
| "Courseware comes from a Licensed Partner Publisher (LPP)" | The current term is Approved Publishing Partner (APP) | LPP used without a note that it is the old label |
| "Exams are delivered through Meazure Learning" | The exam vendor is PSI, at test centers or by remote proctoring | Any exam vendor other than PSI |
| "The exam is optional" | Optional only if you want the education and not the credential. It is mandatory to certify | Course pages that blur course completion with certification |
| "Tier 3 gives you a security clearance" | The Tier 3 determination required for CCP does not grant a security clearance and is not for government employment | The phrase "Tier 3 clearance" |
| "You must be a U.S. citizen" | 32 CFR § 170.13(b)(4) provides a DoD-determined equivalence path where a candidate is not eligible for Tier 3 | A flat citizenship requirement with no citation |
| "Phase 2 begins November 10, 2026" | The transition was suspended July 13, 2026; pending and future milestones are in abeyance | Any live countdown to November 10, 2026 |
| "CMMC now uses NIST SP 800-171 Rev. 3" | NIST's current edition is Rev. 3, but Part 170 still makes Rev. 2 the CMMC Level 2 basis | Treating NIST publication status as an automatic CMMC rule change |
| "You have exactly two years to apply after passing" | ISACA currently publishes both two years and five years | A single confident number with no source |
Compiled by The Defense Compliance Report. Current-state column verified August 28, 2026 against ISACA's published pages, 32 CFR Part 170 on the federal eCFR, and the Department's July 13, 2026 suspension release.
Verify the provider before you pay, in that order
Two minutes of work protects a four-figure purchase:
- Open the CyberAB Marketplace and filter for training providers. Confirm the provider appears as a current ATP.
- Screenshot the listing with a visible date, for your own records.
- Confirm the exact course title is official CCP training, not a general CMMC awareness course.
- Confirm in writing how and when completion is reported, because ISACA validates your registration against that record.
- Confirm whether the exam fee or voucher is included or separate.
- Get the refund, transfer, and missed-session terms in writing.
A polished website is not a proxy for authorization. Some legitimately authorized providers have thin marketing sites, and some slick sites sell courses that will never get you into a testing center. The Marketplace is the check. The homepage is not.
You now know the training is mandatory and what to verify. The next question is who to buy it from.
→ Verify current ATP status on the official CyberAB Marketplace — then send the six questions above before you pay. The listing verifies authorization; the provider's written answers tell you what the price actually buys.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. We earn nothing from any CMMC training provider, and we sell no training ourselves.
What does it actually cost to become a CCP in 2026?
Answer capsule: ISACA's published exam and application fees total $775 for a member or $960 for a non-member: the CCP exam ($575 member / $760 non-member) plus the $200 certification application processing fee. Mandatory ATP training is provider-priced, and some advertised course prices include an exam voucher while others do not. Annual maintenance is $45 for members and $85 for non-members, plus continuing professional education.
A single "CCP costs $X" total is unreliable unless it identifies the training provider and what the bundle includes. The largest line item is provider-set, so let's separate what's fixed from what isn't.
The fixed ISACA fee stack
| Item | ISACA member | Non-member | Verified |
|---|---|---|---|
| CCP exam registration | $575 | $760 | Aug. 28, 2026 |
| Certification application processing fee | $200 | $200 | Aug. 28, 2026 |
| Published exam + application fee total | $775 | $960 | Calculated |
| Annual maintenance, per year | $45 | $85 | Aug. 28, 2026 |
That fee stack is the number to hold in your head. Whether it appears as separate charges depends on whether your training price includes an exam voucher.
The variable stack
- ATP tuition. Our June 29, 2026 snapshot of advertised public CCP course prices ranged from roughly $1,995 to $3,499, depending on provider and delivery format. Bundle contents were not uniform: at least one public price excluded the exam, while other providers advertised an included voucher. This is a dated market snapshot, not a current quote or an apples-to-apples price comparison.
- ISACA membership dues, if you join to get the member rate
- Travel and lodging for in-person training or testing
- Retakes
- Study materials beyond the official course
- Time away from billable work
- CPE activities across the three-year cycle
- CMMC Delta Training, if you want a Marketplace listing
If—and only if—a quoted course price excludes the exam and application fees, adding the published fee stack produces about $2,770 to $4,274 as a member and $2,955 to $4,459 as a non-member, before membership dues, travel, retakes, and CPE. Do not use those totals for a bundle until you subtract the value of any included exam voucher. They are June-snapshot calculations, not current provider quotes.
The membership break-even nobody computes
Membership changes exactly two CCP numbers, and the arithmetic is simple enough to do on a napkin:
- Exam: $760 → $575. You save $185.
- Annual maintenance: $85 → $45. You save $40 per year, or $120 across a three-year cycle.
- Total CCP-specific first-cycle saving: $305.
ISACA currently lists professional membership at $145 per year plus local chapter dues, and members generally must join a local chapter where one exists. The break-even changes depending on how long you stay a member:
| Professional-membership scenario | Base dues | CCP-specific savings | Result before chapter dues |
|---|---|---|---|
| Join for the exam year only | $145 | $185 exam discount | $40 ahead |
| Stay a professional member for all three years | $435 | $185 exam discount + $120 maintenance savings | $130 behind |
So the honest rule is two-part. Joining for the exam year can save money if your required chapter dues are under $40. Maintaining standard professional membership for the full three-year cycle does not pay for itself on CCP fees alone at today's base rate. ISACA also publishes lower-priced recent-graduate and student tiers, but each has eligibility restrictions; confirm the tier and member exam price shown in your own account before budgeting against it. Membership may still be worth it for CPE, other certifications, training discounts, networking, or an employer-paid benefit.
What the course price usually excludes
Before you accept a sticker price as the total, confirm in writing whether it covers the exam fee, the exam voucher, retakes, practice materials, the application fee, ISACA membership, and post-class support. "Cheapest" is a fine strategy when the provider is a current ATP and the exam access is clear in writing. It gets expensive fast when the discount turns out to be a general awareness course.
If your employer is paying
Ask for these in writing before you enroll, because they're much harder to negotiate afterward:
- Authorization covering both tuition and the exam fee
- Whether retakes are reimbursable
- Whether study time counts as work time
- Whether there's a continued-service agreement attached
- Whether the role requires active certification or just the training
- Who pays the annual maintenance fee in years two and three
That last one catches people. A one-time training budget doesn't cover a three-year credential.
→ Run your own numbers in the CCP cost and deadline worksheet — put the provider quote, member status, exact MyISACA eligibility date, evidence route, and maintenance obligations on one page you can hand to whoever approves the spend.
CCP cost and deadline worksheet
Copy this block into your notes or print the page. The point is not to estimate the government-controlled step. The point is to stop losing track of the dates and evidence you do control.
| Field | Your entry | Rule or source |
|---|---|---|
| Eligibility route | Degree / 2+ years related education / 2+ years related experience | ISACA certification requirement |
| ATP and exact course title | Verify current ATP status in the CyberAB Marketplace | |
| ATP tuition and what it includes | Get exam voucher, retake, transfer, and refund terms in writing | |
| Exam fee | $575 member / $760 non-member | ISACA, verified Aug. 28, 2026 |
| Application processing fee | $200 | ISACA, verified Aug. 28, 2026 |
| Registration date | Starts the six-month exam eligibility period | |
| Exact eligibility expiration shown in MyISACA | Copy the account date; do not rely on mental calendar math | |
| Target exam date | Must fall inside eligibility | |
| Passing date | Starts the disputed post-exam application window | |
| Conservative application deadline | Use two years unless ISACA confirms a different deadline in writing | |
| Written ISACA clarification saved | Yes / No | Save the reply with the application record |
| Tier 3/equivalence status | Not started / in process / satisfied | No universal official completion time published |
| Annual CPE plan | 20 minimum each year; 120 over three years | Both thresholds apply |
| Annual maintenance | $45 member / $85 non-member | ISACA, verified Aug. 28, 2026 |
Never put CUI, contract attachments, export-controlled information, Social Security numbers, SF-86 answers, or background-investigation details in this worksheet.
What's on the CCP exam, and the half most candidates under-study
Answer capsule: The CCP exam consists of 170 questions across six job practice domains. The weights are CMMC Ecosystem 5%, Code of Professional Conduct 5%, Governance and Source Documents 15%, Model Construct and Implementation Evaluation 35%, CMMC Assessment Process 25%, and Scoping 15%. The two heaviest domains together account for 60% of the exam.
ISACA publishes the domain weights and the question count. It does not multiply them together. So we did.
| # | Domain | Weight | Approximate questions out of 170 |
|---|---|---|---|
| 1 | CMMC Ecosystem | 5% | 8–9 |
| 2 | CMMC-AB Code of Professional Conduct (Ethics) | 5% | 8–9 |
| 3 | CMMC Governance and Source Documents | 15% | 25–26 |
| 4 | CMMC Model Construct and Implementation Evaluation | 35% | 59–60 |
| 5 | CMMC Assessment Process (CAP) | 25% | 42–43 |
| 6 | Scoping | 15% | 25–26 |
Domain names and weights are ISACA's, from the published CCP Exam Content Outline, verified August 28, 2026. The approximate counts are our multiplication of each percentage by 170; the unrounded products total 170 exactly, while the live exam need not distribute items exactly like the rounded ranges.
Domains 4 and 5 alone are roughly 102 questions. Add Scoping and three domains cover about 128 of the 170. If you allocate study time evenly across six domains, you have misallocated roughly a third of your preparation.
The blueprint detail that should change how you study
Read ISACA's task statements underneath those domains, not just the headings. Two of them say something specific that almost nobody acts on.
Under Domain 4, the heaviest domain on the exam, ISACA's own task statement includes a parenthetical: at a minimum, the CCP candidate must be evaluated on CMMC Level 1 practices during the exam.
Under Domain 6, the scoping task is to analyze an environment and generate an appropriate scope for FCI assets — Federal Contract Information, the Level 1 data type — not CUI assets.
So the heaviest domain on the exam guarantees Level 1 practice coverage, and one of the two 15% domains is framed explicitly around FCI scoping.
Most candidates walk in having ground through all 110 security requirements of NIST SP 800-171 Rev. 2, and having treated Level 1's 15 requirements as the easy part they'll pick up along the way. The published blueprint suggests that's backwards. Level 1 and FCI scoping are not the warm-up. They're written into the heaviest domain and a full 15% scoping domain.
We haven't seen that observation published anywhere else, and it takes about four minutes to confirm on ISACA's exam content outline page.
A study allocation that follows the blueprint
- Source documents first. Domain 3 rewards knowing where a requirement comes from, not just what it says. Read 32 CFR Part 170 and NIST SP 800-171 Rev. 2 properly.
- Then Domain 4. Practice judging whether evidence is adequate and sufficient. Drill Level 1 practices deliberately rather than assuming them.
- Then the CAP. Domain 5 walks the four assessment phases and your role inside each one. The current Cyber AB procedural guide is CAP v2.0, dated December 2024. This is process knowledge, not technical knowledge, and technical people routinely underestimate it.
- Then scoping, with FCI front of mind.
- Ethics and ecosystem last. They're 10% combined. Don't spend a weekend there.
What we deliberately did not publish about the exam
We are not printing an exam duration, a passing score, a pass rate, or a retake policy on this page. Our own prior verification carried a scaled score range and a passing threshold, and we could not reconfirm those against a current official source in this pass. Rather than repeat a number you might plan around, we'll say plainly: check your current candidate guide and your MyISACA registration materials for the scoring and retake rules that apply to your exam.
If that feels like a gap, compare it to the alternative. Several pages ranking for this term publish a passing score with no source at all.
How do I register and schedule the CCP exam?
Answer capsule: Register and pay through ISACA, then schedule through PSI at an authorized test center or as a remotely proctored exam. Registration is continuous with no windows. You can schedule as early as 48 hours after payment, exam eligibility lasts six months from registration, appointments are typically only visible up to 90 days in advance, and rescheduling without penalty requires at least 48 hours' notice.
Four clocks, and they interact in a way that catches people out.
| Clock | Length | Starts | What happens if you miss it |
|---|---|---|---|
| Earliest scheduling | 48 hours after payment | Exam payment clears | Nothing; you just cannot book sooner |
| Appointment visibility | 90 days forward | Rolling | Distant dates simply will not appear yet. Check back closer |
| Free reschedule | At least 48 hours before your slot | Your booked appointment | A penalty may apply under the current scheduling policy |
| Exam eligibility | 6 months | The date you register and pay | Eligibility expires. Do not assume an extension; follow the current MyISACA instructions |
Verified against ISACA's published CCP registration and scheduling instructions, August 28, 2026.
Here is the practical trap. The 90-day visibility window and the six-month eligibility window are different lengths. Candidates register early, discover their preferred test center has nothing available, assume they'll book later, and then run out of eligibility. The window isn't generous once you subtract the provider's course schedule and a realistic study period.
Do not register to lock in a price. Register when your training is done and your study plan makes testing inside six months realistic. That is real scarcity, it's on ISACA's own page, and it's the only deadline pressure we'll apply on this page. We're not going to manufacture urgency out of a suspended program milestone.
Before you register, have these settled: training complete, the name on your ISACA account matching your government-issued ID exactly, a decision between test center and remote proctoring, and the current candidate guide saved somewhere you'll find it.
What happens after you pass, and the deadline ISACA publishes two different ways
Answer capsule: Passing the CCP exam does not make you certified. You must still pay a $200 application processing fee, submit an application demonstrating your education or experience, obtain a positively adjudicated Tier 3 background investigation, and agree to the Code of Professional Ethics and the continuing education policy. Certification is issued after those requirements are satisfied.
This is where the open loop from the top of the page closes.
The official source contradicts itself
On August 28, 2026 we read ISACA's "How to get CCP certified" page. It gives the longer window twice near the top: the exam must have been passed within the last five years, and Step 3 says the certification application is due within five years. Lower on that same page, the certification-requirements section gives a two-year window twice.
The main CCP credential page adds a fifth data point and uses the five-year window.
Five years appears three times. Two years appears twice. Two of the conflicting statements sit on the same page, a few hundred words apart.
We are not telling you ISACA is wrong. Documentation drifts, particularly during a program transition, and this is the kind of thing that gets reconciled quietly. What we are telling you is this:
As of August 28, 2026, the certifying body's published guidance says both. We captured both. You can check it yourself in under a minute.
What to actually do about it
- Plan against the shorter number. Assume two years from your pass date. If it turns out to be five, you lose nothing by having been early.
- Get it in writing. Before you rely on anything longer than two years, email ISACA support and ask for written confirmation of the application window that applies to your exam. Save the reply.
- Check your MyISACA account. Whatever deadline your own account displays is more useful to you than either published sentence.
- Don't wait on purpose. If you have the required evidence, the conflicting public deadlines create no upside to waiting. Apply.
If we ever see this reconciled on ISACA's pages, we'll update this section and note the date. That's what our corrections policy is for.
Your post-exam evidence folder
Keep all of this in one place from the day you pass:
- Exam result notice
- Training completion record and course version
- Degree, transcript, or experience documentation
- Application copy and payment receipt
- Any written deadline clarification you obtained
- Tier 3 or equivalence correspondence, handled through official channels only
- The certification decision itself
- CPE records, starting the day you're certified
You've just seen the one thing on this path that can quietly erase the value of an exam registration costing up to $760. Put your own dates on paper before you forget it.
→ Put your dates into the CCP worksheet now — record the exact MyISACA eligibility expiration, both published application-window readings, your three-year certification cycle, and the CPE due each year.
Do CCP candidates need a security clearance?
Answer capsule: No. CCP candidates must obtain a positively adjudicated Tier 3 background investigation, but 32 CFR § 170.13(b)(3) states directly that this investigation does not result in a security clearance and is not executed for the purpose of government employment. Candidates not eligible for a Tier 3 investigation may meet a DoD-determined equivalent under § 170.13(b)(4).
The phrase "Tier 3 clearance" appears all over the internet. It's wrong, and it sets a materially false expectation for anyone planning a career around it.
Here's what the regulation actually specifies, and this level of detail is not on any competing page we found:
- The investigation is initiated using Standard Form 86 (SF-86), the Questionnaire for National Security Positions
- It results in a determination of national security eligibility
- The positions are designated non-critical sensitive with a risk designation of Moderate Risk
- That designation is made in accordance with 5 CFR 1400.201(b) and (d) and the investigative requirements of 5 CFR 731.106(c)(2)
- The regulation states expressly that it will not result in a security clearance and is not being executed for the purpose of government employment
Source: 32 CFR § 170.13(b)(3), read on the federal eCFR August 28, 2026.
| Tier 3 determination for CCP | A security clearance |
|---|---|
| A credential requirement under the CMMC Program Rule | An authorization tied to classified-information access |
| Does not grant access to classified information | May permit classified access when sponsorship, need-to-know, and adjudication conditions are met |
| Does not create government employment | Does not create government employment either |
| Initiated on SF-86; non-critical sensitive; Moderate Risk | Varies by position sensitivity and investigation tier |
If you're not a U.S. citizen
You are not automatically excluded. 32 CFR § 170.13(b)(4) provides that a candidate who is not eligible to obtain a Tier 3 investigation must "meet the equivalent of a favorably adjudicated Tier 3 background investigation," with DoD determining that equivalence for CMMC Program use.
We are not going to tell you whether your specific circumstances will qualify. That's an individual determination and it isn't ours to make. What we can tell you is that a flat "you must be a U.S. citizen" claim, which several provider pages publish, does not match the regulation's text.
Who initiates it, and how long does it take?
Honest answer: the regulation establishes the requirement, and ISACA lists the Tier 3 determination as the final step after your application. We could not find a published, universal processing time from an official source, and we're not going to invent one.
If a guide tells you Tier 3 takes four to six weeks, ask them for the source. We looked for one.
Follow the instructions supplied through the official credential process. If your account doesn't show a next step, request written clarification rather than acting on a forum post.
One safety note, and we mean this. Never enter SF-86 content, Social Security numbers, background investigation details, security question answers, CUI, or sensitive employer information into any third-party tool. The worksheet on this page is for ordinary cost, date, and evidence planning only.
How long does it take to become a CCP?
Answer capsule: There is no defensible universal answer, because the process combines candidate-controlled steps, provider-controlled schedules, and a government background investigation with no published universal processing time. The clearest pre-application countdown you directly control is the six-month exam eligibility window that begins when you register.
A single timeline range implies precision that doesn't exist. We're going to answer this with a table.
| Stage | What is actually known | What nobody can honestly promise you |
|---|---|---|
| Eligibility evidence | You can gather it before you enroll | How long a borderline eligibility clarification takes |
| ATP training | Each provider publishes its own schedule and access period | A single universal course length |
| Exam eligibility | Six months from registration | That you will be ready in any particular number of weeks |
| Scheduling | Appointments are generally visible 90 days out | Immediate availability at your preferred center or time |
| Application | Required after passing; $200 | One definitive public deadline while ISACA publishes two |
| Tier 3 or equivalence | Required; no universal official processing time published | Any particular completion date |
| Credential issuance | Follows satisfaction of all requirements | A guaranteed end-to-end date |
Compiled by The Defense Compliance Report, August 28, 2026.
A better way to plan. Instead of chasing a total, build backward from the fixed pre-exam clock you control:
- Pick a realistic exam date given your study capacity
- Register no earlier than six months before it
- Finish training before you register, not after
- Have your eligibility evidence assembled before your exam date
- Apply within days of passing, not months
- Treat Tier 3 as an unknown-duration external step and don't promise an employer a start date that depends on it
That plan survives contact with reality. "Three to four months" does not.
How do you keep a CCP certification active?
Answer capsule: CCP certification is valid for three years from the date of issuance under 32 CFR § 170.13(b)(1). Maintaining it requires at least 20 continuing professional education hours annually and 120 hours across the three-year cycle, an annual maintenance fee of $45 for ISACA members or $85 for non-members, and adherence to the Code of Professional Ethics.
The credential is a subscription, not a purchase. Three obligations run continuously:
- CPE hours. Minimum 20 per year, minimum 120 across the three-year reporting period. Note that 20 per year for three years is 60, which does not satisfy the 120-hour total. Both requirements apply. If CPE hours also satisfy another ISACA certification you hold, they can count toward both.
- Annual maintenance fee. $45 member, $85 non-member, per year, verified August 28, 2026.
- Ethics and records. Retain your CPE documentation for at least three years. ISACA conducts CPE audits and can revoke certification for noncompliance.
The third gate: certification does not put you in the Marketplace
Here's the step almost no "how to become a CCP" guide mentions, and it's the one that determines whether work finds you.
The CyberAB Marketplace is the official public directory where Defense Industrial Base contractors go looking for qualified professionals. According to ISACA's own CCP page, to be listed there you need an active CMMC certification (CCP, CCA or LCCA) and you need to have completed Delta Training.
Both. Not one.
So the full ladder looks like this:
| Gate | What it takes | What you get |
|---|---|---|
| 1. Sit the exam | Mandatory ATP training | Exam eligibility under the current pathway |
| 2. Certify | Pass, $200 fee, education-or-experience evidence, Tier 3/equivalence, ethics and CPE commitments | The credential |
| 3. Be findable | Active certification and completed Delta Training | Eligibility for a CyberAB Marketplace listing under the current rule set |
We could not verify a current Delta Training price and we're not going to guess at one. Check the ISACA store before you budget.
Why Delta Training is worth understanding, not just buying
ISACA describes Delta Training as a focused update course, and it currently requires an active CMMC certification plus completed Delta Training for a CyberAB Marketplace listing. That is a current credentialing and directory rule.
Separately, 32 CFR § 170.10(b)(16) requires the CAICO to require retraining and recertification of CCPs, CCAs, and CCIs after a significant change to CMMC Program requirements, when DoD or the CAICO determines the change is significant.
Do not collapse those into one claim. The regulation does not name Delta Training, does not set its price, and does not promise that every future retraining event will use the same course or format.
Now connect the dots carefully. A CMMC Reform Task Force is reviewing the program. If that review produces changes that DoD or the CAICO classifies as significant, retraining and recertification are not optional. Budget for the possibility of another training requirement, but do not budget a format or price that has not been published. That is the real line-item risk in holding this credential through a moving program.
What to do once you have the CCP
Answer capsule: The CCP opens four practical paths: internal Defense Industrial Base compliance work, readiness and implementation consulting, supervised assessment team participation through a C3PAO, and progression toward the CMMC Certified Assessor credential. Choose based on the role you want, not on the credential you just earned.
Internal DIB compliance. Map your responsibilities to your employer's actual program. Be precise about role boundaries and never let your personal credential get described as an organization's CMMC Status. This path ties the credential to a real employer need instead of a suspended deadline.
Readiness or implementation consulting. Describe your services accurately, never guarantee an assessment outcome, and understand the independence boundary precisely: 32 CFR § 170.8(b)(17) prohibits CMMC Ecosystem members from participating in a Level 2 certification assessment for an organization they served as a consultant to prepare for any CMMC assessment within the previous three years. If you're building a practice, RP and RPO registration is a separate track from your CCP.
Assessment team work. Seek engagements through an authorized C3PAO, and go in knowing the CCA retains final determination authority. This is the path most affected by the Phase 2 suspension, and the one to be most realistic about right now.
The assessor path. CCP is the mandatory prerequisite for CCA. The CCA adds real requirements that catch people at the application stage rather than at enrollment: at least three years of cybersecurity experience, at least one year of assessment or audit experience, and a foundational qualification aligned to at least the Intermediate Proficiency Level for the DoD Cyber Workforce Framework Security Control Assessor (612) work role. Map those before you buy CCA training, not after.
→ The full CCA requirements, including the certification prerequisite that trips up most candidates
Frequently asked questions about becoming a CCP
Is the CCP the same as the Certified Compensation Professional? No. The Certified Compensation Professional is an HR compensation credential administered by WorldatWork. The credential on this page is the CMMC Certified Professional, administered by ISACA in its role as the CAICO for the Department of Defense's Cybersecurity Maturity Model Certification program. Different bodies, different exams, no overlap.
Can anyone take the CCP exam? The exam is open to anyone who completes mandatory training through an Approved Training Provider. Certification is different: ISACA requires documented education or experience. You can pass the exam and still be unable to certify, which is why we recommend confirming eligibility before you buy training.
Can I self-study and skip the course? No. Official training through a current ATP listed on the CyberAB Marketplace is mandatory, and your ATP reports your completion to the CAICO. Self-study is useful preparation. It is not a substitute for the required course, and unauthorized "CMMC prep" courses will not unlock the exam.
Who runs CCP certification now, ISACA or the Cyber AB? ISACA was authorized as the CAICO in December 2025, and CAICO services fully transitioned to ISACA in April 2026. It runs the individual training, examination, and certification pathway; the Cyber AB remains the program's Accreditation Body. A guide that sends you to the Cyber AB to register for the current CCP exam is stale.
How much does the CCP exam cost? $575 for ISACA members and $760 for non-members, verified August 28, 2026. The $200 certification application processing fee is separate and is paid after you pass, bringing the published exam-plus-application total to $775 or $960 before any training cost.
Do I need two years of experience? You need one of three routes: a college degree in a cyber or information technical field, 2+ years of related education experience, or 2+ years of related experience (including military) in a cyber, information technology, or assessment field. That requirement applies to certification, not to sitting the exam, and it is ISACA policy rather than a requirement in 32 CFR § 170.13.
Does military experience count? Yes. ISACA's published wording for the experience route names military experience explicitly among qualifying related experience in a cyber, information technology, or assessment field.
Do I need a security clearance to become a CCP? No. You need a positively adjudicated Tier 3 background investigation, initiated on Standard Form 86. 32 CFR § 170.13(b)(3) states directly that this investigation does not result in a security clearance and is not executed for the purpose of government employment.
Can a non-U.S. citizen become a CCP? The regulation provides an equivalence path. Under 32 CFR § 170.13(b)(4), a candidate not eligible to obtain a Tier 3 investigation must meet a DoD-determined equivalent. Individual eligibility is determined through the official process, so confirm your specific situation with ISACA rather than relying on a general claim either way.
Can a CCP conduct a CMMC Level 2 assessment? A CCP can participate on a Level 2 certification assessment team with CCA oversight, and 32 CFR § 170.13(a) specifies that the CCA makes all final determinations. A CCP cannot independently issue a CMMC Status or Certificate of CMMC Status.
How long do I have to apply after passing the exam? ISACA's published guidance currently states both five years and two years, including two conflicting statements on the same page, which we captured on August 28, 2026. Plan against the shorter window, confirm the deadline shown in your MyISACA account, and request written confirmation from ISACA before relying on anything longer.
How many CPE hours does the CCP require? A minimum of 20 continuing professional education hours per year and 120 hours across the three-year reporting period. Both requirements apply; meeting only the annual minimum for three years does not satisfy the three-year total.
How long is the CCP valid? Three years from the date of issuance, under 32 CFR § 170.13(b)(1). Maintaining it requires CPE, the annual maintenance fee, and adherence to the ethics policy.
Is a CCP required before a CCA? Yes. 32 CFR § 170.13(a) establishes that CCPs are eligible to become CMMC Certified Assessors, and ISACA identifies active CCP status as the prerequisite for the CCA path.
Does passing automatically list me on the CyberAB Marketplace? No. ISACA states that Marketplace listing requires an active CMMC certification and completed Delta Training. Certification alone does not produce a public listing.
Does CMMC use NIST SP 800-171 Revision 2 or Revision 3? Revision 2 is still the CMMC-controlling Level 2 version. NIST has superseded it with Revision 3 in the NIST publication library, but 32 CFR Part 170 still incorporates Rev. 2. Revision 3 does not become the CMMC assessment basis unless the controlling rule, clause, deviation, or contract changes.
Did the July 2026 Phase 2 suspension cancel the CCP? No. The suspension paused the planned Phase II expansion of new Level 2 (C3PAO) and Level 3 procurement designations. 32 CFR Part 170 remains in effect, the credential pathway remains active, and Phase I self-assessment requirements continue where the governing instrument requires them. What changed is the deadline-driven demand argument, not the credential's existence.
What if the CMMC program changes again? 32 CFR § 170.10(b)(16) requires the CAICO to mandate retraining and recertification of CCPs, CCAs and CCIs when DoD or the CAICO determines a program change is significant. A Task Force recommendation alone is not the trigger; the significance determination is. Budget for the possibility, not an invented price or schedule.
Your next step
If you're pursuing the credential:
- → Build your CCP cost and deadline plan — fixed costs, provider quote, exact eligibility expiration, application evidence, and maintenance obligations on one printable page
- → Verify a current Approved Training Provider on the official CyberAB Marketplace — confirm authorization, the exact course, voucher handling, completion reporting, and refund terms before you pay
- → Read the current Phase II suspension status — the program review is the event most likely to change the business case on this page
If you're a defense contractor choosing a provider for your company:
Need help deciding what type of CMMC provider you need? Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.
Already know the category and need scoped provider options? Request a quote without sending CUI. Still organizing the work? Start with the 32-point CMMC readiness checklist, see who to hire first, and use the CMMC Level 2 cost guide before you approve a budget.
Do not submit CUI, drawings, export-controlled information, contract attachments, or sensitive system details.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. We earn nothing from any CMMC training provider named or linked on this page.
Primary sources
- 32 CFR Part 170 — CMMC Program Rule, effective December 16, 2024. This page relies particularly on §§ 170.8, 170.9, 170.10, 170.11, 170.12, 170.13, and 170.14. Source rule: 89 FR 83214, October 15, 2024.
- 5 CFR 1400.201 and 5 CFR 731.106 — position sensitivity and investigative requirements referenced by § 170.13(b)(3).
- ISACA: CCP credential page, How to get CCP certified, CCP Exam Content Outline, maintenance requirements, membership pricing, and the April 2026 CAICO transition notice.
- Department: July 13, 2026 Phase II suspension release and the CMMC program materials linked from the Department CIO's CMMC page.
- NIST: SP 800-171 Rev. 2, SP 800-171 Rev. 3, and the SP 800-172 publication record. The NIST library's current edition and the version incorporated into Part 170 are not the same thing.
- DFARS on Acquisition.gov: 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021, and 252.204-7025.
- Supplier Performance Risk System — official tutorials and record-entry guidance for CMMC self-assessments, affirmations, and NIST assessment results.
- Cyber AB: Marketplace, consulting and implementation role page, and CMMC Assessment Process v2.0, December 2024.
For how we distinguish regulation, current-state facts, provider statements, and editorial judgment, see our methodology, editorial standards, editorial and advertising policy, and corrections policy.
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source support for regulatory claims and mapping a contractor's required status, CUI scope, assessment type, and timeline to the right provider category before expensive work begins.
By The Defense Compliance Report Editorial Team · Last reviewed August 2026 · Last verified August 28, 2026
Fees, program requirements, provider statuses, and phase timing change. Verify current ISACA requirements and CyberAB Marketplace status before you register or pay. This guide is educational research, not legal, contractual, employment, security-clearance, or compliance advice. Direct credential-eligibility and application questions to ISACA. Confirm contract-specific scope and applicability with a qualified CMMC practitioner or federal-contracts attorney. See our editorial standards, methodology, and corrections policy.
