Please see Todd Gagnon’s response. 😒 𝐒𝐀𝐃𝐋𝐘, 𝐓𝐇𝐈𝐒 𝐈𝐒 𝐍𝐎𝐓 𝐀𝐍 𝐀𝐏𝐑𝐈𝐋 𝐅𝐎𝐎𝐋’𝐒 𝐉𝐎𝐊𝐄 😒 Over the last 2 weeks, our Cybersecurity Maturity Model Certification (“CMMC”) 3rd Party Assessment Organization (“C3PAO”) line of business has seen a heavy increase in demand for CMMC Level 2 Certification Assessments. Some of the big primes are recompeting their subcontracts and forcing subcontractors to get CMMC Level 2 certified before October 1 (i.e., the new fiscal year). So, despite the fact that the United States Department of War (“DoW”) will be phasing CMMC requirements into its contracts over the next 3 years, at least some prime contractors aren’t waiting that long. The problem? There are currently ~760 assessors. DoW estimates that about 78,000 companies will need CMMC 3rd party assessments. At least 2500-3000 assessors are needed to support this level of demand if the assessments are spread across 3 years. The ecosystem can’t support primes front-loading the demand. 𝐓𝐡𝐞 𝐂𝐌𝐌𝐂 𝐞𝐜𝐨𝐬𝐲𝐬𝐭𝐞𝐦 𝐧𝐞𝐞𝐝𝐬 𝐚𝐬𝐬𝐞𝐬𝐬𝐨𝐫𝐬. 𝐍𝐎𝐖. One of the big hold-ups in adding assessors to the ecosystem is that assessors must “pass” a Tier 3 Background Screening administered by the Defense Counterintelligence and Security Agency (DCSA). It currently takes 12-18 months for new CMMC assessors to get a determination from DCSA. So, smart people who want to become assessors sit for the CMMC Certified Assessor class and exam while they wait for their Tier 3 to process. This allows them to hit the ground running as CCAs the moment the Tier 3 is complete. Yesterday, ISACA, the new CMMC Assessor and Instructors Certification Organization (CAICO), announced that they are stopping that practice. Instead of being able to sit for the CCA exam while their Tier 3 is pending, students will have to wait until their Tier 3 successfully completes. That disincentivizes current CCPs from taking CCA training. Why would someone take training 6-9 months before they sit for an exam? ISACA has also announced that a new CCA exam, and CCA curriculum, are coming in 9-12 months. Right when current CCPs’ Tier 3s will come in. Oh, and ISACA will exclusively control the curriculum. So, say goodbye to any semblance of competition that would improve quality, spur innovation, or reduce cost. Oh, and ISACA is also taking over asynchronous training at some point in the future. And making other changes that will further hurt training providers. But they won’t give details. The net result? ISACA is disincentivizing taking and offering training. We’ll have fewer assessors, RIGHT when the ecosystem needs these the most. These decisions: 🔵 hurt defense contractors and C3PAOs by decreasing supply of CCAs; 🔵 hurt DoW by reducing competition; and, 🔵 hurt the training providers and curriculum developers who invested so much time, effort, and money to build the ecosystem into the very thing that ISACA coveted. The only one who benefits from this is ISACA.
If only someone had been warning the DIB that this was coming for the last 5 years! The bottleneck won’t be assessors, it will be implementers.
Side question, why is the Tier 3 process taking 12-18 months, on the NISP side this is a ~3-6 month process. Something is delaying the process.
The real question is to whom do we appeal the ISACA decisions and questionable practices? Is it CyberAB? DoD/DoW CIO? Congress? The circumstances under which ISACA was selected were completely opaque and highly suspect given there was no apparent public bidding process, open comment period, or opportunity for the practitioners in the ecosystem to weigh in on the matter.
And let’s not forget all the time these companies need to prepare… And hopefully with credentialed CMMC consultants, who can prepare them to pass assessment. #falsestarts
James Goepel Lots of comments below about the DIB not being prepared and the expense of C3PAO assessments. The C3PAO assessment cost is significant, but not to the extent that companies are unprepared for assessment. The lack of DIB preparedness only reinforces the DoD perspective that the DIB has been falsely claiming compliance with DFAR 252.204-7012 cybersecurity for years, placing Controlled Unclassified Information (CUI) at risk.
Great take. We’re actually not seeing an assessment backlog from our C3PAO seat. We are scheduling plenty of assessments but the current gap we are seeing is readiness not assessor bandwidth. We’re ready to go as a C3PAO. Plenty of assessors, plenty of bandwidth. Need OSCs who are ready. The mission continues.
This is a powerful "Ground Truth" breakdown of the current bottleneck. By de-linking the training from the Tier 3 wait period, the ecosystem isn't just slowing down—it's stalling the professional growth of the very practitioners the Department of War is counting on to secure the DIB. Efficiency shouldn't be a casualty of centralization. If we don't find ways to keep candidates engaged and developing their skills during that 12-month background check window, the "Assessor Gap" will only widen.
My assumption is that if ones has their CCP, it’s just a matter of just reviewing, I would hope their isn’t this long drawn out process
James Goepel, I responded to a different post in a similar way, but wanted to do so here as well because I appreciate you raising these concerns and the broader discussion they’ve prompted. I want to clarify one specific point from earlier this week. My interpretation of the CFR, as it related to applying a Tier 3 requirement within the CCA certification pathway, was incorrect—and I take responsibility for that. To be clear for the community: we have not changed the certification process. There are no new technical checks or requirements preventing candidates from progressing. If a candidate passes the CCP exam and completes CCA training, they remain eligible to sit for the CCA exam, consistent with prior practice. We have engaged the PMO to ensure alignment on the intent behind the CFR language and will share any updates if that interpretation evolves. At present, there is no change to the pathway. I recognize the concern this created, particularly given how important predictability and trust are across the ecosystem. As we move through the CAICO transition, my focus is on being transparent, correcting quickly when needed, and maintaining continuity wherever possible. Regards, Todd