CMMC Third-Party Assessment Organization
Also known as: C3PAO
A CMMC Third-Party Assessment Organization (C3PAO) is an entity accredited by the Cyber AB to perform CMMC Level 2 assessments on behalf of DoD contractors. C3PAOs are not used at Level 1, Level 1 is exclusively self-assessed, and they are not used at Level 3, which is assessed by DIBCAC. The DoD suspension of CMMC Phase 2 on July 13, 2026 paused the rollout that would have required C3PAO assessments on covered contracts beginning November 10, 2026, and the memo cites severe shortages in third-party assessment capacity as one reason for the review.
Related terms
- Cyber AB
The Cyber AB is the sole accreditation body for the CMMC ecosystem. It is responsible for authorizing and accrediting C3PAOs, Certified CMMC Assessors (CCAs), Certified CMMC Professionals (CCPs), and Registered Practitioners (RPs).
- CMMC Level 2
CMMC Level 2 is the middle CMMC certification tier, covering contractors who handle Controlled Unclassified Information (CUI). It requires implementing all 110 controls of NIST SP 800-171 and undergoing either a self-assessment or a triennial assessment by a CMMC Third-Party Assessment Organization (C3PAO) depending on the program's prioritization. DoD suspended CMMC Phase 2 on July 13, 2026, which paused the phased arrival of the C3PAO assessment requirement pending a program review, while the obligations that drive Level 2 in the first place, DFARS 252.204-7012 and NIST SP 800-171, are unaffected.
- Defense Industrial Base Cybersecurity Assessment Center
The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) is the Defense Contract Management Agency (DCMA) component that conducts NIST SP 800-171 assessments and CMMC Level 3 assessments on DoD contractors. DIBCAC assessments are the highest assurance level in the program.
- CMMC Phase 2 Suspension
The CMMC Phase 2 suspension is the Department of Defense action of July 13, 2026 that halted Phase 2 of the CMMC rollout and opened a 60 day top to bottom review of the program, under a memo signed by DoD Chief Information Officer Kirsten Davies. Phase 2 would have required third-party C3PAO assessments across contracts involving sensitive but unclassified information starting November 10, 2026, so that date is no longer an operative deadline.