2.1 Governance & Oversight: DoD, DIBCAC, Cyber AB & ISACA

Key Takeaways

  • DoD owns the CMMC program, while 32 CFR part 170 allocates program, assessment, accreditation, and credentialing responsibilities.
  • DCMA DIBCAC conducts Level 3 assessments and assesses the cybersecurity of candidate or authorized C3PAOs as required by the rule.
  • The Cyber AB is the CMMC Accreditation Body for C3PAOs and other ecosystem roles; it is not the current personnel-certification exam provider.
  • ISACA is the current CAICO and administers the CCP and CCA training, examinations, applications, and certification maintenance.
  • Government, accreditation, personnel certification, organizational assessment, and contract administration are separate authority lanes.
Last updated: August 2026

2.1 Governance & Oversight: DoD, DIBCAC, Cyber AB & ISACA

CMMC uses several organizations because program rulemaking, acquisition, assessment, accreditation, and individual certification are different functions. Exam questions often describe a valid activity but assign it to the wrong actor. Build a role map from 32 CFR part 170 and current official organization pages.

Department of Defense program ownership

The Department of Defense owns CMMC. The CMMC Program Management Office and responsible DoD leadership establish policy, maintain the model and scoping guidance, and coordinate implementation. The program rule is codified in 32 CFR part 170. Contractual application occurs through acquisition rules and solicitation or contract clauses. A contracting officer determines the required status for a procurement; neither an assessor nor a training provider can waive that requirement.

The rule distinguishes three assessment levels. Level 1 is a contractor self-assessment for the 15 FAR safeguarding requirements. Level 2 may require a self-assessment or a C3PAO certification assessment, depending on the solicitation or contract. Level 3 is assessed by the government through DCMA DIBCAC. An annual affirmation by an organization's Affirming Official is separate from the underlying assessment cadence.

DCMA DIBCAC

The Defense Industrial Base Cybersecurity Assessment Center is a DCMA organization with government assessment responsibilities. It performs Level 3 certification assessments and the government activities assigned by 32 CFR part 170. It also evaluates candidate or authorized C3PAOs' own information systems at Level 2 as part of the authorization and accreditation framework. DIBCAC is not a commercial consultant and does not administer the CCP exam.

A Level 3 assessment builds on a Final Level 2 (C3PAO) status covering the proposed Level 3 scope and evaluates the selected NIST SP 800-172 requirements. If DIBCAC identifies an unmet underlying Level 2 requirement, the rule permits consequences such as pausing or terminating the Level 3 process. This illustrates why authority and assessment level must be read together.

The Cyber AB

The Cyber AB is recognized in the program as the CMMC Accreditation Body. Its ecosystem responsibilities include authorizing and accrediting CMMC Third-Party Assessment Organizations, maintaining relevant marketplace information, enforcing applicable accreditation and conduct mechanisms, and coordinating the assessment ecosystem under its agreement with DoD. C3PAO conformity involves ISO/IEC 17020 and program-specific requirements.

The Cyber AB does not own the CMMC rule, insert clauses into contracts, or perform every Level 2 assessment. It also is no longer the entity that candidates should treat as the current CCP exam administrator. Historical materials may describe an internal CAICO structure; current materials identify ISACA as the authorized personnel-certification organization.

ISACA as CAICO

ISACA is the current Authorized CMMC Individual Certification Organization (CAICO). It manages approved training relationships, current candidate guides and content outlines, exam registration and delivery through PSI, certification applications, Tier 3 processing, ethics commitments, and ongoing CPE requirements for CCP and CCA credentials. Personnel certification follows its own impartiality and certification-management controls and is distinct from C3PAO organizational accreditation.

Current commercial training terms include Approved Training Provider (ATP) and Approved Publishing Partner (APP). An ATP delivers approved instruction. An APP develops approved curriculum or publications. Training completion does not accredit the provider as a C3PAO, and an instructor does not obtain assessment authority by teaching a course.

Contract and data authorities

The acquisition chain adds more actors. A contracting officer administers the solicitation and contract. A prime contractor determines information flow and applies clauses to subcontracts as required. The National Archives and Records Administration administers the government-wide CUI program, and the CUI Registry identifies categories and authorities. The Information Security Oversight Office exercises CUI oversight within NARA. DoD provides department-specific CUI implementation guidance. These data-governance actors do not score CCP exams or issue CMMC certificates.

Role-separation method

For any scenario, ask five questions:

  1. Who owns the rule or contract decision?
  2. Is the question about individual certification or organizational accreditation?
  3. Is the activity a self-assessment, commercial certification assessment, or government assessment?
  4. Who performs quality assurance and who makes the final determination?
  5. Which system records the result or affirmation?

Example: A candidate registers for CCP through ISACA and tests through PSI. A C3PAO assembles an authorized Level 2 team and applies CAP. The C3PAO quality function reviews and uploads the result to CMMC eMASS. An Authorized Certifying Official within the C3PAO issues the certificate after quality steps. The OSC's Affirming Official submits the required affirmation in SPRS. Each action is legitimate only in its assigned lane.

Current implementation note

Contract rollout is not identical to the permanent program architecture. DoD began Phase I on November 10, 2025. On July 13, 2026, the Department suspended Phase II requirements, leaving rollout paused in Phase I while existing NIST SP 800-171 and DFARS duties continue. That dated implementation status does not dissolve 32 CFR part 170, close the credentialing program, or transfer authorities among organizations.

Test Your Knowledge

Which entity currently administers CCP personnel certification?

A
B
C
D
Test Your Knowledge

Who conducts CMMC Level 3 certification assessments?

A
B
C
D
Test Your Knowledge

Which function belongs to The Cyber AB?

A
B
C
D