3.3 Confidentiality, Incident Escalation & Misconduct Reporting

Key Takeaways

  • Protect OSC, assessment, proprietary, personal, and controlled information according to its actual sensitivity, authorized purpose, contract, and applicable handling rules.
  • NDAs reinforce confidentiality but do not authorize access, override CUI rules, or prevent a required report through an authorized channel.
  • CAP assigns the OSC hashing and six-year retention of assessment artifacts; 32 CFR §170.9 requires the C3PAO to retain its assessment-related records for six years unless the CMMC PMO authorizes another disposition.
  • When active compromise appears, preserve safety and evidence, notify the Lead CCA and authorized OSC channel, and let the OSC apply its incident plan and any applicable DFARS reporting duty.
  • Report conflicts or CoPC misconduct factually through the current C3PAO and Cyber AB process; do not invent a CAICO hearing panel or fixed sanction ladder.
Last updated: August 2026

3.3 Confidentiality, Incident Escalation & Misconduct Reporting

CMMC assessment work can expose CUI, proprietary designs, network topology, vulnerability information, credentials, personnel records, contracts, and assessment conclusions. A professional protects each item according to its actual status and the authorized purpose. “Confidential” is not one universal data category, and an NDA is not a substitute for CUI handling, privacy, export, contract, or CAP requirements.

Access and disclosure

Use least privilege and need to know. Access only evidence relevant to the assigned assessment work, and share it only with authorized recipients through approved channels. Do not reuse an OSC artifact as a template for another customer, paste controlled details into consumer collaboration tools, or discuss findings in public spaces.

InformationPrimary handling question
CUIIs the system, user, transmission, marking, and recipient authorized under the applicable rule and contract?
Proprietary OSC informationDoes the assessment purpose, contract, NDA, and recipient authorize use?
Vulnerability or incident dataCould disclosure create harm, and is the response channel authorized and secure?
Personal informationIs collection limited and protected under applicable privacy requirements?
Assessment result or workpaperDoes CAP, the C3PAO quality system, or an oversight process authorize disclosure?

An NDA can define permitted use and remedies, but it cannot require an assessor to falsify a result, conceal a prohibited conflict, obstruct lawful oversight, or ignore a mandatory reporting duty. When obligations appear to conflict, preserve the information and use the designated legal, ethics, or compliance channel.

Secure evidence handling

The assessment plan and C3PAO procedures should define approved collection, transfer, storage, access, backup, retention, and destruction. Cryptography must use applicable validated modules when CMMC or the information system requires FIPS-validated cryptography; do not claim that every assessment note is automatically CUI or prescribe one product or cipher for every record.

CAP assigns the OSC responsibility to hash assessment artifacts with a NIST-approved algorithm and retain the underlying artifacts for six years. Under 32 CFR §170.9(b)(9), the C3PAO separately maintains all assessment-related records for six years unless the CMMC PMO authorizes another disposition. These include C3PAO-generated materials, working papers, personnel qualification records, OSC agreements, and consulting-relationship records. Raw OSC evidence is not indiscriminately uploaded into CMMC eMASS; required references and hash information support traceability. A final report does not authorize immediate destruction of every workpaper when a retention duty applies.

Protect physical notes, screenshots, recordings, removable media, and exports as carefully as primary systems. Collect the minimum necessary. Avoid unnecessary CUI copies. At the end of the applicable retention period, use the authorized sanitization or destruction method for the media and information rather than a memorized universal shred size.

Active compromise discovered during assessment

An assessor may encounter signs of malware, data exfiltration, or an active intrusion. The assessor should not modify firewalls, isolate hosts, run destructive tools, contact the press, or independently submit an OSC's DIBNet report. Promptly preserve what was lawfully observed, notify the Lead CCA and C3PAO through the incident/escalation procedure, and ensure the designated OSC contact receives the information through the authorized channel.

The OSC activates its incident response plan and determines legal and contractual reporting with counsel and responsible officials. If DFARS 252.204-7012 applies and the event is a covered cyber incident, the contractor must report to DoD within 72 hours of discovery and follow the clause's preservation and support duties. Do not state that every anomaly involving any CUI triggers that clause; the contract, information, system, and event definition matter.

Assessment implications are handled separately. The qualified team evaluates affected scope, evidence reliability, and relevant requirements through CAP. An incident is not automatically proof that every security requirement is NOT MET, and containment work is not performed by the assessment team as consulting.

Reporting professional misconduct

Potential misconduct includes concealed conflicts, evidence falsification, credential misrepresentation, improper disclosure, bribery, retaliation, plagiarism, or work outside an authorized role. Record firsthand facts, protect relevant material lawfully, distinguish observation from inference, and report through the C3PAO and current Cyber AB Code process. Do not bargain privately with the subject or spread allegations beyond those who need to handle them.

The CoPC also specifies a 30-day reporting period for covered personal events such as certain convictions or professional discipline. Use the current Code and reporting instructions to identify the recipient; ISACA certification administration, C3PAO employment action, Cyber AB ecosystem discipline, contract remedies, and government or law-enforcement action are different processes.

Investigation and consequences

The receiving body determines jurisdiction, notice, evidence review, impartial decision-making, and any appeal under its actual procedures. Possible consequences can include corrective action, credential or ecosystem restrictions, suspension or revocation, employment action, loss of organizational status, contract remedies, or referral when law may have been violated. Do not memorize a fabricated five-stage CAICO tribunal, fixed probation duration, automatic fine, or guaranteed notification list.

Due process does not mean silence. Preserve confidentiality, avoid retaliation, cooperate with authorized review, and make no unsupported public claims. The professional objective is accurate reporting through the correct channel—not punishment by rumor.

Scenario sequence

For either an incident or ethics scenario: identify the information and immediate safety risk; preserve authorized evidence; notify the Lead CCA or designated C3PAO channel; notify the authorized OSC contact when it is an OSC incident; apply the contract and Code; document actions; and keep assessment determinations within the qualified CCA process. This sequence protects people, evidence, independence, and reporting authority.

Test Your Knowledge

During artifact review, a team member sees credible signs of an active intrusion. What is the correct immediate response?

A
B
C
D
Test Your Knowledge

A team member concealed consulting payments from the OSC during the conflict check. What should a CCP with firsthand evidence do?

A
B
C
D
Test Your Knowledge

Which statement about assessment records is correct?

A
B
C
D