The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

CMMC training & credentials · primary-sourced · last reviewed August 2026

How to Become a CCP (CMMC Certified Professional) in 2026

Last updated:

Last verified: against 32 CFR Part 170, DFARS and FAR materials, current ISACA CCP credential and certification pages, Cyber AB program materials, NIST publications, SPRS materials, and the Department's current CMMC implementation documents.

Editorial illustration of the six-stage CMMC Certified Professional credential path with eligibility documents, an exam checkpoint, background investigation, and active certification

By The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Last verified: August 28, 2026

How to become a CCP in 2026: verify eligibility, complete official ATP training, pass the ISACA exam, apply for certification, and satisfy Tier 3 or the applicable equivalent—without confusing an exam pass with an active credential.

Program status strip: Current credential administrator: ISACA, authorized as the CAICO in December 2025; CAICO services fully transitioned in April 2026 · CMMC Phase 1 began November 10, 2025 and remains the active implementation phase · CMMC Phase 2 was suspended July 13, 2026, with pending and future implementation milestones held in abeyance

The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We are not affiliated with the Cyber AB, ISACA, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. We sell no training, we run no exam prep, and we earn nothing from any training provider mentioned or linked on this page.


Here is how to become a CCP in 2026, in one paragraph.

Confirm you can document ISACA's certification eligibility. Complete mandatory CMMC Certified Professional training through a current Approved Training Provider. Pass the 170-question CCP exam through PSI, which costs $575 for ISACA members and $760 for non-members. Pay a $200 application processing fee. Submit your education or experience evidence. Then obtain a positively adjudicated Tier 3 background investigation. Your certification is valid for three years under 32 CFR § 170.13. ISACA's published exam and application fees total $775 for a member and $960 for a non-member. Provider tuition is separate in the pathway, but a quoted course may or may not include an exam voucher—so never add both without checking the bundle.

That is the whole path. Six steps, two of which most people don't know exist until they've already spent money.

What changes that answer: if you have no IT, security, audit, or compliance background, this is the wrong first certification and we'll tell you why below. If your employer sent you here, note that certifying a person does not give a company—or any of its in-scope systems—a CMMC Status. And if you're trying to get your business CMMC-ready rather than yourself, you're on the wrong page entirely — we'll route you in about ninety seconds.

One more thing before you scroll. There is a single number in this process that ISACA currently publishes two different ways on its own website, on the same page. It governs how long you have to convert a passing exam score into an actual certification. Get it wrong and you risk losing the value of an exam registration that costs up to $760. We captured both statements on August 28, 2026, we'll show you both, and we'll tell you exactly what to do about it. That section is What happens after you pass.

The six-step path at a glance

Step — What happens — Current published fee
StepWhat happensCurrent published fee
1Confirm you can document certification eligibility$0
2Complete mandatory training through an Approved Training ProviderProvider-variable
3Register through ISACA, schedule and pass the exam through PSI$575 member / $760 non-member
4Pay the certification application processing fee$200
5Submit your application and experience evidenceIncluded above
6Obtain a positively adjudicated Tier 3 determination, or applicable equivalenceNo separate candidate fee published by ISACA or Part 170
OngoingMaintain the credential$45 member / $85 non-member annually, plus CPE

Exam fee, application fee, process order, and annual maintenance fee verified against ISACA's published CCP pages on August 28, 2026.

Is this page for you?

Keep reading if: you work in IT, security, GRC, audit, or MSP delivery · you support or want to support Defense Industrial Base clients · your employer told you to "go get CMMC certified" · you hold Security+, CISA, or CISSP and want the government-adjacent next step · you're mapping a path toward the assessor credential.

Leave now if: you're looking for the Certified Compensation Professional (WorldatWork) or the Certified Cost Professional (AACE). Different credentials, different bodies, nothing on this page applies to you.

And read this carefully if you're a company, not a candidate. Training one employee will not make your business CMMC-ready, and it will not substitute for an assessment.

The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The solicitation provision and resulting contract clause set the required CMMC Status for the in-scope system, not a checklist. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.

→ I'm choosing a provider for my company, not training. Map my company's CMMC path

The CMMC Path Framework routes contractors to a provider category, not a named provider. It is not a score, a ranking, or compliance advice.

Everyone else, keep going.

What we actually verified for this guide

Read on August 28, 2026: 32 CFR Part 170, including §§ 170.8 through 170.14 · DFARS 252.204-7012, -7019, -7020, -7021, and 252.204-7025 · the current ISACA CCP credential, certification, maintenance, membership, transition, and exam-outline pages · NIST SP 800-171 Rev. 2, Rev. 3, and the NIST SP 800-172 publication record · the Cyber AB CMMC Assessment Process v2.0 · the official SPRS materials · and the Department's July 13, 2026 Phase II suspension release and implementation documents.

Captured with a date on August 28, 2026: the $575/$760 exam fee · the $200 application processing fee · the $45/$85 annual maintenance fee · the current $145 professional membership price plus local chapter dues · the 170-question exam structure and all six domain weights · the six-month exam eligibility window · the 90-day appointment horizon · the CyberAB Marketplace listing requirements · the conflicting application-window statements · the fact that NIST has superseded Rev. 2 while 32 CFR Part 170 still incorporates Rev. 2 as the CMMC Level 2 standard.

Carried as a dated market snapshot, not represented as current quotes: public Approved Training Provider course prices captured June 29, 2026.

Claims we deliberately did not publish: the exam duration, the passing score, the pass rate, a universal Tier 3 processing time, a guaranteed end-to-end completion timeline, the CMMC Delta Training price, a current count of active CCPs, or any salary figure. None of those were verifiable to a current official source in this pass. We would rather leave a gap than fill it with a number you might budget against.

That last paragraph may be the most useful thing on this page. When a guide tells you the CCP "typically takes two to six months," ask where that came from. We looked. There is no official service level for the part of the process you don't control.


How to become a CCP: the six steps, and who actually controls each one

Answer capsule: Becoming a CMMC Certified Professional (CCP) requires six sequential steps: documenting certification eligibility, completing the mandatory CCP training through an Approved Training Provider (ATP), passing the 170-question CCP exam administered through PSI, paying a $200 application processing fee, submitting an education-or-experience application to ISACA, and receiving a positively adjudicated Tier 3 background investigation or DoD-determined equivalent. Certification is valid for three years under 32 CFR § 170.13.

Most guides give you those six steps as a numbered list and stop. That's not where people lose money.

People lose money because they don't know who controls each step, which steps carry a hard deadline, and which evidence they were supposed to be collecting the whole time. So here is the version we wish someone had handed us.

The 2026 CCP Pathway Control Matrix

Stage — What you must do — Who controls it — Fixed cost — Official clock — Evidence to keep — Where people lose money
StageWhat you must doWho controls itFixed costOfficial clockEvidence to keepWhere people lose money
1. Confirm fit and eligibilityDecide whether CCP serves your actual goal, and confirm you can document a qualifying education or experience routeYou, against ISACA's published requirements$0NoneTranscripts, employment dates, role descriptions, military recordsPaying for training before checking whether you can ever certify
2. Mandatory trainingComplete the official CCP curriculum through a current Approved Training ProviderISACA sets the current pathway; the ATP delivers itProvider-variableThe provider's scheduleEnrollment record, receipt, completion confirmation, course versionBuying a general "CMMC awareness" course that never unlocks the exam
3. Register and scheduleRegister and pay through ISACA, then schedule through PSIISACA and PSI$575 member / $760 non-memberSix months from registration; appointments visible only 90 days outPayment receipt, eligibility dates, ID name matchRegistering early "to lock in the price" and burning the six-month window
4. Pass the examSit the 170-question exam across six domainsISACA and PSIIncluded in registrationMust fall inside the eligibility windowScore notice, account recordStudying the 110 Level 2 requirements and skipping Level 1 and the CAP
5. Apply for certificationSubmit the application, education-or-experience evidence, and feeISACA$200ISACA currently publishes two conflicting windowsApplication copy, evidence, receipt, written deadline confirmationAssuming a passing score is the same as a certification
6. Tier 3 or equivalenceObtain a positively adjudicated Tier 3 determination, or the applicable equivalenceThe Department background-investigation or equivalence process, with credential-path handoffNo separate candidate fee publishedNo universal processing time publishedFollow official instructions; never retain SF-86 content in an ordinary project folderTreating Tier 3 as a security clearance, or promising an employer a start date
Post-certification: get listedSatisfy current CyberAB Marketplace listing requirements, including Delta TrainingISACA and the MarketplaceCurrent Delta price not verifiedTied to active credential statusCredential record, Delta completion, listing screenshotAssuming certification automatically produces a public listing
Ongoing: maintainEarn CPE, pay the annual fee, follow the ethics rulesISACA$45 member / $85 non-member per year20 CPE hours per year, 120 per three-year cycleCPE certificates and supporting recordsTreating a three-year credential as permanent

Assembled by The Defense Compliance Report from ISACA's published CCP training, examination, certification, maintenance, and Marketplace instructions and from 32 CFR §§ 170.10 and 170.13. Current-state facts verified August 28, 2026.

Passing the exam is not the same as being certified

This trips up more candidates than anything else on this page, so let's be blunt about it. There are seven distinct statuses on this path, and four of them get called "getting your CCP" in casual conversation:

  1. Enrolled in training
  2. Training completed
  3. Exam passed
  4. Application submitted
  5. Tier 3 or equivalence satisfied
  6. Active CCP certification
  7. Listed on the CyberAB Marketplace

Status 3 is not status 6. Status 6 is not status 7. If a recruiter asks whether you're a CCP, the honest answer at status 3 is: "I've passed the CCP exam. I am not yet certified."

Which parts of the clock can you actually control?

You control — Your training provider controls — The external process controls
You controlYour training provider controlsThe external process controls
Evidence collection, provider selection, study schedule, when you register, application completenessCourse schedule, delivery format, completion reporting, refund and transfer termsTier 3 or equivalence processing and final credential issuance

That third column is why we refuse to publish a total timeline. Any guide that gives you one is quoting the first two columns and guessing at the third.

You now know the process. The next question is whether it's worth putting your own money into.

→ Build your CCP cost and deadline plan in the worksheet below — copy your provider quote, exact MyISACA eligibility date, application evidence, and maintenance obligations onto one page. Do not enter CUI, contract data, Social Security numbers, or SF-86 information.


Do I qualify to become a CMMC Certified Professional?

Answer capsule: The CCP exam is open to anyone who completes mandatory training through an Approved Training Provider, but ISACA requires documented education or experience for the certification itself: a college degree in a cyber or information technical field, or 2+ years of related education experience, or 2+ years of related experience including military service in a cyber, information technology, or assessment field. You can pass the exam and still be unable to certify.

Read that twice, because the internet gets it wrong constantly.

ISACA's own language is that the exam "is open to anyone who is interested in the CMMC ecosystem," provided you complete the mandatory ATP course. But on the certification application page, the same organization states that the education or experience minimum "is required for certification."

Two different gates. Two different bars. Nobody tells you that before you swipe the card.

The finding that costs candidates the most

Here's something we haven't seen published anywhere else, and it comes straight from reading the regulation next to the certifying body's own instructions.

The work experience requirement does not appear in 32 CFR § 170.13 at all.

The numbered requirements in 32 CFR § 170.13(b) are exactly six: maintain CAICO certification (valid three years), comply with the Accreditation Body's conflict of interest, code of conduct and ethics policies, complete a Tier 3 background investigation, meet an equivalent where Tier 3 isn't available, provide documentation in English, and keep assessment information confidential.

That's it. No degree. No two years. No $200 fee. The regulation does require successful CCP training and testing, but it does not say the course must be bought from an ATP or that self-study can never qualify; those are current ISACA pathway rules.

Requirement you'll be told about — Where it actually comes from — What that means for you
Requirement you'll be told aboutWhere it actually comes fromWhat that means for you
Successful CCP training and testing32 CFR § 170.13(a)Federal regulation
Training through an ATP; self-study alone does not unlock the examCurrent ISACA certification pathway under the CAICO structureBinding for the current process, but the ATP delivery rule is not written into § 170.13
Degree or 2+ years of related education or experienceISACA certification policyBinding for certification, but not in the regulation
$200 application processing feeISACA policyBinding for the current process, subject to change without rulemaking
Tier 3 background investigation, initiated using SF-8632 CFR § 170.13(b)(3)Federal regulation
Three-year certification term32 CFR § 170.13(b)(1)Federal regulation
Conflict-of-interest and ethics compliance32 CFR § 170.13(b)(2), referencing § 170.8(b)(17)Federal regulation
Confidentiality about assessment information32 CFR § 170.13(b)(6)Federal regulation
Retraining and recertification after a significant program change32 CFR § 170.10(b)(16)Federal regulation when DoD or the CAICO determines the change is significant

Source: 32 CFR §§ 170.10 and 170.13, read August 28, 2026, alongside ISACA's current CCP certification requirements.

Why does this distinction matter to you and not just to lawyers? Because policy requirements can change faster than regulatory ones. The two-year experience bar could be adjusted by ISACA. The Tier 3 requirement cannot be, short of amending 32 CFR Part 170. When you're planning an 18-month career move, knowing which is which is worth something.

The evidence to collect before you enroll, not after

Start a folder today. You'll need some or all of this at the application stage:

  • Degree documentation or transcripts, if you're using the education route
  • Dates and descriptions of related education, if you're using that route
  • Employment dates, role descriptions, and a verifier for each relevant position
  • Military documentation (military experience counts explicitly under ISACA's wording)
  • Legal name consistency across your ISACA account and your government-issued ID
  • A written note to yourself recording which eligibility route you intend to claim

That last one sounds trivial. It isn't. Candidates who float between "I have a degree" and "I have two years" tend to assemble a weak application from both instead of a strong one from either.

What if your experience is close but not obviously qualifying?

Get it in writing from ISACA before you spend money. Not from a training provider's admissions rep, who has an obvious incentive, and not from a forum. A borderline eligibility read is exactly the situation where a $3,000 course purchase turns into a $3,000 education with no credential at the end.

We're not going to tell you that generic IT helpdesk experience will qualify. It might. The wording is specific and the decision isn't ours.


Is CCP the right credential for what you're actually trying to do?

Answer capsule: The CCP is the foundational individual credential in the CMMC ecosystem and the required first credential on the CMMC Certified Assessor (CCA) path. It fits professionals doing CMMC readiness work, advising Defense Industrial Base clients, joining a Level 2 certification assessment team under supervision, or building toward the assessor path. It is not a CMMC Status for an organization's in-scope systems, not a security clearance, and not authority to make final assessment determinations.

Match your goal to the path before you match your wallet to a course.

What you actually want — The honest next step
What you actually wantThe honest next step
Understand CMMC well enough to do your jobTraining alone may be enough. You don't have to sit the exam
Run or support your employer's CMMC readiness programCCP fits well, especially if the role is being formalized
Provide readiness or implementation consultingCCP strengthens your credibility; RP/RPO registration is a separate track
Serve on a Level 2 certification assessment teamCCP, working under CCA oversight
Make final assessment determinations yourselfThat's CCA authority, not CCP authority
Build toward assessor workCCP is the required first rung
Appear in the CyberAB MarketplaceActive certification plus Delta Training. See below
Obtain a CMMC Status for your employer's in-scope systemNot this. You need the right provider category and assessment path, not an employee course

What a CCP can do, and what a CCP cannot do

Answer capsule: Under 32 CFR § 170.13(a), a CMMC Certified Professional provides advice, consulting, and recommendations to client organizations, and may participate on a Level 2 certification assessment team with CCA oversight, where the CCA makes all final determinations. A CCP cannot independently issue a CMMC Status or Certificate of CMMC Status, cannot make final assessment determinations, and holds an individual credential that is separate from any organization's CMMC status.

The regulation is unusually plain here. A CCP "completes rigorous training on CMMC and the assessment process to provide advice, consulting, and recommendations." On assessments, CCPs "participate as a CCP on Level 2 certification assessments with CCA oversight where the CCA makes all final determinations."

Note the word order. Advice and consulting come first in the regulation. Assessment participation comes second, and it's supervised. Training pages tend to reverse that emphasis because "become a CMMC assessor" sells better than "become a well-qualified consultant." The regulation disagrees with the marketing.

A CCP can:

  • Advise organizations on CMMC requirements, readiness, and implementation
  • Support Level 1 self-assessment preparation
  • Serve as an assessment team member on a Level 2 certification assessment, under a CCA
  • Use the credential as the mandatory first step toward the CCA

A CCP cannot:

  • Make final Level 2 certification assessment determinations
  • Issue or determine a company's CMMC Status by virtue of holding the credential
  • Represent the credential as a government endorsement or affiliation
  • Treat the Tier 3 determination as a security clearance
  • Promise any organization that it will pass a CMMC assessment

How the CCP sits next to the other roles

Role — What it is — Individual or organization? — Final Level 2 determination or status authority? — Defined in 32 CFR Part 170?
RoleWhat it isIndividual or organization?Final Level 2 determination or status authority?Defined in 32 CFR Part 170?
CCP (CMMC Certified Professional)Foundational credential; advice, consulting, supervised assessment participationIndividualNoYes, § 170.13
CCA (CMMC Certified Assessor)Certified assessor performing Level 2 certification assessmentsIndividualA CCA makes final assessment determinations within the authorized assessment structureYes, § 170.11 and § 170.13(a)
Lead CCAA CCA who satisfies the additional experience and qualification requirements in § 170.11(b)(10) and oversees an assessment team for a C3PAOIndividualOversees the assessment team; certificate issuance remains a C3PAO functionYes, § 170.11(b)(10); it is a qualified CCA role, not a separate Part 170 section
CCI (CMMC Certified Instructor)Teaches CCP, CCA and CCI candidates within the credential rulesIndividualNoYes, § 170.12
RP / RPO (Registered Practitioner / Registered Practitioner Organization)Cyber AB–registered readiness and implementation rolesIndividual / OrganizationNoNo — these are ecosystem registrations, not credentials created by the Program Rule
C3PAO (CMMC Third-Party Assessment Organization)The authorized or accredited organization that conducts Level 2 certification assessments and issues Certificates of CMMC StatusOrganizationYes, through its authorized personnel and quality processYes, § 170.9

That last column is a distinction almost nobody draws, and it matters. CCP, CCA and CCI are creatures of the federal regulation. RP and RPO are not. They're registrations administered within the Cyber AB ecosystem. If someone tells you an RP designation is "regulated the same way" as a CCP, they haven't read Part 170.

One naming note, since you'll see it both ways: 32 CFR § 170.9 uses "CMMC Third-Party Assessment Organization." Much of the market, including plenty of serious firms, writes "Certified Third-Party Assessment Organization." Same entity. The regulation's version is the one we use.


Did the July 2026 CMMC suspension just make the CCP worthless?

Answer capsule: No, but the reason to earn a CCP has changed. Phase I began November 10, 2025 and, under the original one-year phase-in schedule, was scheduled to run through November 9, 2026. On July 13, 2026 the Department suspended Phase II and placed pending and future implementation milestones in abeyance, pausing the third-party assessment expansion that had been scheduled for November 10, 2026. The Department says Phase I self-assessment requirements remain during the suspension. Separately, where the governing solicitation, contract, option, or subcontract requires them, DFARS safeguarding duties, SPRS records, CMMC Status requirements, and annual affirmations continue.

Here's the part most pages on this topic won't say out loud, so we will.

The demand story you were sold is on hold. If you were told to get a CCP because a wall of mandatory C3PAO assessments was arriving on November 10, 2026, that wall has been postponed indefinitely. Two memoranda issued July 13, 2026 under publication case 26-P-1023 — a policy memo from the Department CIO and implementation procedures for acquisition personnel — suspended Phase II and froze the remaining implementation milestones. Program offices were directed to amend active solicitations that still required Level 2 (C3PAO) or Level 3, and contracting officers were directed to remove those requirements from existing contracts by modification before the next option exercise or during the next scheduled administrative modification.

We're not going to soften that. If your entire business case for this credential was the November 2026 deadline, your business case changed in July.

Now here's why we still think this is a reasonable credential to pursue, and why we'd argue the case got more interesting rather than less.

First, CCP work was never mostly assessment work. Go back to the regulation. Advice, consulting and recommendations come first in § 170.13(a). Readiness work did not disappear, because the underlying duties did not disappear. Where DFARS 252.204-7012 applies, contractors still have to safeguard covered defense information using the contractually controlling standard. Where a Level 2 CMMC Status applies, the assessment basis remains the 110 security requirements of NIST SP 800-171 Rev. 2 across 14 families. Somebody still has to scope the environment, build the evidence, reconcile the SSP and POA&M, and keep the right records current.

The SPRS language gets blurred constantly, so separate these two records:

SPRS record — Controlling source — What the record represents
SPRS recordControlling sourceWhat the record represents
NIST SP 800-171 DoD Assessment resultDFARS 252.204-7019 and -7020, when applicableA Basic, Medium, or High NIST DoD Assessment result and score
CMMC self-assessment/status and affirmation record32 CFR Part 170 and DFARS 252.204-7021; DFARS 252.204-7025 is the solicitation-stage notice that checks current SPRS status and affirmation before awardThe CMMC level, status, scope, date, and current affirmation for the in-scope system

Those are related records. They are not interchangeable, and a CCP candidate who cannot explain the difference is not ready to advise a contractor.

Second, the government's stated reason for pausing was capacity and burden, not excess assessor supply. The July 13 release said the program had created prohibitive compliance costs and bureaucratic burdens, and the Department launched a top-to-bottom review aimed at lowering barriers for small, medium, and non-traditional businesses. The program did not pause because the credentialed workforce had become too large.

Third, nothing about the controlling CMMC standard changed. 32 CFR Part 170 remains in effect. It took effect December 16, 2024 and has not been withdrawn. A policy memo changes implementation direction. It does not repeal a rule.

Revision 3 is current at NIST. It is not the CMMC-controlling version.

NIST superseded SP 800-171 Rev. 2 with Rev. 3 in May 2024, and it superseded the original SP 800-172 with Rev. 3 in May 2026. That publication history does not silently rewrite CMMC.

Question — NIST library status on August 28, 2026 — CMMC-controlling source today
QuestionNIST library status on August 28, 2026CMMC-controlling source today
Level 2NIST SP 800-171 Rev. 3 is NIST's current edition32 CFR Part 170 still incorporates NIST SP 800-171 Rev. 2, all 110 requirements
Level 3NIST SP 800-172 Rev. 3 is NIST's current editionPart 170 still uses selected requirements from the February 2021 SP 800-172, on top of Level 2

Implementing Rev. 3 may be a deliberate forward-looking choice. It is not a substitute for the version currently written into Part 170 or the version your contract, clause, deviation, or assessment path requires. Rev. 3 becomes CMMC-controlling only when the controlling legal or contractual instrument changes.

And now the honest forward risk, because you deserve it before you spend.

A CMMC Reform Task Force is conducting a top-to-bottom review. Its request for information closed August 14, 2026, and its report was due to the CIO within 60 days of July 13 — roughly mid-September 2026. As of our verification date, no report had been published.

If that review produces a change that DoD or the CAICO determines is significant, 32 CFR § 170.10(b)(16) requires retraining and recertification of CCPs, CCAs and CCIs. That trigger is the regulation's own text. Which means a credential you buy this quarter could carry an unbudgeted retraining cost next year. We'll come back to this in the maintenance section, because the current Marketplace listing rule creates a separate training obligation candidates also miss.

Who should wait: if you have no employer funding, no current CMMC-adjacent role, and you were pursuing this purely on the strength of the November 2026 date, the rational move is to wait for the Task Force report. Against the Department's stated 60-day reporting clock, that is a weeks-scale decision, not a years-scale one.

→ See exactly what CMMC still requires today, and what the suspension did and didn't change


What training do I need before the CCP exam?

Answer capsule: Official CCP training through a current Approved Training Provider (ATP) listed on the CyberAB Marketplace is mandatory under ISACA's current pathway. Self-study alone does not satisfy that training requirement. Confirm in writing how and when the ATP reports completion before you register.

There is no way around this one. Not a cheaper way, not a faster way, not a "I already know 800-171" way.

If a course is not official CCP training from a listed ATP, it will not unlock the exam, no matter how good it is or how much it costs. This is the single most expensive mistake on the path, and it happens because the terminology changed and stale pages are everywhere.

Old advice versus the current process

This table is the fastest way to tell whether the page you're reading was written before or after the ISACA transition. If a guide contains anything in the left column, treat everything else on it as suspect.

What an older page will tell you — What is actually true in 2026 — How to spot the stale page
What an older page will tell youWhat is actually true in 2026How to spot the stale page
"The Cyber AB administers the CCP exam"ISACA was authorized as the CAICO in December 2025 and fully transitioned CAICO services in April 2026. The Cyber AB remains the Accreditation BodyAny instruction to register for the CCP exam through the Cyber AB
"Find a Licensed Training Provider (LTP)"The current term is Approved Training Provider (ATP)LTP terminology used as current, not historical
"Courseware comes from a Licensed Partner Publisher (LPP)"The current term is Approved Publishing Partner (APP)LPP used without a note that it is the old label
"Exams are delivered through Meazure Learning"The exam vendor is PSI, at test centers or by remote proctoringAny exam vendor other than PSI
"The exam is optional"Optional only if you want the education and not the credential. It is mandatory to certifyCourse pages that blur course completion with certification
"Tier 3 gives you a security clearance"The Tier 3 determination required for CCP does not grant a security clearance and is not for government employmentThe phrase "Tier 3 clearance"
"You must be a U.S. citizen"32 CFR § 170.13(b)(4) provides a DoD-determined equivalence path where a candidate is not eligible for Tier 3A flat citizenship requirement with no citation
"Phase 2 begins November 10, 2026"The transition was suspended July 13, 2026; pending and future milestones are in abeyanceAny live countdown to November 10, 2026
"CMMC now uses NIST SP 800-171 Rev. 3"NIST's current edition is Rev. 3, but Part 170 still makes Rev. 2 the CMMC Level 2 basisTreating NIST publication status as an automatic CMMC rule change
"You have exactly two years to apply after passing"ISACA currently publishes both two years and five yearsA single confident number with no source

Compiled by The Defense Compliance Report. Current-state column verified August 28, 2026 against ISACA's published pages, 32 CFR Part 170 on the federal eCFR, and the Department's July 13, 2026 suspension release.

Verify the provider before you pay, in that order

Two minutes of work protects a four-figure purchase:

  1. Open the CyberAB Marketplace and filter for training providers. Confirm the provider appears as a current ATP.
  2. Screenshot the listing with a visible date, for your own records.
  3. Confirm the exact course title is official CCP training, not a general CMMC awareness course.
  4. Confirm in writing how and when completion is reported, because ISACA validates your registration against that record.
  5. Confirm whether the exam fee or voucher is included or separate.
  6. Get the refund, transfer, and missed-session terms in writing.

A polished website is not a proxy for authorization. Some legitimately authorized providers have thin marketing sites, and some slick sites sell courses that will never get you into a testing center. The Marketplace is the check. The homepage is not.

You now know the training is mandatory and what to verify. The next question is who to buy it from.

→ Verify current ATP status on the official CyberAB Marketplace — then send the six questions above before you pay. The listing verifies authorization; the provider's written answers tell you what the price actually buys.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. We earn nothing from any CMMC training provider, and we sell no training ourselves.


What does it actually cost to become a CCP in 2026?

Answer capsule: ISACA's published exam and application fees total $775 for a member or $960 for a non-member: the CCP exam ($575 member / $760 non-member) plus the $200 certification application processing fee. Mandatory ATP training is provider-priced, and some advertised course prices include an exam voucher while others do not. Annual maintenance is $45 for members and $85 for non-members, plus continuing professional education.

A single "CCP costs $X" total is unreliable unless it identifies the training provider and what the bundle includes. The largest line item is provider-set, so let's separate what's fixed from what isn't.

The fixed ISACA fee stack

Item — ISACA member — Non-member — Verified
ItemISACA memberNon-memberVerified
CCP exam registration$575$760Aug. 28, 2026
Certification application processing fee$200$200Aug. 28, 2026
Published exam + application fee total$775$960Calculated
Annual maintenance, per year$45$85Aug. 28, 2026

That fee stack is the number to hold in your head. Whether it appears as separate charges depends on whether your training price includes an exam voucher.

The variable stack

  • ATP tuition. Our June 29, 2026 snapshot of advertised public CCP course prices ranged from roughly $1,995 to $3,499, depending on provider and delivery format. Bundle contents were not uniform: at least one public price excluded the exam, while other providers advertised an included voucher. This is a dated market snapshot, not a current quote or an apples-to-apples price comparison.
  • ISACA membership dues, if you join to get the member rate
  • Travel and lodging for in-person training or testing
  • Retakes
  • Study materials beyond the official course
  • Time away from billable work
  • CPE activities across the three-year cycle
  • CMMC Delta Training, if you want a Marketplace listing

If—and only if—a quoted course price excludes the exam and application fees, adding the published fee stack produces about $2,770 to $4,274 as a member and $2,955 to $4,459 as a non-member, before membership dues, travel, retakes, and CPE. Do not use those totals for a bundle until you subtract the value of any included exam voucher. They are June-snapshot calculations, not current provider quotes.

The membership break-even nobody computes

Membership changes exactly two CCP numbers, and the arithmetic is simple enough to do on a napkin:

  • Exam: $760 → $575. You save $185.
  • Annual maintenance: $85 → $45. You save $40 per year, or $120 across a three-year cycle.
  • Total CCP-specific first-cycle saving: $305.

ISACA currently lists professional membership at $145 per year plus local chapter dues, and members generally must join a local chapter where one exists. The break-even changes depending on how long you stay a member:

Professional-membership scenario — Base dues — CCP-specific savings — Result before chapter dues
Professional-membership scenarioBase duesCCP-specific savingsResult before chapter dues
Join for the exam year only$145$185 exam discount$40 ahead
Stay a professional member for all three years$435$185 exam discount + $120 maintenance savings$130 behind

So the honest rule is two-part. Joining for the exam year can save money if your required chapter dues are under $40. Maintaining standard professional membership for the full three-year cycle does not pay for itself on CCP fees alone at today's base rate. ISACA also publishes lower-priced recent-graduate and student tiers, but each has eligibility restrictions; confirm the tier and member exam price shown in your own account before budgeting against it. Membership may still be worth it for CPE, other certifications, training discounts, networking, or an employer-paid benefit.

What the course price usually excludes

Before you accept a sticker price as the total, confirm in writing whether it covers the exam fee, the exam voucher, retakes, practice materials, the application fee, ISACA membership, and post-class support. "Cheapest" is a fine strategy when the provider is a current ATP and the exam access is clear in writing. It gets expensive fast when the discount turns out to be a general awareness course.

If your employer is paying

Ask for these in writing before you enroll, because they're much harder to negotiate afterward:

  • Authorization covering both tuition and the exam fee
  • Whether retakes are reimbursable
  • Whether study time counts as work time
  • Whether there's a continued-service agreement attached
  • Whether the role requires active certification or just the training
  • Who pays the annual maintenance fee in years two and three

That last one catches people. A one-time training budget doesn't cover a three-year credential.

→ Run your own numbers in the CCP cost and deadline worksheet — put the provider quote, member status, exact MyISACA eligibility date, evidence route, and maintenance obligations on one page you can hand to whoever approves the spend.

CCP cost and deadline worksheet

Copy this block into your notes or print the page. The point is not to estimate the government-controlled step. The point is to stop losing track of the dates and evidence you do control.

Field — Your entry — Rule or source
FieldYour entryRule or source
Eligibility routeDegree / 2+ years related education / 2+ years related experienceISACA certification requirement
ATP and exact course titleVerify current ATP status in the CyberAB Marketplace
ATP tuition and what it includesGet exam voucher, retake, transfer, and refund terms in writing
Exam fee$575 member / $760 non-memberISACA, verified Aug. 28, 2026
Application processing fee$200ISACA, verified Aug. 28, 2026
Registration dateStarts the six-month exam eligibility period
Exact eligibility expiration shown in MyISACACopy the account date; do not rely on mental calendar math
Target exam dateMust fall inside eligibility
Passing dateStarts the disputed post-exam application window
Conservative application deadlineUse two years unless ISACA confirms a different deadline in writing
Written ISACA clarification savedYes / NoSave the reply with the application record
Tier 3/equivalence statusNot started / in process / satisfiedNo universal official completion time published
Annual CPE plan20 minimum each year; 120 over three yearsBoth thresholds apply
Annual maintenance$45 member / $85 non-memberISACA, verified Aug. 28, 2026

Never put CUI, contract attachments, export-controlled information, Social Security numbers, SF-86 answers, or background-investigation details in this worksheet.


What's on the CCP exam, and the half most candidates under-study

Answer capsule: The CCP exam consists of 170 questions across six job practice domains. The weights are CMMC Ecosystem 5%, Code of Professional Conduct 5%, Governance and Source Documents 15%, Model Construct and Implementation Evaluation 35%, CMMC Assessment Process 25%, and Scoping 15%. The two heaviest domains together account for 60% of the exam.

ISACA publishes the domain weights and the question count. It does not multiply them together. So we did.

# — Domain — Weight — Approximate questions out of 170
#DomainWeightApproximate questions out of 170
1CMMC Ecosystem5%8–9
2CMMC-AB Code of Professional Conduct (Ethics)5%8–9
3CMMC Governance and Source Documents15%25–26
4CMMC Model Construct and Implementation Evaluation35%59–60
5CMMC Assessment Process (CAP)25%42–43
6Scoping15%25–26

Domain names and weights are ISACA's, from the published CCP Exam Content Outline, verified August 28, 2026. The approximate counts are our multiplication of each percentage by 170; the unrounded products total 170 exactly, while the live exam need not distribute items exactly like the rounded ranges.

Domains 4 and 5 alone are roughly 102 questions. Add Scoping and three domains cover about 128 of the 170. If you allocate study time evenly across six domains, you have misallocated roughly a third of your preparation.

The blueprint detail that should change how you study

Read ISACA's task statements underneath those domains, not just the headings. Two of them say something specific that almost nobody acts on.

Under Domain 4, the heaviest domain on the exam, ISACA's own task statement includes a parenthetical: at a minimum, the CCP candidate must be evaluated on CMMC Level 1 practices during the exam.

Under Domain 6, the scoping task is to analyze an environment and generate an appropriate scope for FCI assets — Federal Contract Information, the Level 1 data type — not CUI assets.

So the heaviest domain on the exam guarantees Level 1 practice coverage, and one of the two 15% domains is framed explicitly around FCI scoping.

Most candidates walk in having ground through all 110 security requirements of NIST SP 800-171 Rev. 2, and having treated Level 1's 15 requirements as the easy part they'll pick up along the way. The published blueprint suggests that's backwards. Level 1 and FCI scoping are not the warm-up. They're written into the heaviest domain and a full 15% scoping domain.

We haven't seen that observation published anywhere else, and it takes about four minutes to confirm on ISACA's exam content outline page.

A study allocation that follows the blueprint

  • Source documents first. Domain 3 rewards knowing where a requirement comes from, not just what it says. Read 32 CFR Part 170 and NIST SP 800-171 Rev. 2 properly.
  • Then Domain 4. Practice judging whether evidence is adequate and sufficient. Drill Level 1 practices deliberately rather than assuming them.
  • Then the CAP. Domain 5 walks the four assessment phases and your role inside each one. The current Cyber AB procedural guide is CAP v2.0, dated December 2024. This is process knowledge, not technical knowledge, and technical people routinely underestimate it.
  • Then scoping, with FCI front of mind.
  • Ethics and ecosystem last. They're 10% combined. Don't spend a weekend there.

What we deliberately did not publish about the exam

We are not printing an exam duration, a passing score, a pass rate, or a retake policy on this page. Our own prior verification carried a scaled score range and a passing threshold, and we could not reconfirm those against a current official source in this pass. Rather than repeat a number you might plan around, we'll say plainly: check your current candidate guide and your MyISACA registration materials for the scoring and retake rules that apply to your exam.

If that feels like a gap, compare it to the alternative. Several pages ranking for this term publish a passing score with no source at all.


How do I register and schedule the CCP exam?

Answer capsule: Register and pay through ISACA, then schedule through PSI at an authorized test center or as a remotely proctored exam. Registration is continuous with no windows. You can schedule as early as 48 hours after payment, exam eligibility lasts six months from registration, appointments are typically only visible up to 90 days in advance, and rescheduling without penalty requires at least 48 hours' notice.

Four clocks, and they interact in a way that catches people out.

Clock — Length — Starts — What happens if you miss it
ClockLengthStartsWhat happens if you miss it
Earliest scheduling48 hours after paymentExam payment clearsNothing; you just cannot book sooner
Appointment visibility90 days forwardRollingDistant dates simply will not appear yet. Check back closer
Free rescheduleAt least 48 hours before your slotYour booked appointmentA penalty may apply under the current scheduling policy
Exam eligibility6 monthsThe date you register and payEligibility expires. Do not assume an extension; follow the current MyISACA instructions

Verified against ISACA's published CCP registration and scheduling instructions, August 28, 2026.

Here is the practical trap. The 90-day visibility window and the six-month eligibility window are different lengths. Candidates register early, discover their preferred test center has nothing available, assume they'll book later, and then run out of eligibility. The window isn't generous once you subtract the provider's course schedule and a realistic study period.

Do not register to lock in a price. Register when your training is done and your study plan makes testing inside six months realistic. That is real scarcity, it's on ISACA's own page, and it's the only deadline pressure we'll apply on this page. We're not going to manufacture urgency out of a suspended program milestone.

Before you register, have these settled: training complete, the name on your ISACA account matching your government-issued ID exactly, a decision between test center and remote proctoring, and the current candidate guide saved somewhere you'll find it.


What happens after you pass, and the deadline ISACA publishes two different ways

Answer capsule: Passing the CCP exam does not make you certified. You must still pay a $200 application processing fee, submit an application demonstrating your education or experience, obtain a positively adjudicated Tier 3 background investigation, and agree to the Code of Professional Ethics and the continuing education policy. Certification is issued after those requirements are satisfied.

This is where the open loop from the top of the page closes.

The official source contradicts itself

On August 28, 2026 we read ISACA's "How to get CCP certified" page. It gives the longer window twice near the top: the exam must have been passed within the last five years, and Step 3 says the certification application is due within five years. Lower on that same page, the certification-requirements section gives a two-year window twice.

The main CCP credential page adds a fifth data point and uses the five-year window.

Five years appears three times. Two years appears twice. Two of the conflicting statements sit on the same page, a few hundred words apart.

We are not telling you ISACA is wrong. Documentation drifts, particularly during a program transition, and this is the kind of thing that gets reconciled quietly. What we are telling you is this:

As of August 28, 2026, the certifying body's published guidance says both. We captured both. You can check it yourself in under a minute.

What to actually do about it

  1. Plan against the shorter number. Assume two years from your pass date. If it turns out to be five, you lose nothing by having been early.
  2. Get it in writing. Before you rely on anything longer than two years, email ISACA support and ask for written confirmation of the application window that applies to your exam. Save the reply.
  3. Check your MyISACA account. Whatever deadline your own account displays is more useful to you than either published sentence.
  4. Don't wait on purpose. If you have the required evidence, the conflicting public deadlines create no upside to waiting. Apply.

If we ever see this reconciled on ISACA's pages, we'll update this section and note the date. That's what our corrections policy is for.

Your post-exam evidence folder

Keep all of this in one place from the day you pass:

  • Exam result notice
  • Training completion record and course version
  • Degree, transcript, or experience documentation
  • Application copy and payment receipt
  • Any written deadline clarification you obtained
  • Tier 3 or equivalence correspondence, handled through official channels only
  • The certification decision itself
  • CPE records, starting the day you're certified

You've just seen the one thing on this path that can quietly erase the value of an exam registration costing up to $760. Put your own dates on paper before you forget it.

→ Put your dates into the CCP worksheet now — record the exact MyISACA eligibility expiration, both published application-window readings, your three-year certification cycle, and the CPE due each year.


Do CCP candidates need a security clearance?

Answer capsule: No. CCP candidates must obtain a positively adjudicated Tier 3 background investigation, but 32 CFR § 170.13(b)(3) states directly that this investigation does not result in a security clearance and is not executed for the purpose of government employment. Candidates not eligible for a Tier 3 investigation may meet a DoD-determined equivalent under § 170.13(b)(4).

The phrase "Tier 3 clearance" appears all over the internet. It's wrong, and it sets a materially false expectation for anyone planning a career around it.

Here's what the regulation actually specifies, and this level of detail is not on any competing page we found:

  • The investigation is initiated using Standard Form 86 (SF-86), the Questionnaire for National Security Positions
  • It results in a determination of national security eligibility
  • The positions are designated non-critical sensitive with a risk designation of Moderate Risk
  • That designation is made in accordance with 5 CFR 1400.201(b) and (d) and the investigative requirements of 5 CFR 731.106(c)(2)
  • The regulation states expressly that it will not result in a security clearance and is not being executed for the purpose of government employment

Source: 32 CFR § 170.13(b)(3), read on the federal eCFR August 28, 2026.

Tier 3 determination for CCP — A security clearance
Tier 3 determination for CCPA security clearance
A credential requirement under the CMMC Program RuleAn authorization tied to classified-information access
Does not grant access to classified informationMay permit classified access when sponsorship, need-to-know, and adjudication conditions are met
Does not create government employmentDoes not create government employment either
Initiated on SF-86; non-critical sensitive; Moderate RiskVaries by position sensitivity and investigation tier

If you're not a U.S. citizen

You are not automatically excluded. 32 CFR § 170.13(b)(4) provides that a candidate who is not eligible to obtain a Tier 3 investigation must "meet the equivalent of a favorably adjudicated Tier 3 background investigation," with DoD determining that equivalence for CMMC Program use.

We are not going to tell you whether your specific circumstances will qualify. That's an individual determination and it isn't ours to make. What we can tell you is that a flat "you must be a U.S. citizen" claim, which several provider pages publish, does not match the regulation's text.

Who initiates it, and how long does it take?

Honest answer: the regulation establishes the requirement, and ISACA lists the Tier 3 determination as the final step after your application. We could not find a published, universal processing time from an official source, and we're not going to invent one.

If a guide tells you Tier 3 takes four to six weeks, ask them for the source. We looked for one.

Follow the instructions supplied through the official credential process. If your account doesn't show a next step, request written clarification rather than acting on a forum post.

One safety note, and we mean this. Never enter SF-86 content, Social Security numbers, background investigation details, security question answers, CUI, or sensitive employer information into any third-party tool. The worksheet on this page is for ordinary cost, date, and evidence planning only.


How long does it take to become a CCP?

Answer capsule: There is no defensible universal answer, because the process combines candidate-controlled steps, provider-controlled schedules, and a government background investigation with no published universal processing time. The clearest pre-application countdown you directly control is the six-month exam eligibility window that begins when you register.

A single timeline range implies precision that doesn't exist. We're going to answer this with a table.

Stage — What is actually known — What nobody can honestly promise you
StageWhat is actually knownWhat nobody can honestly promise you
Eligibility evidenceYou can gather it before you enrollHow long a borderline eligibility clarification takes
ATP trainingEach provider publishes its own schedule and access periodA single universal course length
Exam eligibilitySix months from registrationThat you will be ready in any particular number of weeks
SchedulingAppointments are generally visible 90 days outImmediate availability at your preferred center or time
ApplicationRequired after passing; $200One definitive public deadline while ISACA publishes two
Tier 3 or equivalenceRequired; no universal official processing time publishedAny particular completion date
Credential issuanceFollows satisfaction of all requirementsA guaranteed end-to-end date

Compiled by The Defense Compliance Report, August 28, 2026.

A better way to plan. Instead of chasing a total, build backward from the fixed pre-exam clock you control:

  1. Pick a realistic exam date given your study capacity
  2. Register no earlier than six months before it
  3. Finish training before you register, not after
  4. Have your eligibility evidence assembled before your exam date
  5. Apply within days of passing, not months
  6. Treat Tier 3 as an unknown-duration external step and don't promise an employer a start date that depends on it

That plan survives contact with reality. "Three to four months" does not.


How do you keep a CCP certification active?

Answer capsule: CCP certification is valid for three years from the date of issuance under 32 CFR § 170.13(b)(1). Maintaining it requires at least 20 continuing professional education hours annually and 120 hours across the three-year cycle, an annual maintenance fee of $45 for ISACA members or $85 for non-members, and adherence to the Code of Professional Ethics.

The credential is a subscription, not a purchase. Three obligations run continuously:

  • CPE hours. Minimum 20 per year, minimum 120 across the three-year reporting period. Note that 20 per year for three years is 60, which does not satisfy the 120-hour total. Both requirements apply. If CPE hours also satisfy another ISACA certification you hold, they can count toward both.
  • Annual maintenance fee. $45 member, $85 non-member, per year, verified August 28, 2026.
  • Ethics and records. Retain your CPE documentation for at least three years. ISACA conducts CPE audits and can revoke certification for noncompliance.

The third gate: certification does not put you in the Marketplace

Here's the step almost no "how to become a CCP" guide mentions, and it's the one that determines whether work finds you.

The CyberAB Marketplace is the official public directory where Defense Industrial Base contractors go looking for qualified professionals. According to ISACA's own CCP page, to be listed there you need an active CMMC certification (CCP, CCA or LCCA) and you need to have completed Delta Training.

Both. Not one.

So the full ladder looks like this:

Gate — What it takes — What you get
GateWhat it takesWhat you get
1. Sit the examMandatory ATP trainingExam eligibility under the current pathway
2. CertifyPass, $200 fee, education-or-experience evidence, Tier 3/equivalence, ethics and CPE commitmentsThe credential
3. Be findableActive certification and completed Delta TrainingEligibility for a CyberAB Marketplace listing under the current rule set

We could not verify a current Delta Training price and we're not going to guess at one. Check the ISACA store before you budget.

Why Delta Training is worth understanding, not just buying

ISACA describes Delta Training as a focused update course, and it currently requires an active CMMC certification plus completed Delta Training for a CyberAB Marketplace listing. That is a current credentialing and directory rule.

Separately, 32 CFR § 170.10(b)(16) requires the CAICO to require retraining and recertification of CCPs, CCAs, and CCIs after a significant change to CMMC Program requirements, when DoD or the CAICO determines the change is significant.

Do not collapse those into one claim. The regulation does not name Delta Training, does not set its price, and does not promise that every future retraining event will use the same course or format.

Now connect the dots carefully. A CMMC Reform Task Force is reviewing the program. If that review produces changes that DoD or the CAICO classifies as significant, retraining and recertification are not optional. Budget for the possibility of another training requirement, but do not budget a format or price that has not been published. That is the real line-item risk in holding this credential through a moving program.


What to do once you have the CCP

Answer capsule: The CCP opens four practical paths: internal Defense Industrial Base compliance work, readiness and implementation consulting, supervised assessment team participation through a C3PAO, and progression toward the CMMC Certified Assessor credential. Choose based on the role you want, not on the credential you just earned.

Internal DIB compliance. Map your responsibilities to your employer's actual program. Be precise about role boundaries and never let your personal credential get described as an organization's CMMC Status. This path ties the credential to a real employer need instead of a suspended deadline.

Readiness or implementation consulting. Describe your services accurately, never guarantee an assessment outcome, and understand the independence boundary precisely: 32 CFR § 170.8(b)(17) prohibits CMMC Ecosystem members from participating in a Level 2 certification assessment for an organization they served as a consultant to prepare for any CMMC assessment within the previous three years. If you're building a practice, RP and RPO registration is a separate track from your CCP.

Assessment team work. Seek engagements through an authorized C3PAO, and go in knowing the CCA retains final determination authority. This is the path most affected by the Phase 2 suspension, and the one to be most realistic about right now.

The assessor path. CCP is the mandatory prerequisite for CCA. The CCA adds real requirements that catch people at the application stage rather than at enrollment: at least three years of cybersecurity experience, at least one year of assessment or audit experience, and a foundational qualification aligned to at least the Intermediate Proficiency Level for the DoD Cyber Workforce Framework Security Control Assessor (612) work role. Map those before you buy CCA training, not after.

→ The full CCA requirements, including the certification prerequisite that trips up most candidates


Frequently asked questions about becoming a CCP

Is the CCP the same as the Certified Compensation Professional? No. The Certified Compensation Professional is an HR compensation credential administered by WorldatWork. The credential on this page is the CMMC Certified Professional, administered by ISACA in its role as the CAICO for the Department of Defense's Cybersecurity Maturity Model Certification program. Different bodies, different exams, no overlap.

Can anyone take the CCP exam? The exam is open to anyone who completes mandatory training through an Approved Training Provider. Certification is different: ISACA requires documented education or experience. You can pass the exam and still be unable to certify, which is why we recommend confirming eligibility before you buy training.

Can I self-study and skip the course? No. Official training through a current ATP listed on the CyberAB Marketplace is mandatory, and your ATP reports your completion to the CAICO. Self-study is useful preparation. It is not a substitute for the required course, and unauthorized "CMMC prep" courses will not unlock the exam.

Who runs CCP certification now, ISACA or the Cyber AB? ISACA was authorized as the CAICO in December 2025, and CAICO services fully transitioned to ISACA in April 2026. It runs the individual training, examination, and certification pathway; the Cyber AB remains the program's Accreditation Body. A guide that sends you to the Cyber AB to register for the current CCP exam is stale.

How much does the CCP exam cost? $575 for ISACA members and $760 for non-members, verified August 28, 2026. The $200 certification application processing fee is separate and is paid after you pass, bringing the published exam-plus-application total to $775 or $960 before any training cost.

Do I need two years of experience? You need one of three routes: a college degree in a cyber or information technical field, 2+ years of related education experience, or 2+ years of related experience (including military) in a cyber, information technology, or assessment field. That requirement applies to certification, not to sitting the exam, and it is ISACA policy rather than a requirement in 32 CFR § 170.13.

Does military experience count? Yes. ISACA's published wording for the experience route names military experience explicitly among qualifying related experience in a cyber, information technology, or assessment field.

Do I need a security clearance to become a CCP? No. You need a positively adjudicated Tier 3 background investigation, initiated on Standard Form 86. 32 CFR § 170.13(b)(3) states directly that this investigation does not result in a security clearance and is not executed for the purpose of government employment.

Can a non-U.S. citizen become a CCP? The regulation provides an equivalence path. Under 32 CFR § 170.13(b)(4), a candidate not eligible to obtain a Tier 3 investigation must meet a DoD-determined equivalent. Individual eligibility is determined through the official process, so confirm your specific situation with ISACA rather than relying on a general claim either way.

Can a CCP conduct a CMMC Level 2 assessment? A CCP can participate on a Level 2 certification assessment team with CCA oversight, and 32 CFR § 170.13(a) specifies that the CCA makes all final determinations. A CCP cannot independently issue a CMMC Status or Certificate of CMMC Status.

How long do I have to apply after passing the exam? ISACA's published guidance currently states both five years and two years, including two conflicting statements on the same page, which we captured on August 28, 2026. Plan against the shorter window, confirm the deadline shown in your MyISACA account, and request written confirmation from ISACA before relying on anything longer.

How many CPE hours does the CCP require? A minimum of 20 continuing professional education hours per year and 120 hours across the three-year reporting period. Both requirements apply; meeting only the annual minimum for three years does not satisfy the three-year total.

How long is the CCP valid? Three years from the date of issuance, under 32 CFR § 170.13(b)(1). Maintaining it requires CPE, the annual maintenance fee, and adherence to the ethics policy.

Is a CCP required before a CCA? Yes. 32 CFR § 170.13(a) establishes that CCPs are eligible to become CMMC Certified Assessors, and ISACA identifies active CCP status as the prerequisite for the CCA path.

Does passing automatically list me on the CyberAB Marketplace? No. ISACA states that Marketplace listing requires an active CMMC certification and completed Delta Training. Certification alone does not produce a public listing.

Does CMMC use NIST SP 800-171 Revision 2 or Revision 3? Revision 2 is still the CMMC-controlling Level 2 version. NIST has superseded it with Revision 3 in the NIST publication library, but 32 CFR Part 170 still incorporates Rev. 2. Revision 3 does not become the CMMC assessment basis unless the controlling rule, clause, deviation, or contract changes.

Did the July 2026 Phase 2 suspension cancel the CCP? No. The suspension paused the planned Phase II expansion of new Level 2 (C3PAO) and Level 3 procurement designations. 32 CFR Part 170 remains in effect, the credential pathway remains active, and Phase I self-assessment requirements continue where the governing instrument requires them. What changed is the deadline-driven demand argument, not the credential's existence.

What if the CMMC program changes again? 32 CFR § 170.10(b)(16) requires the CAICO to mandate retraining and recertification of CCPs, CCAs and CCIs when DoD or the CAICO determines a program change is significant. A Task Force recommendation alone is not the trigger; the significance determination is. Budget for the possibility, not an invented price or schedule.


Your next step

If you're pursuing the credential:

If you're a defense contractor choosing a provider for your company:

Need help deciding what type of CMMC provider you need? Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.

→ Find My CMMC Path

Already know the category and need scoped provider options? Request a quote without sending CUI. Still organizing the work? Start with the 32-point CMMC readiness checklist, see who to hire first, and use the CMMC Level 2 cost guide before you approve a budget.

Do not submit CUI, drawings, export-controlled information, contract attachments, or sensitive system details.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. We earn nothing from any CMMC training provider named or linked on this page.


Primary sources

For how we distinguish regulation, current-state facts, provider statements, and editorial judgment, see our methodology, editorial standards, editorial and advertising policy, and corrections policy.


The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source support for regulatory claims and mapping a contractor's required status, CUI scope, assessment type, and timeline to the right provider category before expensive work begins.

By The Defense Compliance Report Editorial Team · Last reviewed August 2026 · Last verified August 28, 2026

Fees, program requirements, provider statuses, and phase timing change. Verify current ISACA requirements and CyberAB Marketplace status before you register or pay. This guide is educational research, not legal, contractual, employment, security-clearance, or compliance advice. Direct credential-eligibility and application questions to ISACA. Confirm contract-specific scope and applicability with a qualified CMMC practitioner or federal-contracts attorney. See our editorial standards, methodology, and corrections policy.