Frequently Asked Questions

Everything you need to know about CMMC, provider types, and this directory.

About CMMC

What is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) is a framework developed by the Department of Defense (DoD) to ensure that defense contractors adequately protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC 2.0 establishes three levels of cybersecurity maturity.
Who needs CMMC certification?
Any organization in the Defense Industrial Base (DIB) that handles FCI or CUI and bids on DoD contracts will need CMMC certification. The specific level required depends on the type of information handled and the contract requirements.
What are the CMMC levels?
CMMC 2.0 has three levels: Level 1 (Foundational) requires 17 practices from FAR 52.204-21 and allows self-assessment. Level 2 (Advanced) aligns with NIST SP 800-171 (110 practices) and requires third-party assessment by a C3PAO for critical CUI contracts. Level 3 (Expert) adds controls from NIST SP 800-172 and requires government-led assessment.
When does CMMC go into effect?
The CMMC final rule was published and is being phased into DoD contracts. Implementation is rolling, meaning new contracts will increasingly require CMMC certification. Organizations should begin preparing now to avoid delays in contract eligibility.

Provider Types

What is a C3PAO?
A CMMC Third-Party Assessment Organization (C3PAO) is authorized by The Cyber AB to conduct official CMMC certification assessments. They evaluate whether an organization meets the required CMMC level and recommend certification.
What is an RPO?
A Registered Provider Organization (RPO) is authorized by The Cyber AB to provide CMMC consulting, preparation, and readiness services. They help organizations prepare for CMMC assessments but cannot conduct certifications.
What is Dual Authorized?
A Dual Authorized organization holds both C3PAO and RPO designations, meaning they can provide consulting services and conduct assessments. However, they cannot assess the same client they consulted for, so these functions must be kept separate.
Can an RPO certify my organization?
No. Only authorized C3PAOs can conduct the official CMMC assessment that leads to certification. RPOs prepare you for that assessment. Think of RPOs as coaches and C3PAOs as referees.

About This Directory

How are providers verified?
Every provider is verified against the official Cyber AB Marketplace, the authoritative catalog maintained by The Cyber AB. We confirm organization-level C3PAO and RPO authorizations directly from this source.
Is this directory affiliated with the DoD or Cyber AB?
No. This is an independent directory. We are not affiliated with, endorsed by, or sponsored by the U.S. Department of Defense or The Cyber AB.
How often is the directory updated?
We regularly re-verify listings against the Cyber AB Marketplace. If you notice any inaccuracies, please submit a correction request through our Claim / Update page.
What are Featured Listings?
Featured Listings are a paid upgrade ($99/month) that gives providers priority placement and a Featured badge. Paid placement does not affect verification, as all providers are verified regardless of Featured status.
How can I get my organization listed?
Our directory includes providers verified on the Cyber AB Marketplace. If your organization is an authorized C3PAO or RPO and is not yet listed, use our Claim / Update page to submit a request for review.