All Posts Next

The Cyber AB (Cybersecurity Maturity Model Certification Accreditation Body, Inc.) is the single accreditation body for the Department of Defense CMMC Program. Under 32 CFR Part 170 it authorizes and accredits the C3PAOs that perform Level 2 certification assessments. It does not write the CMMC requirements, choose your level, or award contracts. DoD does.

If you have searched "cyber ab" or "cyberab" because a prime contractor, a contracting officer, or a vendor mentioned it, you are in the right place. The Cyber AB sits in the middle of the CMMC ecosystem, and understanding exactly what it controls (and what it does not) is the fastest way to avoid hiring the wrong kind of help. This guide walks through the Cyber AB's legal role under the CMMC rule, the roles it authorizes, how to use the Cyber AB Marketplace to verify a provider, and where the DoD CIO and DCMA DIBCAC fit. Every factual statement about the program below comes from the federal rule itself or from the Cyber AB's own published pages, and the sources are linked so you can check them.

What Is the Cyber AB?

The Cyber AB is the operating name of the Cybersecurity Maturity Model Certification Accreditation Body, Inc. On its About Us page, the organization describes itself as "the official accreditation body of the Cybersecurity Maturity Model Certification (CMMC) ecosystem and the sole authorized non-governmental partner of the U.S. Department of Defense (DoD) in implementing and overseeing the CMMC conformance regime."

A few facts about the organization itself, all from that same page:

  • It was founded in January 2020 as The CMMC Accreditation Body, Inc., which is why older articles and forum posts still call it the "CMMC-AB."
  • It is a Maryland-based, nonprofit, 501(c)(3) tax-exempt organization.
  • It states that it does not receive funding from DoD or other taxpayer resources. Its contract with DoD is described as a "no cost" agreement, and its primary revenue comes from application and renewal fees paid by ecosystem participants.
  • Its support to CMMC runs through a direct contract with the CMMC Program Management Office (PMO) within DoD.
  • A full-time professional staff runs the organization, overseen by a Board of Directors whose members serve in a voluntary, uncompensated capacity.

The Cyber AB also states that, as of January 2025, it serves as the exclusive accreditation body for the Secure Controls Framework (SCF) Conformity Assessment Program. That is a separate program from CMMC. For a defense contractor, the CMMC role is the one that matters.

The Cyber AB's role under 32 CFR Part 170

The CMMC Program is codified at 32 CFR Part 170. The rule does not use the brand name "Cyber AB." It uses the defined term "Accreditation Body." Section 170.4 defines the Accreditation Body as "the one organization DoD contracts with to be responsible for authorizing and accrediting members of the CMMC Assessment and Certification Ecosystem." The same definition says the Accreditation Body must be approved by DoD, and that at any given point in time there will be only one Accreditation Body for the DoD CMMC Program.

Section 170.8 then spells out what that one organization must do. The core responsibility is stated in 170.8(a): the Accreditation Body "is responsible for authorizing and ensuring the accreditation of CMMC Third-Party Assessment Organizations (C3PAOs)" in accordance with ISO/IEC 17020:2012(E). It also establishes the C3PAO authorization requirements and the C3PAO Accreditation Scheme and submits both to the CMMC PMO for approval.

The rest of 170.8(b) is a long list of obligations. The ones that affect contractors most directly are:

  • Accreditation standards. The Accreditation Body must achieve full compliance with ISO/IEC 17011:2017(E) within 24 months of DoD approval. Until then, it authorizes C3PAOs that meet the requirements of 170.9 and requires every C3PAO to achieve ISO/IEC 17020 within 27 months of authorization. This is why you see both "authorized" and "accredited" C3PAOs.
  • A public list of C3PAOs. Under 170.8(b)(8), it must "establish, maintain, and manage an up-to-date list of authorized and accredited C3PAOs on a single publicly accessible website." In practice, that is the Cyber AB Marketplace, covered below.
  • Its own security. The Accreditation Body must itself obtain a Level 2 certification assessment conducted by DCMA DIBCAC, performed every three years, and its board, staff, and assessor staff must complete Tier 3 background investigations.
  • Appeals. It must maintain an internal appeals process and render a final decision on all elevated appeals. Under 170.9(b)(19), if a contractor or a C3PAO is not satisfied with a C3PAO's handling of an assessment appeal, either one can elevate the matter to the Accreditation Body for final determination.
  • Conduct rules for the whole ecosystem. Under 170.8(b)(17), it must maintain Conflict of Interest, Code of Professional Conduct, and Ethics policies, approved by the CMMC PMO, that apply across the ecosystem. More on these below, because they are your best protection when you hire help.
  • Oversight of the certification side. It must ensure that the CMMC Assessors and Instructors Certification Organization (CAICO) is compliant with ISO/IEC 17024:2012(E).

What the Cyber AB Does Not Do: Cyber AB vs DoD

Much of the confusion about the Cyber AB comes from assuming it runs CMMC. It does not. The rule draws clear lines between the Accreditation Body and the Department, and knowing those lines helps you ask the right questions of any vendor.

It does not set the security requirements

Section 170.1(c) states that the CMMC Program uses the security standards in 48 CFR 52.204-21, NIST SP 800-171 Revision 2, and selected requirements from NIST SP 800-172. Those requirements come from federal regulation and NIST publications, not from the Cyber AB. Section 170.6(a) assigns the Office of the DoD CIO's Deputy CIO for Cybersecurity responsibility for "establishing CMMC assessment, accreditation, and training requirements as well as developing and updating CMMC Program policies and implementing guidance."

It does not decide which CMMC level your contract needs

Section 170.5(b) is direct: "Program managers and requiring activities are responsible for identifying the CMMC Status that will apply to a procurement." Your required level comes from the solicitation and contract, and it flows down to subcontractors under 170.23. If a vendor tells you the Cyber AB has assigned you a level, that is not how the rule works.

It does not award or cancel contracts

Contract eligibility rests on the CMMC Status recorded in the Supplier Performance Risk System (SPRS), plus the required affirmations. The rule gives DoD, not the Accreditation Body, the power to act when a status is in doubt. Under 170.6(e), the CMMC PMO investigates indications that an active CMMC Status has been called into question. Under 170.6(f), if a later DCMA DIBCAC assessment shows the required status was not achieved or maintained, "the DIBCAC results will take precedence over any pre-existing CMMC Status recorded in SPRS," and standard contractual remedies apply to an active contract.

It does not assess your company itself

The Cyber AB authorizes and accredits the organizations that do the assessing. Level 2 certification assessments are conducted by C3PAOs (170.17), and Level 3 certification assessments are conducted by DCMA DIBCAC (170.18). Level 1 and Level 2 self-assessments are performed by the contractor and submitted in SPRS (170.15 and 170.16).

DoD oversees the Cyber AB, not the other way around

Section 170.6(b) makes the CMMC PMO responsible for "monitoring the CMMC AB's performance of roles assigned in this rule." Section 170.6(c) goes further: the PMO retains the prerogative "to review decisions of the CMMC Accreditation Body" and to evaluate any alleged conflicts of interest. So when people search "cyber ab vs dod," the short answer is that DoD owns the program and the rules, and the Cyber AB is the contracted accreditation body operating inside those rules under DoD oversight.

One more point of confusion worth clearing up. The Cyber AB's own FAQ page states that other organizations that use "CMMC" in their name or marketing "are independent companies and organizations that are not officially endorsed CMMC entities and do not operate under contract with DoD in support of the CMMC initiative." A name that sounds official is not a credential.

CMMC Ecosystem Roles the Cyber AB Authorizes and Lists

The CMMC ecosystem has two kinds of roles: roles defined in 32 CFR Part 170, and designations the Cyber AB runs as its own programs. Knowing which is which tells you what a credential actually means.

Roles defined in the CMMC rule

C3PAO (CMMC Third-Party Assessment Organization). Section 170.9(a) defines C3PAOs as "organizations that are responsible for conducting Level 2 certification assessments and issuing Certificates of CMMC Status to OSCs based on the results." They must be authorized or accredited by the Accreditation Body. Before a C3PAO can be authorized, the rule requires a Foreign Ownership, Control or Influence (FOCI) review and a Level 2 certification assessment of the C3PAO itself, conducted by DCMA DIBCAC. A C3PAO assessment team must include at least two people: a Lead CCA and at least one other CCA. C3PAOs submit assessment results into the CMMC instantiation of eMASS, which transmits them to SPRS.

CCA (CMMC Certified Assessor). Under 170.11, CCAs conduct Level 2 certification assessments in support of a C3PAO. A CCA must first be a CCP, with at least 3 years of cybersecurity experience and at least 1 year of assessment or audit experience, and must complete a Tier 3 background investigation. CCA certification is valid for 3 years from issuance. A Lead CCA needs at least 5 years of cybersecurity experience, 5 years of management experience, and 3 years of assessment or audit experience.

CCP (CMMC Certified Professional). Under 170.13, a CCP "completes rigorous training on CMMC and the assessment process to provide advice, consulting, and recommendations to their OSA clients." CCPs can take part in Level 2 certification assessments, but only "with CCA oversight where the CCA makes all final determinations."

CMMC Instructors (PI and CCI). Section 170.12 covers Provisional Instructors and CMMC Certified Instructors, who teach CCP and CCA candidates. The rule says instructors may not provide CMMC consulting services while serving as a CMMC instructor.

CAICO. Section 170.10 makes the CMMC Assessor and Instructor Certification Organization "responsible for training, testing, authorizing, certifying, and recertifying CMMC assessors, instructors, and related professionals," and states that only the CAICO may make decisions on examination certifications. The Cyber AB's Ecosystem Roles page states that ISACA is now the authorized CAICO for the CMMC program and directs anyone interested in CCP, CCA, Lead CCA, or CCI credentials to ISACA.

Cyber AB designations: RP, RPA, and RPO

The consulting side of the ecosystem is where most contractors start, and it runs through Cyber AB designations rather than rule-defined roles.

CMMC Registered Practitioner (RP) and Registered Practitioner Advanced (RPA). The Cyber AB describes Registered Practitioners as "implementers that are providing consultative preparation services" to Organizations Seeking Certification. Its Consulting and Implementation page lists the RP training modules, which cover the CMMC model, the ecosystem, Federal Contract Information, scoping, and Level 1 implementation. The RPA track adds Controlled Unclassified Information, Level 2 scoping, the assessment process, and POA&M topics, and requires the applicant to be an active RP who meets additional experience requirements. The Cyber AB terminology page is explicit that "Any level of RP cannot participate on assessment teams."

RPO. The Cyber AB states that an RPO "delivers a non-certified advisory service through the employment of RPs," that RPOs are "consultative organizations or MSPs," and that they "do not conduct Certified CMMC Assessments." The Cyber AB pages use both "Registered Practitioner Organization" and "Registered Provider Organization" for this designation. To be designated, an RPO must register with and receive authorization from the Cyber AB, pass an organizational background check, associate at least one Registered Practitioner, and sign the Code of Professional Conduct and an RPO Agreement.

Training and publishing organizations

According to the Cyber AB's Training and Instruction page, Approved Training Providers (ATPs, formerly Licensed Training Providers) are organizations approved by the CAICO to develop and deliver the CMMC certification programs, and Approved Publishing Partners (APPs, formerly Licensed Publishing Partners) are organizations approved by the CAICO to develop the certification curriculum. If you are sending staff to CCP or CCA training, these are the organizations to look for.

Why the separation of roles matters to you

The rule deliberately separates preparing a company from certifying it. Under 170.8(b)(17), the Code of Professional Conduct must "prohibit CMMC Ecosystem members from participating in the Level 2 certification assessment process for an assessment in which they previously served as a consultant to prepare the organization for any CMMC assessment within 3 years." The Cyber AB repeats the same principle on its consulting page: individuals holding both consulting and assessor designations cannot assess a company they previously helped with implementation. The practical takeaway is that your consultant and your assessor should be different organizations, and any vendor who offers to both prepare you and certify you is describing an arrangement the rule prohibits.

How to Verify a Provider in the Cyber AB Marketplace

The Cyber AB describes the CMMC Marketplace as "an online platform established by The Cyber AB to connect organizations seeking CMMC services with C3PAOs and certified assessors." It is also how the Accreditation Body meets its obligation under 170.8(b)(8) to publish an up-to-date list of authorized and accredited C3PAOs. The Marketplace lives at cyberab.org/Catalog. It is a verification tool, not an endorsement, and a listing tells you what role an organization or person holds, not how good their work is.

When we loaded the Marketplace while preparing this guide, it offered a name lookup plus filters for ecosystem role (including CCP, RP, CCA, LCCA, RPO, RPA, PI, C3PAO, ATP, and APP), years in business, scope of services, country, state, and whether the organization supports remote services. A simple verification routine looks like this:

  1. Search the exact legal or trade name. Use the lookup box. If the organization uses a different trade name, ask the vendor which name appears in its listing.
  2. Match the role to the claim. A consulting firm should appear as an RPO. An individual consultant should appear as an RP or RPA. A firm offering your Level 2 certification assessment must appear as a C3PAO. The Cyber AB FAQ states that authorized C3PAOs are posted on the Marketplace as "Authorized C3PAOs" and that "Only Authorized C3PAOs can conduct CMMC assessments for certification."
  3. Check individuals, not just the company. Ask for the names of the practitioners or assessors who will actually work on your engagement and look them up. CCP and CCA credentials are issued through the CAICO, and the Cyber AB states that holders are listed on the Marketplace once certified.
  4. Keep a record. Save a screenshot of the listing with the date in your vendor due diligence file. It supports your own supply chain risk documentation.
  5. Report misrepresentation. The Cyber AB's complaint process covers alleged violations of the Code of Professional Conduct by any ecosystem member. It asks complainants to first try to resolve an issue with the organization directly, then submit through the Cyber AB contact page or by email to complaints@cyberab.org.

This check matters because the rule itself requires honesty about credentials. The Code of Professional Conduct described in 170.8(b)(17) must require ecosystem members "to represent themselves and their companies accurately," including "not misrepresenting any professional credentials or status, including CMMC authorization or CMMC Status, nor exaggerating the services that they or their company are capable or authorized to deliver."

Where the DoD CIO and DCMA DIBCAC Fit

Two government organizations sit above and beside the Cyber AB. Knowing their roles completes the picture.

DoD CIO and the CMMC PMO

The DoD CIO, through its Office of the Deputy CIO for Cybersecurity, "provides oversight of the CMMC Program" under 170.6(a). The CMMC PMO monitors the Accreditation Body's performance, can review its decisions, sponsors the Defense Counterintelligence and Security Agency (DCSA) FOCI risk assessments and Tier 3 background investigations for ecosystem members, and investigates questions about a contractor's CMMC Status. The Cyber AB's own contract runs with this office. Program policy, guidance, and requirement changes come from DoD.

DCMA DIBCAC

The Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) is the government's own assessment team. Under 170.7, DIBCAC assessors:

  • Conduct Level 3 certification assessments and issue Certificates of CMMC Status for Level 3.
  • Conduct Level 2 certification assessments of the Accreditation Body and of prospective C3PAOs' information systems that process, store, or transmit CUI.
  • Conduct an assessment of a contractor when requested by the CMMC PMO.
  • Identify earlier DIBCAC High Assessments that qualify under 170.20 and verify that SPRS reflects the resulting status.

Level 3 has a prerequisite that ties the pieces together. Under 170.18, a contractor must already hold a CMMC Status of Final Level 2 (C3PAO) on the Level 3 assessment scope before DIBCAC will perform the Level 3 certification assessment. In other words, a Cyber AB authorized C3PAO handles the Level 2 certification, and DIBCAC handles Level 3 on top of it.

The chain in one view

  • DoD (DoD CIO and CMMC PMO): writes and oversees the program, sets requirements, and reviews the Accreditation Body.
  • Program managers and requiring activities: pick the CMMC Status required for each procurement.
  • The Cyber AB: authorizes and accredits C3PAOs, maintains the public list, enforces ecosystem conduct policies, and decides elevated appeals.
  • CAICO (ISACA, per the Cyber AB): trains, tests, and certifies CCPs, CCAs, and instructors.
  • C3PAOs with CCAs and CCPs: perform Level 2 certification assessments and issue Certificates of CMMC Status.
  • DCMA DIBCAC: performs Level 3 certification assessments and assesses C3PAOs and the Accreditation Body.
  • RPOs and RPs: help contractors prepare, and do not assess.
  • The contractor: implements the requirements, performs any required self-assessments, submits results and affirmations in SPRS, and flows requirements down to subcontractors.

How to Use the Cyber AB When Choosing CMMC Help

Once the roles are clear, choosing help becomes a sequence of practical decisions.

Step 1: Confirm what your contracts actually require

Start with the solicitation or contract clause, because 170.5(b) puts the choice of CMMC Status with the program manager or requiring activity. If you only handle Federal Contract Information, your path likely starts with a CMMC Level 1 self-assessment, which 170.15 requires annually with results in SPRS. If you handle Controlled Unclassified Information, the contract will call for Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC). Subcontractors inherit requirements through the flowdown rules in 170.23.

Step 2: Hire preparation help from the consulting side of the ecosystem

Readiness work, gap assessments, scoping, remediation planning, and documentation such as your System Security Plan belong with a consultant: an RPO staffed with Registered Practitioners, or CCPs acting in an advisory capacity as 170.13 describes. Verify the firm and the individuals in the Marketplace before you sign. If you are weighing firms, our overview of what to expect from a CMMC consultant covers the questions worth asking.

Step 3: Decide whether a self-assessment is enough

Some Level 2 contracts allow a self-assessment under 170.16, repeated every three years with results in SPRS. Our guide to the CMMC Level 2 self-assessment explains how that path works and where it tends to go wrong. A self-assessment still has to be accurate, and 170.6(f) makes clear that a later DIBCAC assessment can override a status recorded in SPRS.

Step 4: Choose your assessor separately

If your contract requires Level 2 (C3PAO), pick an authorized or accredited C3PAO from the Marketplace, and keep it independent of the firm that prepared you. Our C3PAO selection guide walks through how to compare assessment organizations and plan the engagement.

Step 5: Watch for red flags

  • A firm that offers to prepare you and then certify you.
  • A vendor claiming the Cyber AB "certified" or "approved" your environment. The Cyber AB authorizes and accredits C3PAOs; the C3PAO or DIBCAC performs the certification assessment.
  • A vendor whose Marketplace listing does not match the role it claims, or who cannot name the credentialed individuals doing the work.
  • An organization implying official status because "CMMC" appears in its name. The Cyber AB FAQ says those organizations are not officially endorsed CMMC entities.

Where Petronella Technology Group, Inc. fits

Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization (RPO #1449), and our team members are CMMC Registered Practitioners. Founder Craig Petronella is a CMMC Registered Practitioner (CMMC-RP) who also holds the CCNA and CWNE certifications and is a Digital Forensic Examiner. We sit on the preparation side of the ecosystem described above: readiness, scoping, remediation, and documentation. Consistent with the RPO role, we do not perform CMMC certification assessments. When you are ready for a Level 2 certification assessment, you engage an independent C3PAO, and our job is to have you ready for it. You can learn more about the RPO role on our CMMC RPO page.

Cyber AB FAQ

Is the Cyber AB part of the Department of Defense?

No. The Cyber AB is a Maryland-based 501(c)(3) nonprofit that supports the CMMC Program under a contract with the CMMC Program Management Office inside DoD. It describes itself as the sole authorized non-governmental partner of DoD for CMMC, and it states that it does not receive DoD funding. DoD, through the DoD CIO, oversees the program and can review the Accreditation Body's decisions.

Does the Cyber AB certify my company?

Not directly. Under 32 CFR 170.9, an authorized or accredited C3PAO conducts the Level 2 certification assessment and issues the Certificate of CMMC Status. Level 3 certification assessments are conducted by DCMA DIBCAC. Level 1 and Level 2 self-assessments are performed by the contractor and entered in SPRS. The Cyber AB authorizes and accredits the C3PAOs that do Level 2 certification work.

What is the difference between an RPO and a C3PAO?

An RPO is a consulting organization that employs Registered Practitioners and helps contractors prepare. The Cyber AB states that RPOs do not conduct certified CMMC assessments. A C3PAO is authorized or accredited by the Cyber AB to conduct Level 2 certification assessments and issue Certificates of CMMC Status. The two roles are kept separate by conflict of interest rules.

Can the same company help me prepare and then assess me?

No. 32 CFR 170.8(b)(17) requires the Code of Professional Conduct to prohibit ecosystem members from participating in a Level 2 certification assessment for an organization they served as a consultant within the prior 3 years. The Cyber AB also states that individuals holding both consulting and assessor designations cannot assess a company they helped implement.

How do I check whether a CMMC provider is legitimate?

Search the provider's name in the Cyber AB Marketplace at cyberab.org/Catalog and confirm the listed ecosystem role matches what the provider claims, such as RPO, RP, C3PAO, CCA, or CCP. The Accreditation Body is required by 32 CFR 170.8(b)(8) to keep an up-to-date public list of authorized and accredited C3PAOs.

Who issues CCP and CCA certifications?

The CMMC Assessor and Instructor Certification Organization (CAICO). Under 32 CFR 170.10, the CAICO trains, tests, certifies, and recertifies CCPs, CCAs, and CMMC Certified Instructors. The Cyber AB website states that ISACA is now the authorized CAICO for the CMMC program.

What happens if a provider misrepresents its CMMC credentials?

The Code of Professional Conduct required by 32 CFR 170.8(b)(17) requires ecosystem members to represent themselves accurately and not exaggerate the services they are authorized to deliver. The Cyber AB runs a formal complaint process for alleged Code of Professional Conduct violations, which accepts written complaints through its website or at complaints@cyberab.org.

Get Ready for Your CMMC Assessment

The Cyber AB tells you who is authorized to do what. It does not tell you whether your environment is ready. If you want a clear read on where you stand against your contract's CMMC requirements, what is in scope, and what to fix before a C3PAO or a self-assessment, schedule a CMMC readiness consultation with Petronella Technology Group, Inc. We will review your contract requirements, your current documentation, and your environment, and give you a prioritized plan to get assessment-ready.

Related reading

Get the CMMC Compliance Guide

Free, practical, and specific to regulated environments. We will email it to you.

No spam. Unsubscribe anytime.

Need help implementing these strategies? Our cybersecurity experts can assess your environment and build a tailored plan. Prefer to write? Send us a message.
Call Penny 919-348-4912

About the Author

Craig Petronella, CEO and Founder of Petronella Technology Group
CEO, Founder & AI Architect, Petronella Technology Group

Craig Petronella founded Petronella Technology Group in 2002 and has spent 30+ years professionally at the intersection of cybersecurity, AI, compliance, and digital forensics. He holds the CMMC Registered Practitioner credential issued by the Cyber AB and leads Petronella as a CMMC-AB Registered Provider Organization (RPO #1449). Craig is an NC Licensed Digital Forensics Examiner (License #604180-DFE) and completed MIT Professional Education programs in AI, Blockchain, and Cybersecurity. He also holds CompTIA Security+, CCNA, and Hyperledger certifications.

He is an Amazon #1 Best-Selling Author of 15+ books on cybersecurity and compliance, host of the Encrypted Ambition podcast (95+ episodes on Apple Podcasts, Spotify, and Amazon), and a cybersecurity keynote speaker with 200+ engagements at conferences, law firms, and corporate boardrooms. Craig serves as Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine and is a guest lecturer at NCCU School of Law. He serves as a digital forensics expert witness for law firms on matters involving cybercrime, cryptocurrency fraud, SIM-swap attacks, and data breaches.

Under his leadership, Petronella Technology Group has served hundreds of regulated SMB clients across NC and the southeast since 2002, earned a BBB A+ rating every year since 2003, and been featured as a cybersecurity authority on CBS, ABC, NBC, FOX, and WRAL. The company leverages SOC 2 Type II certified platforms and specializes in AI implementation, managed cybersecurity, CMMC/HIPAA/SOC 2 compliance, and digital forensics for businesses across the United States.

CMMC-RP NC Licensed DFE MIT Certified CompTIA Security+ Expert Witness 15+ Books
Related Service
Achieve Compliance with Expert Guidance

CMMC, HIPAA, NIST, PCI-DSS - we have 80% of documentation pre-written to accelerate your timeline.

Learn About Compliance Services
All Posts Next
Questions about this topic? Talk to our team. Call Penny 919-348-4912 Message us