CMMC Authorities
CMMC Organizations
CMMC Individuals
CMMC LRP Drivers Pt. 1
CMMC LRP Drivers Pt. 2
100

Authorized to certify CMMC assessors and instructors and are required to achieve and maintain ISO/IEC 17024 accreditation requirements.  Recently switched to ISACA.

What is the CMMC Assessors and Instructors Certification Organization (CAICO)?

100

Organization authorized to provide recommendations and consulting advice about CMMC Assessment preparation.

Who are Registered Practitioner Organizations (RPOs)?

100

Individuals credentialed as a consultant or associated with a C3PAO to be on an assessment team.

What is a Certified CMMC Professional (CCP)?

100

48 CF 52.204-21 - Basic Safeguarding of Covered Contractor Information Systems is what kind of driver (authority/compliance) and for what type of information or program?

What is a regulatory authority for FCI?

100

DoD Instruction 5200.48 is what kind of driver (authority/compliance) and for what type of information or program?

What is a policy for CMMC program?

200

Non-profit organization that manages the accreditations of other C3PAOs and CAICO.

What is the CyberAB (CMMC-AB)?

200

Organization that is required to control data flows and define system boundaries, as they will have to obtain a CMMC certificate.

What is the Organization Seeking Certification (OSC)?

200
Individual that delivers a non-certified advisory service on CMMC, but do not participate in CMMC Assessments.

Who is a Registered Practitioner (RP)?

200

DFARS Clause 252.204.7021 is what kind of driver (authority/compliance) and for what type of information or program?

What is a regulatory authority for CMMC?

200

This is also known as "Cloud FISMA."

What is Federal Risk and Management Program (FedRAMP)?

300

Owns CMMC Model, as well as the CMMC Assessment Guides.  They also ensure that CMMC requirements are written in DoD Contracts.

Who is the Office of the Undersecretary of Defense for Acquisition and Sustainment (OUSD A&S).

300

Organizations purpose is to train CCPs and CCAs, and delivers CATM. 

Who is the Licensed Training Provider (LTP)/Approved Training Provider (ATP)?

300

Individuals certified to assess all practiecs on a CMMC Level 2 Assessment and must be associated with a C3PAO to be on an assessment team.

What is a Certified CMMC Assessor (CCA; formerly called a Provisional Assessor (PA))?

300

FISMA - Federal Information Security Modernization Act is what kind of driver (authority/compliance) and for what type of information or program?

What is a legal authority for CUI, FCI, and CMMC information?

300

Executive Order 13556, is this kind of driver (authority/compliance), for this type of information or program.

What is a legal authority for FCI, CUI, and CMMC?

400

Provides overall oversight and strategic management of the Cybersecurity Maturity Model Certification (CMMC) Program (daily management and operations of CMMC).  

Who is the DoD CIO?

400

Organizations purpose is to create accredited content called CMMC Approved Training Material (CATM).

Who are the Licensed Publishing Partners (LPPs)/Approved Publishing Partners (APPs)?

400

Individual qualified to deliver CMMC Approved Training Material (CATM) through a Licensed Training Provider (LTP) and will soon be called CCIs?

What is a Provisiona Instructor (PI)?

400

32 CFR Part 2002, is what kind of driver (authority/compliance) and for what type of information or program?

What is a regulatory authority for Controlled Unclassified Information (CUI)?

400

This is the parent agency for the National Institute of Standards and Technology (NIST).

What is the Department of Commerce?

500
This Authorithy is required to acheive and maintain ISO/IEC 17011.

Who is the CyberAB?

500

Organization is authorized to manage the Assessment process and hires assessors (CCPs and CCAs) for an assessment team.  They are also required to comply with ISO/IEC 17020.

Who is the CMMC Third-Party Organization?

500

A Cyber AB trained person that is responsible for ensuring assessment documentation completeness and accuracy.

Who is the CMMC Quality Assurance Professional (CQAP)?

500

NARA ISOO - National Archive & Records Administration (NARA) Informatin Security Oversight Officer (ISOO) CUI Notices is what kind of driver (authority/compliance) and for what type of information or program?

What is a policy for CUI?

500

The three components/staff of NARA ISOO.

What are the Classification Management Staff, Operations Staff, and the CUI Staff?

M
e
n
u