.jpg?ext=.jpg)
The Cybersecurity Maturity Model Certification (CMMC) program went into effect in December 2024, although it will not become mandated until the 48CFR is published (likely somewhere between July and October of 2025). Hopefully you have begun your CMMC compliance journey at this point. You might be wondering, however, about the role of the Certified Third-Party Assessment Organization (C3PAO) facet of the process. What exactly does a C3PAO do?
A C3PAO is an independent entity authorized by the Cyber AB (formerly the CMMC Accreditation Body) to conduct official CMMC assessments for organizations seeking certification, specifically for Level 2 compliance under CMMC 2.0.
Unless your contracting officer informs you that you need to comply with level 1 only, you cannot rely solely on self-assessments. If you handle, process, or transmit Controlled Unclassified Information, you will need a C3PAO to conduct your CMMC assessment.
C3PAOs cannot offer consultative or remediation services to a company for which they will conduct an assessment. A company can choose a consultant to help prepare for the assessment, but a different company must serve as the C3PAO.
Smithers became an authorized C3PAO in early 2025. Offering more than 30 years of ISO and other management system auditing services, Smithers brings established credentials, experience, and expertise to every CMMC assessment. If you feel you are ready to talk about or schedule your CMMC assessment, contact us today.