2.2 Industry Roles: C3PAOs, OSCs, Consultants, ATPs & APPs
Key Takeaways
- An OSC owns its scope, implementation, evidence, representations, remediation, and affirmations.
- A C3PAO is an authorized or accredited ISO/IEC 17020 assessment organization, not a readiness consultant for the client it assesses.
- Consulting and assessment must remain independent; the Code of Professional Conduct applies a three-year prohibition to specified prior consulting relationships.
- ATPs deliver approved training and APPs develop approved courseware; neither role grants assessment authority.
- The service performed, data handled, contract clause, and marketplace status determine an external party’s actual CMMC role.
2.2 Industry Roles: C3PAOs, OSCs, Consultants, ATPs & APPs
Industry labels describe different legal and operational relationships. A company can employ CCPs without being a C3PAO, can provide readiness consulting without being allowed to assess that client, and can hold multiple organizational recognitions only if it preserves the required independence.
Organization Seeking Assessment
The Organization Seeking Assessment (OSA) is the entity whose environment and implementation are being evaluated. Some materials use Organization Seeking Certification (OSC); CAP and rule context determine the preferred term, but both point to the contractor-side organization rather than the assessor.
The organization owns the facts: contracts, CUI and FCI flows, system boundary, asset inventory, System Security Plan, policies, configurations, evidence, personnel availability, and corrective actions. It must disclose providers and locations that affect the scope. It also designates an Affirming Official, the senior representative responsible for attesting in SPRS that the organization implemented and will maintain the requirements for the stated scope.
An assessment does not transfer implementation responsibility to the C3PAO. Assessors evaluate what exists; they do not write missing policies, configure systems, or choose a passing architecture during the engagement.
C3PAO
A CMMC Third-Party Assessment Organization (C3PAO) performs commercial Level 2 certification assessments when authorized or accredited for that work. It maintains an ISO/IEC 17020-conforming management and quality system, uses qualified personnel, protects assessment records, manages conflicts, follows CAP, and submits results through the authorized process. Its assessment team and its independent quality activities have different responsibilities.
A C3PAO must have the organizational status shown in the authoritative marketplace for the work. Hiring a CCA does not by itself make a consulting company a C3PAO. Likewise, an assessment by an unlisted firm does not become a certification assessment because the report resembles one.
Consulting and provider organizations
Readiness consultants help an organization interpret requirements, build an SSP, identify gaps, design an enclave, or plan remediation. A Registered Provider Organization (RPO) is a recognized consulting-provider role in the Cyber AB ecosystem, and individual practitioner labels may support that service. Readiness findings are not CMMC certification findings.
Independence is decisive. The current Cyber AB Code of Professional Conduct prohibits a C3PAO and assessment-team members from assessing an organization when disqualifying consulting or implementation work occurred within the preceding three years. Corporate affiliates and the substance of the relationship matter; assigning different staff or obtaining a client waiver does not automatically cure the conflict. Disclose potential conflicts before contracting and resolve them through the required process.
A practitioner can consult and assess in a career, but not for the same client in a prohibited relationship. Keep contracts, marketing, workpapers, systems, personnel, and compensation arrangements clear enough to demonstrate the distinction.
Training and publishing roles
An Approved Training Provider (ATP) delivers current approved CCP or CCA education. An Approved Publishing Partner (APP) develops approved learning materials. ISACA manages the current individual-certification program. Historical questions may use Licensed Training Provider or Licensed Publishing Partner; recognize them as legacy terms rather than current titles.
An instructor teaches. A publisher develops courseware. Neither can conduct a certification assessment solely because of that role. A CCI label, when available under the current program, concerns instruction rather than C3PAO authority. Candidates should verify current role availability instead of assuming a transition-era title is active.
External service parties
Cloud service providers, managed service providers, security operations providers, and other external service providers are scoped according to what they do and what they access. A CSP that processes CUI invokes cloud and FedRAMP-equivalency obligations. An ESP that provides security protection may bring its people, technology, and facilities into the assessment evidence. A subcontractor receiving CUI has contract and safeguarding obligations distinct from a consultant that merely advises without CUI access.
Do not decide status from marketing terms such as “CMMC ready.” Ask:
- Does the party process, store, or transmit FCI or CUI?
- Does it provide a security function to an in-scope system?
- Which contract clauses and responsibility assignments apply?
- Is it listed in the authoritative marketplace for a claimed role?
- Will its people, technology, and facilities be available for assessment?
Independence scenario
Suppose one corporate unit designed an OSC's CUI enclave and authored its SSP eighteen months ago, while a sister unit is an authorized C3PAO. The correct analysis is not simply whether different employees will be used. Review the Code, organizational relationships, financial interests, contract, and three-year prohibition. The assessment organization should not accept work that compromises or appears to compromise impartiality.
By contrast, an ATP that trained individual employees in a generally available CCP class did not necessarily consult on the OSC's implementation. The precise service and relationship matter. Good exam answers separate general education from client-specific design and remediation.
Evidence of role legitimacy
Verify marketplace status, credential status, assessment authorization, Tier 3 eligibility where applicable, contracts, nondisclosure terms, conflict checks, and role assignments. No single badge authorizes all ecosystem work. The controlling sources are 32 CFR part 170, current ISACA certification materials, Cyber AB marketplace and accreditation materials, CAP, and the Code of Professional Conduct.
A consulting affiliate designed an OSC enclave 18 months ago. May its sister C3PAO assess the OSC simply by using different personnel?
Which current role develops approved CCP courseware?
What makes a firm able to conduct a CMMC certification assessment?